Frequency
3
occurrences
First Seen
April 16, 2026
Last Seen
May 29, 2026
Related Threat Clusters
-
Attackers Exploit CVE-2026-39987 to Deploy NKAbuse Malware via Hugging Face
A critical vulnerability in the marimo Python notebook platform, tracked as CVE-2026-39987, has been actively exploited to deploy a new variant of NKAbuse malware. The flaw allows for remote code execution without…
5 articles · Updated April 16, 2026 -
Hackers Exploit Marimo RCE Using LLM Agent for Rapid Database Access
On May 10, 2026, threat actors exploited CVE-2026-39987, a remote code execution vulnerability in the marimo notebook environment, to gain unauthorized access to internal databases. The attackers utilized a large…
5 articles · Updated May 28, 2026
Recent Intelligence Reports
- Attackers Use LLM Agent After Marimo Exploit | Let's Data Science — Letsdatascience · May 29, 2026
- Weaponized CVE-2026 — Gbhackers · April 17, 2026
- Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face — Bleepingcomputer · April 16, 2026