Related Threat Clusters
-
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request…
40 articles · Updated September 2, 2026 -
Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
A critical pre-authentication remote code execution (RCE) vulnerability in Marimo, an open-source Python notebook platform, was disclosed on April 8, 2026, and exploited within 9 hours and 41 minutes. The vulnerability,…
16 articles · Updated April 12, 2026 -
Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
On April 8, 2026, a critical pre-authenticated remote code execution vulnerability (CVE-2026-39987) was disclosed in Marimo, an open-source Python notebook platform. The flaw allows unauthenticated attackers to gain a…
2 articles · Updated June 9, 2026 -
Critical Marimo RCE Flaw Exposes Systems to Remote Attacks
A critical vulnerability in the Marimo Python notebook framework, tracked as CVE-2026-39987, allows attackers to execute arbitrary commands remotely without authentication. The flaw, stemming from a missing…
2 articles · Updated May 19, 2026 -
Hackers Exploit Marimo RCE Using LLM Agent for Rapid Database Access
On May 10, 2026, threat actors exploited CVE-2026-39987, a remote code execution vulnerability in the marimo notebook environment, to gain unauthorized access to internal databases. The attackers utilized a large…
5 articles · Updated May 28, 2026 -
AI-Powered Self-Replicating Worm Raises Cybersecurity Alarm
Researchers at the University of Toronto have developed a self-replicating AI worm that autonomously exploits network vulnerabilities. This malware utilizes a small, free large language model (LLM) to devise unique…
29 articles · Updated June 3, 2026 -
DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor
A Chinese-speaking threat actor, identified as knaithe/KnYuan, executed an autonomous cyberattack campaign using DeepSeek AI and the Hermes Agent framework. The campaign targeted over 460 servers, attempting to exploit…
12 articles · Updated August 2, 2026
Recent Intelligence Reports
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners — Thehackernews · September 3, 2026
- Unit 42 Ties DeepSeek Agent to 460+ Autonomous Hack Attempts — Aiweekly.Co · August 1, 2026
- Marimo Oss Python Notebook Rce From Disclosure To Exploitation In Under 10 Hours — webflow.sysdig.com · June 9, 2026
- From Advisory to Attack in Under 10 Hours: Marimo's Critical RCE Flaw — Hivepro · June 9, 2026
- Researchers build self-replicating worm with BYO small AI model — Itnews.Au · June 4, 2026
- Researchers build self — Itnews.Au · June 4, 2026
- Attackers Use LLM Agent After Marimo Exploit | Let's Data Science — Letsdatascience · May 29, 2026
- Critical Marimo RCE Flaw Could Let Attackers Execute Malicious Code Remotely — Gbhackers · May 18, 2026