vulnerability Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode A high-severity vulnerability (CVE-2026-75149) in Marimo notebook software allows an attacker to execute arbitrary commands by crafting a malicious notebook file. The vulnerability is addressed in version 0.23.15 and requires user interaction to exploit. The Hacker News · 5d ago High CVE-2026-75149CVE-2026-67618CVE-2026-39987code injectionnotebookmcp
threat-intel CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited The U.S. CISA has added three vulnerabilities to its KEV catalog, including a critical code injection flaw in Langflow, a Tomcat encryption bypass, and an authentication bypass in N-able N-central. These flaws are curren… The Hacker News · Aug 5, 2026 Critical CVE-2026-9198CVE-2026-34486CVE-2026-18556CNvulnerabilitythreat-actorai
threat-intel Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks A Chinese-speaking threat actor, tracked as ‘KnYuan’ and ‘Knaithe’, utilized the Hermes Agent framework and DeepSeek to autonomously launch attacks against over 460 targets. The agent, leveraging Telegram, identified and… The Hacker News · Jul 31, 2026 High CVE-2026-3055CVE-2026-39987CVE-2026-33017CHautonomous attacksvulnerability exploitationtelegram
threat-intel ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories This week’s ‘ThreatsDay’ bulletin highlights a diverse range of security threats, including AI-powered hacking campaigns, ransomware attacks targeting Russia, and vulnerabilities in various software systems. Notably, a C… The Hacker News · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613RUCCHransomwaresupply chainphishing
threat-intel Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks A Chinese-speaking threat actor, operating under the aliases knaithe and KnYuan, is leveraging AI to conduct autonomous cyberattacks. Using the Hermes Agent framework and DeepSeek, they autonomously identified and exploi… Palo Alto Unit 42 · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613CNaiautonomousvulnerability
threat-intel New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh is actively targeting exposed AI services and cloud infrastructure, specifically seeking AWS keys, Kubernetes tokens, and Docker API access. The botnet, discovered by XLab and previously identi… The Hacker News · Jul 17, 2026 High CVE-2026-39987CVE-2026-41176CVE-2022-22947botnetcloud-securitydocker
malware Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models Researchers at the University of Toronto have developed a novel AI-driven computer worm that operates autonomously by leveraging locally hosted, open-weight large language models. The worm dynamically generates attack st… The Hacker News · Jun 9, 2026 Critical CVE-2026-39987CVE-2026-31431CVE-2026-43284GBaiwormllm
threat-intel Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit An unknown threat actor exploited CVE-2026-39987 in Marimo to gain initial access, subsequently using a large language model (LLM) agent to conduct post-exploitation activities, including stealing credentials and exfiltr… The Hacker News · May 29, 2026 High CVE-2026-39987CNllmpost-exploitationcredential theft