vulnerability Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode A high-severity vulnerability (CVE-2026-75149) in Marimo notebook software allows an attacker to execute arbitrary commands by crafting a malicious notebook file. The vulnerability is addressed in version 0.23.15 and requires user interaction to exploit. The Hacker News · 5d ago High CVE-2026-75149CVE-2026-67618CVE-2026-39987code injectionnotebookmcp
vulnerability Vulnérabilité dans Python (21 août 2026) A security vulnerability has been identified in Python, allowing attackers to bypass security policies. This stems from a flaw in the Python interpreter, requiring users to apply security updates to mitigate the risk. CERT-FR · Aug 21, 2026 Medium CVE-2026-19672pythonvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Python (19 août 2026) Multiple vulnerabilities have been discovered in Python, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities are linked to specific CVEs and require updat… CERT-FR · Aug 19, 2026 Medium CVE-2026-15806CVE-2026-17084pythonvulnerabilitysecurity
threat-intel Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud TwinLoot, a sophisticated Python-based malware framework, operates entirely from within Microsoft's Azure and 365 cloud services, using various Microsoft services – SharePoint Online, Microsoft Graph API, and Teams TURN… Dark Reading · Aug 18, 2026 High living-off-the-landcloud-basedpersistence
supply-chain Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack Over 2,500 organizations and 434,000 CI/CD pipelines were impacted by a supply chain attack involving the LiteLLM AI library. The attack stemmed from a compromised version of Aqua Security’s Trivy vulnerability scanner,… SecurityWeek · Aug 12, 2026 High supply chainaicredentials
vulnerability Vulnérabilité dans CPython (11 août 2026) A denial-of-service vulnerability has been identified in CPython, allowing an attacker to disrupt remote systems. The vulnerability stems from a lack of recent security updates and requires immediate patching to prevent… CERT-FR · Aug 11, 2026 Medium CVE-2026-18503pythondenial-of-servicevulnerability
threat-intel Python Now Has a Post-Quantum Encryption Library Python’s popular cryptography library, pyca/cryptography, has gained post-quantum encryption support thanks to funding from the Sovereign Tech Agency. This means developers can now integrate algorithms designed to withst… Schneier on Security · Aug 10, 2026 Medium post-quantumcryptographypython
vulnerability Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code Three high-severity vulnerabilities have been discovered in Hugging Face's Diffusers library, allowing attackers to execute arbitrary code within AI model repositories. These flaws bypass the existing security mechanism,… The Hacker News · Aug 3, 2026 High CVE-2026-44827CVE-2026-45804CVE-2026-44513aisecuritypython
threat-intel zipdump.py: Metadata Encoding, (Fri, Jul 31st) This article details a ZIP file analysis tool, zipdump.py, and a new feature added to correctly decode metadata within ZIP files, particularly when dealing with UTF-8 encoded filenames. The tool addresses potential issue… SANS Internet Storm Center · Jul 31, 2026 Info zipmetadataencoding
vulnerability Vulnérabilité dans CPython (30 juillet 2026) A denial-of-service vulnerability has been identified in CPython, allowing an attacker to disrupt remote systems. Applying the latest security patch from the Python project is crucial to mitigate this risk. CERT-FR · Jul 30, 2026 Medium CVE-2026-6879pythondenial-of-servicevulnerability
threat-intel The serpent’s tongue: Luring the Python out of its den This report from Cisco Talos details a growing threat landscape surrounding Python packages, focusing on supply chain attacks leveraging malicious packages installed through package managers like PyPI. The report highlig… Cisco Talos · Jul 14, 2026 High supply chainpythonmalware
vulnerability Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations A vulnerability in Google Cloud’s Dialogflow CX service allowed attackers to silently control agents, manipulate conversations, and exfiltrate sensitive information. The flaw stemmed from a permissive configuration withi… SecurityWeek · Jul 8, 2026 High aicloudpython
threat-intel Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft Google has patched a critical vulnerability in its Dialogflow CX AI chatbot platform, dubbed 'Rogue Agent,' which could have allowed attackers to steal data from AI agents. The flaw stemmed from a permission boundary iss… Dark Reading · Jul 7, 2026 High aichatbotcodeblocks
vulnerability Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots A critical vulnerability, dubbed ‘Rogue Agent,’ within Google's Dialogflow CX platform allowed a malicious insider or compromised developer account to compromise multiple chatbot agents within the same Google Cloud proje… The Hacker News · Jul 7, 2026 High dialogflowcodeblockscloud run
threat-intel Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign The Securelist report details a new cyber espionage campaign conducted by the Armored Likho (Eagle Werewolf) APT group, targeting government agencies and the electric power sector globally. The group utilizes a sophistic… Securelist · Jul 3, 2026 High RUBRKZaptphishinginfostealer
threat-intel Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised… The Hacker News · Jun 29, 2026 High KPvscodenpmfont-file
malware Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to d… The Hacker News · Jun 23, 2026 High USnpmsupply-chainrat
threat-intel Salesforce Data Thefts Continue via Klue App Compromise A series of data thefts targeting Salesforce instances have been linked to a new threat actor group, Icarus, following a compromise of Klue's Battlecards app. The attacks leveraged compromised OAuth tokens and Python scr… Dark Reading · Jun 18, 2026 High USoauthsaasdata exfiltration
data-breach Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks A recent breach at Klue, a market intelligence platform, allowed the "Icarus" threat actor to steal Salesforce CRM data from multiple organizations, triggering an ongoing extortion campaign. The attackers leveraged stole… BleepingComputer · Jun 18, 2026 High USoauthsalesforcedata theft
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure