Marimo RCE flaw CVE-2026-39987 exploited within 10 hours of publication

Rabi LakshmananApril 10, 2026Vulnerability/Threat Intelligence A critical security vulnerability in Marimo, an open-source Python notebook for data science and analytics, was exploited within 10 hours of its publication, according to Sysdig findings. The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability that affects all versions of Marimo prior to […]

Backdoored Smart Slider 3 Pro update distributed via compromised Nextend servers

Ravi LakshmananApril 10, 2026Malware/website security An unknown attacker has hijacked the update system of the Smart Slider 3 Pro plugin for WordPress and Joomla and pushed a malicious version containing a backdoor. According to WordPress security firm Patchstack, this incident affects Smart Slider 3 Pro version 3.5.1.35 for WordPress. Smart Slider 3 is a popular […]

EngageLab SDK flaw exposes 50 million Android users, including 30 million crypto wallets

Ravi LakshmananApril 9, 2026Vulnerabilities / Mobile Security Details have emerged of a patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could potentially put millions of cryptocurrency wallet users at risk. “This flaw allows apps on the same device to bypass the Android security sandbox and gain […]

UAT-10362 Spear phishing campaign uses LucidRook malware to target NGOs in Taiwan

Ravi LakshmananApril 9, 2026Malware / Windows Security A previously undocumented threat cluster called UAT-10362 is believed to have originated from a spear-phishing campaign targeting non-governmental organizations (NGOs) and universities in Taiwan that led to the introduction of a new Lua-based malware called LucidRook. “LucidRook is an advanced stager that embeds a Lua interpreter and a […]

Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

Ravie LakshmananApr 09, 2026Hacking News / Cybersecurity News Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting new life, a few “why was that even possible” moments, attackers leaning on platforms and tools you’d normally trust without thinking twice. Quiet escalations more than […]

The hidden security risks of shadow AI in the enterprise

As AI tools become more accessible, employees are adopting them without formal approval from IT or security teams. These tools may increase productivity, automate tasks, and fill gaps in existing workflows, but they also operate behind the scenes of security teams, bypassing their controls and creating new blind spots for so-called shadow AI. Although similar […]

Starting in December 2025, Adobe Reader will be exploited as a zero-day via a malicious PDF

Ravi LakshmananApril 9, 2026Vulnerability/Threat Intelligence Threat actors have been using maliciously crafted PDF documents to exploit previously unknown zero-day vulnerabilities in Adobe Reader since at least December 2025. The discovery, detailed by EXPMON’s Haifei Li, is described as a highly sophisticated PDF exploit. This artifact (“Invoice540.pdf”) first appeared on the VirusTotal platform on November 28, […]

Tough-torn hacking for hire campaign targets journalists in MENA region

The hacking-for-hire campaign, believed to be orchestrated by attackers with suspected ties to the Indian government, targeted journalists, activists, and government officials across the Middle East and North Africa (MENA), according to an investigation by Access Now, Lookout, and SMEX. Targets included prominent Egyptian journalists and government commentators Mostafa Al-Assal and Ahmed Eltantawi, who were […]

New Chaos variant targets misconfigured cloud deployments and adds SOCKS proxy

Ravi LakshmananApril 8, 2026Cryptomining/Network Security Cybersecurity researchers have warned of a new variant of malware called “Chaos” that can attack misconfigured cloud deployments, marking the expansion of infrastructure targeted by botnets. “Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its traditional focus on routers and edge devices,” Darktrace said in a new report. […]

Masjesu botnet launches as a rental DDoS service targeting IoT devices around the world

Ravi LakshmananApril 8, 2026IoT security/network security Cybersecurity researchers have lifted the curtain on a stealth botnet designed for distributed denial of service (DDoS) attacks. The botnet, called Masjesu, has been promoted as a rental DDoS service through Telegram since it first appeared in 2023. This botnet can target a wide range of IoT devices across […]