Critical Marimo pre-auth RCE flaw now under active exploitation

2026-04-13T07:23:30Z0784acef95c1b07df604c8c3c0cedc2b483998d2ae57ea826b292539fc77d4be
active-exploitationbackdoorchipsoftcpu-zcpuidcredential-theftgoogle-chrome-dbschwmonitorindustrial-cyberattacksinfo-stealeriranian-linkedlucidrookmarimophishingphishing-as-a-serviceplcpre-authransomwareremote-code-executionrockwell-automationsession-cookie-protectionsmart-slidersoftware-update-compromisesupply-chain-attackvenom

What happened

This collection of security news highlights a critical pre-authentication remote code execution (RCE) flaw in Marimo now under active exploitation for credential theft, alongside multiple high-impact incidents: a supply-chain compromise at CPUID delivering malware via CPU‑Z/HWMonitor, a hijacked Smart Slider update pushing backdoors, and widespread exposure of Rockwell Automation PLCs targeted by Iranian-linked actors. Other notable items include new LucidRook targeted malware, VENOM phishing-as-a-service stealing executive Microsoft logins, a ransomware incident at healthcare vendor ChipSoft,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0784acef95c1b07df604c8c3c0cedc2b483998d2ae57ea826b292539fc77d4be
Enrichment time
2026-04-13T07:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.