Critical Marimo pre-auth RCE flaw now under active exploitation
2026-04-13T07:23:30Z•0784acef95c1b07df604c8c3c0cedc2b483998d2ae57ea826b292539fc77d4be
active-exploitationbackdoorchipsoftcpu-zcpuidcredential-theftgoogle-chrome-dbschwmonitorindustrial-cyberattacksinfo-stealeriranian-linkedlucidrookmarimophishingphishing-as-a-serviceplcpre-authransomwareremote-code-executionrockwell-automationsession-cookie-protectionsmart-slidersoftware-update-compromisesupply-chain-attackvenom
What happened
This collection of security news highlights a critical pre-authentication remote code execution (RCE) flaw in Marimo now under active exploitation for credential theft, alongside multiple high-impact incidents: a supply-chain compromise at CPUID delivering malware via CPU‑Z/HWMonitor, a hijacked Smart Slider update pushing backdoors, and widespread exposure of Rockwell Automation PLCs targeted by Iranian-linked actors. Other notable items include new LucidRook targeted malware, VENOM phishing-as-a-service stealing executive Microsoft logins, a ransomware incident at healthcare vendor ChipSoft,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0784acef95c1b07df604c8c3c0cedc2b483998d2ae57ea826b292539fc77d4be
- Enrichment time
- 2026-04-13T07:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.