Critical Marimo pre-auth RCE flaw now under active exploitation
2026-04-13T01:23:29Z•24ac0ac4be5d185d524ff0230bd35c3c3cbbc8c9fe36da65ca7df823d2ec3e27
active exploitationbackdoorchipsoftcpu-zcpuidcredential thefthwmonitorindustrial control systemsinfostealer protection','chrome dbsc','gmail e2ee','crypto fraudiran-linkedjoomlalucidrookmarimophaaSphishingplcpre-auth rceransomwareremote code executionrockwell automationsmart-slidersupply chainsupply-chain attackvenomwordpress
What happened
Multiple high-impact security stories from BleepingComputer: a critical pre-authentication remote code execution (RCE) vulnerability in Marimo is now under active exploitation and being used for credential theft. Significant supply-chain compromise at CPUID was used to serve malware via CPU‑Z and HWMonitor downloads. Nearly 4,000 Internet-exposed Rockwell Automation PLCs were identified as part of Iranian-linked targeting of U.S. industrial devices. Other notable incidents include a Smart Slider 3 Pro update hijack distributing backdoored WordPress/Joomla builds, a new LucidRook malware family
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 24ac0ac4be5d185d524ff0230bd35c3c3cbbc8c9fe36da65ca7df823d2ec3e27
- Enrichment time
- 2026-04-13T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.