Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face
2026-04-16T19:23:34Z•b8aa8eecafa5b704fa6b0c0aebb54f5735c46e8aa07f897d7aa8610bb625efc2
AI voice agentsATHRAgingFlyCISACisco Webex ServicesEssentialPluginHugging Face SpacesMCPMarimoMcGraw HillNKAbuseNginx UIShinyHuntersWindows Task HostWordPress compromiseantivirus disableauthentication bypasscredential theftdata breachimproper certificate validationprivilege escalationserver takeoversigned softwaresupply chain compromisevishing
What happened
A cluster of high-impact incidents and active exploits was reported: attackers are exploiting a critical Marimo reactive Python notebook flaw to deploy a new NKAbuse malware variant from Hugging Face Spaces. A separate critical Nginx UI authentication-bypass (MCP) vulnerability is being actively exploited for full server takeover. Cisco released patches for multiple critical Webex Services flaws that require customer action, and CISA warned that a Windows Task Host privilege-escalation bug is being exploited. Other notable events include a 13.5 million-account McGraw Hill data breach (ShinyHun
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- b8aa8eecafa5b704fa6b0c0aebb54f5735c46e8aa07f897d7aa8610bb625efc2
- Enrichment time
- 2026-04-16T19:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.