Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face

2026-04-16T19:23:34Zb8aa8eecafa5b704fa6b0c0aebb54f5735c46e8aa07f897d7aa8610bb625efc2
AI voice agentsATHRAgingFlyCISACisco Webex ServicesEssentialPluginHugging Face SpacesMCPMarimoMcGraw HillNKAbuseNginx UIShinyHuntersWindows Task HostWordPress compromiseantivirus disableauthentication bypasscredential theftdata breachimproper certificate validationprivilege escalationserver takeoversigned softwaresupply chain compromisevishing

What happened

A cluster of high-impact incidents and active exploits was reported: attackers are exploiting a critical Marimo reactive Python notebook flaw to deploy a new NKAbuse malware variant from Hugging Face Spaces. A separate critical Nginx UI authentication-bypass (MCP) vulnerability is being actively exploited for full server takeover. Cisco released patches for multiple critical Webex Services flaws that require customer action, and CISA warned that a Windows Task Host privilege-escalation bug is being exploited. Other notable events include a 13.5 million-account McGraw Hill data breach (ShinyHun

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b8aa8eecafa5b704fa6b0c0aebb54f5735c46e8aa07f897d7aa8610bb625efc2
Enrichment time
2026-04-16T19:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face · Baitaphish