Critical Marimo pre-auth RCE flaw now under active exploitation

2026-04-12T19:23:28Zd63022e996258698b05e6d52f195b043f19732ea9a6bc45066e47e17195d24f0
active-exploitationchipsoftcpu-zcpuidcredential-theftcrypto-fraudexecutive-targetinghwmonitoriranian-actorsjoomlalaw-enforcement-crackdown','storm-2755','payroll-pirate','cisa-#lucidrookmalwaremarimophaaSphishingplcpre-auth-rceransomwareremote-code-executionrockwell-automationsmart-slidersupply-chain-attackvenomwordpress

What happened

Multiple high-impact security incidents reported: a critical pre-authentication RCE in Marimo is under active exploitation for credential theft; several supply-chain compromises delivered malware via CPUID (CPU-Z, HWMonitor) and hijacked Smart Slider updates for WordPress/Joomla; new targeted malware (LucidRook) and VENOM phishing-as-a-service campaigns are harvesting high-value Microsoft credentials; nearly 4,000 Rockwell PLCs were exposed in Iranian-linked attacks against U.S. industrial infrastructure; and a major international law-enforcement action identified over 20,000 cryptocurrency-f欺

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d63022e996258698b05e6d52f195b043f19732ea9a6bc45066e47e17195d24f0
Enrichment time
2026-04-12T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical Marimo pre-auth RCE flaw now under active exploitation · Baitaphish