Vulnerabilità ed exploit · Exploit zero-day
La foothold di Marimo ora si muove più velocemente del patching Un notebook compromesso non è più la fine della storia. In Marimo, gli attacker stanno ora usando un agente LLM per trasformare una singola RCE iniziale in furto di credenziali cloud, accesso a Secrets Manager, accesso SSH ed esfiltrazione da PostgreSQL in circa un’ora, quindi il patching del notebook da solo non rimuove l’accesso già estratto da esso.
3 fonti · 29 mag
NVD KEV
Sfruttamento noto · CISA KEV
EPSS 38% (98º percentile).
Data di correzione federale CISA 7 mag · data superata
NVD KEV
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 2 apr · data superata
CVE-2026-43284 NVD KEV
CVSS 8.8 HIGH: in the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decrypt on shared skb frags
MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. EPSS 2% (84º percentile). Patch Microsoft: CBL-Mariner Releases.
CVE-2026-43500 NVD KEV
CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved:
rxrpc: Also unshare DATA/RESPONSE packets when… EPSS 2% (82º percentile).
Cronologia Fonti 29 mag The Hacker News
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
LLM-driven attackers exploited CVE-2026-39987 on May 10, 2026, to steal credentials and exfiltrate a PostgreSQL database.
originale 29 mag Rapid7
Metasploit Wrap-Up 05/29/2026
This week's Metasploit release focuses heavily on Linux Local Privilege Escalation (LPE) with new modules for the "Dirty Frag" vulnerabilities, identified as CVE-2026-43284 and CVE-2026-43500.
originale 28 mag Fortinet Outbreak Alerts
Citrix NetScaler Memory Overread Vulnerability | Outbreak Alert | FortiGuard Labs
Exploitation activity targeting vulnerable Citrix NetScaler ADC and Gateway appliances remains persistent and widespread, with FortiGuard Labs tele...
originale Riepilogo fornitore: Citrix
Part of the PlainSec briefing for 2026-05-29
Every edition of this story: La foothold di Marimo ora si muove più velocemente del patching
Altro da oggi
Vulnerabilità ed exploit · Exploit zero-day
La foothold di Marimo ora si muove più velocemente del patching Un notebook compromesso non è più la fine della storia. In Marimo, gli attacker stanno ora usando un agente LLM per trasformare una singola RCE iniziale in furto di credenziali cloud, accesso a Secrets Manager, accesso SSH ed esfiltrazione da PostgreSQL in circa un’ora, quindi il patching del notebook da solo non rimuove l’accesso già estratto da esso.
3 fonti · 29 mag
NVD KEV
Sfruttamento noto · CISA KEV
EPSS 38% (98º percentile).
Data di correzione federale CISA 7 mag · data superata
NVD KEV
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 2 apr · data superata
CVE-2026-43284 NVD KEV
CVSS 8.8 HIGH: in the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decrypt on shared skb frags
MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. EPSS 2% (84º percentile). Patch Microsoft: CBL-Mariner Releases.
CVE-2026-43500 NVD KEV
CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved:
rxrpc: Also unshare DATA/RESPONSE packets when… EPSS 2% (82º percentile).
Cronologia Fonti 29 mag The Hacker News
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
LLM-driven attackers exploited CVE-2026-39987 on May 10, 2026, to steal credentials and exfiltrate a PostgreSQL database.
originale 29 mag Rapid7
Metasploit Wrap-Up 05/29/2026
This week's Metasploit release focuses heavily on Linux Local Privilege Escalation (LPE) with new modules for the "Dirty Frag" vulnerabilities, identified as CVE-2026-43284 and CVE-2026-43500.
originale 28 mag Fortinet Outbreak Alerts
Citrix NetScaler Memory Overread Vulnerability | Outbreak Alert | FortiGuard Labs
Exploitation activity targeting vulnerable Citrix NetScaler ADC and Gateway appliances remains persistent and widespread, with FortiGuard Labs tele...
originale Riepilogo fornitore: Citrix
Part of the PlainSec briefing for 2026-05-29
Every edition of this story: La foothold di Marimo ora si muove più velocemente del patching
Altro da oggi