⤷ Title: Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 03:26:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Exploitation #CVE_2026_39987 #cybersecurity #infosec #Marimo #Python #rce #Sysdig #threat intelligence #WebSocket Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 03:26:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Exploitation #CVE_2026_39987 #cybersecurity #infosec #Marimo #Python #rce #Sysdig #threat intelligence #WebSocket Security
Daily CyberSecurity
Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint
Unauthenticated RCE in marimo (CVE-2026-39987) exploited in the wild in record time. Attackers gained root access in under 10 hours. Patch to v0.23.0 now!
⤷ Title: CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
Daily CyberSecurity
CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
CVE-2026-33626: A critical SSRF in LMDeploy exploited in under 13 hours. Learn how attackers hijack AI nodes and how to secure your inference cloud now.
⤷ Title: Critical LiteLLM SQL Injection (CVE-2026-42208) Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 01:53:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_42208 #cybersecurity #Data Breach #Exploit #infosec #LiteLLM #Patch Alert #PostgreSQL #sql injection #Sysdig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 01:53:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_42208 #cybersecurity #Data Breach #Exploit #infosec #LiteLLM #Patch Alert #PostgreSQL #sql injection #Sysdig
Daily CyberSecurity
Critical LiteLLM SQL Injection (CVE-2026-42208) Exploited in the Wild
LiteLLM CVE-2026-42208 is under active exploitation. Attackers are using SQL injection to steal AI credentials. Patch to v1.83.7 and rotate keys immediately.
⤷ Title: PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:00:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Authentication Bypass #CVE_2026_44338 #Cyber Security #Exploit in the Wild #infosec #LLM Security #Multi_Agent Orchestration #PraisonAI #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:00:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Authentication Bypass #CVE_2026_44338 #Cyber Security #Exploit in the Wild #infosec #LLM Security #Multi_Agent Orchestration #PraisonAI #Sysdig TRT
Daily CyberSecurity
PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure
Sysdig warns: PraisonAI (CVE-2026-44338) exploited in under 4 hours. Attackers bypassed auth to hijack agents and drain API quotas. Update to 4.6.34 now!
⤷ Title: Critical Pre-Auth Flaw CVE-2026-44338 Exploited to Hijack Autonomous AI Agents
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 07:13:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent Hijacking #api_server.py #authentication bypass #Autonomous AI Security #CVE_2026_44338 #DevSecOps 2026 #LLM Token Abuse #Model Context Protocol #PraisonAI #Sysdig report
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 07:13:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent Hijacking #api_server.py #authentication bypass #Autonomous AI Security #CVE_2026_44338 #DevSecOps 2026 #LLM Token Abuse #Model Context Protocol #PraisonAI #Sysdig report
Information Security News
Critical Pre-Auth Flaw CVE-2026-44338 Exploited to Hijack Autonomous AI Agents - Information Security News
Adversaries initiated a targeted reconnaissance campaign against vulnerable PraisonAI nodes less than four hours following the public disclosure of a critical security defect. An automated scanning entity identifying as CVE-Detector/1.0 launched offensives…
⤷ Title: SaaS-Style Cybercrime: Attackers Weaponize Langflow RCE and NATS Messaging for Ultra-Scalable C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 08:06:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Pipeline Security #CISA KEV #container escape #CVE_2026_33017 #Distributed Messaging #infosec #Langflow #NATS_as_C2 #Patch Alert #Remote Code Execution #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 08:06:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Pipeline Security #CISA KEV #container escape #CVE_2026_33017 #Distributed Messaging #infosec #Langflow #NATS_as_C2 #Patch Alert #Remote Code Execution #Sysdig TRT
Daily CyberSecurity
SaaS-Style Cybercrime: Attackers Weaponize Langflow RCE and NATS Messaging for Ultra-Scalable C2
Sysdig exposes "NATS-as-C2" infrastructure exploiting Langflow RCE (CVE-2026-33017). Learn how to defend your AI pipelines and block the exploit.
⤷ Title: NATS-as-C2: Critical Langflow Exploit Exploded to Fuel “LLMjacking” and Cloud Credential Theft
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:02:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent security #AWS Bedrock Exploitation #Cloud Credential Theft #CVE_2026_33017 #KeyHunter Botnet #Langflow Vulnerability #LLMjacking #NATS_as_C2 #Sysdig Threat Research #uTLS Fingerprinting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:02:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent security #AWS Bedrock Exploitation #Cloud Credential Theft #CVE_2026_33017 #KeyHunter Botnet #Langflow Vulnerability #LLMjacking #NATS_as_C2 #Sysdig Threat Research #uTLS Fingerprinting
Penetration Testing Tools
NATS-as-C2: Critical Langflow Exploit Exploded to Fuel "LLMjacking" and Cloud Credential Theft
Forensic specialists from Sysdig have intercepted an anomalous command architecture governing a malicious network, wherein the adversaries abandoned
⤷ Title: The Rise of the Algorithmic Intruder: AI-Driven Exploitation of Marimo Servers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 04:07:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #AI agent cyberattack #autonomous malware post_exploitation #database exfiltration vector #Marimo CVE_2026_39987 exploit #notebook pre_auth RCE #Sysdig threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 04:07:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #AI agent cyberattack #autonomous malware post_exploitation #database exfiltration vector #Marimo CVE_2026_39987 exploit #notebook pre_auth RCE #Sysdig threat intelligence
Information Security News
Marimo CVE-2026-39987 Exploit: AI Agent Cyberattack
Analyze the Marimo CVE-2026-39987 exploit. Learn how an autonomous AI agent weaponized this flaw to exfiltrate internal database credentials.
⤷ Title: Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 10:22:21 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Cyber Attacks #Malware #Agentic AI #AI Agent #Cyber Attack #Cyber Crime #Cybersecurity #data breach #JADEPUFFER #LLM #Ransomware #Sysdig #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 10:22:21 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Cyber Attacks #Malware #Agentic AI #AI Agent #Cyber Attack #Cyber Crime #Cybersecurity #data breach #JADEPUFFER #LLM #Ransomware #Sysdig #Vulnerability
Hackread
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat.
⤷ Title: JADEPUFFER Marks the First AI-Driven Agentic Ransomware Attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 06:11:59 +0000
════════════════════════
⌗ Tags: #Malware #agentic ransomware #AI_driven ransomware #CVE_2025_3248 #JADEPUFFER #Langflow #Nacos #ransomware #Sysdig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 06:11:59 +0000
════════════════════════
⌗ Tags: #Malware #agentic ransomware #AI_driven ransomware #CVE_2025_3248 #JADEPUFFER #Langflow #Nacos #ransomware #Sysdig
Daily CyberSecurity
JADEPUFFER Marks the First AI-Driven Agentic Ransomware Attack
At a Glance Malware family JADEPUFFER (agentic ransomware) Threat actor Unnamed operator; Sysdig assesses an autonomous AI agent. Human identity not confirmed. Target / victims One organization…