Connect with us
DAPA Banner

Tech

Critical Marimo pre-auth RCE flaw now under active exploitation

Published

on

Marimo

Hackers started exploiting a critical vulnerability in the Marimo open-source reactive Python notebook platform just 10 hours after its public disclosure.

The flaw allows remote code execution without authentication in Marimo versions 0.20.4 and earlier. It tracked as CVE-2026-39987 and GitHub assessed it with a critical score of 9.3 out of 10.

According to researchers at cloud-security company Sysdig, attackers created an exploit from the information in the developer’s advisory and immediately started using it in attacks that exfiltrated sensitive information.

Wiz

Marimo is an open-source Python notebook environment, typically used by data scientists, ML/AI practitioners, researchers, and developers building data apps or dashboards. It is a fairly popular project, with 20,000 GitHub stars and 1,000 forks.

CVE-2026-39987 is caused by the WebSocket endpoint ‘/terminal/ws’ exposing an interactive terminal without proper authentication checks, allowing connections from any unauthenticated client.

Advertisement

This gives direct access to a full interactive shell, running with the same privileges as the Marimo process.

Marimo disclosed the flaw on April 8 and yesterday released version 0.23.0 to address it. The developers noted that the flaw affects users who deployed Marimo as an editable notebook, and those who expose Marimo to a shared network using –host 0.0.0.0 while in edit mode.

Exploitation in the wild

Within the first 12 hours after the vulnerability details were disclosed, 125 IP addresses began reconnaissance activity, according to Sysdig.

Less than 10 hours after the disclosure, the researchers observed the first exploitation attempt in a credential theft operation.

Advertisement

The attacker first validated the vulnerability by connecting to the /terminal/ws endpoint and executing a short scripted sequence to confirm remote command execution, disconnecting within seconds.

Shortly after, they reconnected and began manual reconnaissance, issuing basic commands such as pwd, whoami, and ls to understand the environment, followed by directory navigation attempts and checks for SSH-related locations.

Next, the attacker focused on credential harvesting, immediately targeting the .env file and extracting environment variables, including cloud credentials and application secrets. They then attempted to read additional files in the working directory and continued probing for SSH keys.

Stealing credentials
Stealing credentials
Source: Sysdig

The entire credential access phase was completed in less than three minutes, notes a Sysdig report this week.

Roughly an hour later, the attacker returned for a second exploitation session using the same exploit sequence.

Advertisement

The researchers say that behind the attack appears to be a “methodical operator” with a hands-on approach, rather than automated scripts, focusing on high-value objectives such as stealing .env credentials and SSH keys.

The attackers did not attempt to install persistence, deploy cryptominers, or backdoors, suggesting a quick, stealthy operation.

Marimo users are recommended to upgrade to version 0.23.0 immediately, monitor WebSocket connections to ‘/terminal/ws,’ restrict external access via a firewall, and rotate all exposed secrets.

If upgrading is not possible, an effective mitigation is to block or disable access to the ‘/terminal/ws’ endpoint entirely.

Advertisement

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

NYT Strands hints and answers for Monday, April 13 (game #771)

Published

on

Looking for a different day?

A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people are always playing ‘today’s game’ while others are playing ‘yesterday’s’. If you’re looking for Sunday’s puzzle instead then click here: NYT Strands hints and answers for Sunday, April 12 (game #770).

Strands is the NYT’s latest word game after the likes of Wordle, Spelling Bee and Connections – and it’s great fun. It can be difficult, though, so read on for my Strands hints.

Advertisement

Source link

Continue Reading

Tech

‘The Audacity’ Is the Broligarchy Takedown You Were Waiting For

Published

on

AMC’s new black comedy about a manchild tech titan spinning out of control is a skewering Silicon Valley’s billionaire class deserves.

Source link

Continue Reading

Tech

The US government wants Reddit to snitch on one of its users through a grand jury

Published

on

Immigration and Customs Enforcement has a certain Redditor in its crosshairs and it’s now strong-arming the social media platform to reveal who they are with a grand jury subpoena, according to a report from The Intercept. The nonprofit news outlet was able to obtain the subpoena that ordered Reddit to provide info on one of its users who’s been accused of criticizing ICE by April 14.

According to the report, ICE has been trying to identify this Redditor for a month without success. More specifically, Reddit is being asked to give up the user’s name, address, phone number and other personal data. The Intercept reported that the subpoena was issued by federal prosecutors in Washington, D.C. after a failed attempt from ICE to do the same through a federal court in Northern California, which has jurisdiction in San Francisco where Reddit is headquartered.

Reddit attorneys said their client’s posts and anonymity are protected under the First Amendment and described ICE’s use of a grand jury as “a disturbing escalation,” according to the report. Reddit didn’t state if it would challenge the government’s order or not, according to The Intercept, but it did provide a statement saying, “privacy is central to how Reddit operates and we take our commitment to protecting that seriously.” Reddit also said in the statement that it does “not voluntarily share information with any government, especially not on users exercising their rights to criticize the government or plan a protest.”

While this grand jury subpoena could set an alarming precedent, it’s not the first time a government agency has requested social media platforms reveal accounts that have spoke negatively about ICE. According to a New York Times report, the Department of Homeland Security has filed hundreds of subpoenas to Google, Discord, Meta and even Reddit again, for identifying details about its users.

Advertisement

Source link

Continue Reading

Tech

Why Is It So Hard to Fix an Electric Bike? (2026)

Published

on

If you Ask any bike shop owner or manager if they fix electric bikes, you get an interesting array of stories.

“I know a guy who has lost a finger working on ebikes,” says MacKenzie Hardt, owner of Hardt Family Cyclery in Aurora, Colorado, and the former executive director of the nonprofit bike shop and community hub Bikes Together. Hardt has torn tendons in his own hand after accidentally triggering a cadence sensor that caused the wheel to spin out of control on the stand, even when the motor and battery were disconnected.

He now has a message on the company voicemail that informs customers the shop will not repair any ebike without third-party UL 2849 certification, the gold standard that certifies that an ebike’s entire package, from electrical drive train to battery to charger system, has been thoroughly tested. (Check out our guide to How to Buy an Electric Bike for more info.)

The Wild, Wild West

A lot of the problem in fixing ebikes is related to the fact that a surprising number of electric vehicles that are sold as ebikes are not, in fact, ebikes. According to PeopleForBikes, the third-party advocacy group, an ebike is a low-speed electric vehicle that “closely resembles traditional bicycles in their equipment, handling characteristic, size, and speed.”

Advertisement
Image may contain Machine Spoke Wheel Adult Person Accessories Bag Handbag and Tire

A mechanic works on a bicycle.Photograph: Dikushin/Getty Images

In 46 states, all ebikes fall under a Class 1, 2, or 3 distinction. The distinction depends on the bike’s maximum motor-assisted speed and how it’s powered. However, many ebikes sold online are way more powerful than the maximum 28 mph speed allowed on a Class 3 ebike, and they operate more like a moped or even a motorcycle.

“That’s really the heart and soul of the service problem,” says Cory Oseland, manager of the Ski Hut, a high-end bike shop in Duluth, Minnesota. “Once you slide out of the three classes, you run into a lot of parts and equipment that aren’t part of the bike industry.”

Repairing an ebike can also land the shop in a quagmire of liability issues. As bike shops are part of the product liability chain, they can be held responsible if they so much as inflate a tire on an electric vehicle and the rider later injures themselves or another person. Ebike-related injuries have jumped more than 1,020 percent nationwide from 2020 to 2024, according to hospital data, so this is not an unforeseen occurrence. “I have known people who have lost their shirt,” says Hardt.

In most states, if the bike doesn’t fit the Class 1-3 classification system, the shop’s insurance will likely be null and void. The problem, says Hardt, is that “we don’t regulate nationally what an ebike is. What is legal here may not be legal somewhere else.” Working on an unregulated bike, he adds, “is like if somebody brought in a Tesla to fix.”

Advertisement

Source link

Continue Reading

Tech

Apple reportedly testing four designs for upcoming smart glasses

Published

on

Apple plans to sell its first smart glasses in 2027, with a possible unveiling at the end of this year, according to Bloomberg’s Mark Gurman.

Gurman has been reporting steadily on the evolution of the company’s smart glasses strategy, but now he has more details about how they’ll look — he said Apple is testing four designs, and could ultimately launch with some or all of them.

Those designs reportedly include a large rectangular frame, a slimmer rectangular frame (similar to the glasses worn by CEO Tim Cook), a larger oval or circular frame, and a smaller oval or circular frame. Apple is also considering different colors including black, ocean blue, and light brown.

In some ways, these glasses are a step back from an ambitious plan that once called for Apple to launch a variety of mixed and augmented reality devices — a plan that already stumbled with product delays and the lackluster reception of the Vision Pro.

Advertisement

These glasses, meanwhile, sound closer to the Meta’s Ray-Ban glasses. They won’t have any displays, but will allow users to take photos and videos (Apple is reportedly oval camera lenses), answer phone calls, play music, and interact with the long-promised Siri upgrade.

Source link

Continue Reading

Tech

Hackaday Links: April 12, 2026

Published

on

At this point, we’ll assume you already know that four humans took a sightseeing trip around the Moon and made their triumphant return to Earth on Friday. Even if you somehow avoided hearing about it through mainstream channels, we kept a running account of the mission’s highlights stuck to the front page of the site for the ten days that the crew was in space.

On the assumption that you might be a bit burned out with space news at this point, we won’t bring up it up in this post… other than to point out that excitement for the lunar flyby has driven the number of simultaneous players of Kerbal Space Program to its highest count ever — nearly 20,000 armchair astronauts spent this weekend trying to cobble together their own rocket in honor of the Artemis II mission.

With so many folks focused on the Moon it would be the perfect time for a company to sneak out some bad news, which is perhaps why Amazon picked this week to announce they would be dropping support for Kindles released before 2012. Presumably there aren’t too many first and second generation Kindles still out there in the wild, but the 2012 cutoff does mean the first iteration of the Paperwhite will be one of the devices being put out to pasture come May 20th.

Amazon says the pre-2012 Kindles that are currently in user’s hands will still function, but they’ll no longer be able to purchase or download new books. The bigger issue is that you won’t be able to register these older devices after May. So if you have to factory reset your own Kindle, or want to buy one on the second hand market that’s already been wiped, you won’t be able to link it to your account to download books you’ve purchased.

Advertisement

Frankly, the idea that Amazon will no longer have their nose in these devices doesn’t bother us one bit. In fact, it sounds like an improvement over the status quo. If you own one of the device’s in question, now would be a fantastic time to download Calibre and start managing your own offline ebook library. In fact, even if your Kindle is new enough to not be affected by this change, you should still download it. Seriously, just use Calibre.

On the subject of software, an entry for XChat has recently popped up on Apple’s App Store. No, not that XChat. Instead of connecting to your favorite IRC server, the new mobile app will let you send messages to… whoever it is still actively using Twitter X. Confusingly, there’s also an XChat on the Google Play Store, but that appears to be a totally different thing altogether.

Finally, we’ve been seeing a lot of chatter online this weekend about France ditching Windows and switching over to Linux. While we applaud any mainstream push towards open source software, it’s worth digging into the details for this one. The directive says that the Interministerial Digital Directorate (DINUM) will be switching its desktop machines over to Linux, but that only represents a few hundred machines.

The experience gained during this roll-out will help shape a larger scale migration in the future, with the rest of the government asked to come up with a migration plan before the end of the year. When those other agencies, and the thousands of machines they use, will actually be penguin-powered is not clear. It’s possible they could come back and say a full migration would take a decade to complete.

Advertisement

So it’s certainly a step in the right direction, but it will likely be quite some time before any significant part of France’s infrastructure is divorced from the Redmond giant.


See something interesting that you think would be a good fit for our weekly Links column? Drop us a line, we’d love to hear about it.

Source link

Advertisement
Continue Reading

Tech

Tesla is working on a smaller, cheaper electric SUV

Published

on


Three of the sources said the new model would be produced in China, while one added that Tesla also aims to expand production to the United States and Europe. Two sources said the vehicle would measure about 4.28 meters (14.0 feet) in length, making it significantly shorter than the Model…
Read Entire Article
Source link

Continue Reading

Tech

Eight years later, Apple quietly shuts the door on AI chief John Giannandrea

Published

on

Since his retirement was announced in 2025, Apple Intelligence head John Giannandrea has been reduced to the role of an advisor, but is now expected to exit Apple Park shortly.

Middleaged man with short gray hair, glasses, and goatee speaking onstage, wearing a dark jacket and headset microphone, with blurred conference text SF 2017 in the background
John Giannandrea – image credit: Apple

If you spend your notice period at home, you’re on gardening leave. If you spend it at work and you’re waiting for when your contracted stock bonuses realize, it’s called “rest and vest”.
It appears that the stock options agreed for John Giannandrea’s contract when Apple hired him in 2018, are due on April 15. According to Bloomberg’s “Power On” newsletter, Giannandrea is consequently going to leave around then.
Continue Reading on AppleInsider | Discuss on our Forums

Source link

Continue Reading

Tech

Who Had “New OS For The Z80” On Their 2026 Bingo Card?

Published

on

Some might say the venerable Z80 doesn’t need another operating system, but [Scott Baker] obviously disagrees. He has come up with a brand new, from scratch OS called NostOS for the Z80-based RC2014 homebrew retrocomputer. [Scott] describes it as CP/M-like, but it’s not CP/M– in fact, it’s totally incompatible with CP/M–and has a few tricks of its own up its sleeve.

As you might expect of an operating system for this vintage of hardware, it is “rommable” — that is, designed to run from read-only-memory, and fit inside 64kB. It of course supports banking memory to go higher than that 16 bit limit, and natively supports common serial devices, along with the good old WD37C65 floppy controller to get some spinning rust into the game. Of course if you don’t have floppies you can plug in a compact flash card– try that with CP/M– or, interestingly Intel Bubble Memory. [Scott] has a soft-spot for bubble memory, which at one point seemed poised to replace both hard drives and RAM at the same time. We also appreciate that he included drivers for vacuum fluorescent displays, another forgotten but very cool technology. Back in the day, this operating system would have enabled a very cool little computer, especially when you take his implementation of text-to-speech with the SP0256A-AL2 chip. Fancy a game of talking Zork? Yes, he ported Zork, and yes, it talks.

The whole thing is, of course, open-source, and available on [Scott]’s GitHub. Unlike too many open-source projects, the documentation is top-notch, to the point that we could picture getting it in a three-ring binder with a 5 1/4 floppy on the inside cover. If you like video, we’ve embedded [Scott]’s walkthrough but his blog and the docs on GitHub have everything there and more if you’re not into rapidly-flickering-pixels as an information exchange medium.

[Scott] isn’t wedded to Zilog, for the record; this OS should run on an Intel 8080, perhaps like the one in the Prompt 80 he restored last year. 

Advertisement

Thanks to [Scott Baker] for the tip!

Source link

Advertisement
Continue Reading

Tech

Trump officials may be encouraging banks to test Anthropic’s Mythos model

Published

on

Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell summoned bank executives for a meeting this week where they encouraged the executives to use Anthropic’s new Mythos model to detect vulnerabilities, according to Bloomberg

Indeed, while JPMorgan Chase was the only bank listed as one of the initial partner organizations with access to the model, Goldman Sachs, Citigroup, Bank of America, and Morgan Stanley are reportedly testing Mythos as well.

Anthropic announced the model this week but said it would be limiting access for now, in part because Mythos — despite not being trained specifically for cybersecurity — is too good at finding security vulnerabilities. (Others suggested this was hype or simply a smart enterprise sales strategy.)

The report is particularly surprising since Anthropic is currently battling the Trump administration in court over the Department of Defense’s designation of Anthropic as a supply-chain risk; that designation came after negotiations fell apart over the company’s efforts to limit how its AI models can be used by the government.

Advertisement

Meanwhile, the Financial Times reports that U.K. financial regulators are also discussing the risk posed by Mythos.

Source link

Continue Reading

Trending

Copyright © 2025