- Unauthenticated RCE in Marimo /terminal/ws WebSocket endpoint; CVSS 9.3
- Marimo RCE exploitWorking exploit built from advisory; used to access shell and exfiltrate credentials
The threat landscape continues to accelerate as critical vulnerabilities are weaponized within hours of disclosure, while supply chain attacks target widely deployed software infrastructure. Today's security briefing covers rapid exploitation of open-source flaws, compromised plugin distribution networks, targeted payroll theft campaigns, and multiple vulnerabilities in medical imaging systems.
An unauthenticated vulnerability in Marimo has been actively exploited in the wild within nine hours of its public disclosure. Threat actors rapidly developed functional exploits from the vulnerability advisory and began deploying them against exposed systems. Source: Critical Marimo Flaw Exploited Hours After Public Disclosure
This incident demonstrates the compressed timeline between vulnerability announcement and active weaponization. The affected vulnerability, tracked as CVE-2026-39987, highlights the critical importance of rapid patching protocols for organizations running exposed Marimo instances. The speed of exploitation underscores how public disclosures can immediately enable threat actors to develop and deploy working exploits.
Unknown threat actors have compromised the update infrastructure for Smart Slider 3 Pro, a WordPress and Joomla slider plugin with over 800,000 active installations, to distribute a backdoored version. The poisoned update affects Smart Slider 3 Pro version 3.5.1.35 for WordPress and was distributed through hijacked Nextend servers. Source: Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
This supply chain attack represents a significant threat to the WordPress ecosystem, as the compromised plugin update mechanism could have infected hundreds of thousands of websites. The attack infrastructure includes the domain wpjs1.com, which was used to deliver the malicious payload. Organizations running Smart Slider 3 Pro should immediately verify their plugin version and integrity, and consider rolling back to trusted versions until the official patch is released.
A financially motivated threat actor tracked as Storm-2755 is conducting payroll theft attacks specifically targeting Canadian employees by compromising their accounts and redirecting salary payments. The attacker uses phishing techniques to gain initial access to employee accounts and subsequently hijack payroll transactions. Source: Microsoft: Canadian Employees Targeted in Payroll Pirate Attacks
The attack infrastructure includes the domain bluegraintours.com, which is utilized in the phishing campaign. This targeted campaign demonstrates the shift toward financially motivated attacks that directly impact employee compensation, making payroll systems and employee account security critical priorities for Canadian organizations.
Multiple vulnerabilities have been identified in Orthanc, an open-source DICOM server, that could enable denial-of-service attacks, information disclosure, and arbitrary code execution. The vulnerabilities span nine distinct CVEs, including CVE-2026-5437 through CVE-2026-5445. Source: Orthanc DICOM Vulnerabilities Lead to Crashes, RCE
These vulnerabilities in medical imaging infrastructure present a significant risk to healthcare organizations relying on Orthanc for DICOM server functionality. The range of impacts—from denial-of-service to remote code execution—means that healthcare providers should prioritize patching these systems to prevent potential disruption to clinical imaging services and unauthorized access to sensitive patient data.
Today's threat activity reflects an increasingly aggressive threat landscape where vulnerabilities are exploited within hours, supply chain mechanisms are weaponized at scale, and financially motivated attackers target critical business processes. Organizations must maintain vigilant patch management practices and implement robust account security measures to defend against these evolving threats.
Source articles and extracted indicators (defanged where appropriate).
wpjs1.combluegraintours[.]com