Skip to content
April 2026 Page 25

April 2026

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

Ravie LakshmananApr 10, 2026Vulnerability / Threat Intelligence A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig. The vulnerability… 

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

Ravie LakshmananApr 10, 2026Malware / Website Security Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts… 

EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets

EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets

Ravie LakshmananApr 09, 2026Vulnerability / Mobile Security Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk.… 

UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns

UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns

Ravie LakshmananApr 09, 2026Malware / Windows Security A previously undocumented threat cluster dubbed UAT-10362 has been attributed to spear-phishing campaigns targeting Taiwanese non-governmental organizations (NGOs) and suspected universities to deploy a new Lua-based malware called LucidRook.… 

Ugreen’s 6-in-1 USB-C hub with 4K HDMI is 36% off (now just )

Ugreen’s 6-in-1 USB-C hub with 4K HDMI is 36% off (now just $14)

NOW 36% OFF Ugreen Revodok Pro 6-in-1 USB-C Hub View Deal (function () { document.querySelector(“#sticky-promo-block a”).addEventListener(“click”, function(e) { const debug = document.location.host.search(/lndo.site|go-vip.net/) !== -1; const text = this.closest(“#sticky-promo-block”).querySelector(“p.promo-title”).textContent; const data = { event: “stickyConversionUnitClick”, eventCategory:…