Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Marimo has patched a high-severity vulnerability in its notebook software that allowed attackers to execute arbitrary Model Context Protocol (MCP) commands through specially crafted notebooks opened in edit mode. The flaw enabled command execution as a local subprocess, posing a risk to users who open untrusted notebook files for editing.
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.
Researchers have demonstrated that prompt injection attacks can evade AI safety measures by concealing malicious instructions within encrypted text, potentially compromising guardrails in popular AI assistants. This technique highlights a significant vulnerability in current AI security implementations, allowing attackers to manipulate models like Grok and Gemini into executing unintended actions despite their built-in protections.
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a
Australian officials are warning TeamCity customers of an active exploitation campaign targeting a critical server vulnerability and urging immediate patching. The alert mirrors a similar warning previously issued by US government authorities, indicating the flaw poses a significant threat across international organizations.