Urgent.News

What's breaking now, across thousands of outlets.

More in Tech

Human operator executes Marimo cloud pivot in eight seconds

A skilled human attacker exploited a critical Marimo notebook flaw and moved from an exposed WebSocket session to authenticated access on an SSH bastion host in eight seconds, Sysdigโ€™s Threat Researchโ€ฆ

  • Human attacker exploited Marimo notebook platform vulnerability in 8 seconds
  • Operator used Python toolkit, manual debugging and deliberate pacing
  • CVE-2026-39987 vulnerability disclosed April 8, rated critical

JeetBot extension routes Twitch tokens to bot servers

A browser extension used by nearly 31,000 Twitch viewers has been found forwarding live OAuth session tokens to proxy infrastructure controlled by the operator of a Russian-language commercial botโ€ฆ

  • Twitch extension JeetBot routes OAuth tokens to Russian proxy servers
  • Extension exposed credentials allowing unauthorized account access
  • Researchers advise users to remove extension and disconnect sessions

Ollama keep_alive: My Model Reloaded 214 Times in One Day

My local chat app was fast every single time I tested it, and slow every single time I actually used it. That's the tell, and I ignored it for weeks.

  • Ollama experienced performance issues due to model eviction from VRAM.
  • Reporter discovered three model persistence options for Ollama.
  • Adjusting keepalive resolved model reloading delays.

More from Tuesday 15 September โ†’