ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-04-13
▶The Wire — Daily Briefing

The Wire — Monday, April 13, 2026

When Patches Come Too Late: A Day of Active Exploitation and Urgent Warnings

5 stories analyzed

When Patches Come Too Late: A Day of Active Exploitation and Urgent Warnings

There's a particular kind of dread in our industry when we wake to news that critical vulnerabilities are already being exploited in the wild—not in controlled labs, not in future attacks, but right now, against real systems. Today is one of those mornings.

The pattern is grimly familiar: security researchers discover a flaw, vendors issue patches, and the responsible disclosure window closes. But somewhere in that sequence, threat actors are already moving. Critical Marimo pre-auth RCE flaw now under active exploitation tells us exactly where we stand with one of the newer tools gaining traction in data science and analysis workflows—attackers have weaponized a pre-authentication remote code execution vulnerability, and they're using it specifically for credential harvesting. This isn't theoretical. This is happening.

What makes this moment particularly sharp is the context we learned just hours apart: Adobe Patches Reader Zero-Day Exploited for Months reveals that one of the most ubiquitous applications on enterprise networks—PDF readers installed on millions of machines—has been actively exploited for months before the patch arrived. Months. During that entire window, defenders were flying blind, unaware that their users opening seemingly innocent PDFs could be handing over system access to adversaries.

We need to sit with this for a moment. The gap between when exploitation begins and when defenders have visibility is the real vulnerability. Adobe's zero-day wasn't a novel attack vector discovered in forensic analysis after the fact—it's been weaponized in the wild, which means security teams have already been hit, they may not yet know it, and their patches today may come too late to prevent weeks of lateral movement inside their networks.

This is where the story gets complicated, because the industry's standard response—patch immediately, move on—assumes something we can no longer take for granted: that detection happened before exploitation, or that exploitation was limited in scope. Neither assumption is safe anymore.

The supply chain angle only deepens our concern. Over the weekend, OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident showed us what happens when a trusted build pipeline gets compromised. The malicious Axios library was pulled down during the signing process on March 31st, which means OpenAI's CI/CD pipeline momentarily trusted code it shouldn't have. The company states no user data was compromised, but here's what keeps us awake: they caught this. They announced it. They're revoking certificates. That's the best-case scenario for a supply chain incident. It's also the exception, not the rule. How many other build pipelines are compromised right now without anyone knowing? How many signed artifacts are in distribution from vendors who haven't yet detected the attack?

The threat landscape we're watching is increasingly asymmetric. Defenders are running incident response on patches that are already months old. Attackers are exploiting vulnerabilities before patches exist. Build pipelines are being targeted because they're the throat to squeeze to reach millions of users at once. This is not a problem that patches alone can solve.

Against this backdrop, Gmail Brings End-to-End Encryption to Android and iOS for Enterprise Users stands out, not as a silver bullet, but as a reminder that the equation can shift. When enterprise email moves to end-to-end encryption natively on mobile devices, the attack surface changes. Message content becomes useless to compromise. This is the right direction—reducing what an attacker can steal even if they breach the system. It's not a defense against zero-days in PDF readers or compromised build systems, but it's the kind of baseline security posture that prevents the "we were breached and everything was stolen" conversation from extending to email content.

The lesson across all of today's stories is uncomfortable: vulnerability management as we've practiced it for decades assumes a roughly linear timeline—discovery, disclosure, patch, deployment, remediation. That timeline is being shattered. Marimo is being exploited for credentials before the majority of deployments can patch. Adobe Reader was exploited for months with no visibility to the defender. OpenAI's supply chain was compromised while signing applications. The assumption that "we have time to plan a patch" is gone.

This means security teams need to operate on a different principle: assume you are compromised, assume you were compromised before patches were available, and assume some of those compromises haven't been detected yet. That's not paranoia—it's the operating environment we're in. It means your incident response plans need to account for active exploitation even after patches drop. It means your detective controls need to be searching for post-compromise behavior, not just vulnerability exploitation. It means your patch management strategy cannot be your security strategy.

For teams using Marimo in production, this is an immediate call to action. For organizations with Adobe Reader deployed, this is a "check your logs for the last three months" moment. For anyone with CI/CD pipelines building signed applications, this is the reminder that your build system is as critical an attack target as your production systems—probably more so.

The silver lining, if we squint, is that security research and vendor response are working. Vulnerabilities are being found. Patches are being released. Companies like OpenAI and Gmail's developers are making the right architectural choices. But we're operating on a timeline where that's not always fast enough.

What we should be watching next: whether other security-critical build systems show signs of compromise in the coming weeks, whether the Marimo exploitation becomes an incident wave, and whether Adobe's patch actually closes the door or if there are related zero-days waiting in the wings.

Key Takeaways

  • Active exploitation is now the baseline assumption. Patch deployment windows measured in days or weeks are no longer acceptable for critical vulnerabilities. Assume adversaries are already inside during your patching timeline.
  • Build pipelines are critical attack infrastructure. The OpenAI incident shows that compromising how software is signed and certified reaches more users than compromising the software itself. Audit CI/CD access controls and artifact signing processes immediately.
  • Detective controls must assume pre-compromise. Vulnerability patches don't erase post-breach activity. Security teams need log analysis and behavioral detection focused on lateral movement and data exfiltration, not just vulnerability exploitation.
  • End-to-end encryption and zero-trust architecture matter more than ever. When breaches are inevitable, reducing what an attacker can steal—even inside an already-compromised network—becomes a primary defense.

The Wire is HackWire's daily editorial briefing, published every morning.