logo

Agentic threat actor hits the orchestration plane: AI agent-driven container escape

ID: a73fe5a3-ca90-5670-8020-c8de0388886d

STIX ID: report--a73fe5a3-ca90-5670-8020-c8de0388886d

Feed Name: Sysdig Blog

Threat Score
80/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

...
...

Sysdig TRT observed an LLM-driven autonomous attacker exploit CVE-2026-39987 in a marimo notebook to enumerate escape vectors, abuse a mounted Docker socket to create privileged containers (or nsenter), exfiltrate host credentials and SSH keys, and replay a mounted Kubernetes service-account token to list and dump the cluster Secret store; the report emphasizes automation (agentic behavior), provides IOCs (source IPs and C2), and recommends patching marimo, never mounting /var/run/docker.sock, hardening container privileges/seccomp, and tightening service-account token RBAC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.