logo

Hackers Pivot from marimo RCE to Internal Database Using LLM Agent

ID: 5b5a1599-acd0-5cbf-bdda-982502d9e255

STIX ID: report--5b5a1599-acd0-5cbf-bdda-982502d9e255

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Mayura Kathir

...
...

Sysdig researchers observed an active intrusion (May 10, 2026) where attackers exploited CVE-2026-39987 on marimo notebooks, harvested cloud credentials, and used an LLM-driven agent to automate post-compromise actions—replaying credentials against AWS APIs, retrieving an SSH key from Secrets Manager, pivoting through an SSH bastion, and dumping an internal PostgreSQL database within minutes while dispersing activity across Cloudflare Workers to evade IP-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.