Tag: LLM Agent

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
News

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

After gaining initial access through the exploitation of a publicly accessible Marimo network using a newly revealed vulnerability, an unidentified threat actor has been seen utilizing a large language model (LLM) agent to carry out post-compromise actions. Using CVE-2026-39987, the attacker gained access to an internet-connected Marimo notebook, took two cloud credentials from the compromised host, replayed them through a fanned-out egress pool to obtain an SSH private key from AWS Secrets Manager, and used that key to initiate eight brief SSH sessions against a downstream SSH bastion server, according to Sysdig. In less than two minutes, the entire contents and schema of an internal PostgreSQL database were exfiltrated by the bastion phase. A significant pre-authenticated remot...