Human Operator Exploits Marimo RCE Vulnerability to Access SSH Bastion in 8 Seconds
A skilled human attacker exploited the Marimo RCE vulnerability (CVE-2026-39987) to access an SSH bastion in 8 seconds using custom Python tools, bypassing detection without AI assistance. The attack highlights the continued effectiveness of manual techniques in bypassing security measures and the urgency of addressing pre-authenticated RCE flaws.
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access.
In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH
*** END OF TRANSMISSION ***