News · curated 15 Sep 2026

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

Coverage timeline

discovered sysdig.com primary 15 Sep 2026thehackernews.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Sysdig's profiling shows that agentic threat actors targeting the same Marimo CVE reliably trip honeypot traps that skilled humans avoid, giving defenders a behavioral signal to distinguish and detect autonomous AI attackers.

Sysdig's Threat Research Team reports a skilled human operator exploited a Marimo notebook remote-code-execution flaw (CVE-2026-39987) and pivoted to an SSH bastion host in eight seconds using a hand-written Python toolkit with no AI agent in the loop. The finding is framed as a contrast: the human moved at 'machine speed' and, unlike every agentic threat actor Sysdig profiled against the same CVE, walked straight past a defensive trap those AI agents fell for.