- A skilled human attacker exploited a critical Marimo vulnerability (CVE-2026-39987) to pivot from a vulnerable notebook to an SSH bastion host in just eight seconds, matching the speed of AI-assisted attacks.
- The attacker hand-wrote a custom Python toolkit, bypassing a trap that automated agents typically fall into, and conducted a nine-hour session with over 850 interactive commands.
- Separately, a cryptomining campaign has compromised 3,562 Redis servers, likely via missing authentication, deploying an XMRig miner through SLAVEOF commands.
- The Redis campaign also targeted WordPress sites and attempted MongoDB sandbox escapes, though those methods proved unsuccessful at scale.
New research from Sysdig reveals that a threat actor exploited a critical remote code execution vulnerability in Marimo notebooks to breach a cloud environment and reach an SSH bastion host in just eight seconds, demonstrating that skilled human operators can move at machine speed. The attack, detailed by the cloud security company, targeted CVE-2026-39987 (CVSS score: 9.3) and occurred on September 15, 2026, with the initial foothold gained via a vulnerable Marimo instance.
The attacker’s end-to-end credential-pivot chain involved leveraging the Marimo flaw to gain a full interactive shell, followed by an AWS Secrets Manager call using harvested credentials, and SSH access to a bastion host with a retrieved private key. “Eight seconds is the kind of speed we expect to see in AI-assisted attacks,” the Sysdig Threat Research Team said, noting the operator achieved this on skill alone and walked past a trap that every automated threat actor fell into. Consequently, the entire activity lasted from 12:52 p.m. to 9:50 p.m., during which the attacker issued more than 850 interactive commands, used no recognizable offensive tooling, and hand-rolled scripts in-session.
Meanwhile, Hunt.io disclosed a separate cryptomining campaign that has compromised 3,562 Redis servers, likely following a broad internet sweep of hosts on port 6379. The primary exploitation method uses the SLAVEOF command to deploy an XMRig miner, with confirmed victims spanning Redis versions from 2.8.17 (2015) to 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels. “The toolkit runs four techniques across three services, but only Redis rogue replication worked at scale,” Hunt.io stated, noting that SSH key-injection and MongoDB sandbox-escape returned zero successes across 2,810 attempts. The activity has not been attributed to any known threat actor or group.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
