BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Human Hackers Match AI Speed in Eight-Second Marimo Exploit

Human attacker matches AI speed in cloud breach, plus 3,562 Redis servers mined.

  • A skilled human attacker exploited a critical Marimo vulnerability (CVE-2026-39987) to pivot from a vulnerable notebook to an SSH bastion host in just eight seconds, matching the speed of AI-assisted attacks.
  • The attacker hand-wrote a custom Python toolkit, bypassing a trap that automated agents typically fall into, and conducted a nine-hour session with over 850 interactive commands.
  • Separately, a cryptomining campaign has compromised 3,562 Redis servers, likely via missing authentication, deploying an XMRig miner through SLAVEOF commands.
  • The Redis campaign also targeted WordPress sites and attempted MongoDB sandbox escapes, though those methods proved unsuccessful at scale.

New research from Sysdig reveals that a threat actor exploited a critical remote code execution vulnerability in Marimo notebooks to breach a cloud environment and reach an SSH bastion host in just eight seconds, demonstrating that skilled human operators can move at machine speed. The attack, detailed by the cloud security company, targeted CVE-2026-39987 (CVSS score: 9.3) and occurred on September 15, 2026, with the initial foothold gained via a vulnerable Marimo instance.

- Advertisement -

The attacker’s end-to-end credential-pivot chain involved leveraging the Marimo flaw to gain a full interactive shell, followed by an AWS Secrets Manager call using harvested credentials, and SSH access to a bastion host with a retrieved private key. “Eight seconds is the kind of speed we expect to see in AI-assisted attacks,” the Sysdig Threat Research Team said, noting the operator achieved this on skill alone and walked past a trap that every automated threat actor fell into. Consequently, the entire activity lasted from 12:52 p.m. to 9:50 p.m., during which the attacker issued more than 850 interactive commands, used no recognizable offensive tooling, and hand-rolled scripts in-session.

Meanwhile, Hunt.io disclosed a separate cryptomining campaign that has compromised 3,562 Redis servers, likely following a broad internet sweep of hosts on port 6379. The primary exploitation method uses the SLAVEOF command to deploy an XMRig miner, with confirmed victims spanning Redis versions from 2.8.17 (2015) to 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels. “The toolkit runs four techniques across three services, but only Redis rogue replication worked at scale,” Hunt.io stated, noting that SSH key-injection and MongoDB sandbox-escape returned zero successes across 2,810 attempts. The activity has not been attributed to any known threat actor or group.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

ARK Sells 1.5M Bitcoin ETF Shares Ahead of Senate Vote

Cathie Wood's Ark Invest sold over 1.5 million shares of its own ARK 21Shares...

DeFi pioneer Balancer considers wind down after hack struggles

Balancer Labs CEO Marcus Hardt has proposed a phased sunset of the protocol after...

US House crypto tax bill omits mining reward deferral

The House Ways and Means Committee will consider H.R. 10357 on Wednesday, omitting a...

Fantom Operations Ltd fires Michael Kong, no further role

Fantom Operations Ltd has officially terminated its relationship with Michael Kong, effective immediately.Kong is...

LiteSpeed Flaw Lets Low-Privilege Users Get Root Access on Shared Hosts

A critical vulnerability in LiteSpeed Web Server Enterprise could allow low-privilege users to gain...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading