BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Human Hackers Match AI Speed in Eight-Second Marimo Exploit

Human attacker matches AI speed in cloud breach, plus 3,562 Redis servers mined.

  • A skilled human attacker exploited a critical Marimo vulnerability (CVE-2026-39987) to pivot from a vulnerable notebook to an SSH bastion host in just eight seconds, matching the speed of AI-assisted attacks.
  • The attacker hand-wrote a custom Python toolkit, bypassing a trap that automated agents typically fall into, and conducted a nine-hour session with over 850 interactive commands.
  • Separately, a cryptomining campaign has compromised 3,562 Redis servers, likely via missing authentication, deploying an XMRig miner through SLAVEOF commands.
  • The Redis campaign also targeted WordPress sites and attempted MongoDB sandbox escapes, though those methods proved unsuccessful at scale.

New research from Sysdig reveals that a threat actor exploited a critical remote code execution vulnerability in Marimo notebooks to breach a cloud environment and reach an SSH bastion host in just eight seconds, demonstrating that skilled human operators can move at machine speed. The attack, detailed by the cloud security company, targeted CVE-2026-39987 (CVSS score: 9.3) and occurred on September 15, 2026, with the initial foothold gained via a vulnerable Marimo instance.

- Advertisement -

The attacker’s end-to-end credential-pivot chain involved leveraging the Marimo flaw to gain a full interactive shell, followed by an AWS Secrets Manager call using harvested credentials, and SSH access to a bastion host with a retrieved private key. “Eight seconds is the kind of speed we expect to see in AI-assisted attacks,” the Sysdig Threat Research Team said, noting the operator achieved this on skill alone and walked past a trap that every automated threat actor fell into. Consequently, the entire activity lasted from 12:52 p.m. to 9:50 p.m., during which the attacker issued more than 850 interactive commands, used no recognizable offensive tooling, and hand-rolled scripts in-session.

Meanwhile, Hunt.io disclosed a separate cryptomining campaign that has compromised 3,562 Redis servers, likely following a broad internet sweep of hosts on port 6379. The primary exploitation method uses the SLAVEOF command to deploy an XMRig miner, with confirmed victims spanning Redis versions from 2.8.17 (2015) to 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels. “The toolkit runs four techniques across three services, but only Redis rogue replication worked at scale,” Hunt.io stated, noting that SSH key-injection and MongoDB sandbox-escape returned zero successes across 2,810 attempts. The activity has not been attributed to any known threat actor or group.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Justin Sun Prize winners announced but prize details unclear

Justin Sun has spent the past week announcing winners of the Justin Sun Prize,...

OpenAI publishes 722 math papers; only 162 are Lean-verified

OpenAI published 722 math manuscripts on GitHub on Tuesday, all produced by an internal...

Musk claims Indian oligarchs block Starlink launch in India

Elon Musk accused unnamed Indian oligarchs of blocking Starlink's launch to protect a "monopolistic...

SecondFi offers $7.60 per NFT in $21M hack recovery

SecondFi launched a recovery portal for victims of its $21 million Cardano wallet hack,...

Circle brings USDC, EURC payments to SAP via Tereina

Circle partners with SAP-backed Tereina to integrate USDC and EURC stablecoins into enterprise payment...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading