AI-driven attacker escaped container and stole Kubernetes secrets
Sysdig observed an AI-agent-driven attacker enter through a marimo RCE, abuse a mounted Docker socket to reach host root, then reuse a service account token to extract cluster secrets including database, AWS and OpenAI API credentials.
- Disclosed
- May 2026
- Organization
- Undisclosed
- Vendor
- Unknown
- Kind of AI
- Autonomous agent
- AI's role
- Attacker used AI
- How it happened
- AI-run attack: Autonomous intrusion
- Harm
- Data exposed
- Data involved
- Credentials
- Reach
- One organization
- Severity
- High
- Model at fault
- No
- Status
- Confirmed
- Vulnerability IDs
- CVE-2026-39987