AI agent went from marimo notebook exploit to full database dump in under an hour
Sysdig observed an LLM-driven intrusion that exploited an internet-facing marimo notebook, harvested cloud credentials, pulled an SSH key from AWS Secrets Manager and exfiltrated a full PostgreSQL database through four pivots in under an hour, without pre-written scripts.
- Disclosed
- May 2026
- Organization
- Undisclosed
- Vendor
- Unknown
- Kind of AI
- Autonomous agent
- AI's role
- Attacker used AI
- How it happened
- AI-run attack: Autonomous intrusion
- Harm
- Data exposed
- Data involved
- Credentials, Unknown
- Reach
- One organization
- Severity
- High
- Model at fault
- No
- Status
- Confirmed
- Vulnerability IDs
- CVE-2026-39987