Sev0AI security incidents, tracked

All incidents / AI-run attack

AI agent went from marimo notebook exploit to full database dump in under an hour

Undisclosed, disclosed May 2026. AI-run attack Data exposed High

Sysdig observed an LLM-driven intrusion that exploited an internet-facing marimo notebook, harvested cloud credentials, pulled an SSH key from AWS Secrets Manager and exfiltrated a full PostgreSQL database through four pivots in under an hour, without pre-written scripts.

Disclosed
May 2026
Organization
Undisclosed
Vendor
Unknown
Kind of AI
Autonomous agent
AI's role
Attacker used AI
How it happened
AI-run attack: Autonomous intrusion
Harm
Data exposed
Data involved
Credentials, Unknown
Reach
One organization
Severity
High
Model at fault
No
Status
Confirmed
Vulnerability IDs
CVE-2026-39987

Sources

  1. https://www.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "AI agent went from marimo notebook exploit to full database dump in under an hour", https://sev0.fyi/incidents/2026-05-01-sysdig-marimo-agent-database-theft/