CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

September 15, 2026

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds Ravie LakshmananSep 15, 2026Vulnerability / Malware With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH bastion host in eight seconds using a custom Python toolkit they "wrote and debugged by hand" without any AI agent in the loop. "Eight seconds is the kind of speed we expect to see in AI-assisted attacks," the Sysdig Threat Research Team said.…

CVEs: CVE-2026-39987, CVE-2021-33044, CVE-2021-33045