hacker-news · Crawled Sep 15, 2026

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

5 IoCs 1 CVEs
Read original article ↗

AI Summary

A skilled human threat actor exploited CVE-2026-39987, a pre-authenticated remote code execution vulnerability in Marimo, to gain initial access and pivot to an SSH bastion host within eight seconds. The attacker used a custom, hand-rolled Python toolkit to extract AWS credentials from the compromised instance, retrieve a private SSH key from AWS Secrets Manager, and establish SSH access to a bastion host. Over a nine-hour session, the operator executed more than 850 interactive commands without using known offensive tools, demonstrating high tradecraft and evasion capabilities. The activity highlights the speed and precision achievable by skilled human attackers, even without AI assistance.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 5 extracted

Type Value Detail
IP 172[.]236[.]12[.]17 Details →
IP 188[.]245[.]99[.]156 Details →
IP 47[.]250[.]92[.]230 Details →
IP 34[.]166[.]99[.]116 Details →
IP 20[.]198[.]10[.]42 Details →

MITRE ATT&CK TTPs 16 techniques