hacker-news · Crawled Sep 15, 2026
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
5 IoCs 1 CVEs
Read original article ↗
AI Summary
A skilled human threat actor exploited CVE-2026-39987, a pre-authenticated remote code execution vulnerability in Marimo, to gain initial access and pivot to an SSH bastion host within eight seconds. The attacker used a custom, hand-rolled Python toolkit to extract AWS credentials from the compromised instance, retrieve a private SSH key from AWS Secrets Manager, and establish SSH access to a bastion host. Over a nine-hour session, the operator executed more than 850 interactive commands without using known offensive tools, demonstrating high tradecraft and evasion capabilities. The activity highlights the speed and precision achievable by skilled human attackers, even without AI assistance.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 5 extracted
MITRE ATT&CK TTPs 16 techniques
T1021 Remote Services · Lateral Movement T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1090 Proxy · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1210 Exploitation of Remote Services · Lateral Movement T1220 XSL Script Processing · Defense Evasion T1484 Domain or Tenant Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1566 Phishing · Initial Access T1588.001 Malware · Resource Development T1659 Content Injection · Initial Access