First Documented In-the-Wild Attack: LLM Agent Autonomously Pivots from Marimo RCE to Internal Database in Four Steps
Sysdig researchers observed the first confirmed in-the-wild use of an LLM agent for post-exploitation โ an attacker exploited a pre-auth RCE in Marimo notebook (CVE-2026-39987), th