Executive Summary

In September 2026, skilled threat actors demonstrated machine-speed exploitation of CVE-2026-39987, a critical remote code execution vulnerability in Marimo notebooks with a CVSS score of 9.3. The attackers pivoted from initial compromise to SSH bastion host access in just eight seconds, using hand-crafted Python toolkits without AI assistance. Over a nine-hour session, they executed over 850 interactive commands, harvested AWS credentials from Secrets Manager, and established persistent access to cloud infrastructure, showcasing how human expertise can rival AI-assisted attacks in speed and stealth.

This incident highlights the evolving threat landscape where skilled human operators are matching the speed traditionally expected from AI-powered attacks, while demonstrating superior evasion techniques that bypass automated defenses and detection systems designed to catch machine-generated attack patterns.

Why This Matters Now

This incident proves that human threat actors can achieve AI-level attack speeds while evading AI-focused defenses, challenging assumptions about automated threat detection and requiring organizations to prepare for hybrid human-AI attack scenarios that combine machine speed with human creativity.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attackers used pre-written Python toolkits and intimate knowledge of AWS infrastructure to pivot from the Marimo vulnerability to SSH bastion access in just 8 seconds, demonstrating expert-level preparation and execution.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of this sophisticated attack by constraining lateral movement paths and limiting access to sensitive AWS resources. The segmentation controls could have restricted the attacker's ability to pivot from the compromised Marimo notebook to the SSH bastion host.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The compromise of the Marimo notebook would likely still occur, but CNSF visibility controls could have provided earlier detection of the WebSocket exploitation and subsequent shell access patterns.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely constrain the scope of AWS service access from the compromised workload, potentially limiting which Secrets Manager resources could be accessed based on workload identity and policy enforcement.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely block or significantly delay the SSH connection to the bastion host by enforcing segmentation policies between the compromised notebook workload and internal infrastructure components.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely detect and flag the sustained outbound SSH connections to external VPS infrastructure, reducing the attacker's ability to maintain covert command channels undetected.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely constrain data exfiltration by enforcing strict outbound connectivity rules and potentially blocking unauthorized data transfers through the SSH tunnel to external destinations.

Impact (Mitigations)

The overall blast radius would likely be reduced to the initially compromised workload and immediately adjacent resources, limiting the attacker's ability to access sensitive production systems or expand their foothold.

Impact at a Glance

Affected Business Functions

  • Cloud Infrastructure Services
  • Application Development Platforms
  • Data Analytics and Notebook Services
  • SSH Bastion Host Management
Operational Disruption

Estimated downtime: 1 days

Financial Impact

Estimated loss: $50,000

Data Exposure

AWS Secrets Manager credentials, SSH private keys, and potential access to bastion host infrastructure with unknown scope of downstream systems

Recommended Actions

  • Implement Zero Trust Segmentation with least privilege access controls to prevent credential harvesting from compromising multiple systems
  • Deploy East-West Traffic Security monitoring to detect and block lateral movement attempts between internal resources
  • Enable Egress Security & Policy Enforcement to prevent unauthorized outbound connections and detect covert channels to external VPS
  • Establish Multicloud Visibility & Control with anomaly detection to identify suspicious interactive sessions and repeated command execution patterns
  • Deploy Inline IPS (Suricata) with updated signatures to detect and block known CVE exploitation attempts like CVE-2026-39987 at network boundaries

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image