Hackers Exploit Marimo RCE to Steal AWS Credentials and Reach Bastion Host in 8 Seconds

Threat actors have been observed exploiting a critical remote code execution vulnerability in the Marimo notebook platform to steal AWS credentials and authenticate to an SSH bastion host within eight seconds. The attack, documented by the Sysdig Threat Research Team, abused CVE-2026-39987, a pre-authentication remote code execution flaw affecting Marimo versions up to and including […]

This article has been indexed from Cyber Security News

Read the original article: