# AWS Secrets Manager exploit

Published articles for AWS Secrets Manager exploit.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## AI agent at the wheel: How an attacker used LLMs to move from a CVE to an internal database in 4 pivots

DevFeed: [AI agent at the wheel: How an attacker used LLMs to move from a CVE to an internal database in 4 pivots](<https://devfeed.tech/articles/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots-53195.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots>)

Author: Michael Clark

Published: 2026-05-26T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig Blog](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [CVE-2026-39987](<https://devfeed.tech/topics/cve-2026-39987.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Workers](<https://devfeed.tech/topics/workers.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [adaptive-attacker-ttps](<https://devfeed.tech/tags/adaptive-attacker-ttps.md>), [agent](<https://devfeed.tech/tags/agent.md>), [agent-driven-intrusion-kubernetes](<https://devfeed.tech/tags/agent-driven-intrusion-kubernetes.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-agent-lateral-movement-cloud](<https://devfeed.tech/tags/ai-agent-lateral-movement-cloud.md>), [ai-driven-intrusion](<https://devfeed.tech/tags/ai-driven-intrusion.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-secrets-manager-exploit](<https://devfeed.tech/tags/aws-secrets-manager-exploit.md>), [cloud-api-enumeration](<https://devfeed.tech/tags/cloud-api-enumeration.md>), [cloud-credential-theft](<https://devfeed.tech/tags/cloud-credential-theft.md>), [cloudflare-workers](<https://devfeed.tech/tags/cloudflare-workers.md>), [cloudflare-workers-egress-pool](<https://devfeed.tech/tags/cloudflare-workers-egress-pool.md>), [credential-access-t1552](<https://devfeed.tech/tags/credential-access-t1552.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-39987](<https://devfeed.tech/tags/cve-2026-39987.md>), [egress](<https://devfeed.tech/tags/egress.md>), [exfiltration-via-command-and-scripting-interpreter](<https://devfeed.tech/tags/exfiltration-via-command-and-scripting-interpreter.md>), [falco](<https://devfeed.tech/tags/falco.md>), [llm-agent-attack](<https://devfeed.tech/tags/llm-agent-attack.md>), [llm-assisted-threat-actor](<https://devfeed.tech/tags/llm-assisted-threat-actor.md>), [llm-powered-cyberattack-detection](<https://devfeed.tech/tags/llm-powered-cyberattack-detection.md>), [llms](<https://devfeed.tech/tags/llms.md>), [marimo-notebook-vulnerability](<https://devfeed.tech/tags/marimo-notebook-vulnerability.md>), [marimo-rce-cve-patch](<https://devfeed.tech/tags/marimo-rce-cve-patch.md>), [post-exploitation-automation](<https://devfeed.tech/tags/post-exploitation-automation.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [postgresql-exfiltration](<https://devfeed.tech/tags/postgresql-exfiltration.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [real-time-ai-attack-chain-cloud-environment](<https://devfeed.tech/tags/real-time-ai-attack-chain-cloud-environment.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [ssh-bastion-attack](<https://devfeed.tech/tags/ssh-bastion-attack.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

A Sysdig Threat Research Team investigation describes an intrusion in which an LLM agent drove post-exploitation activity. The attack used CVE-2026-39987, cloud credentials, AWS Secrets Manager, Cloudflare Workers, SSH sessions, and a bastion host to exfiltrate an internal PostgreSQL database in under one hour.

### Source excerpt

A Sysdig TRT investigation reveals their first seen LLM-agent-driven intrusion: from CVE-2026-39987 to internal database exfiltration in under one hour.