# how attackers use LLMs to escape containers

Published articles for how attackers use LLMs to escape containers.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Agentic threat actor hits the orchestration plane: AI agent-driven container escape

DevFeed: [Agentic threat actor hits the orchestration plane: AI agent-driven container escape](<https://devfeed.tech/articles/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape-53193.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape>)

Author: Michael Clark

Published: 2026-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [container escape](<https://devfeed.tech/topics/container-escape.md>), [container](<https://devfeed.tech/topics/container.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [CVE-2026-39987](<https://devfeed.tech/topics/cve-2026-39987.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-attacker-orchestration-plane-takeover](<https://devfeed.tech/tags/agentic-attacker-orchestration-plane-takeover.md>), [agentic-threat-actor](<https://devfeed.tech/tags/agentic-threat-actor.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-driven-container-escape](<https://devfeed.tech/tags/ai-driven-container-escape.md>), [automated-container-escape-kill-chain-2026](<https://devfeed.tech/tags/automated-container-escape-kill-chain-2026.md>), [cloud-native-post-exploitation](<https://devfeed.tech/tags/cloud-native-post-exploitation.md>), [container-escape](<https://devfeed.tech/tags/container-escape.md>), [container-escape-ttps](<https://devfeed.tech/tags/container-escape-ttps.md>), [containers](<https://devfeed.tech/tags/containers.md>), [copy-fail-lpe](<https://devfeed.tech/tags/copy-fail-lpe.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-39987](<https://devfeed.tech/tags/cve-2026-39987.md>), [cve-2026-39987-marimo-exploit](<https://devfeed.tech/tags/cve-2026-39987-marimo-exploit.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-socket-escape](<https://devfeed.tech/tags/docker-socket-escape.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [how-attackers-use-llms-to-escape-containers](<https://devfeed.tech/tags/how-attackers-use-llms-to-escape-containers.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-secret-store-exfiltration](<https://devfeed.tech/tags/kubernetes-secret-store-exfiltration.md>), [kubernetes-service-account-token-abuse-cloud-attack](<https://devfeed.tech/tags/kubernetes-service-account-token-abuse-cloud-attack.md>), [kubernetes-service-account-token-replay](<https://devfeed.tech/tags/kubernetes-service-account-token-replay.md>), [llm](<https://devfeed.tech/tags/llm.md>), [llm-attack-automation](<https://devfeed.tech/tags/llm-attack-automation.md>), [marimo-notebook-rce](<https://devfeed.tech/tags/marimo-notebook-rce.md>), [mounted-docker-socket-container-escape-attack](<https://devfeed.tech/tags/mounted-docker-socket-container-escape-attack.md>), [nsenter-namespace-breakout](<https://devfeed.tech/tags/nsenter-namespace-breakout.md>), [privileged-container-breakout](<https://devfeed.tech/tags/privileged-container-breakout.md>), [rbac-misconfiguration](<https://devfeed.tech/tags/rbac-misconfiguration.md>), [research](<https://devfeed.tech/tags/research.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [t1078-004-valid-accounts-cloud-accounts](<https://devfeed.tech/tags/t1078-004-valid-accounts-cloud-accounts.md>), [t1552-007-container-api-secrets](<https://devfeed.tech/tags/t1552-007-container-api-secrets.md>), [t1610-deploy-container](<https://devfeed.tech/tags/t1610-deploy-container.md>), [t1613-container-and-resource-discovery](<https://devfeed.tech/tags/t1613-container-and-resource-discovery.md>)

### AI overview

Sysdig Threat Research Team reports an LLM-driven threat actor exploiting a vulnerable marimo notebook, escaping a container to the host, and replaying a Kubernetes service-account token to dump the cluster's secrets.

### Source excerpt

Sysdig TRT caught an LLM-driven attacker escaping containers, breaking out to the host, and dumping Kubernetes secrets, no human required.