# human-operated attack

Published articles for human-operated attack.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit

DevFeed: [Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit](<https://devfeed.tech/articles/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit-53246.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit>)

Author: Sysdig Threat Research Team

Published: 2026-09-11T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig Blog](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [CVE-2026-39987](<https://devfeed.tech/topics/cve-2026-39987.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Python](<https://devfeed.tech/topics/python.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [aws-secrets-manager](<https://devfeed.tech/tags/aws-secrets-manager.md>), [bastion-host](<https://devfeed.tech/tags/bastion-host.md>), [cisa-kev](<https://devfeed.tech/tags/cisa-kev.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-credential-theft](<https://devfeed.tech/tags/cloud-credential-theft.md>), [cve-2026-39987](<https://devfeed.tech/tags/cve-2026-39987.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [human-operated-attack](<https://devfeed.tech/tags/human-operated-attack.md>), [llm-driven-attack](<https://devfeed.tech/tags/llm-driven-attack.md>), [marimo-cve-2026-39987](<https://devfeed.tech/tags/marimo-cve-2026-39987.md>), [marimo-rce](<https://devfeed.tech/tags/marimo-rce.md>), [notebook-security](<https://devfeed.tech/tags/notebook-security.md>), [python](<https://devfeed.tech/tags/python.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [remote-code-execution-vulnerability](<https://devfeed.tech/tags/remote-code-execution-vulnerability.md>), [ssh-bastion-host](<https://devfeed.tech/tags/ssh-bastion-host.md>), [sysdig-threat-research-team](<https://devfeed.tech/tags/sysdig-threat-research-team.md>), [websocket-authentication-bypass](<https://devfeed.tech/tags/websocket-authentication-bypass.md>)

### AI overview

Sysdig's Threat Research Team documents a hand-crafted attack exploiting marimo's CVE-2026-39987. The operator used custom Python tooling to obtain remote code execution, access AWS Secrets Manager, retrieve a private key, and reach a bastion host in eight seconds.

### Source excerpt

Sysdig TRT details a hand-rolled attack against marimo's CVE-2026-39987 without AI, building custom Python tools to breach a cloud bastion host.