Marimo RCE Turns AI Agents Into Intruders
Attackers exploited Marimo CVE-2026-39987 on an exposed notebook, then used an LLM agent to chase cloud credentials, an SSH key, and database access. Patch Marimo, remove public exposure, and rotate cloud, API, and SSH keys.