Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 2IT Vendor NewsSysdig

Machine Speed, Hold the AI: Hand-Rolled Marimo CVE-2026-39987 Exploit

Sysdig, Friday, September 11th, 2026

Sysdig's threat team breached a cloud bastion host through marimo's CVE-2026-39987 using custom Python, no AI.

Sysdig's Threat Research Team documents a manual attack chain exploiting CVE-2026-39987 in marimo notebooks to breach a cloud bastion host, deliberately using custom Python tooling rather than AI assistance.

The framing is a useful corrective to the current narrative: attacks still run at machine speed without AI involvement, and attributing every fast intrusion to AI misdirects defensive investment.

The write-up includes timestamps, code samples, CloudTrail sequences and detection strategies, making it directly usable for building coverage.

more →  ·  More from Sysdig →