Machine Speed, Hold the AI: Hand-Rolled Marimo CVE-2026-39987 Exploit
Sysdig, Friday, September 11th, 2026
Sysdig's threat team breached a cloud bastion host through marimo's CVE-2026-39987 using custom Python, no AI.
Sysdig's Threat Research Team documents a manual attack chain exploiting CVE-2026-39987 in marimo notebooks to breach a cloud bastion host, deliberately using custom Python tooling rather than AI assistance.
The framing is a useful corrective to the current narrative: attacks still run at machine speed without AI involvement, and attributing every fast intrusion to AI misdirects defensive investment.
The write-up includes timestamps, code samples, CloudTrail sequences and detection strategies, making it directly usable for building coverage.