
Hackers Exploit Marimo RCE to Steal AWS Credentials and Reach Bastion Host in 8 Seconds
Threat actors have been observed exploiting a critical remote code execution vulnerability in the Marimo notebook platform to steal AWS credentials and authenticate to an SSH bastion host within eight seconds. The attack, documented by the Sysdig Threat Research Team, abused CVE-2026-39987, a pre-authentication remote code execution flaw affecting Marimo versions up to and including […]
The post Hackers Exploit Marimo RCE to Steal AWS Credentials and Reach Bastion Host in 8 Seconds appeared first on Cyber Security News.