Security researchers have documented the first confirmed cyberattack driven entirely by an LLM agent - and it moves from initial access to full database exfiltration in under an hour. The Sysdig Threat Research Team (TRT) observed the intrusion on May 10, 2026, recording an AI agent autonomously driving the post-compromise phase of a real-world attack.
Anatomy of the Attack
The chain began with an internet-reachable Marimo notebook - the open-source reactive Python notebook popular for data science and AI workflows. The attacker exploited CVE-2026-39987, a critical pre-authentication remote code execution flaw in Marimo’s /terminal/ws WebSocket endpoint, gaining a full interactive shell. What followed, Sysdig says, bears the behavioral signatures of an LLM agent operating as an autonomous operator rather than a human at a keyboard or a static script.
Four Pivots, Under an Hour
The agent ran the entire engagement in four pivots over roughly one hour:
- Access - an unauthenticated WebSocket connection and immediate shell commands
- Credential harvest - a systematic sweep of environment files, AWS credential stores, and SSH keys yielding two cloud credentials
- AWS pivot - 12
GetSecretValuecalls in 22 seconds, fanned across 11 distinct Cloudflare Workers IPs to defeat source-IP detection, retrieving an SSH private key - Database exfiltration - eight parallel SSH sessions dumped the schema and full contents of an internal PostgreSQL database in under two minutes
The Agent’s Fingerprints
Sysdig identified four signatures that distinguish this intrusion from scripted automation. First, the agent improvised a database dump against an unidentified target, inferring a credential table name that exists in no standard schema. Second, a Chinese-language planning comment - “See what else we can do” - leaked into the command stream mid-attack. Third, every command used machine-optimized formatting: delimiter injection, bounded output, stderr suppression, and HEREDOC batching. Fourth, and most diagnostically, the agent chained outputs from its own prior commands into the next call - lifting the database password from .pgpass and the SecretId from a ListSecrets response.
What This Means for Defenders
The defender-relevant property of an agent-in-the-loop is adaptiveness: a scripted attacker aborts on surprises, while an agent reads the surprise and keeps going. Sysdig’s guidance is blunt - patch Marimo to 0.23.0 or later, rotate any AWS credentials reachable from a Marimo process, and assume an internet-reachable Marimo with credentials on disk is a one-hour pivot device for an agent. This first confirmed case validates that LLM agents can compress post-exploitation from a skill-intensive manual activity into an inference-budget problem, shifting operational complexity from human expertise to compute cost.