INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Human Attacker Exploits Marimo RCE to Reach SSH Bastion
| 2026-09-08 16:59 MEDIUM HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
On September 15, 2026, a human attacker exploited the CVE-2026-39987 vulnerability in Marimo to gain SSH access to an Amazon Web Services (AWS) bastion host within eight seconds. The attack chain leveraged the pre-authenticated remote code execution flaw to obtain credentials from a compromised instance and then used those credentials to authenticate to the bastion host. Over the course of nine hours, the attacker issued over 850 interactive commands without using recognizable publicly available tooling, instead relying on custom Python scripts written and debugged by hand. The attack highlights the speed and tradecraft of skilled human attackers who can outperform AI-assisted attacks in exploiting vulnerabilities.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2021-33044, CVE-2026-39987 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ay•••••.net
hu•••••.io
so•••••.net
20.198.•••.•••
188.245.•••.•••
47.250.•••.•••
172.236.•••.•••
420c78••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
f90c8b••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation CameraSwarmOperation CameraSwarm
CVE-2021-33044CVE-2021-33044
CVE-2026-39987CVE-2026-39987
CVE-2021-33045CVE-2021-33045
Target & Sectors
Global Scope
Incident Timeline
February 2026
A February 2026 open directory linked by wallet reuse revealed Meterpreter deployment capabilities.
May 7, 2026
Threat actors used the Marimo RCE exploit to target a system with CVE-2026-39987, which was listed on CISA's Known Exploited Vulnerabilities catalog.
Click on any entity below to view its context and source!
attribution
CVE-2026-39987
CVE-2026-39987 has been on CISA's Known Exploited Vulnerabilities (KEV) catalog for months, with a federal remediation deadline of May 7, 2026.
attribution
Known Exploited
CVE-2026-39987 has been on CISA's Known Exploited Vulnerabilities (KEV) catalog for months, with a federal remediation deadline of May 7, 2026.
tactic
T1588.006 - Vulnerabilities
CVE-2026-39987 has been on CISA's Known Exploited Vulnerabilities (KEV) catalog for months, with a federal remediation deadline of May 7, 2026.
attribution
KEV
CVE-2026-39987 has been on CISA's Known Exploited Vulnerabilities (KEV) catalog for months, with a federal remediation deadline of May 7, 2026.
2026/09/08
A human attacker exploited the CVE-2026-39987 Marimo RCE vulnerability to reach an SSH bastion host in just eight seconds.
Click on any entity below to view its context and source!
infrastructure
3,562 Servers
Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files.
Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts.
The findings come as Hunt.io
disclosed details
of a cryptomining campaign that has compromised 3,562 Redis servers likely following a broad internet sweep of candidate Redis hosts on port 6379, while simultaneously launching three parallel pipelines -
WordPress target discovery, which scans a list of HTTPS hosts for WordPress version, installed plugins, and whether XML-RPC or directory list…
organisation
Redis
Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts.
The findings come as Hunt.io
disclosed details
of a cryptomining campaign that has compromised 3,562 Redis servers likely following a broad internet sweep of candidate Redis hosts on port 6379, while simultaneously launching three parallel pipelines -
WordPress target discovery, which scans a list of HTTPS hosts for WordPress version, installed plugins, and whether XML-RPC or directory lis…
infrastructure
12,966 hosts
Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts.
infrastructure
Windows
An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives.
The operation mined Monero through pool.moneroocean.stream with the same wallet used on the operator's own Windows-based work...
data_breach
147 files
An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives.
organisation
SSH
In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH bastion host in eight seconds using a custom Python toolkit they "wrote and debugged by hand" without any AI agent in the loop.
The toolkit also targeted WordPress, MongoDB, and SSH but achieved zero confirmed compromises through those vectors.
A human attacker has moved from a vulnerable Marimo notebook to an SSH bastion host in eight seconds using a toolkit built by hand, hitting a speed usually associated with AI-driven attacks.
infrastructure
Linux
Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities.
"Confirmed victims span Redis 2.8.17 (2015) through 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels, pointing to missing authentication as the weakness rather than a version-specific bug," Hunt.io said.
infrastructure
2.8.17
Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities.
"Confirmed victims span Redis 2.8.17 (2015) through 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels, pointing to missing authentication as the weakness rather than a version-specific bug," Hunt.io said.
infrastructure
7.2.0
Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities.
"Confirmed victims span Redis 2.8.17 (2015) through 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels, pointing to missing authentication as the weakness rather than a version-specific bug," Hunt.io said.
organisation
Ubuntu
"Confirmed victims span Redis 2.8.17 (2015) through 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels, pointing to missing authentication as the weakness rather than a version-specific bug," Hunt.io said.
organisation
WordPress
The toolkit also targeted WordPress, MongoDB, and SSH but achieved zero confirmed compromises through those vectors.
…omining campaign that has compromised 3,562 Redis servers likely following a broad internet sweep of candidate Redis hosts on port 6379, while simultaneously launching three parallel pipelines -
WordPress target discovery, which scans a list of HTTPS hosts for WordPress version, installed plugins, and whether XML-RPC or directory listings are exposed
AOF-based SSH authorized_keys injection…
infrastructure
9.3
The attack chain has been found to exploit
CVE-2026-39987
(CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo that came under active exploitation within hours of public disclosure.
infrastructure
0.20.4
A Human at Machine Speed
CVE-2026-39987 affects Marimo up to and including 0.20.4 and is fixed in 0.23.0.
infrastructure
0.23.0
A Human at Machine Speed
CVE-2026-39987 affects Marimo up to and including 0.20.4 and is fixed in 0.23.0.
infrastructure
47.250.92
…h uses Redis's append-only file (AOF) mode to perform authorized_keys SSH key injection
Lua sandbox-escape probing, which runs Redis EVAL commands and sandbox escape attempts against three hosts ("47.250.92[.]230," "34.166.99[.]116," and "20.198.10[.]42")
The primary exploitation method is the use of the
SLAVEOF command
to smuggle attacker-controlled content onto a target Redis server, r…
infrastructure
34.166.99
…nd-only file (AOF) mode to perform authorized_keys SSH key injection
Lua sandbox-escape probing, which runs Redis EVAL commands and sandbox escape attempts against three hosts ("47.250.92[.]230," "34.166.99[.]116," and "20.198.10[.]42")
The primary exploitation method is the use of the
SLAVEOF command
to smuggle attacker-controlled content onto a target Redis server, resulting in the dep…
infrastructure
20.198.10
…to perform authorized_keys SSH key injection
Lua sandbox-escape probing, which runs Redis EVAL commands and sandbox escape attempts against three hosts ("47.250.92[.]230," "34.166.99[.]116," and "20.198.10[.]42")
The primary exploitation method is the use of the
SLAVEOF command
to smuggle attacker-controlled content onto a target Redis server, resulting in the deployment of an XMRig min…
organisation
HTTPS
…servers likely following a broad internet sweep of candidate Redis hosts on port 6379, while simultaneously launching three parallel pipelines -
WordPress target discovery, which scans a list of HTTPS hosts for WordPress version, installed plugins, and whether XML-RPC or directory listings are exposed
AOF-based SSH authorized_keys injection, which uses Redis's append-only file (AOF) mode t…
organisation
XML-RPC
…hosts on port 6379, while simultaneously launching three parallel pipelines -
WordPress target discovery, which scans a list of HTTPS hosts for WordPress version, installed plugins, and whether XML-RPC or directory listings are exposed
AOF-based SSH authorized_keys injection, which uses Redis's append-only file (AOF) mode to perform authorized_keys SSH key injection
Lua sandbox-escape p…
organisation
CVE-2021-33045
"
In recent months, a single operator was also linked to a massive campaign dubbed
Operation CameraSwarm
that compromised over 14,000 Dahua IP cameras using brute-force attacks, authentication bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a peer-to-peer (P2P) relay technique.
organisation
Operation CameraSwarm
"
In recent months, a single operator was also linked to a massive campaign dubbed
Operation CameraSwarm
that compromised over 14,000 Dahua IP cameras using brute-force attacks, authentication bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a peer-to-peer (P2P) relay technique.
organisation
Dahua IP
"
In recent months, a single operator was also linked to a massive campaign dubbed
Operation CameraSwarm
that compromised over 14,000 Dahua IP cameras using brute-force attacks, authentication bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a peer-to-peer (P2P) relay technique.
infrastructure
14,000 Dahua IP cameras
"
In recent months, a single operator was also linked to a massive campaign dubbed
Operation CameraSwarm
that compromised over 14,000 Dahua IP cameras using brute-force attacks, authentication bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a peer-to-peer (P2P) relay technique.
organisation
Reaches SSH Bastion
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds.
organisation
ATA
"This operator got there on skill alone, and along the way walked straight past a trap that every agentic threat actor (ATA) we've profiled against this same CVE fell into.
organisation
WebSocket
Fresh WebSocket connection
18:57:26: Lookup against the application's stored credential returns the harvested AWS key
18:57:30: SSH authentication observed at the bastion host
The entire activity lasted from 12:52 p.m., when the first WebSocket connection was made from "172.236.12[.]17" to the "/terminal/ws WebSocket endpoint exposed by Marimo, to 9:50 p.m., during which the threat actor…
The flaw is in the terminal WebSocket endpoint, which skipped the authentication check applied to the platform's other WebSocket endpoints, so any client that opened a connection to it got an interactive shell as the Marimo process user with no credentials.
organisation
VPS
…tored credential returns the harvested AWS key
18:57:30: SSH authentication observed at the bastion host
The entire activity lasted from 12:52 p.m., when the first WebSocket connection was made from "172.236.12[.]17" to the "/terminal/ws WebSocket endpoint exposed by Marimo, to 9:50 p.m., during which the threat actor deployed an asyncssh-style listener setup against an attacker-owned VPS.
organisation
GPU
Sysdig said that matters because Marimo notebooks usually run alongside machine learning pipelines, on hosts holding GPU access, large datasets and credentials for AWS, GCP and model providers.
organisation
AWS
Sysdig said that matters because Marimo notebooks usually run alongside machine learning pipelines, on hosts holding GPU access, large datasets and credentials for AWS, GCP and model providers.
organisation
GCP
Sysdig said that matters because Marimo notebooks usually run alongside machine learning pipelines, on hosts holding GPU access, large datasets and credentials for AWS, GCP and model providers.
September 11
Threat actors exploited CVE-2026-39987, a pre-authentication remote code execution flaw in the Marimo notebook platform.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-39987
In a
technical write-up
published on September 11, Sysdig's Threat Research Team said the operator exploited CVE-2026-39987, a pre-authentication remote code execution flaw in the Marimo notebook platform, and showed no sign of using a large language model (LLM) at any stage.
tactic
Remote Code Execution
In a
technical write-up
published on September 11, Sysdig's Threat Research Team said the operator exploited CVE-2026-39987, a pre-authentication remote code execution flaw in the Marimo notebook platform, and showed no sign of using a large language model (LLM) at any stage.
organisation
Sysdig
In a
technical write-up
published on September 11, Sysdig's Threat Research Team said the operator exploited CVE-2026-39987, a pre-authentication remote code execution flaw in the Marimo notebook platform, and showed no sign of using a large language model (LLM) at any stage.
organisation
Threat Research Team
In a
technical write-up
published on September 11, Sysdig's Threat Research Team said the operator exploited CVE-2026-39987, a pre-authentication remote code execution flaw in the Marimo notebook platform, and showed no sign of using a large language model (LLM) at any stage.
organisation
CVE-2026
In a
technical write-up
published on September 11, Sysdig's Threat Research Team said the operator exploited CVE-2026-39987, a pre-authentication remote code execution flaw in the Marimo notebook platform, and showed no sign of using a large language model (LLM) at any stage.
Sep 15, 2026
Threat actors successfully exploited a remote code execution (RCE) vulnerability in the Marimo system to gain unauthorized access.
Tactical Metrics
Metrics
infrastructure
3,562
Servers
Click for context!
Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files.
Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts.
The findings come as Hunt.io
disclosed details
of a cryptomining campaign that has compromised 3,562 Redis servers likely following a broad internet sweep of candidate Redis hosts on port 6379, while simultaneously launching three parallel pipelines -
WordPress target discovery, which scans a list of HTTPS hosts for WordPress version, installed plugins, and whether XML-RPC or directory list…
Metrics
infrastructure
Windows
Affected Product
An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives.
The operation mined Monero through pool.moneroocean.stream with the same wallet used on the operator's own Windows-based work...
Metrics
data_breach
147
Files
An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives.
Metrics
infrastructure
Linux
Affected Product
Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities.
"Confirmed victims span Redis 2.8.17 (2015) through 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels, pointing to missing authentication as the weakness rather than a version-specific bug," Hunt.io said.
Metrics
infrastructure
2.8.17
Software Version
Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities.
"Confirmed victims span Redis 2.8.17 (2015) through 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels, pointing to missing authentication as the weakness rather than a version-specific bug," Hunt.io said.
Metrics
infrastructure
7.2.0
Software Version
Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities.
"Confirmed victims span Redis 2.8.17 (2015) through 7.2.0 (2023) and Linux from EOL RHEL/CentOS 6 to current Ubuntu kernels, pointing to missing authentication as the weakness rather than a version-specific bug," Hunt.io said.
Metrics
infrastructure
12,966
Hosts
Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts.
Metrics
infrastructure
9.3
Software Version
The attack chain has been found to exploit
CVE-2026-39987
(CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo that came under active exploitation within hours of public disclosure.
Metrics
infrastructure
47.250.92
Software Version
…h uses Redis's append-only file (AOF) mode to perform authorized_keys SSH key injection
Lua sandbox-escape probing, which runs Redis EVAL commands and sandbox escape attempts against three hosts ("47.250.92[.]230," "34.166.99[.]116," and "20.198.10[.]42")
The primary exploitation method is the use of the
SLAVEOF command
to smuggle attacker-controlled content onto a target Redis server, r…
Metrics
infrastructure
34.166.99
Software Version
…nd-only file (AOF) mode to perform authorized_keys SSH key injection
Lua sandbox-escape probing, which runs Redis EVAL commands and sandbox escape attempts against three hosts ("47.250.92[.]230," "34.166.99[.]116," and "20.198.10[.]42")
The primary exploitation method is the use of the
SLAVEOF command
to smuggle attacker-controlled content onto a target Redis server, resulting in the dep…
Metrics
infrastructure
20.198.10
Software Version
…to perform authorized_keys SSH key injection
Lua sandbox-escape probing, which runs Redis EVAL commands and sandbox escape attempts against three hosts ("47.250.92[.]230," "34.166.99[.]116," and "20.198.10[.]42")
The primary exploitation method is the use of the
SLAVEOF command
to smuggle attacker-controlled content onto a target Redis server, resulting in the deployment of an XMRig min…
Metrics
infrastructure
14,000
Dahua Ip Cameras
"
In recent months, a single operator was also linked to a massive campaign dubbed
Operation CameraSwarm
that compromised over 14,000 Dahua IP cameras using brute-force attacks, authentication bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a peer-to-peer (P2P) relay technique.
Metrics
infrastructure
0.20.4
Software Version
A Human at Machine Speed
CVE-2026-39987 affects Marimo up to and including 0.20.4 and is fixed in 0.23.0.
Metrics
infrastructure
0.23.0
Software Version
A Human at Machine Speed
CVE-2026-39987 affects Marimo up to and including 0.20.4 and is fixed in 0.23.0.
Intelligence Sources
The Hacker News
2026-09-15
Infosecurity-Magazine
2026-09-14
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
Infosecurity-Magazine
AlienVault OTX
2026-09-08
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-09T06:20
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
Redis
entity
9x
timeline
Temporal Reference
188.245.99.156
date
8x
infrastructure
Software Version
2.8.17
version
6x
tactic
MITRE ATT&CK Technique
T1584.005 - Botnet
technique
4x
attribution
Attributing Entity
Vulnerability /
authority
3x
vulnerability
Exploited CVE
CVE-2026-39987
cve
2x
tactic
Cyber Operation Type
Botnet
tactic
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
10 METRICS
infrastructure
Servers
3,562
servers
data breach
Files
147
files
infrastructure
Hosts
12,966
hosts
general metric
Attack Chain
9
attack chain
general metric
Centos
6
centos
campaign
Campaign
Operation CameraSwarm
operation
infrastructure
Dahua Ip Cameras
14,000
dahua ip cameras
general metric
Sep
15
sep
general metric
Interactive Commands
850
interactive commands
general metric
Attempts
2,810
attempts
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.