Human Attacker Exploits Marimo RCE at Machine Speed
Score: 7/10

Human Attacker Exploits Marimo RCE at Machine Speed

A skilled human threat actor exploited a Marimo RCE vulnerability to pivot into an AWS environment in eight seconds, while concurrent campaigns targeted Redis servers for cryptomining and Dahua cameras.

Executive Summary

Recent threat intelligence highlights a high-speed manual exploitation of CVE-2026-39987, a pre-authenticated Remote Code Execution (RCE) flaw in Marimo notebooks. In a notable incident, a human operator transitioned from initial access to an SSH bastion host in just eight seconds—a speed typically associated with automated AI agents. The attacker demonstrated advanced tradecraft by using custom Python scripts and avoiding honeypots to harvest AWS Secrets Manager credentials and establish persistent access via a VPS-hosted listener.

Separately, broad internet sweeps are targeting misconfigured Redis servers to deploy XMRig miners using rogue replication (SLAVEOF command) and SSH key injection. Additionally, 'Operation CameraSwarm' has successfully compromised over 14,000 Dahua IP cameras by leveraging credential brute-forcing and known authentication bypass vulnerabilities. These concurrent activities underscore the persistent threat to exposed cloud services, data science environments, and IoT infrastructure.

Key Details

Threat Name

CVE-2026-39987

Affects

Marimo, Dahua IP cameras

Adversary

—

Malware/Tools

XMRig, Headcrab

Report Score

7out of 10
Quality Score
Good
IOC Quality6
TTP Details7
Detection Guidance4
Enterprise Relevance9
Clarity & Structure8
Technical Depth6

Sources