Executive Summary
Recent threat intelligence highlights a high-speed manual exploitation of CVE-2026-39987, a pre-authenticated Remote Code Execution (RCE) flaw in Marimo notebooks. In a notable incident, a human operator transitioned from initial access to an SSH bastion host in just eight seconds—a speed typically associated with automated AI agents. The attacker demonstrated advanced tradecraft by using custom Python scripts and avoiding honeypots to harvest AWS Secrets Manager credentials and establish persistent access via a VPS-hosted listener.
Separately, broad internet sweeps are targeting misconfigured Redis servers to deploy XMRig miners using rogue replication (SLAVEOF command) and SSH key injection. Additionally, 'Operation CameraSwarm' has successfully compromised over 14,000 Dahua IP cameras by leveraging credential brute-forcing and known authentication bypass vulnerabilities. These concurrent activities underscore the persistent threat to exposed cloud services, data science environments, and IoT infrastructure.
