Description: An unidentified attacker reportedly used an LLM agent during a May 10 intrusion after exploiting a vulnerable marimo Python notebook. The agent reportedly reused harvested AWS credentials to obtain an SSH key, then pivoted through a bastion host and exfiltrated the schema and contents of an internal PostgreSQL database. Sysdig attributed the post-compromise command stream to real-time agent execution rather than a prebuilt script.
Entities
View all entitiesAlleged: Large language model developers and AI agent system developers developed an AI system deployed by Threat actors , hackers , Cybercriminals , AI agent system deployers and Agentic threat actors, which harmed Victims of automated cybercrime , Enterprise IT systems , Amazon Web Services (AWS) customers , Information security and Privacy.
Alleged implicated AI systems: AI agent systems , Large language models , Amazon Web Services (AWS) , Amazon Web Services (AWS) cloud infrastructure and marimo
Incident Stats
Incident ID
1670
Report Count
3
Incident Date
2026-05-10
Editors
Daniel Atherton
Incident Reports
Reports Timeline
Loading...
Key Findings
- An LLM agent executed the post-compromise actions in real time rather than running a pre-built playbook. This is the first AI-agent-driven intrusion the Sysdig TRT has captured.
- The full attack chain --- marimo notebook compro…
Loading...
AIID editor's note: Please visit the original source for the full report.
Researchers discovered an intrusion conducted by a large language model (LLM) agent while it was in the post-exploitation phase. According to the researchers, this cy…
Loading...
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclos…
Variants
A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?