Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Entities

marimo

Incidents implicated systems

Incident 16703 Report
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

2026-05-10

An unidentified attacker reportedly used an LLM agent during a May 10 intrusion after exploiting a vulnerable marimo Python notebook. The agent reportedly reused harvested AWS credentials to obtain an SSH key, then pivoted through a bastion host and exfiltrated the schema and contents of an internal PostgreSQL database. Sysdig attributed the post-compromise command stream to real-time agent execution rather than a prebuilt script.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Threat actors

Incidents involved as Deployer
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

hackers

Incidents involved as Deployer
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Cybercriminals

Incidents involved as Deployer
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Agentic threat actors

Incidents involved as Deployer
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

AI agent system developers

Incidents involved as Developer
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Victims of automated cybercrime

Incidents Harmed By
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Enterprise IT systems

Incidents Harmed By
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Amazon Web Services (AWS) customers

Incidents Harmed By
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Information security

Incidents Harmed By
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Privacy

Incidents Harmed By
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

AI agent systems

Incidents implicated systems
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Large language models

Incidents implicated systems
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • dd3f754