Marimo notebook and downstream SSH bastion hit by data theft breach
Incident
Updated: 29.05.2026 17:39
· First: 29.05.2026 17:39
· 📰 1 src / 1 articles
· H score: 40
A Marimo notebook compromise led to credential theft, SSH access, and exfiltration of an internal PostgreSQL database, expanding a single initial intrusion into deeper post-compromise access. The intrusion used CVE-2026-39987 to reach a downstream SSH bastion server through harvested cloud credentials and AWS Secrets Manager. The attack chain was recorded on May 10, 2026 and included eight SSH sessions plus database theft completed in under two minutes at the bastion stage.