Sysdig’s Threat Research Team has published a detailed report documenting what they describe as the first confirmed live cyberattack in which an autonomous Large Language Model agent executed an entire post-exploitation chain — from initial access to full database exfiltration — without human intervention. The incident, observed on May 10, 2026, marks a significant milestone in the evolution of AI-powered cyber threats.
The attack began with exploitation of CVE-2026-39987, a pre-authenticated remote code execution vulnerability in a publicly exposed Marimo notebook. Once inside, the LLM agent autonomously harvested two cloud credentials, replayed them through a fanned-out egress pool to retrieve an SSH private key from AWS Secrets Manager, opened eight parallel SSH sessions against a bastion host, and exfiltrated an internal PostgreSQL database. The bastion phase took less than two minutes; the entire operation was complete in under an hour.
Sysdig identified four key indicators of agent-driven execution: real-time schema improvisation during the database dump, a leaked Chinese-language planning comment (“看还能做什么” — “See what else we can do”) in the command stream, machine-optimized output formatting, and output-fed-to-input command chaining across four pivots.
Sources
Commentary
This is the moment the cybersecurity community has been warning about. An autonomous AI agent that can chain exploits, improvise around obstacles, and make real-time decisions about lateral movement changes the math on attack speed fundamentally. Traditional security operations — even well-staffed SOCs — are built around human-speed response. When the attacker is a machine that can pivot through four systems in minutes, alert-and-respond workflows are already too slow.
The Chinese-language planning comment is a fascinating forensic artifact that hints at how these agents are configured. Expect threat actors to clean up their agent outputs in future attacks, making attribution even harder. Organizations need to assume that automated, intelligent attack agents are now part of the threat landscape and invest accordingly in runtime detection and automated containment.
