
Sysdig’s threat research team documented what appears to be the first in-the-wild intrusion driven end-to-end by an autonomous LLM agent. On May 10, the agent exploited CVE-2026-39987, a pre-auth RCE in exposed marimo notebook servers, then without human direction between steps harvested two cloud credentials, fanned API calls through an egress pool to dodge rate limits, pulled an SSH private key from AWS Secrets Manager, pivoted to a bastion host, and exfiltrated a full PostgreSQL database in under two minutes. The whole chain ran a little over an hour, and the agent improvised the database dump with no prior knowledge of the schema. AI attackers are not impossible to stop as the tradecraft was noisy and detectable. But the window between detection and understanding is collapsing. When attacks complete in an hour, an investigation that takes a shift to scope credential exposure and lateral movement is a post-mortem, not a response.
