Attackers Use LLM Agent for PostExploitation After Marimo CVE202639987 Exploit
An unknown threat actor has been observed using a large language model LLM agent to conduct postcompromise actions after obtaining initial access following the exploitation of a publiclyaccessible Marimo network using a recently disclosed vulnerability The attacker compromised an internetreachable Marimo notebook via CVE202639987 extracted two cloud credentials from the compromised