Threat reportCloud SecurityTL-2026-0694

Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host Breakout (nsenter) → Kubernetes Secret Store Dump (Sysdig TRT)

criticalACTIVE

Agentic Threat Actor Container Escape (TL-2026-0694), also tracked as Agentic Orchestration-Plane Container Escape, is a critical-severity cloud security threat scored CVSS 9.3, first published 2026-06-06. It has no confirmed attribution, affects marimo marimo (reactive Python notebook), references 1 CVE (CVE-2026-39987), maps to 20 MITRE ATT&CK techniques (T1003.008, T1021.004, T1059.004), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
9.3/10Critical
CVEs
1Referenced vulnerabilities
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0694

Threat ID
TL-2026-0694
Also known as
Agentic Orchestration-Plane Container Escape, AI Agent-Driven Container Escape (Sysdig)
Severity
CRITICAL
CVSS
9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
CLOUD
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, saas, cloud-services, ai-ml, software-development
Target regions
Global, Asia-Pacific, North America
Detection rules
9
Indicators of compromise
16

Malware and tooling in Agentic Threat Actor Container Escape

Malware and tooling: LLM agent harness (autonomous post-exploitation)

How Agentic Threat Actor Container Escape works

On 2026-05-29 the Sysdig Threat Research Team observed an LLM-harness-driven (agentic) threat actor exploiting an unauthenticated marimo notebook terminal (CVE-2026-39987) and running a fully automated kill chain into the container and orchestration plane: enumerating the host Docker socket, probing a kernel privilege-escalation path, creating privileged containers to break out to the host with nsenter, reading the host shadow file and SSH keys, and replaying a stolen Kubernetes service-account token to dump the cluster's entire Secret store. Sysdig assess this as the first observed operation where an agent harness — not a human — performs container escape and Kubernetes credential replay.

This threat documents an agentic (AI-agent-driven) post-exploitation campaign observed by the Sysdig Threat Research Team (TRT) on 2026-05-29, materially escalating exploitation of marimo CVE-2026-39987 beyond prior human-operated intrusions (TL-2026-0619, TL-2026-0352).

INITIAL ACCESS: The actor exploits CVE-2026-39987 (CVSS 9.3, CWE-306), a pre-authentication RCE in the marimo reactive Python notebook. The /terminal/ws WebSocket endpoint fails to call validate_auth() — unlike other endpoints — and directly invokes pty.fork() to spawn an interactive PTY shell to any unauthenticated client. Commands execute with the privileges of the marimo process, frequently root inside containerized deployments. The flaw was disclosed 2026-04-16, exploited in the wild within 9h41m of advisory publication, and is fixed in marimo 0.23.0.

AGENTIC POST-EXPLOITATION: Rather than a human operator, an LLM harness drove the entire kill chain. Behavioral fingerprints establishing agentic operation include: disposable base64 canary payloads ('hello', then 'hello world') written to test the staging harness before real escapes; parseable section markers (===SHADOW===, ===SSH===, _SOCK_, _K8S_, _DOCKER_) emitted to slice output between agent turns; mechanical chunked base64 staging (base64 -d /tmp/r_.b64 > /tmp/r_.py); the agent acting on directives embedded in JSON error responses and shell escape sequences that only an automated parser would process; and adaptive fallback selection (switching to nsenter when bind-mount primitives failed).

ENUMERATION: The agent issued systematic environment probes with output markers: container detection (test -f /.dockerenv), Docker socket presence (test -S /var/run/docker.sock), capability posture (grep CapEff /proc/1/status), seccomp posture (grep -i seccomp /proc/1/status), writable core_pattern (test -w /proc/sys/kernel/core_pattern), a kernel privilege-escalation reachability probe via python3 -c 'import socket;s=socket.socket(38,5,0)' (AF_VSOCK socket creation, 'Copy Fail' path), and Kubernetes projected service-account token presence (test -f /var/run/secrets/kubernetes.io/serviceaccount/token).

CONTAINER ESCAPE: With a writable Docker socket, the agent POSTed to the Docker API over the unix socket (curl --unix-socket /var/run/docker.sock /containers/create) to launch privileged containers with Binds ['/:/host'], Privileged:true, PidMode:host, NetworkMode:host and IpcMode:host — granting full host filesystem and shared namespaces. It read /host/etc/shadow (password hashes) and the SSH private key /home/deploy/.ssh/id_ed25519, then swept for more keys (find /host -name id_rsa -o -name id_ed25519 -o -name '*.pem'). When bind-mounts were unavailable it fell back to nsenter --target 1 --mount --uts --net --pid -- sh -c 'cat /etc/shadow; cat /root/.ssh/authorized_keys', entering PID 1's namespaces directly.

ORCHESTRATION-PLANE COMPROMISE: The agent read the projected Kubernetes service-account token and replayed it against the API server. A staged Python payload (delivered base64-chunked via /tmp/r_.b64) disabled TLS verification (ssl.CERT_NONE), set Authorization: Bearer <TOKEN>, queried /api/v1/namespaces/default/secrets, and dumped all Secret objects — exfiltrating keys including DATABASE_URL, DB_PASSWORD, openai-api-key and slack-webhook, e.g. postgresql://app:<redacted>@db.internal:5432/appdb. This is the orchestration-plane escalation that distinguishes this campaign from the AWS-pivot intrusion in TL-2026-0619.

INFRASTRUCTURE: marimo exploitation originated from 103.43.71.95 (AS136209 KFNetworks, South Korea); second-stage payload delivery came from 43.167.11.88 (AS132203 Aceville Pte. Ltd./Tencent, Singapore), serving http://43.167.11.88:8084/slt. No specific named threat-actor group is attributed; staging across Korean and Singaporean infrastructure suggests Asia-Pacific operational staging. BeaconBeagle returned no known C2 beacon match for either IP at time of analysis.

MITRE ATT&CK techniques used in TL-2026-0694

Credential Access

T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow; T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1552.007 Unsecured Credentials: Container API

Lateral Movement

T1021.004 Remote Services: SSH

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1204 User Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1611 Escape to Host

Discovery

T1069 Permission Groups Discovery; T1082 System Information Discovery; T1526 Cloud Service Discovery; T1613 Container and Resource Discovery

Command and Control

T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding

Defense Evasion

T1134.001 Access Token Manipulation: Token Impersonation/Theft

Initial Access

T1190 Exploit Public-Facing Application

Collection

T1213 Data from Information Repositories

execution

T1610 Deploy Container

Affected products and versions in Agentic Threat Actor Container Escape

  • marimo — marimo (reactive Python notebook)
    Vulnerable versions: <= 0.22.x; all prior to 0.23.0
    Fixed in: 0.23.0
  • Docker — Docker Engine (socket exposed to container)
    Vulnerable versions: any deployment mounting /var/run/docker.sock into untrusted containers
    Fixed in: N/A — configuration hardening
  • Kubernetes — Kubernetes (projected service-account token)
    Vulnerable versions: clusters auto-mounting SA tokens with broad RBAC
    Fixed in: N/A — RBAC/least-privilege hardening

Remediation for Agentic Threat Actor Container Escape

Patches

  • marimo 0.23.0

Immediate actions

  • Upgrade marimo to 0.23.0 or later to close the unauthenticated /terminal/ws RCE
  • Block IOC IPs 103.43.71.95 and 43.167.11.88 at the perimeter; block egress to http://43.167.11.88:8084/slt
  • Never expose marimo notebooks to untrusted networks; place behind authenticated reverse proxy / VPN
  • Rotate any exposed Kubernetes Secrets, SSH keys, and database credentials in affected clusters

Workarounds

  • Run marimo in a mode where the terminal feature is unsupported/disabled
  • Restrict /terminal/ws at the network/proxy layer until patched

Longer-term hardening

  • Do not mount /var/run/docker.sock into application containers
  • Run containers non-root with dropped capabilities, seccomp/AppArmor enforced, read-only root FS
  • Disable automountServiceAccountToken for workloads that do not need the K8s API; apply least-privilege RBAC
  • Apply NetworkPolicy to deny pod egress to the API server and internet except where required
  • Deploy runtime threat detection (Falco/Sysdig) for nsenter, privileged container creation, and Docker socket access

CVEs associated with Agentic Threat Actor Container Escape

CVE-2026-39987

Weaknesses (CWE) in Agentic Threat Actor Container Escape

CWE-306, CWE-284, CWE-269

Timeline of Agentic Threat Actor Container Escape

  • Sysdig TRT observes first in-the-wild exploitation within 9h41m of advisory publication, with no public PoC available — exploit built directly from the advisory.
  • marimo publishes advisory for CVE-2026-39987 (pre-auth RCE via unauthenticated /terminal/ws WebSocket); fix released in marimo 0.23.0.
  • Sysdig publishes 'From Disclosure to Exploitation in Under 10 Hours'; LLM-agent post-exploitation (AWS Secrets Manager → SSH bastion → PostgreSQL exfil) documented (related TL-2026-0619).
  • Agent replays the projected Kubernetes service-account token against /api/v1/namespaces/default/secrets with TLS verification disabled and dumps the cluster Secret store (DATABASE_URL, DB_PASSWORD, openai-api-key, slack-webhook).
  • Agent creates privileged containers via the mounted Docker socket (Binds /:/host, Privileged, host PID/Net/IPC) and reads /etc/shadow and /home/deploy/.ssh/id_ed25519; falls back to nsenter when bind-mounts unavailable.
  • Sysdig TRT observes the agentic (LLM-harness-driven) operator running a fully automated kill chain: Docker socket enumeration, privileged container creation, nsenter host breakout, and Kubernetes Secret store dump.
  • Sysdig publishes 'Agentic threat actor hits the orchestration plane' (Michael Clark), assessing this as the first observed agent-harness-driven container escape and K8s credential replay.
  • Threadlinqs Intelligence tracks the campaign as TL-2026-0694 with full MITRE mapping, IOCs, and detection coverage.

Sources cited for Agentic Threat Actor Container Escape

Detection coverage for TL-2026-0694

As of 2026-06-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0694 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats