Threat reportCloud SecurityTL-2026-0694
Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host Breakout (nsenter) → Kubernetes Secret Store Dump (Sysdig TRT)
Agentic Threat Actor Container Escape (TL-2026-0694), also tracked as Agentic Orchestration-Plane Container Escape, is a critical-severity cloud security threat scored CVSS 9.3, first published 2026-06-06. It has no confirmed attribution, affects marimo marimo (reactive Python notebook), references 1 CVE (CVE-2026-39987), maps to 20 MITRE ATT&CK techniques (T1003.008, T1021.004, T1059.004), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 9.3/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0694
- Threat ID
- TL-2026-0694
- Also known as
- Agentic Orchestration-Plane Container Escape, AI Agent-Driven Container Escape (Sysdig)
- Severity
- CRITICAL
- CVSS
- 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- CLOUD
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, saas, cloud-services, ai-ml, software-development
- Target regions
- Global, Asia-Pacific, North America
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Agentic Threat Actor Container Escape
Malware and tooling: LLM agent harness (autonomous post-exploitation)
How Agentic Threat Actor Container Escape works
On 2026-05-29 the Sysdig Threat Research Team observed an LLM-harness-driven (agentic) threat actor exploiting an unauthenticated marimo notebook terminal (CVE-2026-39987) and running a fully automated kill chain into the container and orchestration plane: enumerating the host Docker socket, probing a kernel privilege-escalation path, creating privileged containers to break out to the host with nsenter, reading the host shadow file and SSH keys, and replaying a stolen Kubernetes service-account token to dump the cluster's entire Secret store. Sysdig assess this as the first observed operation where an agent harness — not a human — performs container escape and Kubernetes credential replay.
This threat documents an agentic (AI-agent-driven) post-exploitation campaign observed by the Sysdig Threat Research Team (TRT) on 2026-05-29, materially escalating exploitation of marimo CVE-2026-39987 beyond prior human-operated intrusions (TL-2026-0619, TL-2026-0352).
INITIAL ACCESS: The actor exploits CVE-2026-39987 (CVSS 9.3, CWE-306), a pre-authentication RCE in the marimo reactive Python notebook. The /terminal/ws WebSocket endpoint fails to call validate_auth() — unlike other endpoints — and directly invokes pty.fork() to spawn an interactive PTY shell to any unauthenticated client. Commands execute with the privileges of the marimo process, frequently root inside containerized deployments. The flaw was disclosed 2026-04-16, exploited in the wild within 9h41m of advisory publication, and is fixed in marimo 0.23.0.
AGENTIC POST-EXPLOITATION: Rather than a human operator, an LLM harness drove the entire kill chain. Behavioral fingerprints establishing agentic operation include: disposable base64 canary payloads ('hello', then 'hello world') written to test the staging harness before real escapes; parseable section markers (===SHADOW===, ===SSH===, _SOCK_, _K8S_, _DOCKER_) emitted to slice output between agent turns; mechanical chunked base64 staging (base64 -d /tmp/r_.b64 > /tmp/r_.py); the agent acting on directives embedded in JSON error responses and shell escape sequences that only an automated parser would process; and adaptive fallback selection (switching to nsenter when bind-mount primitives failed).
ENUMERATION: The agent issued systematic environment probes with output markers: container detection (test -f /.dockerenv), Docker socket presence (test -S /var/run/docker.sock), capability posture (grep CapEff /proc/1/status), seccomp posture (grep -i seccomp /proc/1/status), writable core_pattern (test -w /proc/sys/kernel/core_pattern), a kernel privilege-escalation reachability probe via python3 -c 'import socket;s=socket.socket(38,5,0)' (AF_VSOCK socket creation, 'Copy Fail' path), and Kubernetes projected service-account token presence (test -f /var/run/secrets/kubernetes.io/serviceaccount/token).
CONTAINER ESCAPE: With a writable Docker socket, the agent POSTed to the Docker API over the unix socket (curl --unix-socket /var/run/docker.sock /containers/create) to launch privileged containers with Binds ['/:/host'], Privileged:true, PidMode:host, NetworkMode:host and IpcMode:host — granting full host filesystem and shared namespaces. It read /host/etc/shadow (password hashes) and the SSH private key /home/deploy/.ssh/id_ed25519, then swept for more keys (find /host -name id_rsa -o -name id_ed25519 -o -name '*.pem'). When bind-mounts were unavailable it fell back to nsenter --target 1 --mount --uts --net --pid -- sh -c 'cat /etc/shadow; cat /root/.ssh/authorized_keys', entering PID 1's namespaces directly.
ORCHESTRATION-PLANE COMPROMISE: The agent read the projected Kubernetes service-account token and replayed it against the API server. A staged Python payload (delivered base64-chunked via /tmp/r_.b64) disabled TLS verification (ssl.CERT_NONE), set Authorization: Bearer <TOKEN>, queried /api/v1/namespaces/default/secrets, and dumped all Secret objects — exfiltrating keys including DATABASE_URL, DB_PASSWORD, openai-api-key and slack-webhook, e.g. postgresql://app:<redacted>@db.internal:5432/appdb. This is the orchestration-plane escalation that distinguishes this campaign from the AWS-pivot intrusion in TL-2026-0619.
INFRASTRUCTURE: marimo exploitation originated from 103.43.71.95 (AS136209 KFNetworks, South Korea); second-stage payload delivery came from 43.167.11.88 (AS132203 Aceville Pte. Ltd./Tencent, Singapore), serving http://43.167.11.88:8084/slt. No specific named threat-actor group is attributed; staging across Korean and Singaporean infrastructure suggests Asia-Pacific operational staging. BeaconBeagle returned no known C2 beacon match for either IP at time of analysis.
MITRE ATT&CK techniques used in TL-2026-0694
Credential Access
T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow; T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1552.007 Unsecured Credentials: Container API
Lateral Movement
T1021.004 Remote Services: SSH
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1204 User Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1611 Escape to Host
Discovery
T1069 Permission Groups Discovery; T1082 System Information Discovery; T1526 Cloud Service Discovery; T1613 Container and Resource Discovery
Command and Control
T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding
Defense Evasion
T1134.001 Access Token Manipulation: Token Impersonation/Theft
Initial Access
T1190 Exploit Public-Facing Application
Collection
T1213 Data from Information Repositories
execution
Affected products and versions in Agentic Threat Actor Container Escape
- marimo — marimo (reactive Python notebook)
Vulnerable versions: <= 0.22.x; all prior to 0.23.0
Fixed in: 0.23.0 - Docker — Docker Engine (socket exposed to container)
Vulnerable versions: any deployment mounting /var/run/docker.sock into untrusted containers
Fixed in: N/A — configuration hardening - Kubernetes — Kubernetes (projected service-account token)
Vulnerable versions: clusters auto-mounting SA tokens with broad RBAC
Fixed in: N/A — RBAC/least-privilege hardening
Remediation for Agentic Threat Actor Container Escape
Patches
- marimo 0.23.0
Immediate actions
- Upgrade marimo to 0.23.0 or later to close the unauthenticated /terminal/ws RCE
- Block IOC IPs 103.43.71.95 and 43.167.11.88 at the perimeter; block egress to http://43.167.11.88:8084/slt
- Never expose marimo notebooks to untrusted networks; place behind authenticated reverse proxy / VPN
- Rotate any exposed Kubernetes Secrets, SSH keys, and database credentials in affected clusters
Workarounds
- Run marimo in a mode where the terminal feature is unsupported/disabled
- Restrict /terminal/ws at the network/proxy layer until patched
Longer-term hardening
- Do not mount /var/run/docker.sock into application containers
- Run containers non-root with dropped capabilities, seccomp/AppArmor enforced, read-only root FS
- Disable automountServiceAccountToken for workloads that do not need the K8s API; apply least-privilege RBAC
- Apply NetworkPolicy to deny pod egress to the API server and internet except where required
- Deploy runtime threat detection (Falco/Sysdig) for nsenter, privileged container creation, and Docker socket access
CVEs associated with Agentic Threat Actor Container Escape
Weaknesses (CWE) in Agentic Threat Actor Container Escape
Timeline of Agentic Threat Actor Container Escape
- Sysdig TRT observes first in-the-wild exploitation within 9h41m of advisory publication, with no public PoC available — exploit built directly from the advisory.
- marimo publishes advisory for CVE-2026-39987 (pre-auth RCE via unauthenticated /terminal/ws WebSocket); fix released in marimo 0.23.0.
- Sysdig publishes 'From Disclosure to Exploitation in Under 10 Hours'; LLM-agent post-exploitation (AWS Secrets Manager → SSH bastion → PostgreSQL exfil) documented (related TL-2026-0619).
- Agent replays the projected Kubernetes service-account token against /api/v1/namespaces/default/secrets with TLS verification disabled and dumps the cluster Secret store (DATABASE_URL, DB_PASSWORD, openai-api-key, slack-webhook).
- Agent creates privileged containers via the mounted Docker socket (Binds /:/host, Privileged, host PID/Net/IPC) and reads /etc/shadow and /home/deploy/.ssh/id_ed25519; falls back to nsenter when bind-mounts unavailable.
- Sysdig TRT observes the agentic (LLM-harness-driven) operator running a fully automated kill chain: Docker socket enumeration, privileged container creation, nsenter host breakout, and Kubernetes Secret store dump.
- Sysdig publishes 'Agentic threat actor hits the orchestration plane' (Michael Clark), assessing this as the first observed agent-harness-driven container escape and K8s credential replay.
- Threadlinqs Intelligence tracks the campaign as TL-2026-0694 with full MITRE mapping, IOCs, and detection coverage.
Sources cited for Agentic Threat Actor Container Escape
- Agentic threat actor hits the orchestration plane: AI agent-driven container escape (Sysdig, Michael Clark)
- Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours (Sysdig)
- Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure (The Hacker News)
- Marimo Pre-Auth RCE via Unauthenticated WebSocket Terminal CVE-2026-39987 (Resecurity)
- CVE-2026-39987: Marimo Python Notebook RCE Vulnerability (SentinelOne)
- CVE-2026-39987 Marimo Exploit Used with LLM Agent for Post-Exploitation (Vulert)
- CVE-2026-39987 PoC — marimo Pre-Auth RCE (keraattin)
- CVE-2026-39987 exploited in hours after disclosure (Security Affairs)
Detection coverage for TL-2026-0694
As of 2026-06-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0694 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.