<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Marimo-Rce on CuraSec</title><link>https://curasec.metacog.co.kr/tags/marimo-rce/</link><description>Recent content in Marimo-Rce on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 15 Sep 2026 15:32:56 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/marimo-rce/index.xml" rel="self" type="application/rss+xml"/><item><title>Human Attacker Pivots from Marimo RCE to SSH Bastion in 8 Seconds</title><link>https://curasec.metacog.co.kr/insights/2026-09-15-human-attacker-exploits-marimo-rce-reaches-ssh-bastion-in-ei/</link><pubDate>Tue, 15 Sep 2026 15:32:56 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-15-human-attacker-exploits-marimo-rce-reaches-ssh-bastion-in-ei/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If Marimo notebooks are exposed in your environment, audit their network isolation and check for available patches; the RCE-to-SSH-bastion pivot path indicates notebook sandboxing deserves review this quarter. Enrichment signals are absent, so no immediate patch-or-burn urgency, but the attack surface is real for data/ML platform teams.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The 8-second lateral movement window from a compromised notebook to a bastion host is a useful calibration point for detection SLA expectations, but the summary provides no IOCs, ATT&amp;amp;CK mappings, or detection guidance to act on immediately.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Sysdig research illustrating that skilled human operators can pivot as quickly as AI-assisted attacks is useful framing for board conversations about mean-time-to-detect targets, but this is not a systemic breach or regulatory event requiring leadership action this week.&lt;/li>
&lt;/ul></description></item></channel></rss>