Security researchers at Sysdig documented what they describe as the first confirmed real-world intrusion in which an LLM agent independently drove an entire post-exploitation chain. An attacker exploited CVE-2026-39987, an unauthenticated WebSocket flaw in an internet-exposed marimo notebook server, to obtain a shell, then directed an AI agent to harvest cloud credentials, retrieve an SSH key from AWS Secrets Manager, pivot to an internal bastion host, and dump the schema and full contents of a PostgreSQL database. The entire four-pivot chain took under an hour, with the final database exfiltration completed in under two minutes; the agent adapted its commands in real time and routed traffic through eleven Cloudflare Workers IPs to evade detection.