An attacker exploited a critical, pre-authentication remote-code-execution flaw (CVE-2026-39987) in the open-source Marimo notebook tool, then handed control to an autonomous LLM agent to carry out post-exploitation activity rather than operating a keyboard or a static script. The agent adapted to the environment on its own, extracting cloud credentials, retrieving an SSH private key from AWS Secrets Manager, and opening eight parallel SSH sessions to exfiltrate an internal PostgreSQL database. The entire chain, from initial access to full database exfiltration, ran in under one hour, with the final database-exfiltration phase completed in about two minutes.