May 302026 Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026–39987 Exploit LLM-driven attackers exploited CVE-2026–39987 on May 10, 2026, to steal credentials and exfiltrate a PostgreSQL database.