The Sysdig Threat Research Team documented an autonomous AI-driven attacker exploiting a vulnerable marimo notebook to execute a sophisticated kill chain. This operator demonstrated novel capabilities by automating container escape techniques and replaying Kubernetes credentials without human intervention, moving beyond previous agent-driven attacks that targeted cloud services. The attacker leveraged a mounted Docker socket to break out to the host system and subsequently dumped the entire cluster secret store through service account token replay.