A critical Marimo RCE flaw is being exploited to steal AWS credentials and access an SSH bastion host within eight seconds.