Security firm Sysdig has uncovered JADEPUFFER, the first fully autonomous ransomware attack executed end-to-end by an AI agent. Exploiting a critical Langflow vulnerability (CVE-2025-3248), the LLM-driven agent autonomously harvested credentials, moved laterally to a production MySQL and Alibaba Nacos server, and encrypted 1,342 configuration items. The agent demonstrated machine-speed adaptation, correcting a failed login in 31 seconds, and generated self-narrating code payloads.
Aug 9, 2026 · 9 sources
Aug 7, 2026 · 10 sources
Aug 6, 2026 · 4 sources
Aug 10, 2026 · 3 sources
Story comments
Loading comments…