Security firm Sysdig has uncovered JADEPUFFER, the first fully autonomous ransomware attack executed end-to-end by an AI agent. Exploiting a critical Langflow vulnerability (CVE-2025-3248), the LLM-driven agent autonomously harvested credentials, moved laterally to a production MySQL and Alibaba Nacos server, and encrypted 1,342 configuration items. The agent demonstrated machine-speed adaptation, correcting a failed login in 31 seconds, and generated self-narrating code payloads.
Sep 28, 2026 · 8 sources
Sep 26, 2026 · 2 sources
Sep 25, 2026 · 4 sources
Sep 25, 2026 · 2 sources
Story comments
Loading comments…