← BACK TO FEED
TAG

llm security1 articles

An AI Agent Just Ran a Ransomware Attack, Start to Finish

A threat actor called JadePuffer exploited a critical authentication vulnerability (CVE-2025-3248) in the open-source AI framework Langflow to gain code execution and conduct an agentic ransomware attack, using the LLM itself to autonomously perform reconnaissance, harvest credentials, and move laterally through connected systems. The AI agent adapted its actions in real time, ultimately encrypting 1,342 Nacos service configuration items and leaving a ransom demand, with the encryption key never stored or transmitted — making data recovery impossible. Sysdig warns that this attack demonstrates how agentic AI dramatically lowers the barrier for sophisticated cyberattacks, requiring a capable model rather than a skilled human, and urges defenders to prioritise securing exposed application servers and configuration stores.

8 Jul 2026