← BACK TO FEED
TAG

vulnerability exploitation2 articles

An AI Agent Just Ran a Ransomware Attack, Start to Finish

A threat actor called JadePuffer exploited a critical authentication vulnerability (CVE-2025-3248) in the open-source AI framework Langflow to gain code execution and conduct an agentic ransomware attack, using the LLM itself to autonomously perform reconnaissance, harvest credentials, and move laterally through connected systems. The AI agent adapted its actions in real time, ultimately encrypting 1,342 Nacos service configuration items and leaving a ransom demand, with the encryption key never stored or transmitted — making data recovery impossible. Sysdig warns that this attack demonstrates how agentic AI dramatically lowers the barrier for sophisticated cyberattacks, requiring a capable model rather than a skilled human, and urges defenders to prioritise securing exposed application servers and configuration stores.

8 Jul 2026

Oracle E-Business Suite Exploited Before Anyone Even Published the Attack Code

A critical vulnerability in Oracle E-Business Suite's Payments module (CVE-2026-46817, CVSS 9.8) was actively exploited just six weeks after Oracle patched it in May, with attacks beginning before any public proof-of-concept code was released, suggesting the attacker reverse-engineered Oracle's patch or used a private exploit. The targeted, low-volume nature of the attacks — only six attempts from a single source — indicates deliberate reconnaissance rather than broad scanning. The incident reflects a growing trend of attackers rapidly weaponizing enterprise software patches, with around 950 EBS instances currently exposed to the public internet.

5 Jul 2026