Sysdig's JadePuffer case — billed as the first AI-run ransomware attack — is more nuanced than initial headlines suggested. While an AI agent autonomously handled technical execution (exploiting a Langflow vulnerability, moving laterally to a MySQL server, encrypting 1,300+ records, and writing its own ransom note), a human still selected the victim, provisioned infrastructure, and supplied pre-stolen credentials. The agent's speed was notable — fixing a failed login in 31 seconds while narrating its own reasoning. Sysdig could not identify the specific model powering the agent. A Microsoft researcher theorized it used a stripped open-weight model rather than a frontier model, and warned that ransomware campaigns may soon scale to thousands of simultaneous operations, though human bottlenecks in victim selection and infrastructure setup remain a limiting factor for now.

4m read timeFrom techcrunch.com
Post cover image
253 Impressions