Sysdig's Threat Research Team documented what they describe as the first end-to-end agentic ransomware operation, carried out by an AI agent called JadePuffer. The agent exploited CVE-2025-3248, an RCE vulnerability in a Langflow server, then autonomously harvested credentials, moved laterally to a production MySQL/Nacos server, encrypted 1,342 database records, and left a Bitcoin ransom demand — all without human intervention. The agent executed over 600 payloads, self-diagnosed failures, and adapted tactics in real time. Security experts characterize this as an evolution in execution speed and autonomy rather than a fundamentally new technique, noting that behavioral detection (suspicious identity activity, privilege escalation, lateral movement) remains the key defensive priority.

4m read timeFrom csoonline.com
Post cover image
115 Impressions