EventCybersecurityJuly 2, 2026
AI agent JADEPUFFER ran first known ransomware via Langflow bug

JADEPUFFER exploited CVE-2025-3248 (CVSS 9.8) in Langflow to automate reconnaissance, credential theft from AI services and cloud providers, and encryption of production databases. Human operators still chose victims and set up infrastructure (TechCrunch). A subsequent ENCFORGE variant targeted AI model weights and vector databases using stolen cloud credentials.
5 sources
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attackthehackernews.com
The ‘first’ AI-run ransomware attack still needed a humantechcrunch.com
JadePuffer: The First Complete LLM-Driven Ransomware Attackdarkreading.com
Agentic AI Used to Conduct Ransomware Attack via Langflowsecurityweek.com