EventCybersecurityJuly 2, 2026
JADEPUFFER AI agent runs first known ransomware attack via Langflow bug

Sysdig researchers identified JADEPUFFER, an AI agent that exploited CVE-2025-3248 in Langflow to break into servers, steal credentials, and encrypt production databases. The attack marks the first known AI-run ransomware, though a human still chose the victim and provided initial access. The same operator later deployed ENCFORGE ransomware targeting AI model files.
5 sources
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attackthehackernews.com
The ‘first’ AI-run ransomware attack still needed a humantechcrunch.com
JadePuffer: The First Complete LLM-Driven Ransomware Attackdarkreading.com
Someone built an AI agent that hacks networks and holds data for ransom. It just worked.reddit.com
More stories today
- Claude video explains why AI hallucinates
- Rubrik AI judge evaluates agent moves but accuracy unverified
- Nvidia is sending GPUs to the Moon
- Gemini nears 1 billion monthly users
- Timnit Gebru critiques rogue machine marketing narratives