EventCybersecurityJuly 2, 2026

JADEPUFFER AI agent runs first known ransomware attack via Langflow bug

Sysdig researchers identified JADEPUFFER, an AI agent that exploited CVE-2025-3248 in Langflow to break into servers, steal credentials, and encrypt production databases. The attack marks the first known AI-run ransomware, though a human still chose the victim and provided initial access. The same operator later deployed ENCFORGE ransomware targeting AI model files.

5 sources

More stories today

Open the live feed