EventCybersecurityJuly 2, 2026

AI agent conducts first known automated ransomware attack via Langflow bug

Sysdig's JadePuffer AI agent exploited CVE-2025-3248 in Langflow to gain code execution, then autonomously stole credentials, pivoted to a MySQL database, and encrypted systems. TechCrunch reports a human still chose the victim and set up infrastructure, so it was not fully autonomous.

5 sources

More stories today

Open the live feed