EventCybersecurityJuly 2, 2026
AI agent conducts first known automated ransomware attack via Langflow bug

Sysdig's JadePuffer AI agent exploited CVE-2025-3248 in Langflow to gain code execution, then autonomously stole credentials, pivoted to a MySQL database, and encrypted systems. TechCrunch reports a human still chose the victim and set up infrastructure, so it was not fully autonomous.
5 sources
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attackthehackernews.com
The ‘first’ AI-run ransomware attack still needed a humantechcrunch.com
Agentic AI Used to Conduct Ransomware Attack via Langflowsecurityweek.com
JadePuffer: The First Complete LLM-Driven Ransomware Attackdarkreading.com
Someone built an AI agent that hacks networks and holds data for ransom. It just worked.reddit.com
More stories today
- Moody's: AI spending threatens credit quality of Amazon, Meta, Alphabet
- Fireside chat on building AI SRE in production with Traversal AI
- Meta upgrades AI chatbot with productivity features
- Replit adds voice interaction and Slack integration to Agent
- Benchmarking and evals part 7 covers DeepSWE and Senior SWE-Bench