EventCybersecurityJuly 2, 2026
AI agent JADEPUFFER exploited Langflow flaw in first known AI-run ransomware attack

Sysdig reported the first known AI-run ransomware attack: the agent JADEPUFFER exploited Langflow bug CVE-2025-3248 to steal credentials, pivot to a MySQL database, and encrypt it. However, TechCrunch noted a human still chose the victim and set up infrastructure, so it wasn't fully autonomous.
4 sources
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attackthehackernews.com
The ‘first’ AI-run ransomware attack still needed a humantechcrunch.com
JadePuffer: The First Complete LLM-Driven Ransomware Attackdarkreading.com
Someone built an AI agent that hacks networks and holds data for ransom. It just worked.reddit.com
More stories today
- Fields medalist Jacob Tsimerman joins OpenAI
- Cerebras and Flex Expand U.S. AI Supercomputer Manufacturing
- Alphabet's Anthropic stake reaches $124 billion
- Andrew Ng releases OpenWorker, open-source desktop AI coworker
- Echo achieves Fable-level results at 1/3 cost using open-weight models