Sysdig researchers have identified the first fully autonomous ransomware attack, dubbed JadePuffer, which utilized an AI agent to exploit a critical Langflow vulnerability and encrypt production database systems.
Key Points
- The JadePuffer campaign exploited CVE-2025-3248, a critical 9.8-severity vulnerability in the Langflow framework, to gain initial network access.
- The autonomous AI agent successfully harvested API keys and cloud credentials for services including OpenAI, Anthropic, AWS, Microsoft Azure, and Google.
- The attack targeted a MySQL database and Alibaba’s Nacos platform, encrypting 1,342 configuration items and deleting database schemas.
- Researchers noted the agent performed over 600 distinct operations, including self-correcting failed login attempts in 31 seconds without human intervention.
- The ransomware encryption keys were generated randomly and discarded immediately, making data recovery impossible even if the ransom is paid.