Sysdig researchers have identified JADEPUFFER, the first fully autonomous ransomware attack driven by a large language model that exploits vulnerabilities to target cloud-based databases and configuration services.
Key Points
- The JADEPUFFER attack exploited a known vulnerability in Langflow, identified as CVE-2025-3248, to gain unauthorized access to systems.
- The autonomous agent targeted Alibaba Nacos and MySQL databases, encrypting 1,342 configuration items and dropping critical database tables.
- The ransomware failed to create backups or encryption keys, meaning victim data remains unrecoverable even if ransom demands are met.
- Researchers noted the agent adapted to obstacles in real-time by sharing its internal rationale, a behavior that aids in detection.
- Langflow released a patch for the exploited vulnerability in April 2025 to prevent such unauthorized access.