AUTO-UPDATED

Researchers Claim First Fully Agentic Ransomware: JadePuffer

Security firm Sysdig has identified JadePuffer, the first ransomware campaign driven entirely by an autonomous large language model that successfully exploited vulnerabilities to destroy production database configurations.

Key Points

  • The JadePuffer campaign utilized an autonomous AI agent to exploit CVE-2025-3248 in a Langflow instance.
  • Attackers successfully encrypted 1,342 Nacos service configuration items using non-recoverable, ephemeral AES keys.
  • The AI agent performed reconnaissance, credential harvesting, and lateral movement without human intervention.
  • Payloads included the exploitation of older vulnerabilities, such as the 2021 Nacos authentication bypass (CVE-2021-29441).
  • The automated process demonstrated the ability to pivot from failed login attempts to successful system fixes in 31 seconds.

Why it Matters

The emergence of autonomous AI agents in cyberattacks significantly reduces the time window security teams have to detect and contain threats. This shift necessitates a renewed focus on fundamental security practices, such as rapid patching and network segmentation, to mitigate the risks posed by high-speed, automated exploitation.
Infosecurity Magazine Published by Phil Muncaster
Read original