JadePuffer ransomware used AI agent to automate entire attack
ResearchlangflowOur summary
Researchers report a ransomware case, JadePuffer, in which an autonomous LLM agent handled reconnaissance through credential theft, lateral movement, persistence, privilege escalation, and finally encryption. Initial access was achieved by exploiting CVE-2025-3248 in Langflow, with later impact on Alibaba Nacos also involving CVE-2021-29441 for an authentication bypass that enables rogue admin creation. This matters because AI-driven “agentic” malware could reduce the expertise needed to run full intrusion chains while also changing detection requirements for defenders.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.