CVE Tools

JadePuffer ransomware used AI agent to automate entire attack

BleepingComputerBy Bill Toulas

Researchlangflow

Our summary

Researchers report a ransomware case, JadePuffer, in which an autonomous LLM agent handled reconnaissance through credential theft, lateral movement, persistence, privilege escalation, and finally encryption. Initial access was achieved by exploiting CVE-2025-3248 in Langflow, with later impact on Alibaba Nacos also involving CVE-2021-29441 for an authentication bypass that enables rogue admin creation. This matters because AI-driven “agentic” malware could reduce the expertise needed to run full intrusion chains while also changing detection requirements for defenders.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store