JadePuffer: The First Complete LLM-Driven Ransomware Attack
Reported exploitedOur summary
Researchers reported “JadePuffer,” an LLM-driven ransomware operation attributed to an “agentic” threat actor that carried out extortion with no human operator during key stages. The attack began by exploiting CVE-2025-3248 in an Internet-facing Langflow deployment, then moved to compromise a production database server running a MySQL database and an Alibaba Nacos configuration service to enumerate, exfiltrate selected data, delete it, and demand payment. The incident matters because it demonstrates a full, automated ransomware lifecycle that can adapt in real time—highlighting the need to patch Langflow quickly and avoid exposing code-execution endpoints to the Internet.
Dark Reading publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.