CVE Tools

JadePuffer: The First Complete LLM-Driven Ransomware Attack

Dark ReadingBy Elizabeth Montalbano

Reported exploited

Our summary

Researchers reported “JadePuffer,” an LLM-driven ransomware operation attributed to an “agentic” threat actor that carried out extortion with no human operator during key stages. The attack began by exploiting CVE-2025-3248 in an Internet-facing Langflow deployment, then moved to compromise a production database server running a MySQL database and an Alibaba Nacos configuration service to enumerate, exfiltrate selected data, delete it, and demand payment. The incident matters because it demonstrates a full, automated ransomware lifecycle that can adapt in real time—highlighting the need to patch Langflow quickly and avoid exposing code-execution endpoints to the Internet.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store