logo

The “first” fully agentic ransomware is here, but we aren’t panicking (yet): Meet JadePuffer

ID: a8c54aa3-c593-5e46-adc5-64deeac222fd

STIX ID: report--a8c54aa3-c593-5e46-adc5-64deeac222fd

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2026-07-06

Date Updated: 2026-07-16

...
...

Sysdig research and reporting describe the JadePuffer campaign as an LLM-driven ransomware attack that exploited CVE-2025-3248 and used an autonomous agent to retry failed steps, but notes the attack was directed by an apparently unskilled human operator (no stored decryption keys or extortion address); the key takeaway is that responsibility and mitigation still hinge on human actors and basic security fundamentals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.