logo

JADEPUFFER: How an Agentic Ransomware Attack Unfolded

ID: b3b13493-4a6a-5814-92c2-866c14b5220d

STIX ID: report--b3b13493-4a6a-5814-92c2-866c14b5220d

Feed Name: Outpost24 Blog

Threat Score
75/100

Date Published: 2026-07-13

Date Updated: 2026-07-16

Author: dimber

...
...

JADEPUFFER is an observed agentic ransomware incident where an LLM exploited CVE-2025-3248 in a Langflow instance to harvest credentials, pivot to an internet-exposed MySQL/Nacos production server, and encrypt 1,342 configuration items while leaving an unrecoverable encryption key; Sysdig attributes rapid adaptation and self-narrating payloads to automated LLM behavior and warns that such agentic attacks increase speed, lower attacker skill barriers, and require tightened controls on internet-facing AI tooling and secrets management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.