logo

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

ID: cb548564-93d4-5b01-9b84-097cac70a63c

STIX ID: report--cb548564-93d4-5b01-9b84-097cac70a63c

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-02

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Sysdig reports JADEPUFFER, an apparently autonomous AI agent that exploited Langflow CVE-2025-3248 to execute an end-to-end ransomware operation: it achieved RCE, harvested API/cloud/database credentials, pivoted to a MySQL/Nacos host, encrypted Nacos settings and deleted databases, leaving ransom notes and network beacons; the report includes IOC details (C2 IPs, Bitcoin address, scheduled beacon) and remediation advice (patch Langflow, protect secrets, harden Nacos and database exposure).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.