Why this fully agentic ransomware attack is giving researchers nightmares
Follow ZDNET: Add us as a preferred source on Google.
ZDNET's key takeaways
- Researchers have documented a ransomware campaign that appears to be entirely AI-driven.
- JadePuffer could be the first known case of an AI agent orchestrating a full attack chain.
- The case underscores the urgency with which organizations must defend themselves.
Security researchers have identified JadePuffer, a ransomware campaign that they're calling the "first documented case of agentic ransomware." The entire operation is driven end-to-end by AI.
Also: 5 ways to fortify your network against the new speed of AI attacks
What is JadePuffer and how does it work?
According to the cloud security firm Sysdig, JadePuffer uses a large language model (LLM) to handle the campaign without human intervention.
The JadePuffer operator -- or cybercriminal group -- exploited CVE-2025-3248, an unauthenticated remote code execution (RCE) vulnerability in Langflow, an open source builder for agentic AI applications.
...
Copyright of this story solely belongs to zdnet.com. To see the full text click HERE