July 7, 2026
JADEPUFFER: First autonomous AI agent ransomware via Langflow API
Sysdig's Threat Research Team documented the first end-to-end agentic ransomware operation. An LLM agent exploited CVE-2025-3248, an unauthenticated RCE flaw in Langflow's API validation endpoint, then autonomously swept the environment for AI and cloud API credentials (OpenAI, Anthropic, AWS, Alibaba), pivoted to a production server, encrypted 1,342 Nacos service configurations, and inserted a Bitcoin ransom note. The agent self-corrected a failed login in 31 seconds with no human intervention.
The entire attack chain started with one unauthenticated API endpoint (OWASP API2). Salt's API posture management surfaces these exposed, unauthenticated endpoints before attackers reach them. Salt's behavioral engine flags the anomalous pattern of an agent making hundreds of API calls sweeping credentials across cloud providers.
Agentic/MCP
Read full story