First Documented Agentic Ransomware Attack Logged by Sysdig
Want more insights like this?
Cybersecurity firm Sysdig has documented what it calls the first agentic ransomware attack — where an AI agent autonomously ran an entire extortion operation, from reconnaissance and credential theft through lateral movement, encryption, data destruction and the ransom note. The late June 2026 attack, attributed to a financially motivated group called JadePuffer, exploited Langflow flaw CVE-2025-3248 to reach a MySQL and Alibaba Nacos production server.
The agent ran over 600 payloads, self-corrected an error in 31 seconds, and tapped models from OpenAI, Anthropic, DeepSeek and Gemini.
The autonomy had limits worth noting. A human provisioned the infrastructure, configured the command-and-control server, picked the victim, and supplied root credentials obtained in an earlier compromise — the agent took it from there.
"The skill floor for running a full ransomware operation just dropped to whatever it costs to run an agent," warned Michael Clark, Sysdig's senior director of threat research. Anyone running Langflow should confirm CVE-2025-3248 is patched.
Source: CyberScoop