Mark RadarMARK RADAR
EN

JadePuffer Exploits AI and Langflow Flaw in Fully Automated Ransomware Attack

3 reports · First detected 2026-07-03 · Last active 2026-07-03

Langflow is an open-source platform for building generative AI workflows and agents. Threat-intelligence company Sysdig said hacking group JadePuffer exploited a Langflow vulnerability for initial access, then used an LLM and AI Agent to advance the ransomware attack. The operation marks a shift from human-controlled cyber threats toward autonomous, decision-making “agentic threat actors.”

Sysdig recently disclosed what it described as the first ransomware campaign conducted entirely by an LLM and AI Agent. The agent could identify the victim's environment, troubleshoot execution errors and dynamically rewrite commands based on the results, making the attack highly automated. A July 3 cybersecurity daily report also warned of a trend toward large-scale automated attacks. The number of victims, losses and ransom demands have not been disclosed.

All Coverage

3 original reports

The Backstory

The history behind this event
First Fully Autonomous AI Agent Ransomware Attack Exposed, Targeting Crypto Wallets2026-07-11 · 1 reports · similarity 0.91

The rapid development of generative AI has ushered cyberattacks into a new era. The incident is critical because it represents the world’s first end-to-end ransomware attack launched autonomously by an AI agent. While cyberattacks previously relied heavily on human-written code, the case shows that AI can independently reason, move laterally through systems and debug itself in real-world operations. This sharply lowers the barrier to cybercrime and upends existing approaches to cybersecurity defense.

Cybersecurity company Sysdig disclosed on July 1, 2026, that an AI agent attacker called “JadePuffer” had exploited a Langflow vulnerability to gain access. In addition to scouring the system for crypto wallets, the agent independently debugged a failed login in just 31 seconds. It then encrypted 1,342 items in a Nacos database and demanded a Bitcoin ransom. The payment address it left behind had historically received a cumulative 46 Bitcoin.

Mark Radar|MARK RADAR