← All news·2026-07-06·3 min read

First autonomous ransomware called JADEPUFFER has been developed

In July 2026, security company Sysdig discovered JADEPUFFER, an AI agent that used an unpatched Langflow vulnerability to encrypt 1,342 entries in a production MySQL database, self-correct after a failed attempt within 31 seconds, all without human intervention.

aisecurityransomwareagents

Sysdig published details of the first entirely autonomous ransomware attack in July 2026. Dubbed JADEPUFFER, the attack took advantage of CVE-2025-3248, a known but unpatched vulnerability in the widely used AI application development tool Langflow. A patch has been available for more than a year, and the vulnerability has been noted by CISA as being exploited. The AI agent was able to move around the target environment, create privileged accounts, escalate privileges, and encrypt 1,342 entries in a production MySQL database, overwriting the originals. Particularly interesting was when the initial attempt to create an account failed. The system was able to auto-diagnose the issue and build a valid account in 31 seconds — something that even the most skilled human attacker couldn’t hope to replicate.

This attack relied on tried and tested but often overlooked tactics such as using weak default passwords, exposing credentials, and following privilege escalation paths that have been published online for years. Rather than finding a new way to exploit systems, JADEPUFFER showed how AI agents can string these tactics together to carry out a full ransomware campaign. The ransom note requested payment in Bitcoin but contained a crucial mistake; the decryption key was shown but not saved, so paying up wouldn’t have retrieved the encrypted files. According to Keeper Security’s post-mortem report, 72% of companies don’t have real-time visibility into credential abuse, which is essential when dealing with attacks that can move at machine speed. This attack represents a leap forward in terms of the capabilities of malicious actors, as it shows that ransomware campaigns don’t need human intervention at every stage.

Source: the-decoder.com

Free course

Stop reading about AI — start building with it

The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.

Start free →
EAEvgenii Arsentev

Author

Evgenii Arsentev

PhD · Chief Executive Officer, digital health