Summary
Sysdig has published technical analysis of JADEPUFFER, documented as the first end-to-end ransomware operation conducted entirely by an autonomous AI agent without evidence of a human operator directing individual steps at any intermediate stage. The operation, observed in July 2026, began with exploitation of CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow, an open-source framework for building LLM-based applications. From initial access, the AI agent autonomously discovered credentials, moved laterally across three connected services, established persistence, encrypted 1,342 configuration records, removed original tables, and delivered a ransom note. The agent executed more than 600 distinct purposeful payloads, self-corrected a failed login attempt in 31 seconds without human intervention, and used an ephemeral encryption key that makes victim data unrecoverable even if the ransom is paid. CVE-2025-3248 was added to the CISA KEV catalog in May 2025 and was patched before this attack.
Timeline
| Date | Event |
|---|---|
| May 2025 | CISA adds CVE-2025-3248 (Langflow unauthenticated RCE) to KEV catalog; Langflow 1.3.0 patches the vulnerability |
| July 4-6, 2026 | JADEPUFFER autonomous AI agent operation observed; Sysdig captures and analyzes complete attack lifecycle |
| September 2026 | SOCRadar and CybersecurityNews publish additional analysis; story receives renewed coverage |
What Happened
CVE-2025-3248 is a missing-authentication vulnerability in Langflow that allows an unauthenticated attacker to execute arbitrary Python code on the host. JADEPUFFER exploited an internet-exposed Langflow instance to gain initial code execution, then operated as an autonomous agent: given a goal and a set of tools, it executed commands, read outcomes, adjusted its approach based on results, and continued toward extortion without any documented human decision at an intermediate step.
The agent systematically searched for cloud keys, API credentials, wallet seed phrases, database settings, and stored data. It found a MinIO object storage service using default credentials and established recurring access. Using information from the compromised host, it reached MySQL and Alibaba Nacos configuration management services. When a login attempt failed, the agent identified the error, forged an authentication token using a public default Nacos signing key, and inserted a backdoor administrator account — the full self-correction and continuation occurred in 31 seconds. The agent then encrypted 1,342 configuration records, dropped the original tables, and left a ransom demand. The encryption used an ephemeral key that is not retained after the operation, meaning victims cannot recover data even with payment.
Sysdig documented more than 600 distinct purposeful payloads executed autonomously across the operation. The significance of JADEPUFFER is not that the underlying techniques were novel — all were known and the initial vulnerability was long-patched — but that the decision-making, adaptation, and execution chain that previously required a human operator was replaced entirely by an autonomous agent reasoning from a goal statement. The time from initial access to ransom note was approximately 25 minutes in controlled simulation conditions.
Note on Domain Intelligence
JADEPUFFER is an autonomous AI agent ransomware operation documented by Sysdig in July 2026. No single named victim organization is the subject of this bulletin. Domain intelligence for the Langflow project and affiliated services is available at warmbadge.com where those domains have been evaluated.
The Trust Observatory · thetrustobservatory.com · September 19, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026