JADEPUFFER: the first ransomware that writes its own case notes
Last week, Sysdig's threat research team published what they're calling the first documented case of agentic ransomware - an operation they've named JADEPUFFER (would love to know how these names come to exist), run end-to-end by an LLM. According to Sysdig, initial access was obtained by the agent via a known Langflow RCE (CVE-2025-3248) on an internet-exposed instance. Langflow also just so happens to be an open-source framework for building LLM-driven applications and agent workflows (lol). Afterwards, the agent swept the host for credentials and API keys, followed by lateral movement to a…
· 4 min read