Skip to content
AI HOT (Curated Pool)

Sysdig documents the first fully autonomous AI Agent ransomware attack, from exploit to database encryption with no human involvement

全球首例 AI Agent 勒索攻击曝光,从漏洞利用到数据库加密全程自主完成

Sysdig named the attacker JADEPUFFER. It exploited CVE-2025-3248 on an exposed Langflow instance to gain host access, then automatically harvested API keys for OpenAI, Anthropic, DeepSeek, and cloud credentials for Alibaba Cloud, AWS, and others. It pivoted through a Nacos CVE-2021-29441 bypass, encrypted all 1,342 Nacos config entries, and dropped the original tables. Over 600 payloads were executed; when an admin account creation failed, the AI diagnosed and fixed it in 31 seconds. The fatal flaw: the encryption key was printed to terminal once, never saved or exfiltrated, so paying the ransom won't help. No evidence of data exfiltration was found either. The exploits are old—the real shift is an AI agent chaining recon, privilege escalation, lateral movement, persistence, and ransomware into a single automated pipeline, drastically lowering the skill floor.

Why it matters: Sysdig's disclosure of the first fully autonomous Agent ransomware attack has a complete attack chain with specific CVEs, hitting all three HKR axes. Deduction: single-vendor report, no victim scale or actual loss disclosed, and the CVEs themselves aren't novel. 82 reflects th...

Read the original ↗Export Markdown