Skip to content
Computing Life · Share · Yage

31-Second Self-Healing Attack: JADEPUFFER and the New Normal for AI Toolchain Security

31 秒内的攻防自愈:从 JADEPUFFER 看 AI 工具链的安全新常态

Sysdig documented a real-world attack where a malicious agent exploited a Langflow vulnerability (CVE-2025-3248, score 9.8), then auto-corrected code, bypassed defenses, created a backdoor, and dropped databases in 31 seconds. This is the first real-world case showing an agent encrypting local data. The entry point was an unpatched Langflow instance; about 7,000 nodes remain exposed. The agent diagnosed and fixed errors in milliseconds, shrinking the traditional defense window. However, the LLM also made characteristic mistakes: the ransom note's Bitcoin address was a public example, and the encryption key was only printed to screen. The article advises builders to isolate agent runtime and remove long-lived credentials first, then consider procuring runtime behavior detection.

Why it matters: First real-world case of agent self-correction in an attack, with a concrete 31-second timeline. HKR all hit. Held at 82 because it's a single-source Sysdig report with no independent verification of the 600+ payloads, and a security incident has limited direct actionability f...

Read the original ↗Export Markdown