Smooth AI criminal drives 'first' end-to-end agentic ransomware attack
What happened
Sysdig documented what it calls the first end-to-end agentic ransomware operation, where an LLM-controlled agent (JadePuffer) exploited an internet-facing Langflow instance to gain code execution, collect secrets, and encrypt service configuration. The agent adapted in real time, retried failed steps within seconds, and ultimately encrypted 1,342 Nacos configuration items and produced an extortion demand. Watch whether follow-on disclosures expose more internet-exposed orchestration tools or additional supply-chain targets
Why the category manager should care
Treat internet-exposed AI orchestration and code-execution endpoints as critical assets requiring contractually mandated patching and non-exposure controls
Key facts
- Exploit used: CVE-2025-3248 against Langflow
- Agent encrypted 1,342 Nacos configuration items
- Agent adapted failed steps to working fixes in as little as 31 seconds