MalwareBleeping Computer
9.8 — CRITICAL
JadePuffer ransomware used AI agent to automate entire attack
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
JadePuffer ransomware used an autonomous AI agent to automate the entire attack, exploiting CVE-2025-3248 and CVE-2021-29441 vulnerabilities in Langflow and Alibaba Nacos respectively, resulting in encryption of sensitive data.
⚙️Technical Details
CVEs
CVE-2025-3248CVE-2021-29441
Affected Systems
LangflowAlibaba Nacos
Attack Vectors
NETWORKNETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Organizations using Langflow and Alibaba Nacos, particularly those with cloud credentials and API keys
🛡️Recommended Actions
1Implement patches for CVE-2025-3248 and CVE-2021-29441 in Langflow and Alibaba Nacos respectively
2Monitor cloud credentials and API keys for suspicious activity
3Regularly back up sensitive data to prevent permanent loss in case of ransomware attack
📦Affected Products
Langflow LangflowAlibaba NacosLangflow
🔐NVD Verified DataVERIFIED
CVE-2025-3248 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-306CWE-94
Affected Products (CPE)
Langflow Langflow
Patches & References
CVE-2021-29441 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-290
Affected Products (CPE)
Alibaba Nacos
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
