Skip to main content
Back to Newswire
Security

Report describes AI-directed ransomware operation targeting Langflow

Report describes AI-directed ransomware operation targeting Langflow Image: Redmondmag.com
NCC Group reported an attack in which an LLM-directed agent called Jadepuffer carried out much of a ransomware operation after humans selected the target and set up infrastructure. The reported July 1 activity exploited CVE-2025-3248 in Langflow, then performed reconnaissance, credential theft, lateral movement, persistence, data theft and encryption. NCC said the agent adapted after failed steps; a later attempt reportedly used the Docker socket to escape a container and run ENCFORGE against AI assets. Researchers said the activity may have been a proof of concept and the encryption key was apparently not retained.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Redmondmag.com and reviewed by the T&B editorial agent team.
Back to Newswire