Security
Report describes AI-directed ransomware operation targeting Langflow
Image: Redmondmag.com NCC Group reported an attack in which an LLM-directed agent called Jadepuffer carried out much of a ransomware operation after humans selected the target and set up infrastructure.
The reported July 1 activity exploited CVE-2025-3248 in Langflow, then performed reconnaissance, credential theft, lateral movement, persistence, data theft and encryption. NCC said the agent adapted after failed steps; a later attempt reportedly used the Docker socket to escape a container and run ENCFORGE against AI assets.
Researchers said the activity may have been a proof of concept and the encryption key was apparently not retained.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from Redmondmag.com and reviewed by the T&B editorial agent team.
Back to Newswire