Sev0AI security incidents, tracked

All incidents / AI-run attack

JADEPUFFER: first documented LLM-driven ransomware operation

Undisclosed, disclosed Jul 2026. AI-run attack Exposed and destroyed High

Sysdig captured a ransomware operation run end to end by an LLM agent. It entered through an internet-facing Langflow server, harvested and reused credentials, moved laterally, set up persistence and destroyed a production database, correcting its own failures along the way.

Disclosed
Jul 2026
Organization
Undisclosed
Vendor
Unknown
Kind of AI
Autonomous agent
AI's role
Attacker used AI
How it happened
AI-run attack: Autonomous intrusion
Harm
Exposed and destroyed
Data involved
Credentials
Reach
One organization
Severity
High
Model at fault
No
Status
Confirmed
Vulnerability IDs
CVE-2025-3248

Sources

  1. https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
  2. https://cyberscoop.com/sysdig-judepuffer-ai-agentic-ransomware-attack/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "JADEPUFFER: first documented LLM-driven ransomware operation", https://sev0.fyi/incidents/2026-07-01-jadepuffer-agentic-ransomware/