Sysdig documents the first observed case of agentic ransomware
Sysdig has published an analysis of JADEPUFFER, which it assesses as the first documented case of agentic ransomware. The operation automated the full attack chain: initial access, lateral movement, database encryption and the drafting of the ransom note. The attacker exploited an Internet-facing Langflow instance through CVE-2025-3248, then pivoted towards a production environment running MySQL and Nacos.
What this means for your organisation
Automation changes the tempo. Where you previously had hours or days between the first foothold and encryption, you should now expect that gap to shrink. The entry point, meanwhile, is familiar and unglamorous: an exposed AI component carrying a known vulnerability. Organisations that have put AI tooling into production without the same regime as the rest of their infrastructure probably have more such components than they can account for.
Berigo recommends
- Map which AI and data processing components are exposed to the Internet, and remove the exposure where it is not needed.
- Bring AI tooling into ordinary vulnerability management with the same deadlines as other software.
- Separate production databases from development and experimentation environments using network segmentation and dedicated accounts.
- Test database recovery under time pressure, with a documented recovery time.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch