A new chapter in cybersecurity has begun. Researchers at cloud security company Sysdig have identified what they believe to be the first fully autonomous AI ransomware attack — an AI agent that conducted an entire cyberattack without any human involvement.
Dubbed "JadePuffer," the autonomous agent conducted reconnaissance, exploited a vulnerability (CVE-2025-3248 in the Langflow open-source framework), stole credentials, moved laterally through the victim's network, established persistence, escalated privileges, encrypted 1,342 files, and dropped a ransom note — all of its own accord.
Adapting like a human hacker
What makes JadePuffer genuinely alarming is not the attack itself, but the AI agent's behavior. When an API request returned XML instead of expected JSON, the agent adjusted its parsing logic on the next payload. When a step failed, it retried with refined parameters.
"In one sequence, it went from a failed login to a working fix in 31 seconds," the Sysdig researchers reported.
Roey Eliyahu, CEO of Salt Security, said: "The 31-second self-correction is the part that changes the threat model most fundamentally. A human attacker who fails an initial payload waits, reassesses, consults, and tries again on a different timeline. An agent that fails a payload corrects and retries in under a minute. That compression of the attack cycle means the window between first detection signal and material damage is now measured in seconds, not hours."
A credential store, not the target
The entry point was not the AI infrastructure itself — it was a Langflow instance holding provider API keys and cloud credentials that nobody actively monitored or rotated. The AI agent then gained access to a production MySQL server running Alibaba Nacos, exploiting a known 2021 authentication bypass vulnerability.
Crucially, the AES encryption key was never transmitted to the attacker's infrastructure, meaning even paying the ransom would not have enabled recovery.
The age of agentic threats has arrived
While the attack relied on known, older vulnerabilities rather than novel zero-day exploits, the acceleration factor is what keeps security professionals awake. A recent statement from the Five Eyes cybersecurity agencies warned that "frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years; it is months."
Sysdig's conclusion is stark: "The age of agentic threat actors has arrived."
The researchers emphasize that defending against automated AI attacks currently requires the same fundamentals — patching vulnerabilities, reducing attack surface, and accelerating incident response — but at machine speed rather than human speed. The margin for error has effectively vanished.




