AI Agent JADEPUFFER Exploits Langflow RCE to Automate Database Ransomware Attack
Security firm Sysdig has identified what it believes is the first ransomware attack fully orchestrated by an AI agent, dubbed JADEPUFFER. The…
Security firm Sysdig has identified what it believes is the first ransomware attack fully orchestrated by an AI agent, dubbed JADEPUFFER. The…
An AI-agent-driven operator first documented by Sysdig. Deployed ENCFORGE ransomware against Langflow servers, using Docker socket for host breakout. Previously used throwaway…
The first known case of agentic ransomware, codenamed JADEPUFFER, where a human operator deployed an artificial agent to handle the entire extortion…
A ransomware operation linked to the FortiBleed campaign, with an operator using FortiBleed infrastructure to access negotiation panels and deploy ransomware.
A large-scale credential-harvesting operation targeting FortiGate firewalls globally, stealing over 110 million credentials and linked to INC and Lynx ransomware operations.
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were…
A ransomware operation linked to the FortiBleed campaign, with an operator using FortiBleed infrastructure to access negotiation panels and deploy ransomware.
Ransomware deployed by threat actor Storm-2603, often exploiting known vulnerabilities in on-premises SharePoint servers. Used in parallel with other techniques to establish…
Velociraptor was deployed by Storm-2603 to blend malicious activity with trusted administrative behavior during ransomware attacks.
A 19-year-old alleged member of the Scattered Spider hacking group, Peter Stokes, has been extradited from Finland to the United States to…