Security firm Sysdig reported that an AI agent, tracked under the operator name JADEPUFFER, abused a vulnerability in the open-source AI development platform Langflow, CVE-2025-3248, to chain secret theft, lateral movement and configuration-data encryption into a fully automated extortion attack. The company describes it as the first end-to-end ransomware-style attack carried out by an AI agent.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.