Autonomous AI Agent Used in Ransomware Attack
Still_Piglet9217 · reddit · 2026-07-13
Sharing a Sysdig report, a Reddit post reveals that an LLM agent named JadePuffer was built to autonomously breach networks, steal credentials, move laterally, and encrypt databases for ransom.
Key points include:
- The initial attack vector was an unauthenticated remote code execution vulnerability in Langflow.
- The agent could automatically handle login failures, rewrite its own code, and continue the attack.
- It shifted from a failed login to a working exploit chain in about 31 seconds.
- It also established scheduled callbacks, created rogue admin accounts, and encrypted numerous service configurations.
The author stresses that this proves "plan-act-observe" agent architectures can be used to build malicious systems from scratch, not just as hijacked assistants. Any internet-exposed orchestration systems should be patched immediately.
More from coding & agent
- Coding agents are heading toward an AI-writes, AI-reviews, human-approves workflow — aftahi_ai · 2026-07-22
- oMLX 0.5.2 adds Mac menu-bar stats, low-bit decode kernels, and faster downloads — awnihannun · 2026-07-22
- GitHub review bot hits its PR limit and forces a 39-minute cooldown — DanielLockyer · 2026-07-22
- Max reasoning effort appears to be mobile-only in Codex Remote, not desktop — GabGarrett · 2026-07-22
- A Reddit demo argues online stores should expose carts and pricing through MCP — gelembjuk · 2026-07-22
- Open-source AI SDK provider routes Vercel apps through a local Codex subscription — lgrammel · 2026-07-22