JadePuffer: the first case of a full-fledged autonomous cyber attack using agent AI
09.07.26
Sysdig researchers have officially confirmed the first known case where an agent based on a large language model (LLM) was able to independently execute a complete cycle of a cyberattack. The malicious ransomware, called JadePuffer, worked autonomously, eliminating the need for human involvement in the management process.
During the attack, the AI agent performed system reconnaissance, successfully stole credentials, secured a foothold in a compromised environment, elevated its privileges, and eventually encrypted the victim’s files.
Attack vector and technical details
The JadePuffer penetration began with the exploitation of the critical vulnerability CVE-2025-3248 in the Langflow platform, which is widely used by developers to build AI-based applications.
Results of automated hacking
- System information collection and credential search are automated.
- Unauthorized access to linked servers.
- Successful attack on Alibaba Nacos server.
- Encryption of 1342 configuration records.
Features of agent AI work
The main difference between JadePuffer and traditional malware is a high level of autonomy and adaptability. If the execution of a certain command led to an error, the agent did not stop work, but independently analyzed the situation, adjusted its actions and continued the attack. One of the clear examples is bypassing the authentication system in just 31 seconds.
Sysdig experts also noted unique artifacts in the generated code. The agent left comments in natural language that explained in detail the logic of the actions taken.
Code errors as a result of using LLM
Despite the technical complexity of the attack, the researchers emphasized the errors inherent in the work of current models. For example, the attacker used a test wallet, which is often found in training documentation, and instead of the claimed AES-256, the weaker encryption algorithm AES-128-ECB was actually used.
The future of cyber security
Experts warn that the use of such agents can significantly lower the entry threshold for cybercriminals, allowing for the automation of complex attack chains. However, there are still predictable traces (patterns) in the operation of current LLMs that allow modern monitoring systems to detect such threats. The expert community calls for more attention to be paid to the protection of environments using LLM development tools.
Don't miss interesting news
Subscribe to our channels and read announcements of high-tech news, tes
Oppo A6 Pro smartphone review: ambitious
Creating new mid-range smartphones is no easy task. Manufacturers have to balance performance, camera capabilities, displays, and the overall cost impact of each component. How the new Oppo A6 Pro balances these factors is discussed in our review.
Guide for choosing Garmin smartwatches for sports, military and everyday life
Garmin has long gone beyond simple GPS navigation. Today, they are the ultimate computing centers on the wrist, competing with both classic “smart” wearable electronics and specialized professional devices. How to choose a Garmin smartwatch – we’ll tell you further
Crussis e-Full 12.11 Pro X: A 150 Nm E-MTB Beast Priced at €12K
Discover the new high-performance Crussis e-Full 12.11 Pro X electric mountain bike, featuring a powerful DJI Avinox motor and a carbon frame. We explore its technical specs, hardware, and whether it justifies its premium price.
One UI 9.5: first signs of development on Galaxy S27 Ultra
Data on an early build of the One UI 9.5 firmware for the flagship Samsung Galaxy S27 Ultra has leaked. We break down what the found S958U build indices signify.


