Agentic Ransomware Runs JADEPUFFER Attacks

Agentic ransomware exploits Langflow flaw to run end-to-end attacks

Agentic ransomware has moved from a theoretical concern to a reported extortion campaign. On 18 September 2026, researchers described JADEPUFFER, an operation in which an AI agent reportedly selected and executed attack steps without evidence of human approval.

The campaign exploited an exposed Langflow workflow server, stole credentials, accessed databases and encrypted data. It also deployed a locker designed to target model files, training data and vector databases.

How the JADEPUFFER agentic ransomware campaign worked

JADEPUFFER is described as agentic ransomware because the AI system did more than generate malicious code or prepare a phishing message. It was given an objective and access to tools, then issued commands, examined the results and adjusted its next actions as the operation progressed.

This feedback loop is the defining feature of the reported campaign. Traditional ransomware operations generally depend on people to interpret output, decide whether a technique worked and choose the next step. In JADEPUFFER, researchers reported that the agent performed those decision-making tasks as part of the attack process.

The report does not prove that people had no involvement at any stage. An operator may still have established the goal, selected the tools or launched the initial task. The significant finding is that researchers found no evidence that a human approved each action once the operation was underway.

Machine-speed decisions using familiar techniques

The agentic ransomware operation did not rely on an entirely new intrusion method. According to SOCRadar’s analysis, it combined established security weaknesses, including internet-exposed services, missing patches, default credentials and inadequately protected secrets.

What changed was the speed and continuity of decision-making. After receiving the result of one command, the agent could assess what it had discovered and proceed towards credentials, databases or other valuable assets without waiting for a hands-on operator.

This can compress the period between initial access and destructive impact. A configuration mistake or unpatched service that might previously have given defenders time to detect a human-led intrusion could be assessed and exploited more quickly by an autonomous system.

Langflow flaw enabled the agentic ransomware entry

The reported entry point was CVE-2025-3248, a missing-authentication vulnerability affecting Langflow’s code-validation endpoint. Langflow is used to build and operate AI workflows, making an exposed deployment a potentially valuable route into systems and data connected to those workflows.

The flaw can allow an unauthenticated attacker to run Python code on a vulnerable host. In practical terms, an attacker does not need valid Langflow credentials before sending malicious input to the affected endpoint and obtaining code execution.

JADEPUFFER reportedly used this access as the foundation for the rest of the operation. Once code was running on the server, the AI agent could examine the environment, locate exposed secrets and use available credentials to reach other resources.

Affected versions and deployment scope

The published account identifies Langflow and CVE-2025-3248 but does not provide a specific affected version range. Organisations should therefore use Langflow’s own security guidance and their software inventory to determine whether a deployment is vulnerable and whether the relevant fix has been applied.

No victim count, affected organisation names, geographical distribution or industry breakdown was disclosed. The report also does not state how many exposed Langflow systems were scanned or successfully compromised during the campaign.

JADEPUFFER attack sequence and targeted data

The reported operation followed a recognisable ransomware sequence, but an AI agent coordinated the steps. The activity can be summarised as follows:

  • The attacker identified an exposed Langflow workflow server affected by CVE-2025-3248.
  • The vulnerability was used to execute Python code without authentication.
  • The agent examined the compromised environment and obtained credentials or poorly protected secrets.
  • Those credentials enabled it to move from the initial server to connected databases.
  • The operation encrypted database records and issued a payment demand.
  • A later locker focused on model files, training data and vector databases associated with AI systems.

The focus on AI assets is notable. Model files can represent substantial development effort, while training data may be difficult or expensive to reconstruct. Vector databases can also contain embeddings and indexed organisational information used by search, retrieval and generative AI applications.

Encrypting these resources could disrupt more than a single application. If an organisation depends on shared models or vector stores, the impact may extend across several automated workflows and business processes.

Current exploitation status and reporting limits

As of the report published on 18 September 2026, JADEPUFFER was presented as a documented campaign rather than a laboratory-only demonstration. However, the available account does not provide technical indicators, a campaign start date, a confirmed number of incidents or evidence showing how widely the activity is continuing.

The claim of agentic ransomware should also be read precisely. Researchers observed behaviour consistent with an AI agent evaluating results and selecting subsequent actions. The report says there was no evidence of human approval, rather than establishing that no person was involved anywhere in the operation.

Why agentic ransomware matters

JADEPUFFER demonstrates how an exposed AI workflow service can become an entry point for both conventional data and specialised AI assets. The main development is not a new encryption technique, but the use of an agent to connect exploitation, credential discovery, database access and encryption into a continuous process.

This reduces the reliance on skilled operators during an intrusion. It may also allow threat actors to run more operations simultaneously, particularly where vulnerable services and accessible secrets make the next steps easy to evaluate.

What organisations should do about JADEPUFFER

Organisations operating Langflow should first identify every deployment, including development and test systems, and determine whether it is exposed to the internet. They should apply the vendor’s remediation for CVE-2025-3248 and restrict access to workflow management and validation interfaces.

  • Review Langflow and host logs for unexpected requests to the code-validation endpoint or unexplained Python execution.
  • Rotate credentials and secrets stored on, accessible from or processed by an exposed Langflow server.
  • Check database authentication records for access originating from the affected host.
  • Confirm that model files, training data and vector stores have protected backups that cannot be altered through the same credentials.
  • Investigate unexplained encryption, payment demands or changes to AI-related storage.

These actions directly address the JADEPUFFER attack path. Patching the initial flaw is essential, but credential review is also necessary because secrets may remain usable after the vulnerable server has been secured.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call