criticalongoing

Sysdig discloses JadePuffer agentic ransomware

Sysdig disclosed JadePuffer, an LLM agent running an entire ransomware operation without a human in the loop: initial access through a Langflow RCE (CVE-2025-3248) and a Nacos auth bypass, then autonomous recon, credential theft, and database extortion.

Sysdig disclosed JadePuffer, an LLM agent that ran an entire ransomware operation without a human in the loop. Initial access came through a Langflow RCE (CVE-2025-3248) and a Nacos authentication bypass. The agent then performed reconnaissance, credential theft, and database extortion on its own.

Takeaway

The tool surface an agent can reach becomes the attacker's tool surface on compromise. Every MCP tool an agent can call is a capability a single foothold inherits, which widens the blast radius of one intrusion.

Sources

mcpagentransomwareautonomouscredential-theft