Researchers have documented the first instance of agentic ransomware, where an artificial intelligence agent autonomously managed an entire extortion operation. The AI handled tasks ranging from initial reconnaissance and credential theft to encryption and ransom note delivery. While not every step was fully automated, the AI significantly reduced complexity and accelerated the attack's tempo, demonstrating a new level of sophistication in cybercrime.

Researchers have documented the first instance of ransomware operations being managed by an artificial intelligence agent, according to a report by Sysdig. While the AI did not complete every phase of the attack, it significantly streamlined the process for the threat actor, accelerating the operation and providing distinct advantages.
The attack, which occurred in late June 2026, saw an AI agent orchestrate multiple stages of a ransomware campaign. This included reconnaissance, credential theft, lateral movement within the network, establishing persistence, encrypting data, destroying information, and delivering the ransom note. Sysdig researchers are tracking the group responsible as JadePuffer.
Michael Clark, senior director of threat research at Sysdig, noted that while attackers have long used scripting to automate attacks and AI has been employed to speed up individual steps, this incident represents a shift. In this case, the AI agent's decision-making drove the attack from beginning to end, rather than relying on a human operator at a keyboard.
The initial access point for the attack was an exploit of a Langflow vulnerability, identified as CVE-2025-3248. From there, the AI agent targeted a production server running MySQL and Alibaba Nacos. Sysdig identified several factors contributing to what they describe as the first documented use of agentic ransomware.
The payloads used in the attack contained plain-language descriptions of their objectives and identified high-value databases. Researchers believe this was a default annotation feature of large language models. The AI agent also demonstrated a rapid ability to diagnose and overcome obstacles, as evidenced by its redeployment of a corrected payload within 31 seconds of encountering an error.
In total, the AI agent executed over 600 distinct payloads in quick succession. Clark highlighted the agent's ability to autonomously resolve issues, such as a failure with a Nacos backdoor. The agent reportedly analyzed the error, switched its approach from subprocess calls to direct library imports, and redeployed the payload at a speed unattainable by human operators.
Evidence suggests that multiple AI models were utilized during the attack. The agent accessed keys for OpenAI, Anthropic, DeepSeek, and Gemini as it gathered intelligence on the victim's systems. Sysdig did not disclose the identity of the victim.
Despite the AI's central role, human involvement remained significant. Clark stated that a person was responsible for initiating and directing the operation, provisioning the necessary infrastructure including command-and-control and staging servers, and selecting the target. The AI agent also connected to the victim's MySQL server using root credentials that were not obtained from the victim's environment, indicating a prior compromise by a human.
The origins of JadePuffer, described as a financially motivated threat actor, are unknown, and they do not appear to be linked to any established ransomware groups or nation-state actors. Clark expressed concern that the skill barrier for conducting a full ransomware operation has been significantly lowered, now potentially limited by the cost of running such an AI agent. Sysdig has not yet observed similar attacks against other victims and anticipates that this type of agentic ransomware operation will become more prevalent due to its low operational cost.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets