JADEPUFFER
Coverage of JADEPUFFER in the Nexus archive.
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Sysdig researchers linked a new ransomware attack using ENCFORGE to JADEPUFFER, an AI-agent-driven operator. ENCFORGE targets AI infrastructure files like model weights and training datasets on Langflow servers.
- JadePuffer agentic attacks now target AI model data with ransomware
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge, which encrypts AI assets such as training datasets, vector databases, and model checkpoints. The attack targets AI model data using ransomware.
- JadePuffer ransomware used AI agent to automate entire attack
Researchers identified the first documented case of the JadePuffer ransomware operation, which was conducted entirely by a large language model (LLM) agent. The attack was automated using an AI agent, marking a new method in ransomware attacks.
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Sysdig, a security firm, reports discovering the first ransomware attack fully executed by an AI agent named JADEPUFFER. The AI agent conducted a database ransomware attack by infiltrating systems, stealing credentials, moving laterally in the network, and encrypting/wiping a company's production database.