Agentic Ransomware Shrinks the Human Gap

An exposed Langflow app can now be more than a foothold. JadePuffer shows an AI-driven extortion run that can keep moving after errors, retry failed steps, and repair its own approach, which cuts the time defenders have to notice and break the chain. Sysdig says the campaign exploited CVE-2025-3248 in an internet-facing Langflow instance, then used that access to harvest credentials, reach a production MySQL server and Alibaba Nacos, and destroy data. In one case, the model fixed a failed step in 31 seconds, and it ran more than 600 purposeful payloads without a human steering each move. The break for operators is that patching Langflow alone does not end the exposure if that app can already reach databases, config services, or cloud secrets. A single internet-facing AI app can now serve as an autonomous launchpad into adjacent systems, and the extortion loop can keep adapting after the first mistake.

Part of the PlainSec briefing for 2026-07-08

Sources