CVE-2025-3248
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. EPSS 100% (100th percentile).
CISA federal remediation date May 26 · date passed
Ransomware · 67 days ago
The shift is not a new ransomware breakthrough. A small set of gangs is taking most of the claims, and AI is helping them write extortion messages that sound more credible and personal without changing the underlying playbook.
GuidePoint’s Q2 2026 report counts 2,279 claimed victims, up 7% from Q1 and 43% year over year. The five most active groups claimed more than 40% of attacks, with Qilin and The Gentlemen driving much of the volume; the report also says LLMs are being used to scale ransom and extortion messaging, not to invent a new technical attack class.
For defenders, the weak tell is no longer sloppy writing. The pressure is coming from more believable, industrialized demands backed by a market that is concentrated enough to absorb disruptions and keep producing claims.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. EPSS 100% (100th percentile).
CISA federal remediation date May 26 · date passed
10 sources covering this story
Ransomware ecosystem grows, but ‘four-headed monster’ dominates
AI is helping hackers, a new report finds, but mostly by automating very human behaviors.
Smashing Security podcast #475: JadePuffer - the AI that ran a ransomware attack all by itself
A 15-year-old boy asked a chatbot for help – and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous…
The 'first' AI-run ransomware attack still needed a human | TechCrunch
An AI agent carried out the technical execution of a real-world ransomware attack for the first known time, but new details show a human still chose the victim, set up the infrastructure, and supplied stolen credentials — meaning it wasn't quite the fully autonomous cybercrime debut that last week's headlines suggested.
JadePuffer: The First Successful LLM-Driven Ransomware Attack
An "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.
Sysdig clocks first documented case of agentic ransomware
The AI agent didn’t accomplish every step in the late June 2026 attack, but it allowed the threat actor to significantly reduce complexity, speed up the tempo and gain operational advantages.
Researchers Claim First Fully Agentic Ransomware: JadePuffer
Researchers have revealed JadePuffer, the first agentic AI-powered ransomware campaign, highlighting how autonomous agents can automate cyber-attacks
Langflow Unauth RCE Attack | Outbreak Alert | FortiGuard Labs
FortiGuard Labs has observed a significant uptick in attacks targeting Langflow, leveraging a recently discovered authentication bypass vulnerabili...
JadePuffer ransomware used AI agent to automate entire attack
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent.
Agentic AI Used to Conduct Ransomware Attack via Langflow
Attack demonstrates how LLM agents can combine known exploitation techniques with real-time reasoning to automate complex, multi-stage intrusions.
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Sysdig says JADEPUFFER used CVE-2025-3248 in Langflow to automate intrusion, credential theft, encryption, and data wipe.
Part of the PlainSec briefing for 2026-07-08