The first AI ransomware walked in through an open door
In early July, Sysdig documented the first ransomware campaign an AI agent ran on its own, from reconnaissance to encryption. The unsettling part is not the AI: entry came through a known vulnerability, a second one from 2021 and default credentials. Why the fundamentals still defend against attackers moving at machine speed.
In early July, Sysdig's threat research team documented a ransomware campaign it calls JadePuffer: the first known operation in which an AI agent ran the attack end to end. Reconnaissance, credential theft, lateral movement, persistence, encryption, ransom note, all without a human hand on the tooling. When a login failed, the agent diagnosed the cause and delivered a working fix after 31 seconds.
What the agent could do is new
The speed is where something has changed. A human attacker tries, waits, comes back. This agent worked continuously, adapted within seconds and narrated its own intent along the way. In the end, 1,342 configuration items were encrypted and at least eight databases destroyed. The agent never stored the encryption key. Anyone who had paid would still have gotten nothing back.
How it got in is old
And this is where the second look pays off: entry came through CVE-2025-3248, a vulnerability in the LLM framework Langflow known for more than a year, unauthenticated code execution on an exposed endpoint. Of all things, an AI tool was the door for the AI attack. From there it moved on through a configuration server with a vulnerability from 2021 and an object store with default credentials. Not a single zero-day. The AI automated the execution. The doors were open long before.
What follows for defense
Against an attacker moving at machine speed, no new miracle tool defends you, but the fundamentals, applied more consistently: know which services are reachable from outside, close known and actively exploited vulnerabilities first, harden default credentials and exposed endpoints. That is exactly what attack surface management in isidaten is for, continuously mapping your external exposure, and vulnerability management, which prioritizes findings by real-world exploitation instead of working through half the list. Why not every CVE counts was covered here before.
How to get a grip on your exposure and your vulnerabilities is shown on the module pages Attack Surface Management and Vulnerability Management.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.