Organizations/security vendor

Sysdig

Cloud and container security company; its Threat Research Team publishes intrusion analyses.

1 records1 attackWebsite
Jul 1, 2026
Sysdig documents JADEPUFFER, a database-extortion intrusion it says an LLM agent ran end to end
AttackIncidentSysdig, JADEPUFFER

Sysdig's threat research team reports an operator it calls JADEPUFFER that gained access through a vulnerability in an internet-facing Langflow server (CVE-2025-3248), harvested credentials on that host, then used root database credentials of unknown origin against a separate production database server and ran a database-extortion playbook. Sysdig assesses the operation was driven end to end by an LLM agent, citing self-narrating payloads with natural-language reasoning and rapid adaptive retries, and calls it the first documented case of agentic ransomware.