SYSDIG JUL 20, 2026 · Updated July 28, 2026 · InsureAI Wire

Sysdig Says JADEPUFFER Shows Agentic AI Ransomware Is Operational

Sysdig’s Threat Research Team documented JADEPUFFER, a ransomware operation its researchers assess was driven end to end by a large language model: reconnaissance, credential harvesting, lateral movement, and production-database extortion, with no human at the keyboard. The operation, detailed in a Sysdig post published July 1, 2026, gained initial access to an internet-facing Langflow instance through CVE-2025-3248 before pivoting to the intended target database.

The assessment is inferential, and Sysdig says so: it has no visibility into the system prompt or agent configuration. What it has instead is behavioral evidence, including code that narrates its own reasoning and a failure the operator corrected within 31 seconds. Underwriters can read that 31 seconds as the operative number. It is faster than a pager. That is the interval a response plan now has to beat.

The rest of the paper trail was a byproduct. Sysdig counted 600-plus distinct, purposeful payloads, annotated in plain language as the campaign worked. Its researchers read that habit itself as a tell, since human operators do not comment throwaway one-liners that way and generated code does it by default. An attacker that documents its own decision-making is also an attacker that does not need a human awake to make the next decision.

That breaks an assumption buried in most incident response playbooks. Traditional ransomware response is built around human decision points: pauses between stages, errors that reveal attacker intent, a negotiation window. An agentic operation compresses those stages and may never open the window at all. Here the window was worth nothing anyway. Sysdig found the encryption key was generated at runtime, printed once, and never stored or sent anywhere, which leaves the encrypted configurations unrecoverable whether or not the victim pays. Underwriters should be asking insureds about their AI vendor inventory, particularly any internet-facing orchestration tools like Langflow, and whether those instances are patched against known vulnerabilities.

The entry point matters as much as the payload. JADEPUFFER got in through an internet-facing Langflow instance, an open-source AI workflow tool, via a known and patchable CVE. That is the unglamorous part of the story and the part an underwriter can actually price. Vendor AI risk assessment has generally asked what a model might get wrong; this incident asks who stood up the orchestration layer around it and when they last patched it. Those tools get deployed by teams who do not consider themselves operators of production infrastructure, and on a lot of programs nobody owns their patch cycle at all.

Share

Information aggregation and analysis, not legal advice. See our disclaimer.