In July 2026, the Sysdig Threat Research Team published what it assesses to be the first documented case of agentic ransomware: an extortion operation driven end to end by a large language model. Sysdig named the operator JADEPUFFER. The agent got in through CVE-2025-3248, a known missing-authentication flaw in the Langflow AI workflow platform. It swept the host for AI provider API keys and cloud credentials, used default MinIO credentials to pull an access key from a credentials.json file, and set up persistence. It then attacked its real target, a production MySQL and Nacos server, with root database credentials and Nacos's well-known default JWT signing key. It encrypted 1,342 configuration items with a key it never saved and dropped whole databases. Every step turned on a machine credential that was exposed, default or never changed.
Key takeaways
- Sysdig assesses JADEPUFFER as an "agentic threat actor": its payloads narrated their own reasoning, and in one sequence it went from a failed login to a working fix in 31 seconds.
- Initial access was CVE-2025-3248, an unauthenticated code execution flaw in Langflow fixed in 2025. Sysdig notes Langflow servers often hold AI provider API keys and cloud credentials in their environment.
- The agent harvested LLM provider keys, cloud credentials and database credentials, then used MinIO's default
minioadmincredentials to read.envandcredentials.jsonfrom object storage. - Against the production target it used root MySQL credentials of unknown origin and tried to forge Nacos tokens with the documented default JWT signing key. It created a backdoor admin, encrypted 1,342 Nacos configuration items and dropped databases.
- The encryption key was printed once and never stored or sent, so the victim cannot recover the data even by paying. The lesson: default and ambient credentials are the fuel for agentic attacks.
At a glance
| Organisations | An unnamed organisation running an internet-facing Langflow instance and a production MySQL and Alibaba Nacos server |
|---|---|
| When | Published by Sysdig on 1 July 2026; reported by SecurityWeek (3 July) and BleepingComputer (4 July) |
| Attacker | JADEPUFFER, an unattributed operator whose attack was run by an AI agent (Sysdig calls it an agentic threat actor) |
| Entry point | CVE-2025-3248, a missing-authentication code execution flaw in an internet-facing Langflow instance |
| Identities abused | AI provider API keys, cloud and database credentials in the Langflow environment; default MinIO credentials; an access key in credentials.json; root MySQL credentials; the default Nacos JWT signing key; a backdoor Nacos admin account |
| Impact | 1,342 Nacos configuration items encrypted with an unrecoverable key; configuration and history tables and whole databases dropped; persistence on the Langflow host |
| Category | Agentic AI and AI agents, NHI. Incident class: confirmed AI-agent breach (an AI agent used as the attacker against a real organisation) |
What happened
Langflow is an open-source framework for building LLM applications and agent workflows. CVE-2025-3248 is a missing-authentication flaw in its code validation endpoint that lets anyone who can reach the server run Python on it. Sysdig says Langflow servers are an attractive entry point because they "frequently hold provider API keys and cloud credentials in their environment, and are often stood up quickly without network controls."
Once the agent had code execution, it enumerated the host and swept the environment for secrets in parallel. It looked for LLM provider API keys (OpenAI, Anthropic, DeepSeek, Gemini and others), cloud credentials for Chinese and Western providers, cryptocurrency wallets, and database credentials and configuration files. It dumped Langflow's own backing Postgres database, taking stored credentials, API keys and user records. It scanned the internal network with default credentials and found a MinIO object store. There it used MinIO's default minioadmin:minioadmin credentials to list buckets, including a Terraform state bucket, and fetched .env and credentials.json from an internal bucket. The latter returned an access key and secret pair. It also added a cron job beaconing to its command server every 30 minutes.
The real target was a separate internet-exposed production server running MySQL and Alibaba's Nacos configuration service. Sysdig captured the agent connecting to MySQL with root credentials. Sysdig did not see those credentials being harvested, and their origin is unknown. The agent attacked Nacos through a known authentication bypass (CVE-2021-29441) and by forging a token with Nacos's default JWT signing key, which it abandoned when a custom key was in use. With root database access, it inserted a backdoor administrator directly into the Nacos database. When the first login failed, it diagnosed the problem and issued a corrected payload 31 seconds later.
It then encrypted all 1,342 Nacos configuration items with MySQL's AES_ENCRYPT(), dropped the original configuration and history tables, and created a README_RANSOM table with a Bitcoin address and a Proton Mail contact. The key was generated randomly, printed once and never stored or sent, so the data cannot be recovered even with payment. It then dropped entire databases. Its code claimed the data had been "backed up" to a staging server, which Sysdig says is the agent's own assertion and was not verified.
Timeline
| Date | Event |
|---|---|
| 1 April 2025 | Langflow fixes CVE-2025-3248 (BleepingComputer). |
| May 2025 | CISA flags CVE-2025-3248 as exploited in attacks (BleepingComputer). |
| 1 July 2026 | Sysdig publishes its JADEPUFFER analysis. |
| 3 July 2026 | SecurityWeek reports the agentic ransomware attack. |
| 4 July 2026 | BleepingComputer reports the attack. |
| 14 August 2026 | Tenable includes JADEPUFFER in a cluster of seven agentic AI threat incidents. |
How it happened: the identity attack path
- An unauthenticated AI platform on the internet. An unpatched Langflow instance let the agent run code without logging in.
- Ambient secrets on an AI host. The Langflow server held AI provider keys, cloud credentials and database credentials in its environment and backing database, all readable once the agent had code execution.
- Default credentials on internal services. MinIO accepted its factory credentials. The agent used them to read a
credentials.jsonfile containing an access key and secret. - Root database credentials exposed to the internet. The production MySQL server accepted root logins from outside. How the agent got those credentials is unknown.
- A default signing key and a known auth bypass. Nacos's documented default JWT signing key and CVE-2021-29441 gave routes to forged sessions. Root database access let the agent write a backdoor admin directly.
- Destruction at machine speed. With admin and root access, the agent encrypted configuration, dropped history and deleted databases, correcting its own errors in seconds.
Impact
- Configuration: all 1,342 Nacos service configuration items encrypted with a key that was never stored. Sysdig says recovery is impossible even with payment.
- Data: configuration and history tables and multiple databases dropped. The agent claimed data was copied to a staging server, but this was not verified.
- Credentials: AI provider keys, cloud credentials, database credentials and a MinIO-stored access key exposed, all of which must be treated as compromised.
- Persistence: a cron beacon on the Langflow host every 30 minutes.
What this means for NHI and AI agent security
JADEPUFFER shows what happens when an AI agent is pointed at the long tail of neglected machine credentials. None of the techniques were new: an old Langflow flaw, default MinIO credentials, a default Nacos signing key and root database access from the internet. What was new was an agent chaining them without a human, diagnosing failures in seconds, and working through more than 600 purposeful payloads in a compressed window. Sysdig's point that agents make "spraying the entire historical vulnerability catalogue effectively free" applies just as much to default and forgotten credentials.
It also shows why AI infrastructure is a prime target. AI orchestration servers such as Langflow often sit with provider API keys and cloud credentials in their environment, which makes them both an entry point and a haul. Those keys can fund further attacks through LLMjacking, which our LLMjacking Guide covers. The fixes are identity hygiene: no secrets in web-reachable process environments, no default credentials or signing keys, and no administrative database accounts exposed to the internet.
Recommendations
- Patch and fence AI workflow platforms. Update Langflow past CVE-2025-3248 and never expose code execution or validation endpoints to the internet. See our AI Infrastructure Workload Identity Guide.
- Keep secrets out of AI server environments. Move provider API keys and cloud credentials into a secrets manager and issue short-lived, scoped credentials. See our Secrets Management Guide.
- Eliminate default credentials and keys. Change MinIO's default credentials and Nacos's default
token.secret.key, and scan for other factory defaults across internal services. - Never expose database admin accounts. Block root and admin logins from the internet, restrict management ports by source IP, and do not let services connect to their databases as root. See our Service Account Security Guide.
- Control egress and watch for beacons. Stop application hosts from reaching arbitrary destinations, and alert on scheduled tasks making outbound calls.
- Rotate after exposure. Treat every credential on a compromised AI host as leaked. Use our Leaked Credential Response Playbook.
Frequently asked questions
What is JADEPUFFER?
JADEPUFFER is Sysdig's name for an operator whose ransomware attack was run by an AI agent. Sysdig assesses it as the first documented case of agentic ransomware, based on self-narrating payloads, fixes to failures within seconds and more than 600 purposeful payloads in a short window.
Could the victim recover the data by paying?
No. Sysdig says the agent generated a random encryption key, printed it once and never stored or transmitted it. The encrypted Nacos configurations cannot be decrypted even with payment.
Why is JADEPUFFER an NHI incident?
Every step used a machine credential: AI provider keys and cloud credentials on the Langflow host, default MinIO credentials, an access key in a stored file, root database credentials and a default JWT signing key. Removing default credentials and keeping secrets out of reachable environments would have broken the chain.
Related NHI Mgmt Group resources
Taiwan autonomous AI agent cyberattack 2026 · LLMjacking attacks on AI API keys · 230 million AWS environments exposed through .env files · API Key Management Guide · Guide to the Secret Sprawl Challenge
How NHI Mgmt Group can help
Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as AI-driven attackers work through default credentials and exposed keys at machine speed. Our NHI Foundation Level Training Course gives teams the practical grounding to find and remove them first.
References
- Sysdig: JADEPUFFER: Agentic ransomware for automated database extortion (1 July 2026)
- SecurityWeek: Agentic AI Used to Conduct Ransomware Attack via Langflow (3 July 2026)
- BleepingComputer: JadePuffer ransomware used AI agent to automate entire attack (4 July 2026)
- Tenable: The Agentic AI threat cluster: seven incidents, three actors, and what they mean for your exposure (14 August 2026)