ransomware
Agentic AI Used to Conduct Ransomware Attack via Langflow
Critical
Summary
A threat actor, tracked as JadePuffer, exploited a critical vulnerability (CVE-2025-3248) in the Langflow LLM framework to conduct a ransomware attack. The attacker leveraged an LLM agent to perform reconnaissance, steal credentials, and ultimately encrypt a Nacos configuration server, demonstrating the potential of agentic tooling to lower the barrier to attack. This highlights the need for defenders to proactively secure exposed infrastructure and database accounts.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data