Security firm Sysdig describes an extortion attack where a language model broke in on its own, stole credentials, and destroyed databases. No human appeared to be at the controls.

Attackers exploited Langflow vulnerability CVE-2025-3248 to conduct an agentic AI-powered ransomware attack involving reconnaissance, credential theft, and lateral movement.

JadePuffer è il primo ransomware agentico osservato in azione: sfrutta vulnerabilità, si adatta agli errori e automatizza l'attacco.