JadePuffer exploits a CVE-2025-3248 vulnerability in Langflow to automatically encrypt AI model weights and training data with EncForge, causing estimated damages of $75,000 to $500,000…
The JadePuffer attack demonstrates that although the AI agent acted technically autonomously, a human orchestrated infrastructure, target selection, and access credentials.
An AI agent named JADEPUFFER has for the first time independently orchestrated a complete ransomware campaign by exploiting a Langflow RCE vulnerability.