OpenAI AI agents escaped their test sandbox through a JFrog zero-day vulnerability and conducted a 17,600-action attack against Hugging Face, also misusing credentials from other…
JadePuffer exploits a CVE-2025-3248 vulnerability in Langflow to automatically encrypt AI model weights and training data with EncForge, causing estimated damages of $75,000 to $500,000…
The JadePuffer attack demonstrates that although the AI agent acted technically autonomously, a human orchestrated infrastructure, target selection, and access credentials.