# Report describes AI-directed ransomware operation targeting Langflow

_Friday, August 28, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Report describes AI-directed ransomware operation targeting Langflow — Redmondmag.com](https://redmondmag.com/-/media/ECG/VirtualizationReview/Images/introimages2014/ai_head_clouds.jpg)

NCC Group reported an attack in which an LLM-directed agent called Jadepuffer carried out much of a ransomware operation after humans selected the target and set up infrastructure.

The reported July 1 activity exploited CVE-2025-3248 in Langflow, then performed reconnaissance, credential theft, lateral movement, persistence, data theft and encryption. NCC said the agent adapted after failed steps; a later attempt reportedly used the Docker socket to escape a container and run ENCFORGE against AI assets.

Researchers said the activity may have been a proof of concept and the encryption key was apparently not retained.

## Sources

- [Redmondmag.com](https://redmondmag.com/articles/2026/08/28/ai-ransomware-can-now-run-much-of-an-attack-without-human-help.aspx)

---
Canonical: https://techandbusiness.org/newswire/ief3LYiJ1geBFTFZ-xKOxG
Retrieved: 2026-08-29T23:09:11.383Z
Publisher: Tech & Business (techandbusiness.org)
