đ Zaprep: Tus redes sociales al mĂĄximo. Empezar gratis â automatiza 1,000 DMs/mes y convierte el engagement en leads. con 1,000 DMs automatizados/mes.
Enviar tu herramienta
AI NewsThe âfirstâ AI-run ransomware attack still needed a human
The âfirstâ AI-run ransomware attack still needed a human
8:26 AM IST · July 7, 2026

Last week, researchers at cloud security firm Sysdig said theyâd documented the first known case of âagentic ransomware.â It was an extortion operation, dubbed JadePuffer, in which an AI agent â not a human â handled the technical execution of a real-world cyberattack from start to finish. The agent broke into a vulnerable server, stole credentials, moved through the targetâs network, encrypted files, and even wrote its own ransom note, adapting to obstacles along the way like a human hacker would. Coverage of the funding described it as run âwithout any human oversight,â with âno human at the keyboard.â Thatâs not quite thefullpicture. In aninterviewon Monday with CyberScoop, Sysdigâs Michael Clark, the companyâs senior director of threat research, clarified that a human was still very much involved â just not in the technical execution. âA human still set up and pointed the operation and provisioned the infrastructure behind it, the command-and-control server, the staging server used for the stolen data and chose a victim,â Clark said. The credentials used to break into the victimâs database, he added, werenât harvested by the AI agent itself; someone obtained them separately, through a prior compromise, and handed them to the operation. None of this contradicts Sysdigâs original claim, and the technical details of the attack remain notable on their own â wild, even. The agent got in through a known bug inLangflow, a popular open-source tool for building LLM apps, then moved on to a production MySQL server and exploited another known flaw to gain admin access. It encrypted over 1,300 configuration records and not only left behind a ransom note that it wrote itself but it left a Bitcoin address where the ransom could be sent. Sysdig hasnât disclosed who was targeted. The techniques were fairly ordinary apparently, what stood out was the speed and transparency involved. The agent fixed a failed login in 31 seconds, narrating its own reasoning in natural-language code comments the whole way. One detail that initially seemed to muddy the picture has since been clarified. Clark had told CyberScoop that Sysdig found âmultiple models were used in the attack,â citing harvested keys for OpenAI, Anthropic, DeepSeek, and Gemini â language that left open the question of whether several models actively powered different stages of the intrusion. Asked to clarify, Clark told TechCrunch that those keys were simply part of what the agent stole, not evidence of what was driving it. âThe agent swept the Langflow host for anything valuable â provider API keys, cloud credentials, cryptocurrency wallets, and database configs â and those provider keys were part of the loot,â he said via email. âThey are indicative of what the attacker considered worth taking, but they do not tell us which model was making the decisions.â On the model actually running JadePuffer, Clark said Sysdig âwas not able to identify the specific model driving the agentâ and has no visibility into its system prompt or configuration. Microsoft researcher Geoff McDonaldâs theory,offered on LinkedInseveral days ago, is worth revisiting in that light. McDonald suspected an open-weight model with safety training stripped out, rather than a frontier model, was behind the attack, based on his own red-teaming experience showing frontier labsâ safety layers hold up well. Sysdigâs own account doesnât confirm or rule that out. McDonaldâs post also warned that ransomware campaigns are now bounded primarily by attacker budget rather than human effort, raising the possibility of âthousands or tens of thousands of simultaneous campaigns.â That concern is a little harder to square with what Clark described Monday. (If a human still has to choose each victim, provision infrastructure, and obtain database credentials for every operation, thatâs a bit of a bottleneck, at least.) Either way, Clark told CyberScoop, while Sysdig hasnât seen the same operation hit other victims yet, given how cheap it is to run an agent, he expects that to change.
read moreĂltimas noticias de IA
Ver todas las noticias âEnviar tu herramienta
PoweredByAI.app es un directorio de herramientas de IA que ayuda a personas, empresas y creadores a descubrir las mejores herramientas de IA para escritura, programación, diseño, productividad y mås.
© 2026 , Producto de011BQ. Todos los derechos reservados.




