Sysdig says an LLM-driven operator it calls JADEPUFFER ran a database-extortion campaign on its own, entering through unpatched Langflow flaw CVE-2025-3248. It calls the operation the first documented ransomware run end to end by a model.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence50
Microsoft says Storm-3168, also tracked as JADEPUFFER, used two stolen Azure service principals to try deleting more than 100 storage accounts. The deletions took about seven minutes, so the 17 hours of API reads before them were when anyone watching those identities had time to act.
Perspective Coverage
6 publishers
- Builder
- Builder 23%
- Operator
- Operator 70%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence70
One HTTP request runs Python on an exposed Langflow server, and Sysdig's honeypots logged exploit attempts inside a day of the March 17 advisory, before any public proof-of-concept existed. The traffic identified itself as nuclei.
Reality
- Evidence58
- Adoption34
- Hype gap+30
- Incentives78
- Confidence52
VulnCheck logged more than 15,000 successful hits on decoy Langflow instances while eleven new flaws joined the exploited-in-the-wild list, on a product whose first deployment model expects to face the internet.
Reality
- Evidence60
- Adoption66
- Hype gap+18
- Incentives80
- Confidence55
Tenable says autonomous agents mapped 21 Taiwanese government systems in four days. The way in was discoverable federation configuration and weak credentials, not a novel exploit.
Reality
- Evidence38
- Adoption54
- Hype gap+28
- Incentives82
- Confidence44