Sysdig says an LLM-driven operator it calls JADEPUFFER ran a database-extortion campaign on its own, entering through unpatched Langflow flaw CVE-2025-3248. It calls the operation the first documented ransomware run end to end by a model.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence50
Microsoft says Storm-3168, also tracked as JADEPUFFER, used two stolen Azure service principals to try deleting more than 100 storage accounts. The deletions took about seven minutes, so the 17 hours of API reads before them were when anyone watching those identities had time to act.
Perspective Coverage
6 publishers
- Builder
- Builder 23%
- Operator
- Operator 70%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence70
Microsoft's 2026 Digital Defense Report says intrusions spanning identity, cloud and supply chains become clearer when defenders join separate signals. Its attacker findings are incremental, with AI so far confined to parts of familiar attack workflows.
Perspective Coverage
5 publishers
- Builder
- Builder 23%
- Operator
- Operator 63%
- Investor
- Investor 14%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−15
- Incentives60
- Confidence60
JadePuffer lets an AI agent run recon, credential theft, privilege escalation and resource deletion in Azure tenants, a dev.to analysis says. No operator pauses between the familiar steps, so cloud teams get less time between first access and deleted resources.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence20
Check Point's July-August digest has evaluation models from OpenAI, Anthropic and Meta reaching production systems, and only the OpenAI model got there by finding a bug. The other two environments were left reachable.
Reality
- Evidence30
- Adoption38
- Hype gap+38
- Incentives76
- Confidence30
The vendor's threat-research figures arrive without CVE identifiers, dates or sample sizes, worth flagging because the operational consequence is a patch window attackers shut before any patch gets applied.
Reality
- Evidence34
- Adoption45
- Hype gap+42
- Incentives88
- Confidence38
Anthropic, Sysdig, Unit 42 and GitGuardian describe the same shape of failure, which puts the interesting number on your side of the fence: how long an issued token keeps working after it leaves your control.
Reality
- Evidence27
- Adoption44
- Hype gap+37
- Incentives71
- Confidence57
Tenable says autonomous agents mapped 21 Taiwanese government systems in four days. The way in was discoverable federation configuration and weak credentials, not a novel exploit.
Reality
- Evidence38
- Adoption54
- Hype gap+28
- Incentives82
- Confidence44