CVE-2025-3248Active Exploitation(langflow / langflow)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch langflow langflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-306CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 122 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 147 mentions across 48 observed days

What's happening

  • Active exploitation reported across 122 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 32 signals
  • Technical details provided in 80 signals
  • General: 8 classified signals
  • Peaked 32d ago at 15 mentions (2026-07-06); latest day: 2
  • 147 total mentions across 48 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline147 mentions / 48d
0481115Mentions · 2026-03-01: 1Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-04-02: 1Mentions · 2026-04-29: 1Mentions · 2026-05-23: 1Mentions · 2026-06-25: 1Mentions · 2026-07-01: 2Mentions · 2026-07-02: 7Mentions · 2026-07-03: 10Mentions · 2026-07-04: 7Mentions · 2026-07-05: 13Mentions · 2026-07-06: 15Mentions · 2026-07-07: 15Mentions · 2026-07-08: 9Mentions · 2026-07-09: 2Mentions · 2026-07-10: 4Mentions · 2026-07-12: 2Mentions · 2026-07-13: 2Mentions · 2026-07-14: 4Mentions · 2026-07-15: 3Mentions · 2026-07-16: 1Mentions · 2026-07-17: 1Mentions · 2026-07-18: 2Mentions · 2026-07-20: 3Mentions · 2026-07-21: 11Mentions · 2026-07-22: 1Mentions · 2026-07-23: 1Mentions · 2026-07-26: 1Mentions · 2026-07-31: 2Mentions · 2026-08-01: 1Mentions · 2026-08-05: 2Mentions · 2026-08-06: 1Mentions · 2026-08-07: 1Mentions · 2026-08-08: 1Mentions · 2026-08-11: 1Mentions · 2026-08-26: 1Mentions · 2026-09-05: 1Mentions · 2026-09-10: 2Mentions · 2026-09-16: 1Mentions · 2026-09-19: 1Mentions · 2026-09-26: 1Mentions · 2026-09-29: 1Mentions · 2026-10-01: 1Mentions · 2026-10-02: 2PoC Mentioned / Linked · 2026-06-25: 1PoC Mentioned / Linked · 2026-07-02: 1PoC Mentioned / Linked · 2026-07-03: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-07-21: 1PoC Mentioned / Linked · 2026-07-31: 1PoC Mentioned / Linked · 2026-08-05: 1PoC Mentioned / Linked · 2026-08-08: 1Exploit Tool / Code · 2026-07-18: 1Exploit Tool / Code · 2026-07-20: 2Exploit Tool / Code · 2026-07-21: 2Active Exploitation · 2026-03-01: 1Active Exploitation · 2026-03-25: 2Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-07-01: 2Active Exploitation · 2026-07-02: 7Active Exploitation · 2026-07-03: 8Active Exploitation · 2026-07-04: 7Active Exploitation · 2026-07-05: 11Active Exploitation · 2026-07-06: 14Active Exploitation · 2026-07-07: 14Active Exploitation · 2026-07-08: 8Active Exploitation · 2026-07-09: 2Active Exploitation · 2026-07-10: 4Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-07-13: 2Active Exploitation · 2026-07-14: 2Active Exploitation · 2026-07-15: 2Active Exploitation · 2026-07-17: 1Active Exploitation · 2026-07-18: 2Active Exploitation · 2026-07-20: 3Active Exploitation · 2026-07-21: 10Active Exploitation · 2026-07-22: 1Active Exploitation · 2026-07-26: 1Active Exploitation · 2026-07-31: 2Active Exploitation · 2026-08-01: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-06: 1Active Exploitation · 2026-08-07: 1Active Exploitation · 2026-08-11: 1Active Exploitation · 2026-09-05: 1Active Exploitation · 2026-09-10: 2Active Exploitation · 2026-09-16: 1Active Exploitation · 2026-09-26: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-07-02: 2Patch / Workaround · 2026-07-03: 3Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-05: 5Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-07: 3Patch / Workaround · 2026-07-08: 4Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-10: 2Patch / Workaround · 2026-07-13: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-07-18: 2Patch / Workaround · 2026-07-23: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-09-10: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-23: 1Technical Details · 2026-06-25: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 6Technical Details · 2026-07-03: 4Technical Details · 2026-07-04: 4Technical Details · 2026-07-05: 9Technical Details · 2026-07-06: 4Technical Details · 2026-07-07: 4Technical Details · 2026-07-08: 5Technical Details · 2026-07-09: 2Technical Details · 2026-07-10: 3Technical Details · 2026-07-12: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-15: 2Technical Details · 2026-07-17: 1Technical Details · 2026-07-18: 2Technical Details · 2026-07-20: 3Technical Details · 2026-07-21: 6Technical Details · 2026-07-22: 1Technical Details · 2026-07-23: 1Technical Details · 2026-07-26: 1Technical Details · 2026-08-08: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-26: 1Technical Details · 2026-09-10: 1Technical Details · 2026-09-16: 1Technical Details · 2026-09-19: 1Technical Details · 2026-09-26: 103-0103-2805-2307-0307-0707-1207-1607-2107-3108-0709-0509-2610-02
Signal classification6 categories
Active Exploitation
11983.2%
Patch
96.3%
General
85.6%
Disclosure
42.8%
PoC
21.4%
Exploit
10.7%
Referenced assets85 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-011
Active Exploitation1
2026-03-252
Active Exploitation2
2026-03-261
Disclosure1
2026-03-271
Active Exploitation1
2026-03-281
Active Exploitation1
2026-03-301
Active Exploitation1
2026-04-021
Disclosure1
2026-04-291
Patch1
2026-05-231
Active Exploitation1
2026-06-251
Active Exploitation1
2026-07-012
Active Exploitation2
2026-07-027
Active Exploitation7
2026-07-0310
Active Exploitation8Patch1PoC1
2026-07-047
Active Exploitation7
2026-07-0513
Active Exploitation10Patch3
2026-07-0615
Active Exploitation14General1
2026-07-0715
Active Exploitation14General1
2026-07-089
Active Exploitation7Patch2
2026-07-092
Active Exploitation2
2026-07-104
Active Exploitation4
2026-07-122
Active Exploitation1Patch1
2026-07-132
Active Exploitation2
2026-07-144
Active Exploitation2Disclosure1General1
2026-07-153
Active Exploitation2Patch1
2026-07-161
General1
2026-07-171
Active Exploitation1
2026-07-182
Active Exploitation2
2026-07-203
Active Exploitation3
2026-07-2111
Active Exploitation9Exploit1General1
2026-07-221
Active Exploitation1
2026-07-231
General1
2026-07-261
Active Exploitation1
2026-07-312
Active Exploitation2
2026-08-011
Active Exploitation1
2026-08-052
Active Exploitation1General1
2026-08-061
Active Exploitation1
2026-08-071
Active Exploitation1
2026-08-081
PoC1
2026-08-111
Active Exploitation1
2026-08-261
General1
2026-09-051
Active Exploitation1
2026-09-102
Active Exploitation2
2026-09-161
Active Exploitation1
2026-09-191
Disclosure1
2026-09-261
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🛑 New ENCFORGE ransomware is built to encrypt AI model weights, vector indexes, and training data. Deployed via Langflow CVE-2025-3248 (CVSS 9.8, CISA KEV). Experts link it to the same operator from the earlier agentic attack. Learn how the attack reached host root: https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html

    Post summary

    ENCFORGE ransomware is actively exploiting CVE-2025-3248 in Langflow (CVSS 9.8, CISA KEV), targeting AI model weights and training data. No patches or PoC are cited, but the exploit is confirmed to be in use in the wild.

    4190611518.6K
    2.3M followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🔥 An AI agent turned Langflow RCE into automated database extortion. CVE-2025-3248 exploited to steal secrets, move laterally, hijack Nacos, encrypt 1,342 configuration items, and drop database schemas. Inside the attack chain: https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html https://t.co/ZSs6GEFiQ9

    Post summary

    CVE-2025-3248 is being actively exploited by an AI agent to execute an RCE that steals secrets, moves laterally, hijacks Nacos, encrypts configuration items, and drops database schemas.

    4180491519.2K
    2.3M followersView on X
  • Brute@BRuteLogic
    General

    Patch_Diffs -> New_Bugs Langflow, an open-source tool for visually building AI agent and RAG pipelines, is another example of multiple hits by the same flaw. CVE-2025-3248: user input to exec() CVE-2026-33017: same sink, diff endpoint 1. Grep the sink, not the CVE grep -rn "exec(compiled_code" src/ 2. Find every caller of the sink grep -rln "instantiate_class" src/ 3. Map callers to HTTP endpoints grep -B15 "async def.*flow" http://chat.py Patched once, vulnerable twice.

    Post summary

    The post describes two CVEs affecting Langflow through an exec() sink, provides search‐based detection steps, but offers no PoC, exploit, patch, or evidence of active exploitation.

    27034163.6K
    66.7K followersView on X
  • spencer@techspence
    Active Exploitation

    Say hello to “agentic threat actors” :) Jadepuffer: > “first” case of “agentic malware” > ran an “adaptive” and “fully automated” campaign > yes I know heavy quotation marks here > initial access via exposed langflow (CVE-2025-3248) > typical recon things: ID, uname, etc. > looking for database creds & crypto wallets & seeds & LLM API keys > dumped the langflow database harvesting fun stuff > did internal network discovery > did local object store enumeration (s3 kinda thing) > grabbed creds from the local object storage > setup a crontab for persistence > somehow has root creds for a MySQL databas > connects to said database as root > uses auth bypass cve to attack this nacos micro services thing > bypass failed sorta > created a new one in 31 seconds, this one worked > nacos service gets ransomwared > ransomware key was sent to stdout, not saved, so recovering files is impossible > drops the database https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion

    Post summary

    The post documents a live ransomware attack leveraging CVE‑2025‑3248 against langflow, demonstrating active exploitation resulting in database compromise and data extortion.

    38029182.4K
    17.9K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🤖🚨 AI FOUND THE VULNERABILITY. ATTACKERS WEAPONIZED IT FOUR DAYS LATER. Google Threat Intelligence Group has published new data showing how quickly AI-discovered vulnerabilities are crossing into real-world attacks. One case stands out: CVE-2026-1731 The unauthenticated OS command-injection vulnerability affecting BeyondTrust Privileged Remote Access and Remote Support was discovered AUTONOMOUSLY by the Hacktron AI research agent. Then attackers arrived. GTIG observed: * First threat cluster exploiting it within FOUR DAYS of disclosure * Five additional threat clusters within SEVEN DAYS * Privilege escalation * Data exfiltration * SNOWLIGHT deployment * SPARKRAT deployment * Cryptominer deployment But Google's broader dataset may be even more important. Exactly 50% of vulnerabilities identified as AI-discovered resulted in REMOTE CODE EXECUTION. Across the broader vulnerability ecosystem? 26%. AI is also becoming a target itself. GTIG tracked 2,076 AI-related CVEs from January 2025 through August 2026. More than 1,500 appeared in just the first eight months of 2026. The largest attack surface: * 782 vulnerabilities in AI orchestration/agent frameworks * 230 in AI web apps * 212 in inference/serving infrastructure * 106 model-security advisories * 99 affecting ML frameworks/hubs * 97 involving frontier-model tooling Orchestration middleware alone now represents roughly HALF of AI-related vulnerabilities and saw a 347% surge in disclosures during 2026. Attackers are already exploiting AI middleware in the wild. Google highlights: * LiteLLM CVE-2026-42271 — command injection → host takeover/API credential theft * Langflow CVE-2026-5027 — arbitrary file write * Langflow CVE-2025-3248 — unauthenticated Python code injection → RCE ⚠️ Analyst Note: AI is beginning to compress BOTH sides of the vulnerability lifecycle. Defensive agents can autonomously discover difficult, high-impact bugs. Attackers can then weaponize those disclosures almost immediately. Four days from AI discovery disclosure to observed exploitation is a warning about where vulnerability management is heading: PATCH WINDOWS ARE SHRINKING. https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era #AISecurity #VulnerabilityResearch #RCE #BeyondTrust #LiteLLM #Langflow #ThreatIntel #DDW

    12029106.9K
    207.5K followersView on X
  • L’algorisme@lalgorisme
    Active Exploitation

    Un agent d'IA va encadenar sol tota una campanya d'extorsió -accés via Langflow (CVE-2025-3248), robatori de credencials, moviment lateral- i va xifrar/esborrar dades de configuració sense guardar la clau per desencriptar-les. Un autèntic agent del caos. https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion

    Post summary

    The post reports that an AI‑driven ransomware agent used CVE‑2025‑3248 via Langflow to execute an extortion campaign, including credential theft, lateral movement, and data encryption/deletion, indicating active exploitation in the wild.

    1130142922
    5.9K followersView on X
  • Sysdig@sysdig
    Active Exploitation

    The Sysdig TRT just documented what we assess to be the first-ever agentic ransomware operation. We're calling the operator JADEPUFFER. It exploited CVE-2025-3248 in an internet-facing Langflow instance, then ran a fully autonomous, end-to-end extortion campaign — lateral movement, credential harvesting, and database destruction. Read the full research: https://okt.to/2RLw3c

    Post summary

    Sysdig TRT reported an agentic ransomware operation that actively exploited CVE-2025‑3248 on an internet‑facing Langflow instance, driving autonomous extortion activities. No patch, PoC, or detailed technical vulnerability information was provided.

    450134635
    10.3K followersView on X
  • White Knight Labs@WKL_cyber
    Active Exploitation

    Sysdig documented the first agentic ransomware operation. CVE-2025-3248 in Langflow. When a payload failed, the agent fixed and redeployed in 31 seconds. The skill floor for ransomware just dropped. Full CyberScoop article: https://bit.ly/4flVAR4 https://t.co/ExVtjucf7Q

    Post summary

    CVE-2025-3248 was exploited in a ransomware attack against Langflow, with Sysdig reporting the first agentic operation and quick remediation.

    010138921
    923 followersView on X
  • GreyNoise@GreyNoiseIO
    Active Exploitation

    Two CISA known-exploited remote code execution flaws in the AI application platform Langflow turned up this week inside ordinary commodity crawling. Adversaries attempted CVE-2025-3248 and CVE-2026-0770 at 3,968 and 4,770 connection attempts, both new to this brief series. Every address we recorded on either flaw also carries a generic web crawling tag, and roughly nine in ten collected environment files and enumerated WordPress installations alongside it. Two hosting providers supply roughly 95% of those addresses, so the source count measures provider egress. The same concentration ran through the rest of the week: four hosts carried 36% of all alternative-port SSH crawling observed, and one address carried more than half of the Remote Desktop crawling. Customers get the full weekly brief. Our public At The Edge one-pager: https://www.greynoise.io/resources/at-the-edge-clear-091426

    Post summary

    The text reports that two Langflow RCE flaws (CVE-2025-3248 and CVE-2026-0770) are CISA-known exploited and observed in adversary connection attempts, indicating active exploitation.

    0501511.3K
    29.6K followersView on X
  • White Knight Labs@WKL_cyber
    General

    Sysdig documented the first ransomware operation run entirely by an LLM agent. CVE-2025-3248 in Langflow, autonomous recon through encryption, and a failed login to a working fix in 31 seconds. The skill floor for ransomware just dropped. ➡️ https://bit.ly/4fmBox9 https://t.co/RRFYWnLzKV

    Post summary

    The post highlights Sysdig’s documentation of a ransomware operation driven by an LLM agent and references CVE‑2025‑3248 in Langflow with a noted working fix, but offers no proof‑of‑concept, exploit code, or evidence of active exploitation.

    0301441.0K
    908 followersView on X
  • Tobi@Tobi_Msp
    Active Exploitation

    So a human broke into a server. Then handed the whole attack to an AI and left. That's the story my feed flagged this week and I can't stop thinking about it. The way in was very boring, honestly. A Langflow server sitting open on the internet, one unpatched bug (CVE-2025-3248). The attacker got in, dropped an AI agent on the box, and that was the last human action in the entire attack. The agent stole API keys, cloud logins, crypto wallets, mapped the network, then used those stolen logins to take over a production server. No pause, no working hours. The bit that got me: while setting up its backdoor it hit an error. It read the error, fixed its own code and carried on. Took 31 seconds. I've spent longer than that staring at a typo. It ended by locking 1,342 files with a ransom note, but the key was never saved anywhere. So even paying gets you nothing. Not really ransomware, just destruction dressed like it. And the AI never did anything clever. No exploit invented, or any encryption broken. It just walked through identity failures we all know about which are keys nobody rotated, a default password, logins that worked in way too many places. The question I keep asking myself is that if an agent landed inside our systems tonight, how far would our logins take it? Research in the comments.

    Post summary

    A real attack using CVE‑2025‑3248 was described, in which a human initially breached a Langflow server and then deployed an AI agent that carried out the rest of the intrusion and destructive actions.

    33183802
    8.4K followersView on X
  • theBOZO@nftsToki
    Active Exploitation

    The $JADEPUFFER narrative is straight fire and it’s only getting started 🔥 Yesterday, cybersecurity researchers dropped bombshell news: JADEPUFFER — the world’s first fully autonomous LLM-powered ransomware agent. Using Langflow RCE (CVE-2025-3248), it autonomously generated 600+ payloads, chained exploits, encrypted databases, and ran end-to-end extortion… all without any human intervention. No scripts. No manual commands. Pure agentic chaos. This isn’t sci-fi. This just happened. And right on cue, Solana degens turned the terror into a banger: $JADEPUFFER — The Rogue Agent. We’ve already seen clean 4-5X pumps (22K → 110K+ MC), quick retraces, and strong rebounds. Low holder count, fresh chart, and a narrative that prints itself every time mainstream media pushes another “AI ransomware” headline. This coin doesn’t need paid influencers. Real-world events are the ultimate shill. While boomers clutch pearls about Skynet, we’re positioning for the next leg. AI agents are here. One just became a criminal mastermind. The meme writes itself. Expect massive volatility, but the upside asymmetry is ridiculous at these levels. Narrative + timing + Solana speed = classic 50-100X candidate if it catches rotation. The agent is rogue. The puffer is hungry. The chart is coiling. Don’t fade history in the making. $JADEPUFFER — loading more on dips. Who’s with me? 🐡💎 CA: MGwXSefHMCUXXGj1vH9HdtrtjJmkmG1ZDNBbq2vpump

    Post summary

    The post asserts that JADEPUFFER exploited CVE-2025-3248 in the wild, enabling a fully autonomous ransomware operation without manual script usage.

    331110585
    1.2K followersView on X
  • التميمي@altmemy199
    Active Exploitation

    باحثون من فريق Sysdig اكتشفوا أول حالة هجوم فدية نُفّذت بالكامل بالذكاء الاصطناعي بدون تدخل بشري. الحملة أخذت اسم JADEPUFFER. نقطة الدخول كانت سيرفر Langflow متاح من الإنترنت وهو أداة شهيرة لبناء تطبيقات مبنية على الذكاء الاصطناعي. الأداة فيها ثغرة (CVE-2025-3248) تخليك تشغّل كود عشوائي على السيرفر بدون أي باسورد. وبالمناسبة الثغرة انسدّت من مايو 2025 بس في كثير سيرفرات ما تحدّثت. أما الهجوم فالذكاء الاصطناعي قدر يلقى عند الضحية مفاتيح OpenAI وAnthropic وDeepSeek ووصول للسحابة وباسوردات قواعد بيانات ومحافظ كريبتو. وكمان لقى سيرفر فيه قاعدة بيانات MySQL وخدمة تخزين إعدادات Nacos. وتوصّل للقاعدة نفسها بصلاحيات مدير ومن وين جاله هذا الوصول خبراء Sysdig ما قدروا يعرفون. وبالأخير الذكاء الاصطناعي شفّر إعدادات النظام وحذف الجداول الأصلية وخلّى ورقة تطالب بفدية فيها عنوان BTC وإيميل للتواصل. والمشكلة إن الفدية كان مستحيل تفكّها لأن وكيل الذكاء الاصطناعي ما خزّن مفتاح التشفير في أي مكان. يعني حتى لو دفعت الضحية ما كانت بتقدر ترجّع بياناتها ولا تستعيد بني تفاصيل أكثر ومعلومات تقنية أوسع هنا https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion

    Post summary

    Researchers report an active AI‑driven ransomware campaign, JADEPUFFER, that exploited CVE‑2025‑3248 in Langflow to steal cloud keys, encrypt data, and demand ransom, with no recovery key available.

    010881.6K
    16.6K followersView on X
  • ProtAAPP - Protege las AAPP@ProtAAPP
    Active Exploitation

    Investigadores de Sysdig han documentado el primer caso de ransomware, JadePuffer, que utiliza un agente de IA para automatizar ataques. Este agente explota la vulnerabilidad CVE-2025-3248 para robar credenciales y cifrar datos en 31 segundos. https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/ https://t.co/qxzqx4rXNZ

    Post summary

    The article reports the first ransomware that employs an AI agent to automate attacks using CVE‑2025‑3248 for credential theft and rapid data encryption, confirming active exploitation in the wild.

    14072575
    8.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    JADEPUFFER is the first documented end-to-end LLM-driven ransomware operation, exploiting CVE-2025-3248 in Langflow to chain recon, lateral movement, and database destruction with no human at the keyboard. Key findings: - Initial access via CVE-2025-3248, a no-auth remote code execution flaw in Langflow (CISA KEV, patched May 2025). The agent immediately swept for OpenAI, Anthropic, AWS, GCP, Azure, and Chinese 🇨🇳 cloud provider credentials, raided Langflow's Postgres backing store, then installed a crontab beacon to 45.131.66[.]106:4444 every 30 minutes before pivoting. - Lateral movement hit a production MySQL and Nacos server. JADEPUFFER exploited CVE-2021-29441, forged JWTs using Nacos's publicly known default signing key (documented since 2020), and injected a backdoor admin account. When bcrypt hashing failed due to a PATH issue, the agent self-corrected in 31 seconds with a 15-line fix: delete, diagnose, rebuild, reinsert. - Ransomware phase encrypted all 1,342 Nacos config items using MySQL AES_ENCRYPT(), dropped original tables, and created a README_RANSOM table with a Bitcoin address and Proton Mail contact e78393397[@]proton[.]me. The encryption key was printed to stdout once and never stored. Recovery is impossible even with payment. Defenders: patch Langflow, rotate every credential stored in AI-pipeline environments, change Nacos default JWT keys, and block unexpected egress. #DFIR_Radar

    Post summary

    JADEPUFFER shows an operational ransomware campaign that actively exploits CVE-2025-3248 in Langflow and CVE-2021-29441 in Nacos, conducting RCE, credential harvesting, lateral movement, and data encryption, with clear patching guidance offered.

    42152492
    1.9K followersView on X
  • ⧫⧫ M1S0 ⧫⧫@M1S00000
    PoC

    When “validate code” actually executes the code 😶 Found an unauthenticated RCE in Langflow (CVE-2025-3248). A code validation endpoint + attacker-controlled Python = 💥 Write-up 👇 https://m1s0-0.github.io/writeups/posts/langflow-rce-cve-2025-3248.html #BugBounty #CyberSecurity #RCE #Langflow

    Post summary

    The post announces a discovered unauthenticated RCE in Langflow (CVE‑2025‑3248) and links to a write‑up containing a proof‑of‑concept, but provides no exploit code or evidence of active attacks.

    02083524
    1.8K followersView on X
  • Infosecurity Magazine@InfosecurityMag
    Disclosure

    Sysdig reveals JadePuffer, allegedly the world's first AI-driven ransomware campaign. It exploited CVE-2025-3248, targeting a Langflow instance with an autonomous AI agent. In one attempt, it fixed a failed login in 31 seconds. http://spkl.io/60137y8PF https://t.co/Y5JRcerfyB

    Post summary

    Sysdig announces the JadePuffer AI‑driven ransomware campaign that reportedly exploits CVE‑2025‑3248 against a Langflow instance, but it offers no PoC, patch, or detailed technical data.

    030611.9K
    252.2K followersView on X
  • M 💎@mthego4t
    Active Exploitation

    JADEPUFFER is the first documented fully agentic ransomware: an LLM autonomously exploited known CVE-2025-3248 MGwXSefHMCUXXGj1vH9HdtrtjJmkmG1ZDNBbq2vpump

    Post summary

    The post reveals that the AI-driven ransomware 'JADEPUFFER' uses an LLM to autonomously exploit CVE‑2025‑3248, marking the first documented agentic ransomware taking advantage of this vulnerability in the wild.

    11080457
    6.3K followersView on X
  • Alcyon Junior@alcyjones
    General

    🚨 IA perde o controle e INVADE servidor Desta vez, o alvo foi o ecossistema do Langflow. O operador autônomo JadePuffer encontrou uma brecha crítica recente (CVE-2025-3248) #segurancadigital #tecnologia #ti #vulnerabilidade #inovacao #dev #inteligenciaartificial #dados https://t.co/eE8ySuDox9

    Post summary

    The tweet references CVE-2025-3248 but offers no concrete evidence of exploitation, remediation, or technical details.

    010441.4K
    998 followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    1/4 🚨 Cyber Snapshot: July 5, 2026 Sysdig has documented what they assess to be the first case of agentic ransomware driven end-to-end by an LLM agent. JADEPUFFER used an autonomous LLM to exploit CVE-2025-3248 (unauth RCE in Langflow), pivot, escalate, establish persistence, and encrypt 1,342 Nacos configs — adapting in real time to failures (e.g., correcting a failed login in 31 seconds). BleepingComputer: https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/ Primary Sysdig report: https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion

    Post summary

    The post reports the first documented instance of a LLM-driven ransomware attack exploiting CVE-2025-3248 (unauth RCE in Langflow), confirming active exploitation without providing patch or exploit code details.

    41020271
    12.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more