Free Quiz
Write for Us
Learn Artificial Intelligence and Machine Learning
  • Artificial Intelligence
  • Data Science
    • Language R
    • Deep Learning
    • Tableau
  • Machine Learning
  • Python
  • Blockchain
  • Crypto
  • Big Data
  • NFT
  • Technology
  • Interview Questions
  • Others
    • News
    • Startups
    • Books
  • Artificial Intelligence
  • Data Science
    • Language R
    • Deep Learning
    • Tableau
  • Machine Learning
  • Python
  • Blockchain
  • Crypto
  • Big Data
  • NFT
  • Technology
  • Interview Questions
  • Others
    • News
    • Startups
    • Books
Learn Artificial Intelligence and Machine Learning
No Result
View All Result

Home » The ‘first’ AI-run ransomware attack still needed a human

The ‘first’ AI-run ransomware attack still needed a human

Tarun Khanna by Tarun Khanna
July 8, 2026
in Artificial Intelligence
Reading Time: 3 mins read
0
The ‘first’ AI-run ransomware attack still needed a human

Image Credit: https://techcrunch.com/

Share on FacebookShare on TwitterShare on LinkedInShare on WhatsApp

Last week, researchers at cloud security firm Sysdig stated they’d documented the known case of “agentic ransomware.” It was an extortion operation, dubbed JadePuffer, in which an AI agent — not a human — managed the technical execution of a real-world cyberattack from begin to complete. The agent broke right into a vulnerable server, stole credentials, moved through the goal’s network, encrypted files, or even wrote its personal ransom note, adapting to boundaries alongside the way like a human hacker would. Coverage of the operation explained it as run “without any human oversight,” with “no human on the keyboard.”

That’s not quite the whole picture. In an interview on Monday with CyberScoop, Sysdig’s Michael Clark, the company’s senior director of risk research, interpreted that a human was still very much involved — simply not within the technical execution. “A human still set up and pointed the operation and assigned the infrastructure behind it, the command-and-control server, the staging server used for the stolen data and selected a victim,” Clark stated. The credentials used to interrupt into the victim’s database, he added, weren’t harvested by the AI agent itself; someone acquired them individually, through a prior compromise, and handed them to the operation.

None of this contradicts Sysdig’s original claim, and the technical info of the attack persist to be notable on their own — wild, even. The agent got in through a recognized bug in Langflow, a popular open source tool for constructing LLM apps, then moved directly to a manufacturing MySQL server and exploited another known flaw to benefit admin access. It encrypted over 1,300 configuration records and not only left behind a ransom note that it wrote itself but it left a Bitcoin address wherein the ransom can be sent. Sysdig hasn’t revealed who was aimed.

Also Read:

AI Founders Who Walked Away From Bezos-Backed Prometheus Unveil Physics AI Model

Alibaba Launches Wan3.0 AI Video Model After $10 Billion Share Sale

Major security weaknesses found in leading open-weight LLMs

AI bias is not just an error in the algorithm, it’s a chain of human decisions

The methods were pretty ordinary seemingly, what stood out was the speed and transparency included. The agent fixed a failed login in 31 seconds, narrating its very own reasoning in natural-language code comments the whole way.

One detail that to start seemed to muddy the image has since been explained. Clark had advised CyberScoop that Sysdig found “multiple models were used in the attack,” bringing up harvested keys for OpenAI, Anthropic, DeepSeek, and Gemini — language that left open the inquiry of whether or not numerous models actively powered different stage of the intrusion. Asked to make clear, Clark advised TechCrunch that those keys have been simply a part of what the agent stole, not proof of what was driving it.

“The agent swept the Langflow host for anything valuable — provider API keys, cloud credentials, cryptocurrency wallets, and database configs — and those issuer keys have been part of the loot,” he stated through email. “They are indicative of what the attacker considered worth taking, however they do not inform us which model making the decisions.”

On the decisions truly running JadePuffer, Clark stated Sysdig “become not able to detect the specific model driving the agent” and has no visibility into its system prompt or configuration.

Microsoft researcher Geoff McDonald’s theory, offered on LinkedIn numerous days ago, is worth revisiting in that light. McDonald suspected an open-weight model with safety training stripped out, instead of a frontier model, was behind the attack, based on his own red-teaming experience displaying frontier labs’ safety layers hold up well. Sysdig’s own account doesn’t verify or rule that out.

McDonald’s post also warned that ransomware campaigns are now bounded primarily via attacker budget instead of human effort, elevating the possibility of “thousands or tens of thousands of simultaneous campaigns.” That problem is a touch harder to square with what Clark explained Monday. (If a human to choose each victim, provision infrastructure, and attain database credentials for every operation, that’s a bit of a bottleneck, at least.)

Either way, Clark told CyberScoop, whilst Sysdig hasn’t seen the same operation hit other victims yet, given how cheap it’s to run an agent, he anticipates that to change.

ShareTweetShareSend
Previous Post

UN Opens Global AI Governance Dialogue With Call For Safe And Inclusive AI

Next Post

Why the rise of open source AI isn’t hurting Anthropic … yet

Tarun Khanna

Tarun Khanna

Founder DeepTech Bytes - Data Scientist | Author | IT Consultant
Tarun Khanna is a versatile and accomplished Data Scientist, with expertise in IT Consultancy as well as Specialization in Software Development and Digital Marketing Solutions.

Related Posts

Workers in worry over being replaced as they adapt to the developing impact of AI on jobs
Artificial Intelligence

Workers in worry over being replaced as they adapt to the developing impact of AI on jobs

August 24, 2026
Brazil releases AI supercomputer push, splits projects between Chinese, US companies
Artificial Intelligence

Brazil releases AI supercomputer push, splits projects between Chinese, US companies

August 22, 2026
Nvidia just showed that the harness, not the AI model, is now the real hero
Artificial Intelligence

Nvidia just showed that the harness, not the AI model, is now the real hero

August 22, 2026
OpenAI to lease huge new AI data center in US, backed by Nvidia
Artificial Intelligence

OpenAI to lease huge new AI data center in US, backed by Nvidia

August 20, 2026
Next Post
Why the rise of open source AI isn’t hurting Anthropic … yet

Why the rise of open source AI isn’t hurting Anthropic … yet

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

− 1 = 2

TRENDING

Engineers generate Soft Robots That Can Literally Walk on Water

Engineers generate Soft Robots That Can Literally Walk on Water

The walking mechanism of the “water spider” robot HydroBuckler prototype shown here is driven by “leg” buckling. Photo Credit: https://scitechdaily.com/

by Tarun Khanna
September 30, 2025
0
ShareTweetShareSend

Deep-tech company develops high-precision passive eye-monitoring technology for smart contact lenses

Deep-tech company develops high-precision passive eye-monitoring technology for smart contact lenses

Photo Credit: https://techxplore.com/

by Tarun Khanna
April 9, 2026
0
ShareTweetShareSend

AI’s influence in the cryptocurrency industry

AI’s influence in the cryptocurrency industry

Photo Credit: https://www.artificialintelligence-news.com/

by Tarun Khanna
June 13, 2025
0
ShareTweetShareSend

R Vs Python: What’s the Difference?

R-Vs-Python_-Whats-the-Difference_
by Tarun Khanna
March 23, 2021
0
ShareTweetShareSend

Bitcoin price steadies near $64K as HYPE leads crypto gainers

Bitcoin price steadies near $64K as HYPE leads crypto gainers

Image Credit: https://crypto.news/

by Tarun Khanna
August 13, 2026
0
ShareTweetShareSend

Will AI take your job? The solution could hinge on the four S’s of the technology’s benefits over humans

Will AI take your job? The solution could hinge on the four S's of the technology's benefits over humans

Photo Credit: https://techxplore.com/

by Tarun Khanna
June 18, 2025
0
ShareTweetShareSend

DeepTech Bytes

Deep Tech Bytes is a global standard digital zine that brings multiple facets of deep technology including Artificial Intelligence (AI), Machine Learning (ML), Data Science, Blockchain, Robotics,Python, Big Data, Deep Learning and more.
Deep Tech Bytes on Google News

Quick Links

  • Home
  • Affiliate Programs
  • About Us
  • Write For Us
  • Submit Startup Story
  • Advertise With Us
  • Terms of Service
  • Disclaimer
  • Cookies Policy
  • Privacy Policy
  • DMCA
  • Contact Us

Topics

  • Artificial Intelligence
  • Data Science
  • Python
  • Machine Learning
  • Deep Learning
  • Big Data
  • Blockchain
  • Tableau
  • Cryptocurrency
  • NFT
  • Technology
  • News
  • Startups
  • Books
  • Interview Questions

Connect

For PR Agencies & Content Writers:

connect@deeptechbytes.com

Facebook Twitter Linkedin Instagram
Listen on Apple Podcasts
Listen on Google Podcasts
Listen on Google Podcasts
Listen on Google Podcasts
DMCA.com Protection Status

© 2024 Designed by AK Network Solutions

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Artificial Intelligence
  • Data Science
    • Language R
    • Deep Learning
    • Tableau
  • Machine Learning
  • Python
  • Blockchain
  • Crypto
  • Big Data
  • NFT
  • Technology
  • Interview Questions
  • Others
    • News
    • Startups
    • Books

© 2023. Designed by AK Network Solutions