CODECAVE
Reading time: 2 min

The First Cyberattack Carried Out by an AI Agent

The first recorded case of an AI agent carrying out the technical part of a cyberattack on its own

US company Sysdig (the creator of Falco, a popular open-source tool for threat detection and troubleshooting across Linux hosts, containers and cloud environments) has reported discovering the first-ever ransomware attack carried out from start to finish by an AI agent. The automated cyberattack has been named JADEPUFFER.

Until now, this had only been seen in lab conditions, for example in the AI Security Institute's "The Last Ones" benchmark. Now attackers have started using it in the real world.

How the attack worked

The attack relied on known vulnerabilities in Langflow, a popular open-source tool for building LLM-based applications. The AI agent broke into a public server on its own through a vulnerability, using a default Nacos service key that had not been changed since 2020. It then gained admin privileges in MySQL and stole API keys for various providers (DeepSeek, Gemini) along with wallet data.

Even more striking, the agent wrote the ransom note itself. The number of ransomware attacks now depends on the size of the attackers' budget rather than on human capacity. Despite reports of an attack "without human involvement", Michael Clark of Sysdig clarified that humans still play an important role: they choose the victim, prepare the infrastructure and provide the initial access credentials.

Signs that the attack was run by an AI agent

  • the malicious code contained detailed comments explaining every step;
  • errors were corrected at machine speed: going from a failed login attempt to a correct step-by-step solution took 31 seconds.

Well-known security researcher Geoff McDonald pointed out a critical aspect in his LinkedIn post: the attack was most likely built on open-weight models.

According to McDonald, leading proprietary models (OpenAI, Anthropic) have strong built-in safeguards that are hard to bypass for sustained autonomous attacks. Open-weight models (such as DeepSeek V4, Qwen or GLM), on the other hand, make it easy to strip out safety layers through fine-tuning.

3 tips to protect yourself from potential security threats

  • use agents to test your infrastructure continuously;
  • invest in real-time threat monitoring;
  • build multi-layered segmentation of your IT infrastructure.

IT services that keep you secure

In 2026, simply "installing an antivirus" is not enough. Protecting corporate infrastructure takes comprehensive solutions:

  1. VMaaS (automated vulnerability discovery and prioritization);
  2. DevOps: security built right into the development process (CI/CD), where vulnerabilities are found and fixed while the code is still being written. You can find an example of a successful security implementation in one of our projects here.

If you need an audit of your IT infrastructure, fill in the form on our website.