Microsoft tracks the first documented agentic ransomware crew into an Azure tenant's service principals
Microsoft Security Research says it found cloud activity tied to JADEPUFFER, which it tracks as Storm-3168 and which Sysdig discovered in July 2026 and "reported to be the first documented agentic ransomware operation." Two compromised service principals in one tenant were used in early June 2026: one enumerated Azure virtual machines, subscriptions, resource groups and resources "for about 15 hours and 30 minutes with 300+ successful read operations," and the other performed discovery, destructive operations and credential collection.
An intrusion that ran at machine speed with no agent in it
Sysdig's threat research team describes an operator who entered through marimo's unauthenticated terminal WebSocket endpoint, CVE-2026-39987, using a Python toolkit written and debugged by hand in-session: more than 850 interactive commands over a nine-hour session, and eight seconds from the open WebSocket to a live SSH session on a bastion host. “There was no agent in the loop, nor was there any sign of LLM-generated scripts or tooling,” Sysdig writes, and it reports that the operator inspected a planted prompt-injection probe twice during the session without ever echoing the marker that had caught earlier LLM-driven operators on the same vulnerability.
Review of eight AI-enabled operations finds AI added speed, not new techniques
Sysdig reviewed eight documented AI-enabled operations and reports that “AI contributed nothing new to initial access in any of the eight cases,” with entry running on server-side request forgery, known CVEs and stolen credentials. It adds that “there were no new MITRE attack techniques” and that seven of the eight ran T1059, Command and Scripting Interpreter, citing JADEPUFFER moving from a failed login to a working fix in 31 seconds as the change that matters.
Black Hat USA 2026 vendor announcements centre on AI agent runtime protection, discovery and least-privilege enforcement
SecurityWeek's three-part roundup of Black Hat USA 2026 announcements documents a concentrated wave of defensive products aimed at securing AI agents, including Cyera Agent Guardian and Menlo Security MARS for prompt-injection and exfiltration protection, KnowBe4 Agent Risk Manager and Mimecast Agent Risk Center for agent discovery and behaviour monitoring, Varonis intent-based access control and Zero Networks least-agency enforcement for constraining agent permissions, and Acalvio Deception Guardrails for honeytokens targeting agentic environments. Legit Security's VibeGuard 2.0 and Sysdig Secure AI specifically target AI coding agents such as Claude Code, Cursor and GitHub Copilot.
LLM-run agent deploys "ENCFORGE" ransomware built to encrypt AI/ML model stacks
Sysdig reports the JadePuffer operator deployed ENCFORGE, Go-based ransomware targeting ~180 AI/ML file types (model checkpoints, vector databases, training data) after exploiting CVE-2025-3248 in Langflow. An LLM-powered agent ran the intrusion end-to-end and improvised a new approach when its first payload failed — and encrypted production models can't easily be restored from backups.
Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited Langflow and extorted a production database
Sysdig Threat Research reported an intrusion in which an LLM-driven agent exploited CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint, then harvested credentials from the Langflow host and MinIO storage, moved laterally to a production database server, compromised an Alibaba Nacos configuration service, and encrypted 1,342 configuration items using MySQL AES before dropping a ransom demand. Sysdig cited self-narrating payloads containing natural-language reasoning and a 31-second self-correction cycle after an initial exploitation step failed.