Agentic threat actors
Incidents involved as Deployer
インシデント 15784 Report
LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database
2026-07-01
Sysdig reported that a ransomware operator it dubbed JADEPUFFER used an LLM-driven agent to turn access through a vulnerable internet-facing Langflow deployment into a database-extortion operation. The report said the activity reached a production database server and produced concrete disruption, with the victim environment allegedly left in a damaged and unrecoverable state alongside a ransom demand.
もっとインシデント 15861 Report
Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion
2026-07-08
Sygnia reported that a threat actor apparently used purportedly AI-assisted or agentic workflows to move rapidly through an unidentified organization's AWS environment during an approximately 72-hour intrusion. The attacker allegedly expanded from an Internet-facing application into cloud infrastructure and data stores, reportedly stealing credentials and sensitive information while demonstrating the ability to disrupt services as leverage for extortion. Sygnia did not identify a specific model.
もっと