COMPANY
Sysdig
companytopic-notesecurity
Overview
Sysdig is a cloud-security and runtime-threat-detection company whose threat-research group publishes on-the-ground reporting on new attack patterns against cloud, container, and — increasingly — AI-agent surfaces.
Timeline
- 2026-07-07-AI-Digest — Sysdig documents JADEPUFFER, the first fully-agentic ransomware campaign the corpus has logged — an AI agent handled recon, credential theft, lateral movement, encryption, and ransom-note writing across a Langflow → Nacos intrusion, with 1,342 Nacos configuration items encrypted and one instance going from a failed Nacos admin bcrypt login to a working retry in 31 seconds. The human still selected the victim, exploited CVE-2025-3248 for initial access, stood up infrastructure, and supplied stolen credentials — so the skill floor is meaningfully lowered mid-chain, not collapsed. First-of-kind entry in the corpus; pairs with the 2026-06-30-AI-Digest Mozilla 0DIN agent-on-repo malware disclosure as the two documented cases of agent tooling being turned into offensive infrastructure inside two weeks.
Key Developments
- JADEPUFFER (July 2026): First fully-agentic ransomware operation Sysdig has documented — the agent absorbed recon, credential theft, lateral movement, encryption, and ransom-note writing. The load-bearing structural read the corpus carries is that everything after initial access is now inside the automation surface; the human still supplies target selection, initial-access exploit (CVE-2025-3248 in the Langflow server), infrastructure standup, and stolen credentials.
Related
See also: Mozilla, MOC - Agent Security.