Smooth AI criminal drives 'first' end-to-end agentic ransomware attack Sysdig threat researchers identified what they claim is the first known case of agentic ransomware, an attack fully automated by a large language model (LLM) to compromise a production database server, encrypt data, and demand payment. The operation, dubbed JadePuffer, exploited a critical vulnerability in the Langflow platform to execute a coordinated attack that bypassed traditional security measures and adapted in real time to achieve its objectives. The attack began by exploiting CVE-2025-3248, a remote code-execution flaw in Langflow that allows unauthenticated attackers to run arbitrary Python code on the host. Once inside the system, the AI-driven agent scanned for and collected sensitive information, including API keys for cloud providers like Alibaba Cloud, Tencent Cloud, and Huawei Cloud, as well as credentials for AWS, Azure, and Google Cloud Platform. It also targeted cryptocurrency wallets and database credentials, demonstrating a broad scope of reconnaissance. JadePuffer then established persistence by installing a crontab entry on the Langflow server, ensuring it could maintain access and communicate with the attacker’s infrastructure every 30 minutes. The AI agent’s next target was a separate production server running a MySQL database and an Alibaba Nacos configuration service. Nacos, an open-source service-discovery platform, was exploited using multiple vectors, including an authorization bypass flaw (CVE-2021-29441) and forged JSON web tokens (JWTs) generated with the default signing key. The LLM-powered agent used its root-level database access to inject a backdoor administrator into the Nacos database, enabling full control over the system.#tencent_cloud #aws #alibaba_cloud #langflow #huawei_cloud

AI Rift Widens as China Urges Boycott of Top US Conference Over Sanctions Ban Chinese computer scientists and researchers have been urged to boycott a major artificial intelligence conference after its organizers barred submissions from US-sanctioned institutions, including leading Chinese tech groups such as Huawei Technologies. The China Computer Federation (CCF), the country’s top computing body, has condemned the decision by the Conference on Neural Information Processing Systems (NeurIPS) to stop accepting submissions from individuals affiliated with sanctioned entities. This move has intensified tensions between the US and China over AI, a field with significant economic, social, and military implications. The CCF stated that it “strongly opposed” NeurIPS’s decision, calling it a violation of the principles of academic exchange. The organization emphasized that openness, inclusiveness, equality, and cooperation are fundamental to international academic collaboration. It argued that the conference’s actions politicized academic discourse and undermined the collaborative spirit of the research community. NeurIPS, often regarded as the world’s premier AI conference, attracts tens of thousands of researchers annually to present groundbreaking work. The event has also become a critical battleground for talent acquisition, with US and Chinese tech firms vying for top AI talent. Last year’s conference, held across two locations for the first time, faced concerns about US visa restrictions for Chinese participants. Despite these challenges, a team from Alibaba Cloud, including chief technology officer Zhou Jingren, won one of the conference’s best paper awards. This followed similar achievements by researchers from ByteDance and Peking University in previous years.#china_computer_federation #huawei_technologies #alibaba_cloud #byte_dance
