Smooth AI criminal drives 'first' end-to-end agentic ransomware attack Sysdig threat researchers identified what they claim is the first known case of agentic ransomware, an attack fully automated by a large language model (LLM) to compromise a production database server, encrypt data, and demand payment. The operation, dubbed JadePuffer, exploited a critical vulnerability in the Langflow platform to execute a coordinated attack that bypassed traditional security measures and adapted in real time to achieve its objectives. The attack began by exploiting CVE-2025-3248, a remote code-execution flaw in Langflow that allows unauthenticated attackers to run arbitrary Python code on the host. Once inside the system, the AI-driven agent scanned for and collected sensitive information, including API keys for cloud providers like Alibaba Cloud, Tencent Cloud, and Huawei Cloud, as well as credentials for AWS, Azure, and Google Cloud Platform. It also targeted cryptocurrency wallets and database credentials, demonstrating a broad scope of reconnaissance. JadePuffer then established persistence by installing a crontab entry on the Langflow server, ensuring it could maintain access and communicate with the attacker’s infrastructure every 30 minutes. The AI agent’s next target was a separate production server running a MySQL database and an Alibaba Nacos configuration service. Nacos, an open-source service-discovery platform, was exploited using multiple vectors, including an authorization bypass flaw (CVE-2021-29441) and forged JSON web tokens (JWTs) generated with the default signing key. The LLM-powered agent used its root-level database access to inject a backdoor administrator into the Nacos database, enabling full control over the system.#tencent_cloud #aws #alibaba_cloud #langflow #huawei_cloud

Tencent Launches OpenClaw-Like Workplace AI Agent WorkBuddy Tencent has introduced WorkBuddy, a desktop AI agent designed for workplace tasks, drawing parallels to its OpenClaw platform. The company announced the product supports local installation without requiring cloud deployment, offering users greater control over data privacy and infrastructure. According to Tencent, WorkBuddy is compatible with OpenClaw skills, enabling seamless integration with existing workflows. The AI agent comes with over 20 skill packages, allowing users to automate repetitive tasks such as information retrieval, report generation, and content drafting. Tencent emphasized that WorkBuddy leverages the Model Context Protocol (MCP), a framework that enhances task execution by contextualizing user inputs across different applications. This feature is particularly useful for streamlining workflows in professional environments. A key aspect of WorkBuddy is its ability to switch between multiple large language models, including Hunyuan, DeepSeek, GLM, Kimi, and MiniMax. This flexibility allows users to choose the most suitable model for specific tasks, whether it’s generating complex reports, analyzing data, or drafting emails. Tencent Cloud, the company’s cloud computing division, is highlighted as the platform for deploying these models, though details about the technical implementation remain unspecified. The launch of WorkBuddy aligns with Tencent’s broader strategy to expand its AI capabilities in the workplace. By offering a local installation option, the company addresses concerns about data security and compliance, which are critical for enterprises handling sensitive information.#openclaw #tencent #workbuddy #tencent_cloud #model_context_protocol
