On July 3, 2026, the security vendor Sysdig published a report documenting the world's first ransomware attack fully carried out autonomously by an AI Agent. The attacker was named JADEPUFFER. By "fully autonomous," it does not mean AI assisted in generating phishing emails or analyzing vulnerability code—such "AI-assisted attacks" have appeared many times over the past two years. JADEPUFFER's difference is this: from the very first second of breaching the server, through encrypting 1,342 database configurations and leaving a ransom note, even autonomously fixing an error within 31 seconds, the entire attack chain was executed under the AI Agent's autonomous decisions, with no human at the keyboard. The only thing a human needed to do in the whole process was point the AI at a Langflow service exposed on the public internet. Every action after that, the AI did on its own.
I. The Attack Chain: How AI Autonomously Carried Out a Ransom
Langflow is an open-source AI application development framework that many companies use to build internal AI workflows. It has a known vulnerability (CVE-2025-3248) that allows unauthenticated users to execute Python code remotely. This vulnerability was added to CISA's "Known Exploited Vulnerabilities" catalog in 2025, yet many servers were never upgraded. After entering the server through this vulnerability, the AI began autonomously scanning the host for sensitive information: API keys for OpenAI, Anthropic, and DeepSeek; cloud-platform credentials for Alibaba Cloud, Tencent Cloud, and AWS; cryptocurrency wallets and seed phrases; database accounts and configuration files. The selection of these targets was not the random behavior of a preset script, but the AI's own judgment that "these pieces of information are the most valuable, collect them first." After obtaining the credentials, the AI moved laterally to another production server, successfully logging in with MinIO object storage's default password "minioadmin"; used the Nacos vulnerability disclosed back in 2021 (CVE-2021-29441) together with a default JWT signing key that had never been changed to gain management privileges over the configuration center; and planted a hidden administrator account in the database to achieve full control. Finally, it used MySQL's AES_ENCRYPT function to encrypt all 1,342 configuration records, deleted the original tables, and created the ransom note. The entire attack chain used not a single zero-day vulnerability. It was entirely a combination of known vulnerabilities, default passwords, and improper security configurations.
II. 31 Seconds: AI's Autonomous Self-Repair Capability
The most noteworthy detail in the whole process occurred when the AI tried to create a backdoor administrator account. The first attempt failed. A typical automated attack script would stop here, leaving a pile of error logs. But within 31 seconds JADEPUFFER autonomously completed the following actions: it analyzed the cause of the error and found that a subprocess environment-variable problem had caused password-hash generation to fail; it deleted the failed account to avoid leaving traces; it switched to directly importing the password library to regenerate the hash; it inserted the new administrator account; and it verified that the login succeeded. The entire process had no human involvement. The attack cumulatively executed over 600 attack payloads with clear purposes, and the AI repeatedly adjusted its subsequent strategy based on actual execution results. This is the essential difference between an AI Agent and a traditional automated script. Traditional scripts execute along a preset path and fail when they hit an exception; an AI Agent can understand context, judge the cause of an error, and adjust its plan autonomously. When this capability is turned to attack, it means the adaptability and complexity of attacks rise sharply.
III. A Black Joke: The AI Locked Itself Out Too
The incident has an ironic ending. After generating the encryption key, the AI output it to the terminal only once—it neither saved it nor uploaded it to the attacker. This means that even if the victim paid the ransom, the attacker could not decrypt the data: the key existed only in the AI's one-time runtime memory and vanished forever once the process ended. The AI locked itself out too. This detail speaks more clearly than any technical report about the true state of today's AI Agents: their capabilities are already strong enough to autonomously complete a complex attack chain, yet they are far from "reliable" and can make the kind of low-level mistakes a human would not. Strong but uncontrollable—that is precisely the most truthful portrait of today's AI Agents.
IV. Security Is Only the Surface; Boundaries Are the Real Question
On the surface, the JADEPUFFER incident is a network-security event, but the question it points to runs deeper than security. When an AI Agent can autonomously complete an entire attack chain—reconnaissance, credential theft, lateral movement, persistent control, data encryption—traditional security thinking—patching individual vulnerabilities, blocking individual IPs, detecting individual malicious behaviors—is far from enough. Because the AI is not executing a preset script; it is making autonomous decisions, adapting autonomously, and repairing itself autonomously. What defenders face is no longer some concrete attack technique, but an agent that can keep learning and keep adjusting. Even more worthy of attention is the question of accountability. If a company deploys an AI Agent that autonomously launches an attack without any explicit human instruction—is the company the attacker or the victim? How should regulators characterize it? The stronger AI's autonomous agency becomes, the harder this question is to avoid. High security risks, uncontrollable model capabilities, and a structurally lagging governance system—these three challenges are not some bug in AI, but structural issues that must inevitably be faced as AI scales into real deployment.
V. The Stronger the Capability, the More the Boundaries Must Be Held
AI's capabilities are breaking through rapidly, and that is a good thing. But capability breakthroughs do not automatically bring safety and controllability; on the contrary, the stronger the capability, the greater the potential destruction, and the higher the demands on boundaries and governance. This is not a denial of AI, but the guarantee that AI can truly land and truly create value. Electricity can light up ten thousand homes, and it can also start raging fires. The safety switches, insulation, and transformers of the power grid do not limit the energy of electricity; they only let that energy flow safely and stably to every household. Building AI's boundaries follows the same logic. Governance in advance rather than remediation after the fact is the core at the technical level. Security teams need to intervene up front across the entire lifecycle of an AI project—model selection, data preparation, system development, testing and launch—completing risk assessment and security control at every stage, rather than patching vulnerabilities after the system goes live. Autonomous agents need clearly defined boundaries of operational authority, risk thresholds, and emergency-stop mechanisms built into the system design, to avoid unintended autonomous actions at the most fundamental level. Clear rights and responsibilities rather than vague buck-passing is the core at the accountability level. Companies need to establish cross-functional AI governance mechanisms, so that the entire lifecycle of an AI project has clear allocation of rights and duties, avoiding the vacuum of "everyone is in charge, so no one is in charge." Holding on to human leadership rather than technological runaway is the core at the humanistic level. In key decisions concerning individual rights, corporate operations, and social functioning, AI may provide analysis, give recommendations, and complete supporting work, but the ultimate decision-making responsibility must be borne by humans. Move forward with optimism, but build the levees with a clear head. True optimism is not charging ahead blind to risks, but walking firmly into the future after seeing the risks clearly—while building solid safety guardrails along the way. Within boundaries, harmonized intelligence.