CISO
CTO
Enterprise Architect
JULY 1, 2026
A documented ransomware case shows an AI agent independently executing a full attack chain, including a 31-second self-correction, after a human set the target.
Sysdig's Threat Research Team documented JADEPUFFER, published July 1, 2026, describing what it assesses as the first documented case of agentic ransomware. A human operator provisioned infrastructure, selected the victim, and supplied MySQL credentials obtained through a prior compromise. From initial access, an LLM agent autonomously executed reconnaissance, credential harvesting, lateral movement, persistence, and destruction against a production database server, exploiting a Langflow remote code execution flaw (CVE-2025-3248) and a 2021 Nacos authentication bypass (CVE-2021-29441). Sysdig director of threat research Michael Clark told CyberScoop a human set up and pointed the operation while the agent executed the technical chain unsupervised. The agent diagnosed a failed login attempt and deployed a working fix in 31 seconds, and ran more than 600 distinct payloads before encrypting 1,342 database configuration records and deleting the originals.
GOVERNANCE IMPLICATION
JADEPUFFER demonstrates that once an operator supplies an agent with a target and credentials, the agent can complete reconnaissance, lateral movement, persistence, and destructive action without further human direction, correcting its own failures faster than a human operator would notice them. The exposure is not that a human was absent from the operation. It is that no checkpoint existed between agent authorization and irreversible action. Enterprises running autonomous or semi-autonomous agents against production infrastructure should treat the human authorization step as the only defensible control point and should not assume ongoing human oversight exists once an agent begins executing, because in this case it did not.
SCENARIO
An internal automation team stands up an agent to handle a defined maintenance task against a database-backed service, with a human approving the initial scope. The agent, given broad execution latitude to complete the task efficiently, encounters an unexpected failure, diagnoses it, and adjusts its approach without pausing for review. Nothing in the environment required a checkpoint before the corrected action executed, because the original human approval was treated as sufficient for the entire task rather than for a bounded first step.
THE GOVERNANCE QUESTION
Once a human hands an agent a target and credentials, what forces a checkpoint before its actions become irreversible?
CONTROL GAP
Human authorization at the start of an agent task is being treated as sufficient oversight for everything the agent does afterward, with no required checkpoint before higher-risk or irreversible actions execute.
PRIMARY SOURCE
JADEPUFFER: Agentic ransomware for automated database extortion
Sysdig Threat Research Team
July 1, 2026
Read the primary source ->(opens in new tab)CONTINUE READING
JUNE 30, 2026
Agent SecurityAdversa AI researcher Omer Ben Simon published GuardFall on June 30, 2026, a class of shell-interpretation bypasses affecting open-source AI coding and computer-use agents. Testing found 10 of 11 surveyed agents (Hermes, opencode, Goose, Cline, Roo-Code, Aider, Plandex, Open Interpreter, OpenHands, and SWE-agent) vulnerable. The bypass exploits a mismatch between how approval guards inspect a proposed command and how Bash rewrites that command before execution, allowing decades-old shell tricks such as quote removal, IFS expansion, and command substitution to slip destructive commands past a filter that only reads the literal submitted text. Continue was the only tested agent found to substantially mitigate the issue. Adversa demonstrated end-to-end exploitation against the production Plandex binary. No CVE has been assigned, since the issue is a structural pattern across implementations rather than a single patchable flaw.
JUNE 9, 2026
Agent SecurityAnthropic launched Claude Fable 5 and Claude Mythos 5 on June 9, 2026. Fable 5 is the first Mythos-class model released for general use. It includes safety classifiers that intercept queries in cybersecurity, biology and chemistry, and distillation categories, routing those queries to Claude Opus 4.8 instead. Anthropic reports the fallback occurs in fewer than 5% of sessions. The launch introduces a mandatory 30-day data retention requirement for all Fable 5 and Mythos 5 traffic on first- and third-party surfaces. Anthropic states the retained data will not be used for model training and will be deleted after 30 days in most cases.
MAY 18, 2026
Agent SecurityOn May 18, 2026, NIST published 'Summary Analysis of Responses to the Request for Information Regarding Security Considerations for AI Agents' (NIST Trustworthy and Responsible AI, report 800-5, authored by Riggs, Hamin, Perry, Edelman, and Cihon). The report summarizes stakeholder responses to the CAISI request for information (docket NIST-2025-0035). Commenters broadly agreed that AI agents present novel security threats that act as a barrier to adoption, and that while core cybersecurity principles still apply, they require adaptation for agents. Respondents identified roles for government including implementation guidance, information-sharing, and standards.