IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE2 IOCs

AI Security Incident – JadePuffer Ransomware Leverages AI Agent to Automate Attacks

NS
NSFOCUS Security Labs
Published July 7, 2026Original Report

Diamond Model

Attack Flow9 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1190
1/9
Exploit Public-Facing Application
ActionExploit public-facing application
The AI agent exploited a Langflow vulnerability (CVE-2025-3248) to gain initial access.

Indicators of Compromise

Indicators of Compromise2

TypeIndicatorConfidenceScoreFirst Seen
CVECVE-2021-29441
exploitintel-blogmalware
Medium
51
Jul 8, 26
CVECVE-2025-3248
botnetddosexploit
High
64
Jun 29, 26

IOC Relationship Graph

IOC Relationship Graph2 total IOCs
CVE
CVE2REPORTAI Security Incident – Jad
scroll to zoom · drag to pan · click IOC to open