JadePuffer ransomware used AI agent to automate entire attack

2026-07-05T07:23:25Z0d63299a9a625e75784c0e4401a259df93e79bbb2dbfcc71eb0cc11e16edf06d
AndroidCISACisco Unified CMClickFixConsentFixFortiBleedINCLLM-agentLynxMFA-bypassMicrosoft 365OAuthPhaaSSharePoint RCEShinyHuntersartificial-intelligencebotnetcredential-theftdata-breachincident-responsephishingransomwareresidential-proxytakedownvulnerability-exploitation

What happened

This collection highlights an uptick in high-impact cyber activity: researchers documented what appears to be the first ransomware operation (JadePuffer) fully automated by an LLM agent; Google-partnered takedown of the NetNut residential proxy network that had ~2M compromised Android devices; exposure of ARToken PhaaS revealing EvilTokens’ Microsoft 365 phishing toolkit; widespread MFA/OAuth bypass techniques (ConsentFix, ClickFix) and mitigations such as Opera’s Paste Protect; active exploitation of enterprise vulnerabilities including a Microsoft SharePoint RCE (actively exploited per CISA)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0d63299a9a625e75784c0e4401a259df93e79bbb2dbfcc71eb0cc11e16edf06d
Enrichment time
2026-07-05T07:23:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · JadePuffer ransomware used AI agent to automate entire attack · Baitaphish