JadePuffer ransomware used AI agent to automate entire attack
2026-07-05T07:23:25Z•0d63299a9a625e75784c0e4401a259df93e79bbb2dbfcc71eb0cc11e16edf06d
AndroidCISACisco Unified CMClickFixConsentFixFortiBleedINCLLM-agentLynxMFA-bypassMicrosoft 365OAuthPhaaSSharePoint RCEShinyHuntersartificial-intelligencebotnetcredential-theftdata-breachincident-responsephishingransomwareresidential-proxytakedownvulnerability-exploitation
What happened
This collection highlights an uptick in high-impact cyber activity: researchers documented what appears to be the first ransomware operation (JadePuffer) fully automated by an LLM agent; Google-partnered takedown of the NetNut residential proxy network that had ~2M compromised Android devices; exposure of ARToken PhaaS revealing EvilTokens’ Microsoft 365 phishing toolkit; widespread MFA/OAuth bypass techniques (ConsentFix, ClickFix) and mitigations such as Opera’s Paste Protect; active exploitation of enterprise vulnerabilities including a Microsoft SharePoint RCE (actively exploited per CISA)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0d63299a9a625e75784c0e4401a259df93e79bbb2dbfcc71eb0cc11e16edf06d
- Enrichment time
- 2026-07-05T07:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.