JadePuffer ransomware used AI agent to automate entire attack
2026-07-04T19:23:25Z•6d7ee2905fbcf8178b151d667922d8bb9659db141fcd40545c68414b1e62cfa2
AI-driven attacksARTokenAndroid compromiseCisco Unified CMClickFixConsentFixEvilTokensFortiBleedJadePufferKubota breachLLM-agent ransomwareLynx ransomwareMedtronic breachMicrosoft 365 phishingMicrosoft SharePoint RCENetNutOAuth MFA bypassScattered SpiderUnified Communications Manageractive exploitationbotnetcredential theftphishing-as-a-serviceransomwareresidential proxy
What happened
Digest of multiple security incidents and developments: Researchers documented JadePuffer as the first observed ransomware operation fully automated by an LLM agent. CISA warned that a high-severity Microsoft SharePoint RCE patched in May is now being actively exploited, and Cisco confirmed exploitation of a recently patched Unified Communications Manager flaw. Google-backed action disrupted the NetNut residential proxy network that abused millions of compromised Android devices. A new phishing-as-a-service, ARToken, exposes an extensive Microsoft 365 phishing toolkit tied to EvilTokens, while
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 6d7ee2905fbcf8178b151d667922d8bb9659db141fcd40545c68414b1e62cfa2
- Enrichment time
- 2026-07-04T19:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.