JADEPUFFER: First End-to-End AI-Driven Ransomware Operation

2026-07-03T20:51:43Z5c96eaa3602426aaf25507bc4d8b73dfb0f20fb2ebd67653cdce9c5a166300ac
AI-driven ransomwareAdobe patchesCISA KEVCVE-2026-45659CVSS 10.0 vulnerabilities`,`Scattered Spider`,`extradition`,`insCampaign ClassicColdFusionDKIMDMARCFortiBleedFortiGate compromiseJADEPUFFERMTA-STSMicrosoft SharePointNetNutSPFVercel breachemail securitylarge-language-modellaw enforcement takedownransomwareransomware campaignsresidential proxyshadow AIsupply-chain

What happened

Feed highlights multiple high-impact incidents and vulnerability developments: Sysdig documents JADEPUFFER, an apparent first end-to-end LLM-driven ransomware operation; the Vercel 2026 breach traced to an unvetted “shadow AI” tool and a $2M extortion; law enforcement disruption of the NetNut malicious residential-proxy service; and research showing government and healthcare sectors lagging on email authentication. On vulnerabilities and exploits, CISA added Microsoft SharePoint CVE-2026-45659 to its KEV list (CVSS 8.8), Oracle E-Business Suite CVE-2026-46817 is being actively exploited with ~

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5c96eaa3602426aaf25507bc4d8b73dfb0f20fb2ebd67653cdce9c5a166300ac
Enrichment time
2026-07-03T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.