JADEPUFFER: First End-to-End AI-Driven Ransomware Operation

2026-07-03T14:51:43Z93ec6077a5301f832c8036fc13a5e57f45c819818798d7ac6d5d23b172a8b50d
active-exploitationadobeai-driven-attackcampaign-classiccisacoldfusioncve-2026-45659cve-2026-46817dkimdmarcemail-securityfortibleedfortigateinc-ransomjadepufferlynx-ransomwaremicrosoft-sharepointnetnutoracle-e-businessransomwareresidential-proxyshadow-aispfsupply-chainvercel

What happened

Multiple high-impact incidents and trends: Sysdig documents JADEPUFFER, an apparent first end-to-end LLM-driven ransomware operation that automated exploitation, credential theft, lateral movement and encryption; a Vercel shadow-AI supply-chain breach led to data theft and a $2M extortion; Google/FBI disrupted the NetNut residential proxy abuse network; SOCRadar links FortiBleed harvesting from ~430,000 FortiGate devices to INC Ransom and Lynx ransomware operations; CISA added Microsoft SharePoint flaw CVE-2026-45659 (CVSS 8.8) to its KEV catalog; Oracle E-Business Suite CVE-2026-46817 is the-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
93ec6077a5301f832c8036fc13a5e57f45c819818798d7ac6d5d23b172a8b50d
Enrichment time
2026-07-03T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · JADEPUFFER: First End-to-End AI-Driven Ransomware Operation · Baitaphish