JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)
Contained by: PEC, EGR
JADEPUFFER exploited an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then accessed MinIO, PostgreSQL, MySQL, and Alibaba Nacos environments. The operation encrypted exactly 1,342 Nacos configuration items, deleted original tables, and attempted additional database destruction; a later ENCFORGE payload targeted AI and machine-learning files. No victim organization or affected-person count was publicly reported, and the degree of human involvement in the agentic campaign remains unresolved.