Opening SecureFlowJADEPUFFER Agentic Ransomware via Langflow RCE
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Sysdig aidefend-sf0009

JADEPUFFER Agentic Ransomware via Langflow RCE

  • Autonomous Agents
  • AI Infrastructure
  • Financial Fraud & Abuse
  • System Compromise & RCE

Sysdig reported JADEPUFFER exploiting Langflow CVE-2025-3248, executing Base64-encoded Python payloads, harvesting secrets from the Langflow host and backing services, discovering reachable MinIO, Nacos, and MySQL infrastructure, abusing Nacos/MySQL access, encrypting Nacos configuration rows, writing ransom artifacts, and dropping database schemas.

Mapped threat techniques

Source