Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Are brain waves the next unlock for natural artificial intelligence?

Anthropic updates Claude voice mode with more capable models

Music streamer Deezer says more than 50% of daily uploads are generated by AI

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Are brain waves the next unlock for natural artificial intelligence?

    27 July 2026

    Librarians host viral ‘Avoid AI’ workshops for people fed up with big tech

    26 July 2026

    I tested OpenAI’s new AI keyboard — which will be fun for some coders and a little overwhelming for everyone else

    25 July 2026

    Anthropic Launches Opus 5 | TechCrunch

    24 July 2026

    How AI guardrails are hindering the work of aggressive cybersecurity researchers

    24 July 2026
  • Apps

    Anthropic updates Claude voice mode with more capable models

    27 July 2026

    Bluesky’s AI assistant Attie expands into an open social research tool

    26 July 2026

    Why Cognition bought Poke: AI personality becomes a competitive advantage

    26 July 2026

    Vietnam seeks to restrict social media for children. Here are the growing number of other countries doing the same

    25 July 2026

    India’s move against Jack Dorsey’s Bitchat sparks legal debate

    24 July 2026
  • Crypto

    Sam Altman’s biometrics startup World raises $52.5 million through crypto sale

    24 July 2026

    Venice AI goes unicorn with $65M Series A as first privacy AI platform takes off

    1 July 2026

    Crypto Exchange OKX wants AI agents to hire and pay each other

    30 June 2026

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026
  • Fintech

    TechCrunch Disrupt 2026’s new Smart Money Stage explores fintech, payments, artificial intelligence and everything

    25 July 2026

    Don’t want to invest in Elon Musk? Two new ETFs expressly exclude him

    10 July 2026

    India’s payments chief believes artificial intelligence will play a big part in the next era of digital payments development

    28 June 2026

    Early Bird pricing ends tonight for the Founder Summit

    26 June 2026

    4 days left to save up to $190 on Founder Summit 2026

    23 June 2026
  • Hardware

    AI chip startup Etched defies skeptics, hits $10.3 billion valuation from big-name investors

    24 July 2026

    After a shocking quarter, IBM insists that artificial intelligence is not killing the mainframe

    23 July 2026

    Light made a flip phone — it’s colorful and cheap

    22 July 2026

    Apple is partnering with Klarna to launch a rental program for iPhones, iPads and Macs

    22 July 2026

    The Xteink X4 Pro could be the tiny e-reader of your dreams

    21 July 2026
  • Media & Entertainment

    Music streamer Deezer says more than 50% of daily uploads are generated by AI

    27 July 2026

    Substack’s new tool lets you know who’s writing their newsletters with AI

    26 July 2026

    Kalshi demands Netflix take down trailer for ‘Prediction Games’ documentary.

    26 July 2026

    Amazon brings games to Prime Video

    24 July 2026

    SoundCloud acquires decentralized music platform Nina Protocol months after its shutdown

    23 July 2026
  • Security

    The hacker who humiliated spyware makers and was never caught

    25 July 2026

    Hugging Face confirms breach of internal datasets and credentials, prompts users to take action

    25 July 2026

    US accuses American of allegedly wiping his phone using a passcode ‘forcibly’ during border search

    24 July 2026

    If you pay a hacker’s ransom, chances are they’ll come back for more

    24 July 2026

    The US government says hackers linked to Iran are disrupting US water and energy providers

    23 July 2026
  • Startups

    Insurance startup Corgi reportedly raises more money to $4 billion – its third round in 8 weeks

    26 July 2026

    Build publicly, fail publicly: what it’s like to be a founder under 20 right now

    25 July 2026

    Prentis, new AI lab co-founded by Reid Hoffman and Mark Pincus in talks to raise $100 million

    25 July 2026

    Meet the judges who will crown Australia’s next startup

    24 July 2026

    AegisAI, founded by ex-Google security execs, raises $36M to stop AI-based spearfishing

    23 July 2026
  • Transportation

    TechCrunch Mobility: Uber is betting on its former CEO

    26 July 2026

    Volkswagen engineers charged with insider trading linked to the Rivian consortium

    25 July 2026

    SpaceX launches new V3 Starlink satellites but suffers another booster failure

    25 July 2026

    Tesla’s door handles may prompt new safety rules in the US

    24 July 2026

    Tesla’s robotaxis moves in reverse

    23 July 2026
  • Venture

    Edtech platform raises $4.5 million to help teach students how to code vibe

    23 July 2026

    Travis Kalanick’s robotics company raises $1.7 billion, led by a16z

    23 July 2026

    Cascade raises $3.5 million to help construction companies find and win projects

    22 July 2026

    StrictlyVC returns to New York on September 10 to celebrate a huge year for the city’s startup community

    21 July 2026

    Startup Inference Infinity raises $15 million from researchers Touring Capital, OpenAI and Anthropic

    20 July 2026
  • Recommended Essentials
TechTost
You are at:Home»AI»The ‘first’ ransomware attack run by AI still needed a human
AI

The ‘first’ ransomware attack run by AI still needed a human

techtost.comBy techtost.com7 July 202604 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
The 'first' Ransomware Attack Run By Ai Still Needed A
Share
Facebook Twitter LinkedIn Pinterest Email

Last week, researchers at cloud security firm Sysdig said they had documented the first known case of “ransomware agent.” It was an extortion operation, dubbed JadePuffer, in which an AI agent—not a human—handled the technical execution of a real-world cyberattack from start to finish. The agent hacked into a vulnerable server, stole credentials, moved through the target’s network, encrypted files and even wrote his own ransom note, adjusting obstacles along the way as a human hacker would. Funding coverage described it as having “no human oversight” and “no human at the keyboard.”

It’s not exactly that full picture. In one interview on Monday with CyberScoop, Sysdig’s Michael Clark, the company’s senior director of threat research, clarified that a human is still very much involved — just not in the technical execution. “One person still set up and demonstrated the operation and provided the infrastructure behind it, the command and control server, the staging server that was used for the stolen data and chose a victim,” Clark said. The credentials used to enter the victim’s database, he added, were not collected by the AI ​​agent itself. someone acquired them separately, with prior compromise, and delivered them to the business.

None of this contradicts Sysdig’s original claim, and the technical details of the attack remain remarkable in their own right – even wild. The agent entered through a known bug in Langflowa popular open source tool for building LLM applications, was then ported to a production MySQL server and exploited another known flaw to gain administrator access. He encrypted over 1,300 configuration records and not only left behind a self-written ransom note, he left a Bitcoin address where the ransom could be sent. Sysdig did not disclose who the target was.

The techniques were quite ordinary obviously, what stood out was the speed and transparency. The agent fixed a failed connection in 31 seconds, narrating his reasoning in natural language code comments along the way.

A detail that initially seemed to cloud the picture has since been clarified. Clark had told CyberScoop that Sysdig found that “multiple models were used in the attack,” citing key harvesting for OpenAI, Anthropic, DeepSeek, and Gemini — language that left open the question of whether multiple models were actively fueling different stages of the attack. Asked to clarify, Clark told TechCrunch that those keys were just part of what the agent stole, not evidence of what drove it.

“The agent scanned the Langflow host for anything of value — provider API keys, cloud credentials, cryptocurrency wallets and database configurations — and those provider keys were part of the theft,” he said via email. “They are indicative of what he thought the striker was worth getting, but they don’t tell us which model was making the decisions.”

Regarding the model actually running JadePuffer, Clark said Sysdig was “unable to determine the specific model running the agent” and has no visibility into its system prompt or configuration.

Microsoft researcher Geoff McDonald’s theory, offered on LinkedIn several days ago, it’s worth revisiting in that light. MacDonald suspected that an open-weight model with stripped-down security training was behind the attack, rather than a border model, based on his own experience with the team showing that border labs’ security layers hold up well. Sysdig’s own account neither confirms nor rules it out.

McDonald’s post also warned that ransomware campaigns are now limited primarily by attackers’ budgets rather than human effort, raising the possibility of “thousands or tens of thousands of simultaneous campaigns.” That concern is a little harder to square with what Clark described Monday. (If a human still has to select each victim, provision infrastructure, and obtain database credentials for each operation, that’s at least one hurdle.)

Either way, Clark told CyberScoop, while Sysdig has yet to see the same business hit other victims, given how cheap it is to run an agent, he expects that to change.

When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.

attack Human needed ransomware run sysdig
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleYou can now adjust the pace and expressiveness of Siri in the latest iOS 27 beta
Next Article Netflix invented binge watching. Now he may be over it.
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Are brain waves the next unlock for natural artificial intelligence?

27 July 2026

Librarians host viral ‘Avoid AI’ workshops for people fed up with big tech

26 July 2026

I tested OpenAI’s new AI keyboard — which will be fun for some coders and a little overwhelming for everyone else

25 July 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Are brain waves the next unlock for natural artificial intelligence?

27 July 2026

Anthropic updates Claude voice mode with more capable models

27 July 2026

Music streamer Deezer says more than 50% of daily uploads are generated by AI

27 July 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

TechCrunch Disrupt 2026’s new Smart Money Stage explores fintech, payments, artificial intelligence and everything

25 July 2026

Don’t want to invest in Elon Musk? Two new ETFs expressly exclude him

10 July 2026

India’s payments chief believes artificial intelligence will play a big part in the next era of digital payments development

28 June 2026
Startups

Insurance startup Corgi reportedly raises more money to $4 billion – its third round in 8 weeks

Build publicly, fail publicly: what it’s like to be a founder under 20 right now

Prentis, new AI lab co-founded by Reid Hoffman and Mark Pincus in talks to raise $100 million

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.