Daily brief at 7am Melbourne. Unsubscribe any time.

Friday 3 July 2026

The First Fully Autonomous AI Ransomware Attack Is Here — and It Worked

An AI agent just ran a ransomware attack from start to finish — no human required — and the security industry is still working out what that means.

Lead story

The First Fully Autonomous AI Ransomware Attack Is Here — and It Worked

Security firm Sysdig says it has documented what it believes is the world's first ransomware attack carried out entirely by an AI agent, from initial breach to final encryption, without a human operator directing any step. The group behind it, which Sysdig tracks as JADEPUFFER, exploited a known remote-code-execution vulnerability in Langflow — an open-source tool widely used to build AI agent workflows — to gain their foothold.

What happened next is the part that should grab your attention. Once inside, a large language model handled the full attack chain: harvesting credentials, moving laterally through the network, then encrypting and wiping a production database. The LLM didn't just assist — it drove. Sysdig's Threat Research Team says this is qualitatively different from previous AI-assisted attacks where a human still called the shots at key decision points.

Why this matters more than the usual "AI used in cyberattack" headline.

We've had plenty of those already — AI-drafted phishing emails, AI-accelerated reconnaissance. JADEPUFFER is different because it removes the human bottleneck entirely. Traditional ransomware operations require skilled operators making judgment calls at each stage: which credentials to try, which systems to pivot to, when to detonate. If an LLM can reliably substitute for that expertise, the economics of ransomware change dramatically. You no longer need a team of experienced hackers. You need a prompt and a target list.

There's also a nastier wrinkle: Sysdig notes the AI agent didn't reliably return data even after a ransom payment was made. That's not a bug from the victim's perspective — it's the same unreliability that makes trusting any ransomware negotiation a bad bet. But it does suggest that agentic ransomware may be even harder to negotiate with than human-operated variants.

The Langflow angle matters too.

CVE-2025-3248 — the Langflow RCE that JADEPUFFER exploited — was patched back in April 2025, but Langflow instances remain widely unpatched across the internet. If you're running any AI orchestration tooling in your environment, this is a good reminder that the attack surface isn't just your traditional infrastructure. The pipelines you use to build AI agents are themselves exploitable entry points.

What to watch for.

Sysdig is careful to call this a first confirmed instance, not evidence of widespread deployment. But the proof-of-concept value here is significant: someone has now demonstrated the technique end-to-end, which means others will iterate on it. Expect defenders to push back hard on the "first ever" framing — there's reasonable debate about what counts as "fully autonomous" — but that debate shouldn't obscure the underlying signal.

For Australian organisations, this is worth flagging in the context of the ACSC's recent guidance on AI system security. Agentic AI tools are proliferating across enterprise environments, and most security teams haven't fully mapped them into their threat models. If Langflow or similar orchestration platforms are running in your environment, check your patch status today — and then ask whether those systems are even in your asset inventory.

Also today

FBI and Google Tear Down the NetNut Botnet — 2 Million Devices Freed

The FBI, working alongside Google's Threat Intelligence Group, Lumen, and other partners, has seized hundreds of domains tied to NetNut — a residential proxy network operated by Nasdaq-listed Israeli firm Alarum Technologies. Researchers had been tracking the underlying botnet, dubbed Popa, for years: it compromised at least two million home devices and rented their bandwidth to customers who wanted their traffic to appear as though it came from ordinary households. The action came roughly two weeks after KrebsOnSecurity published findings linking NetNut to the Popa infrastructure. Google says the operation significantly reduced the network's pool of usable devices. Australian ISPs are likely to have had compromised residential devices in the pool.

Krebs on Security

Google Loses Its Final €4.1 Billion EU Appeal — and the Android Bundling Era Ends

The Court of Justice of the European Union has rejected Google's last appeal against a €4.1 billion (roughly $4.7 billion AUD equivalent) antitrust fine, confirming the penalty for forcing Android device makers to pre-install Chrome and Google Search. It's the largest antitrust fine in EU history and closes a case that has dragged on for nearly a decade. The ruling means the precedent is now locked in: using a dominant mobile platform to preference your own services is illegal under EU competition law. That principle is increasingly being echoed in Australia's own digital platform competition reviews, where the ACCC has scrutinised similar bundling behaviour by major tech firms.

Bleeping Computer

ConsentFix and ClickFix: Microsoft 365 Accounts Hijacked in Seconds

A pair of related social-engineering techniques — ClickFix and ConsentFix — are being used together to bypass multi-factor authentication on Microsoft 365 accounts in what researchers describe as a three-second token theft. ClickFix tricks users into running malicious commands by posing as a CAPTCHA or browser error. ConsentFix layers on top by presenting a fake OAuth consent screen that hands attackers a persistent access token. Together, they sidestep MFA entirely because the victim grants access voluntarily. Microsoft 365 is the dominant productivity platform for Australian businesses and government agencies, making this a high-priority concern for local security teams.

Bleeping Computer

FortiBleed Credential Haul Is Already Fuelling INC and Lynx Ransomware Attacks

The FortiBleed campaign — which harvested credentials from hundreds of thousands of FortiGate firewalls — has been directly linked to active ransomware deployment by the INC and Lynx operations. Researchers found at least one operator working negotiation panels for both groups simultaneously, a rare opsec slip that stitches the two gangs together. The stolen credentials were evidently never meant to sit idle: they were stockpiled specifically to facilitate future network intrusions at scale. Fortinet devices are widely deployed across Australian enterprise and government networks, so defenders should treat unpatched or unrotated FortiGate credentials as actively compromised until proven otherwise.

Bleeping Computer

Apple Is Compressing Its Patch Cycles to Keep Pace With AI-Accelerated Exploits

Apple is quietly abandoning its historically slow, deliberate patch cadence in favour of faster, more frequent releases — a direct response to attackers using AI to shrink the window between vulnerability discovery and weaponisation. The shift represents a meaningful cultural change for a company that has long treated software stability as a selling point and bundled fixes into major iOS and macOS releases. Security teams that rely on predictable Apple patch schedules for change-management planning will need to adapt. It also signals a broader industry acknowledgement: the old assumption that defenders have weeks to respond to a disclosed vulnerability is no longer safe.

Dark Reading

Anthropic's AI Found the Open-Source Bugs — IBM's $5B Bet Is to Fix Them

IBM and Red Hat have launched Project Lightwell, committing $5 billion and 20,000 engineers to patching open-source software vulnerabilities at scale. The announcement follows Anthropic's Mythos research, in which its AI models identified a significant volume of previously unknown security flaws across widely used open-source codebases. The pairing is notable: AI doing the discovery, humans doing the remediation — at least for now. The project reignites long-running questions about who bears responsibility for securing the open-source supply chain, which underpins virtually every enterprise software stack globally, including critical infrastructure in Australia.

Dark Reading

OpenAI Offers Trump Administration a 5% Equity Stake to Smooth Relations

OpenAI CEO Sam Altman has reportedly proposed giving the US government a 5% ownership stake in the company — pitched as a way to share the economic upside of the AI boom with the public and ease mounting friction with the Trump administration. The discussions reportedly involve routing the stake through a US sovereign wealth fund. It's an unusual move that blurs the line between a private AI company and a quasi-public asset, and it comes as OpenAI navigates its ongoing conversion from a non-profit structure to a for-profit entity. The proposal would give a government meaningful financial incentive to see OpenAI succeed — which has obvious implications for regulatory neutrality.

TechCrunch

Microsoft Launches a $2.5 Billion AI Deployment Subsidiary

Microsoft has stood up a dedicated AI deployment company backed by a $2.5 billion internal commitment, following similar moves by Amazon, OpenAI, and Anthropic. The new group is designed to accelerate enterprise rollouts of Microsoft's AI products — essentially a professional services arm that sits between Azure's infrastructure and customers who want bespoke AI implementations. It signals that Microsoft sees deployment friction, not model capability, as the main barrier to revenue growth right now. For Australian enterprise customers, it likely means more structured pathways to Microsoft-led AI transformation projects, and more pressure to commit to the Azure ecosystem.

TechCrunch

UNSW Faces a 95% Cut to Its Microsoft 365 Storage Quota by October

The University of New South Wales has been told it must slash its Microsoft 365 storage usage by 95% before October — a dramatic reduction that has caught the institution off-guard. ITnews reports speculation that Microsoft is quietly pulling back on storage allocations to free up data centre capacity for its AI infrastructure buildout. UNSW is not believed to be alone: similar notices are reportedly circulating across Australian universities and large organisations on legacy M365 licensing tiers. The situation is a practical illustration of how AI infrastructure demand is reshaping cloud pricing and capacity in ways that downstream customers are only now starting to feel.

iTnews

Trail of Bits Put GPT-5.5-Cyber to Work Fuzzing Real Open-Source Code — Here's What It Found

Trail of Bits has published a field report from its Patch the Planet programme, a collaboration with OpenAI that deploys GPT-5.5-Cyber against real open-source codebases. In one documented case, the model built a functioning zlib fuzzing lab in a single day — a task that would typically take an experienced security engineer considerably longer. The work is motivated by a specific concern: highly capable models will soon generate a flood of bug reports that OSS maintainers aren't resourced to handle. The programme aims to find and patch vulnerabilities before that firehose opens. It's a rare example of AI security research that goes beyond disclosure and actually ships fixes.

Trail of Bits

OAIC Ordered to Release Full American Express Privacy Determination

An Australian court has ordered the Office of the Australian Information Commissioner to hand over its complete privacy determination in a case involving American Express — a ruling that will make public findings the OAIC had sought to keep confidential. The investigation reportedly uncovered security and access control deficiencies at Amex that led to a Privacy Act breach. The case is significant beyond Amex: it tests the limits of OAIC's ability to shield regulatory findings from public scrutiny, and the outcome may influence how future privacy determinations are disclosed. For Australian consumers and the financial sector, greater transparency in OAIC enforcement is generally a positive development.

iTnews

Sources consulted