Updated October 2026 to our current guidance. The original reporting date is unchanged.
In the newsletter I mentioned that researchers had documented an attack run almost entirely by an AI. Here is how it worked, and the detail that matters most for an owner: every door it went through had a fix or a setting that had been available for a long time.
Count What’s on Your Computers → See how many programs each Windows PC has, how many are current, and how many need updating. No credit card needed. The scan is on us. If you want step-by-step instructions afterward, that’s a paid report, and you’ll see the price before you decide.
In this article
Hey folks! When I ask owners about the basics, I usually hear the same thing. Updates run, and someone looks after the network. In most of the businesses I see, that is true, and it covers a lot.
Keep that in mind, because this story is about the few things that sit just outside it.
In early July, the threat research team at Sysdig, a cloud security company, published what it believes is the first ransomware attack run from start to finish by an AI agent. They named the operation JadePuffer.
A person pointed the agent at a target. From there the agent ran the steps a criminal would normally run by hand. It got into a server and mapped what was on it. It searched for stored secrets, such as passwords, cloud account keys, and database logins, and collected what it found. It set itself up to check in with the attacker every 30 minutes. It moved on to a second server that ran a MySQL database and Nacos, a configuration tool, and logged into the database with full rights.
Then it locked up the data. It encrypted all 1,342 of the Nacos settings, deleted the original tables, and left a ransom note asking for Bitcoin. One detail stands out: the agent generated a key to unlock the data, printed it to the screen once, and never saved or sent it. Paying would not have brought the data back.
How did the researchers know an AI was driving? The commands carried plain-English comments explaining themselves, and when a step failed, the agent worked out why and tried a different approach within moments. Sysdig counted more than 600 separate payloads, the individual pieces of code it ran. Sysdig itself described the case as “a warning sign rather than a crisis.”
Sources: The Hacker News, “AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack,” July 2, 2026; The Next Web on Sysdig’s findings.
This is the part I want every owner to read, because it changes what the story is about.
The first door was Langflow, a tool for building AI apps. It had a flaw, CVE-2025-3248, that let anyone who could reach the server run their own code on it without signing in. The fix shipped in Langflow version 1.3.0, and the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its list of known exploited vulnerabilities in May 2025. That is more than a year before Sysdig’s report. The server had not been updated.
The second door was a storage server still using its factory login, the username and password it shipped with. The third was Nacos, which the agent got into through a flaw published in 2021 and a default signing key nobody had changed since 2020.
Count them. An old fix not installed. A default password not changed. A five-year-old flaw. A default key. None of those needed AI to find. The agent just went through them faster than a person would have.
Here is the boundary that matters for most businesses.
Windows Update never touches third-party software.
It keeps Windows current, and it does that well. It does not update Langflow, or a database, or your PDF reader, the file compression tool, the remote-access program a vendor installed, or the specialty app the office runs on. Each has its own updater, or none at all. And no update anywhere changes a default password. Someone has to do that on purpose.
Nobody did anything wrong by relying on Windows Update. That is where its job ends, and many routines were built around it.
So who has been checking the rest?
My opinion, and I will put my name on it: the businesses that run into trouble with tools like this will mostly be the ones with an old fix waiting somewhere. Missing the newest product matters much less. The useful response to JadePuffer is knowing which programs on your computers are current and which are not, and having someone close the gap on a schedule.
One more thing from the JadePuffer report deserves its own paragraph, because no amount of patching fixes it. Two of the doors the agent used were settings, not flaws: a storage server still on its factory login, and a signing key left at its default for six years. Updates do not change those. A person has to go in and change them on purpose, once, and write down that it was done.
The good news is that this is quick work. A default password takes a minute to change. The hard part is knowing which devices still have one, which comes back to the same theme as the rest of this story: someone has to look.
None of this is exotic. That is the point.
Find your oldest, least-watched system and ask when it was last updated. Every business has one: the server in the closet, the app the office cannot work without, the remote-access setup someone configured years ago. Ask whoever looks after it for the date of its last update, and whether any of its logins are still the ones it came with.
Turn on two-step sign-in and test a real restore. JadePuffer collected stored passwords and used them to move deeper. Two-step sign-in on email, banking, and remote access limits what a stolen password can do. And restore something from your backup, for real, at least once. Keep one copy disconnected from the network. A backup you have restored from is one you know works.
Count what is on your computers. Before you run it, guess how many programs are on one of your computers and write the number down. Then run the Reveal Scan on your Windows computers. It counts the programs on each one and tells you how many are current and how many need updating. If you run it and never speak to us again, that’s a fine outcome.
If the second number is higher than you expected, that is common. You don’t have to be able to do this. We’ll do it with you.
My father fell for a phishing email. I have spent my whole career in this, and it still reached him. Someone got remote access to his computer and went looking for his financial papers. My step-mother noticed something was off, called me, and I stopped them before they reached the spreadsheet with his bank credentials.
That is why I built Forward to Safety around people who check the machines, backed by good technology. I have spent 35+ years in cybersecurity. FBI InfraGard trainer. Dozens of managed clients since 1991. None has had ransomware.
Get the basics right first. This attack is the evidence. JadePuffer went through an old flaw with a published fix, a factory password, and a default key. None of those needed another AI to stop. They needed someone to install a fix and change a setting.
Good technology helps, and we use it. But in my experience, what keeps a business running is a person checking the machines and closing what is open on a schedule. A tool nobody is minding does not do that.
Here is a question to answer just for yourself. Is there a system in your business you have been meaning to get to? Most owners I talk to can name one within a few seconds. That is a good place to start.
When a serious flaw shows up in something your business runs, the useful thing is to know about it and close it soon after the fix comes out. That is the whole job.
Start with the counts. Run the Reveal Scan on your Windows computers and see how many programs on each one need updating.
Count What’s on Your Computers →
When you have your counts, you can book a 15-minute conversation with me or one of our experts about what the scan found. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#JadePuffer #Patching #ThirdPartySoftware #SmallBusinessSecurity #ForwardToSafety
Join the owners who get Craig's Insider Notes every week.