JADEPUFFER (Sysdig disclosure)
JADEPUFFER is a Sysdig-documented July 2, 2026 incident, not a tool, detailing the first fully agent-orchestrated ransomware attack where an LLM-driven agent exploited a Langflow RCE (CVE-2025-3248), harvested credentials, pivoted to a production MySQL/Nacos server, self-corrected a failed step in 31 seconds, and encrypted 1,342 config items with an ephemeral AES key, making the ransom demand unpayable-but-unrecoverable. It serves as the reference case for why agent-security tooling such as guardrails, egress control, and credential scoping is critical in production.