Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Where Should Apple Go After The iPhone Duo? Bring On Smaller And Larger Foldables

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    One of AI’s Fiercest Critics Says All the Doom Talk Is ‘Meant to Distract Us’

    September 11, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»JADEPUFFER’s Second Wave Multi-Agent Attacks
    Cybersecurity

    JADEPUFFER’s Second Wave Multi-Agent Attacks

    InfoForTechBy InfoForTechSeptember 11, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Sysdig disclosed ENCFORGE later in July: the same operator, identified through a matching extortion contact address, returned to the previously compromised Langflow instance and staged a compiled Go ransomware binary purpose-built for AI infrastructure.

    Where the original campaign relied on improvised Python scripts and a database’s own encryption function, ENCFORGE targets roughly 180 file extensions across the AI/ML stack, including model checkpoints, vector databases, training data, and embedding indices.

    The operator escalated through an exposed Docker socket to reach root-level host access, then iterated through successive delivery scripts over roughly five minutes to work around failures before the payload landed.

    The recovery problem is different from a conventional database attack. Production models, training data, and embedding assets may not have the same backup and recovery coverage as conventional business data.

    Sysdig estimates that rebuilding a single affected model can cost $75,000 to $500,000 in compute and engineering time.

    The more significant escalation is the one Unit 42 documented independently, in a different environment with a different operator. Unit 42 describes a human attacker who set objectives and then left tactical execution to AI agents that monitored, evaluated, acted, and re-planned in real time.

    On September 2, researchers Renzon Cruz, Nicolas Bareil, Eric Semaan, and Omar Jbari published an account of an intrusion that began with a breach of a public-facing API and, ten hours later, had reached across the victim’s cloud, identity, CI/CD, and AI infrastructure.

    Rather than one agent working sequentially, specialized agents worked in parallel: one mapped internal microservices, others combed source repositories for hard-coded tokens and service passwords, another used the harvested credentials to reach the secrets manager and pull root-level administrative credentials, and a pipeline-focused agent triggered unauthorized CI/CD builds and obtained cloud access keys, which it then used against the victim’s AI infrastructure.

    The agents then used those stolen keys to route their own orchestration traffic through the victim’s own AI endpoints, which made it harder to distinguish from ordinary model usage.

    One persistence attempt, a backdoor planted in Terraform configuration, failed because branch-protection controls required a second human reviewer before the change could merge.

    The attacker told Unit 42 during negotiations that they had used frontier AI models and purpose-built agentic attack frameworks.

    Unit 42 found independent technical indicators consistent with that claim: parallel calls to multiple frontier models, structured Markdown files passing state between agent sessions, and the same kind of self-narrating, heavily commented code Sysdig had flagged in JADEPUFFER’s payloads.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026

    200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

    September 10, 2026

    Microsoft Fixes 974 Flaws in Record Patch Tuesday

    September 10, 2026

    U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

    September 9, 2026

    Before You Paste Anything Into ChatGPT, Check This List

    September 9, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026333 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202627 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026333 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202627 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.