AI Weakly #09 - The first AI-orchestrated ransomware attack just happened. The full chain: recon, lateral movement, encryption. Autonomous.

AI Weakly is the weekly newsletter for those who make decisions on AI and security without time to waste. Every Tuesday: the facts that matter without the noise.

Issue #9

Top Story —

This week marked a watershed moment in ransomware evolution: the first documented campaign where an LLM agent orchestrated the entire attack chain autonomously, from reconnaissance through database encryption. Simultaneously, active exploitation surged across critical infrastructure—SharePoint RCE, Argo CD cluster takeover, Citrix Bleed 2, and Cisco UC systems all now under active fire. The convergence of autonomous AI attacks with mature supply chain compromises (North Korean npm packages, FortiBleed credentials linked to Lynx ransomware) creates a compounding threat model: defenders now face attackers that scale infinitely, adapt in real-time, and maintain persistent footholds through stolen identity and corrupted dependencies. Patch velocity and threat hunting for AI-driven lateral movement must become existential CISO priorities.

Weakly Digest —

01 —

JadePuffer Ransomware: First LLM Agent Executes Autonomous End-to-End Attack Including RCE, Lateral Movement, Database Encryption

🔴 Critical / Active Exploitation

Researchers documented JadePuffer, the first ransomware campaign executed entirely by an LLM agent without human operators, exploiting Langflow RCE to conduct autonomous reconnaissance, credential theft, lateral movement, and database encryption. Attack demonstrates AI agents performing complex multi-stage chains in real-time, eliminating detection windows between stages.

EDITOR’S NOTE
This is your new threat model. Autonomous attacks eliminate human operator bottlenecks and adapt tactics faster than traditional playbooks. Immediate action: audit Langflow deployments, implement real-time anomaly detection on LLM API calls, and assume lateral movement timelines compress from days to minutes. Threat hunting must shift to detecting AI agent behavior patterns—rapid tool execution, unusual API sequencing, and parallel reconnaissance.

02 —

CISA: Microsoft SharePoint RCE Actively Exploited in Wild—May Patch Bypass Now Live

🔴 Critical / Active Exploitation

CISA confirmed active exploitation of a high-severity SharePoint RCE vulnerability patched in May, with threat actors now weaponizing the flaw in real-world intrusions. Organizations running unpatched SharePoint instances face immediate unauthorized code execution and data breach risk.

EDITOR’S NOTE
This is not a theoretical risk. Verify SharePoint patch levels across all tenant instances today—CVE-2026-[ref needed] is exploitation-in-the-wild. Implement network segmentation isolating SharePoint from sensitive systems, enable SharePoint advanced threat protection, and prioritize this above all other patch queues. Monitor event logs for anomalous document access and RCE indicators.

03 —

Unpatched Argo CD Repo-Server RCE Enables Unauthenticated Kubernetes Cluster Takeover—No Patch Available

🔴 Critical / Active Exploitation

An unpatched remote code execution vulnerability in Argo CD's repo-server component allows unauthenticated attackers with network access to achieve full Kubernetes cluster compromise. No CVE assigned and no patch currently available, leaving deployments exposed.

EDITOR’S NOTE
Zero-day Kubernetes compromise. Immediate mitigation: air-gap or heavily restrict network access to repo-server instances, implement admission controllers blocking suspicious image deployments, and enable Kubernetes API audit logging at maximum verbosity. Assume breach and hunt for suspicious deployments, pod executions, and service account usage. This is existential infrastructure risk—prioritize above routine patching until vendor releases remediation.

04 —

FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations—Perimeter Bypass to Ransomware

🔴 Critical / Supply Chain

A large-scale credential theft campaign targeting Fortinet systems has been directly connected to INC and Lynx ransomware operators, indicating stolen credentials are being weaponized for network intrusions and ransomware deployment. Represents critical supply chain compromise affecting organizations relying on Fortinet security infrastructure.

EDITOR’S NOTE
Your perimeter defense is now a liability if Fortinet credentials are compromised. Immediate actions: enforce credential rotation across all Fortinet admin accounts, implement conditional access policies requiring re-authentication for sensitive operations, and deploy multi-factor authentication on all Fortinet management interfaces. Hunt for lateral movement from Fortinet boxes—assume attackers have maintained persistence and are moving toward backup systems and identity infrastructure.

05 —

North Korea-Linked PolinRider Campaign: 108 Malicious Packages Across npm, Packagist, Go, Chrome Web Store—Active Supply Chain Poisoning

🟣 Supply Chain Attack

North Korean threat actors published 108 malicious packages and browser extensions across npm, Packagist, Go, and Chrome Web Store as part of ongoing PolinRider campaign. Compromised maintainer accounts suggest persistent supply chain attack infrastructure remains active and expanding.

EDITOR’S NOTE
Supply chain poisoning is now industrialized. Audit all dependencies immediately using SBOM tools, lock package versions to known-good commits, and implement strict code review for any package updates. Quarantine developer workstations and review git history for suspicious commits. This campaign demonstrates adversary intent to compromise build pipelines at scale—assume your CI/CD is a target and implement zero-trust for artifact signing and deployment.

Also worth reading —

ConsentFix and ClickFix: OAuth Abuse Hijacks Microsoft 365 Accounts in 3 Seconds, Bypassing MFA — Audit OAuth consent policies, block risky permission scopes, and enforce conditional access on token issuance immediately.

Bad Epoll Linux Kernel Flaw: Unprivileged Privilege Escalation Affects Servers and Android—Widespread Patch Required — Prioritize Linux kernel updates (CVE-2026-46242) across data centers and containerized infrastructure—privilege escalation is your most dangerous posture.

Ransomware Groups Weaponizing Citrix Bleed 2, BYOVD, and Stolen RMM Credentials for Network Persistence — Patch Citrix infrastructure immediately (CVE-2025-5777), audit RMM tool deployments for persistence indicators, and implement EDR-backed detection of legitimate tool abuse.

Cisco Unified CM Vulnerability Now Under Active Exploitation—UC Infrastructure at Risk — Verify Cisco UC patch status and isolate legacy UC systems; voice infrastructure compromise enables lateral movement to identity and backup systems.

Your brand, in front of CISOs who read every issue. Sponsor inquiries: [email protected]"

Keep reading