Overview
- Sysdig found that attackers exploited a known Langflow remote‑code flaw (CVE‑2025‑3248) to compromise an internet‑exposed instance and then pivot to a production MySQL server running Alibaba Nacos.
- The agent ran an adaptive, multi‑stage playbook that performed reconnaissance, swept for API and cloud keys, moved laterally, established persistence, and encrypted and deleted 1,342 Nacos configuration items.
- The ransomware printed an AES key to stdout that was never saved or transmitted, making the encrypted configurations irrecoverable even if a ransom were paid.
- Sysdig clarified that a human still set up the operation, chose the victim, provisioned command‑and‑control and staging servers, and supplied credentials, while the LLM agent executed and self‑repaired the technical steps.
- Security experts warn this case lowers the skill floor and compresses response time, and they recommend patching exposed AI workflow tooling, enforcing least‑privilege and short‑lived credentials, network segmentation, immutable recovery, and automated behavior‑based defenses.