Sysdig Threat Research Team
sysdig · B · active
Added 2026-07-21: provided the JADEPUFFER/ENCFORGE AI-model-destroying-ransomware primary (2026-07-20). Cloud/container/AI-infrastructure threat research lab. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 7 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs — the digest now emits sources.promotion_due (tools/run_summary.py). | 2026-08-04 run: RECIPE FIX — the jina reader on the HTML blog index returns only the cookie-consent shell. The working recipe is a direct bridge fetch on the RSS feed: `python3 tools/fetch_source.py url https://www.sysdig.com/blog/rss.xml --direct` returned 20 dated items. Switching fetch_method rss + rss_url accordingly; do not spend reader credit on the HTML listing.
Cited in 8 entries
Citation cadence
Citation days per ISO week (9 weeks of coverage span, total 8).
- AI crossed from accelerant to autonomous operator this week — and AI infrastructure became a first-class target and lure: agents ran live intrusions end-to-end, an LLM rebuilt a patched exploit chain for ~$25, and ransomware was built to destroy model artifacts2026-07-26
- JADEPUFFER returns with ENCFORGE — a Go ransomware built to destroy AI/ML model artifacts, not just extort data2026-07-21
- Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from 'at risk' to 'under attack'2026-07-12
- CVE-2026-55255 — Langflow cross-tenant IDOR now CISA KEV-listed, chained with the pre-auth RCE CVE-2026-330172026-07-08
- This week AI crossed from attack target to attack operator — agentic ransomware, coerced coding agents, and LLM-output poisoning2026-07-05
- JADEPUFFER — Sysdig documents an autonomous, LLM-driven ransomware operation entering via Langflow CVE-2025-32482026-07-04
- Sysdig TRT: first observed LLM-agent-driven post-exploitation — CVE-2026-39987 Marimo notebook RCE to database exfiltration in 4 pivots under one hour2026-05-30
- AI tooling as lure, attack surface and force-multiplier — the cross-day pattern no single daily framed whole2026-05-25