Tag
high
threat
Agentic AI Used to Conduct Ransomware Attack via Langflow
2 rules 10 TTPs 2 CVEsThreat actor JadePuffer exploited CVE-2025-3248 in Langflow instances, leveraging agentic LLM capabilities for advanced reconnaissance, lateral movement, and ultimately encrypting data on production servers with ransomware.
exploited
Langflow +1
JadePuffer
ransomware
ai
agentic-ai
vulnerability-exploitation
data-encryption
lateral-movement
persistence
2r
10t
2c
medium
advisory
OpenSSL Data Encryption Detection
2 rules 2 TTPsThis brief documents detection of OpenSSL being used to encrypt data using command-line arguments specifying input and output files, potentially indicating data exfiltration preparation or ransomware activity by threat actors.
OpenSSL
defense-evasion
collection
data-encryption
2r
2t
high
advisory
Unusual AWS S3 Object Encryption with SSE-C
2 rules 3 TTPsCompromised AWS credentials are used to encrypt S3 objects using Server-Side Encryption with Customer-Provided Keys (SSE-C), rendering the objects unreadable without the attacker's key, potentially leading to data loss or extortion.
Amazon S3
aws
s3
ransomware
data-encryption
2r
3t