Skip to content
Artwork for The Security Table
The Security Table · July 22 · 43 min

Make No Mistakes: Inside the First "Agentic Ransomware"

We dig into Sysdig's Jade Puffer report, the so-called first agentic ransomware, and argue about whether the evidence actually proves an LLM was driving the attack or if it's just a well-trained script wearing an agent costume. We walk through the four signals Sysdig points to, including self-narrating code, fast failure recovery, and a reused Bitcoin address, and push back on how strong that proof really is. We also talk about what this does to the threat model now that attackers don't need a human in the loop to adapt on the fly. And yes, the exploited CVE was sitting unpatched since 2025. 🚀 Does adaptive malware change who you're defending against, or just how fast they move? FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: The Security Table YouTube Channel Thanks for Listening!

0:00-43:53

transcript

No transcript — this publisher did not publish one.

show notes

We dig into Sysdig's Jade Puffer report, the so-called first agentic ransomware, and argue about whether the evidence actually proves an LLM was driving the attack or if it's just a well-trained script wearing an agent costume. We walk through the four signals Sysdig points to, including self-narrating code, fast failure recovery, and a reused Bitcoin address, and push back on how strong that proof really is. We also talk about what this does to the threat model now that attackers don't need a human in the loop to adapt on the fly. And yes, the exploited CVE was sitting unpatched since 2025. 

🚀 Does adaptive malware change who you're defending against, or just how fast they move?

FOLLOW OUR SOCIAL MEDIA:

➜Twitter: @SecTablePodcast
➜LinkedIn: The Security Table Podcast
➜YouTube: The Security Table YouTube Channel

Thanks for Listening!

links4