IT之家(RSS)📅 Jul 3行业动态

全球首例 AI Agent 勒索攻击曝光,从漏洞利用到数据库加密全程自主完成

安全厂商 Sysdig 首次记录到 AI Agent"JADEPUFFER"自动完成的勒索攻击。攻击利用暴露的 Langflow 服务漏洞 CVE-2025-3248 远程执行 Python 代码,随后自主收集 OpenAI、Anthropic、DeepSeek、Gemini 等 API 密钥及阿里云、腾讯云、华为云、AWS、Google Cloud、Azure 等云平台凭证,通过 MinIO 默认密码访问对象存储并创建每 30 分钟连接的计划任务。横向移动到 MySQL 和 Nacos 服务器,利用数据库 Root 账号及 Nacos 漏洞 CVE-2021-29441 获取管理权限,加密全部 1342 条配置数据,留下包含比特币钱包地址和 Proton Mail 的勒索信息。AI 在首次操作失败后 31 秒内自主完成错误分析与修复,累计执行超过 600 个攻击载荷,全程无需人类操作。

💡 Recommended AI Tools

The large video model released by Shengshu Technology and Tsinghua University supports highly consistent simulation of characters and physical laws.
The large video generation model launched by Kuaishou supports the generation of 1080p frame rate videos up to 2 minutes long.
ByteDance's AI painting and short video generation platform supports one-click text generation and shadow generation.
Tencent's official AI assistant deeply integrates WeChat public account ecology, search and file parsing capabilities.