The Ransomware That Ran Itself

The Ransomware That Ran Itself

July 18, 2026 · 39 min · Season 3 · Episode 38

About this episode

The episode discusses the first AI-driven ransomware attack executed autonomously by JadePuffer and features insights from Threat Labs on a new exploit.

A complete attack chain run by an AI agent – with zero human hands on the keyboard. JadePuffer is the first AI-driven threat actor to execute a ransomware attack end-to-end – autonomously prioritizing targets, adapting in real time to exploit vulnerabilities, and harvesting sensitive data for extortion. Join Matt and David as they break down what made this attack possible – and why JadePuffer pushes independent AI threat actors from science fiction into real-world operation. Plus: In our Voices from the Frontlines segment, Threat Labs research Dolev Taler shares his team’s discovery of SearchLeak, the one-click Copilot exploit that turns an AI assistant into a data exfiltration tool.

More episodes of State of Cybercrime

Explore listener stats, chart rankings, contacts and more on the State of Cybercrime podcast page.