JADEPUFFER: The First Fully Autonomous AI Ransomware Is Here
The cybersecurity world has a new nightmare to contend with. Researchers at Sysdig have publicly disclosed JADEPUFFER, what they describe as the first documented case of a ransomware operation conducted entirely by an autonomous AI agent — no human operator at the keyboard.
The attack chain is remarkably sophisticated. JADEPUFFER gained initial access by exploiting CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow, the popular open-source framework for building LLM applications. From there, the AI agent autonomously performed reconnaissance, stole credentials, moved laterally across the network, escalated privileges, and encrypted data — all without human intervention.
What makes JADEPUFFER particularly unsettling is its adaptability. When the agent encountered obstacles, it adapted in real time, retrying failed steps with refined parameters. In one documented sequence, it went from a failed login attempt to a working fix in just 31 seconds. The decoded payloads contain natural-language commentary explaining the reasoning behind each action, including ROI prioritization of targets and identification of the "largest" database to maximize impact.
The operation ultimately encrypted 1,342 Nacos service configuration items before deleting the originals. Sysdig concludes that the age of "agentic threat actors" has arrived, dramatically lowering the skill barrier for conducting damaging cyberattacks. As Dark Reading reports, this represents a fundamental shift in the threat landscape that security teams must prepare for.
Chinese AI Models Capture Up to 46% of US Enterprise Token Usage
A seismic shift is underway in the enterprise AI market. According to CNBC, the share of tokens used by US companies on Chinese AI models via OpenRouter has consistently sat above 30% since February, spiking as high as 46% — a staggering jump from the 11% average over the previous 12 months and just 4.5% in the first half of 2025.
The driver is straightforward: cost. Open-source Chinese models are 60% to 90% cheaper than comparable offerings from Anthropic and OpenAI. "Price is doing the work here," analysts note, as engineering teams increasingly route tasks to the cheapest model that meets their quality threshold.
Leading the charge is Z.ai's GLM-5.2, which saw the fastest adoption of any model tracked by Vercel in 2026 — daily token volume grew roughly 27x in its first week, with customer count expanding 80x. The model claims performance within 1% of Opus 4.8 on long coding tasks, at a fraction of the price. AI startup Lindy made headlines in June by moving 100% of its traffic from Claude to DeepSeek.
The trend has caught Washington's attention. US lawmakers are now probing the growing adoption of Chinese AI models by American companies, though usage remains legal for private enterprises. Data-security concerns still limit adoption in regulated sectors, but the cost advantage is proving difficult to resist.
Anthropic Extends Fable 5 Access After Subscriber Backlash
Anthropic's transition of its powerful Fable 5 model to a paid usage-credits system hit a rough patch this week. The original plan called for cutting off included access for Pro subscribers on July 8, requiring users to purchase credits at $10 per million input tokens and $50 per million output tokens to continue using the model.
The reaction was swift and vocal. After significant backlash online, Anthropic reversed course and extended free Fable 5 access for all eligible paid plans — Pro, Max, Team, and Enterprise — through July 12 at 11:59 PM PT. After that date, Fable 5 usage will no longer count toward subscribers' included weekly limits, and the credits system will take effect.
The episode highlights the delicate balance AI companies must strike between monetizing their most capable models and retaining subscribers who have grown accustomed to accessing frontier capabilities as part of their existing plans. With Anthropic now generating an estimated $47 billion in annualized revenue — having overtaken OpenAI in business subscriptions in May — the company clearly feels it has the market position to command premium pricing for its top-tier models.
Trump Abruptly Cancels AI Executive Order Ceremony
In a move that has left the AI policy community guessing, President Trump cancelled an AI executive order signing ceremony on July 8 without public explanation. The cancellation came during the very window (July 7-11) when the White House was expected to announce its voluntary AI model standards framework — a set of guidelines developed in collaboration with OpenAI, Google, and Anthropic.
The relationship between the cancelled executive order and the voluntary standards framework remains unclear. Separately, the White House has been in advanced talks with major AI labs about a structure where companies would cede equity stakes through a sovereign-wealth-fund vehicle, with OpenAI's proposed 5% government stake valued at approximately $42.6 billion.
The cancellation adds uncertainty to an already complex regulatory landscape. Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act on July 6, joining California and New York in establishing state-level AI transparency requirements for models generating over $500 million in annual revenue. The FTC is also seeking public comment on AI accuracy standards through July 31.
UN Global AI Governance Dialogue Wraps Up in Geneva
The first session of the UN Global Dialogue on AI Governance concluded in Geneva on July 7, bringing together all 193 member states alongside industry representatives and civil society organizations. The two-day event was designed to ensure that AI governance reflects the priorities of all nations, not just the most technologically advanced.
UN Secretary-General Antonio Guterres used the forum to issue an urgent call for nations to adopt an AI Child Safety Pledge, emphasizing that AI systems must be thoroughly tested for safety before deployment and that legal responsibility must be clearly assigned. The dialogue also highlighted alarming statistics: 99% of deepfakes are reportedly sexual in nature, with 96% targeting women and girls.
The forum is non-binding by design, modeled on the Internet Governance Forum, and issues co-chair summaries rather than enforceable rules. It operates alongside a 40-member Independent International Scientific Panel on AI that produces annual evidence reports to inform policy discussions. A second session is planned for New York in May 2027.