// Alert

Openai threat report

// OpenaiMEDIUM

The JadePuffer ransomware campaign exploited CVE-2025-3248 in Langflow to compromise a production database server and steal credentials for multiple LLM providers including OpenAI, Anthropic, DeepSeek, and Gemini, along with cloud credentials and database logins. An AI agent then pivoted through the network, exploited additional vulnerabilities, and encrypted 1,342 Nacos service configuration records before demanding ransom. The attack highlights risks for organizations using Langflow or similar AI orchestration tools that integrate with multiple cloud and LLM provider credentials.

// Get alerts for Openai