← Back to Feed
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
CVE-2025-3248
August 15, 2026 · Tenable Blog · Severity: HIGH
Tenable's RSO team tracks a cluster of seven agentic AI offensive incidents from November 2025 through August 2026, anchored by Taiwan's confirmed near-autonomous attack that mapped 21 systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records. The cluster also includes JADEPUFFER, which exploited CVE-2025-3248 in Langflow to automate database extortion, and the common entry vector is identity and authentication exposure such as discoverable federation endpoints, weak credentials, and misconfigured SSO. Organizations running affected Langflow versions should apply vendor patches immediately and audit exposed authentication surfaces.
Key Takeaways
- Taiwan confirmed a near-autonomous AI attack in July 2026, mapping 21 systems, compromising 85 accounts, and exfiltrating 2,564 personnel records.
- The threat cluster includes JADEPUFFER exploiting CVE-2025-3248 in Langflow for automated database extortion and autonomous vulnerability scanning.
- Identity and authentication exposure, including weak credentials and misconfigured SSO, is the common entry point exploited at machine speed.