The Security Table

Make No Mistakes: Inside the First "Agentic Ransomware"

• Izar Tarandach, Matt Coles, and Chris Romeo • Season 4 • Episode 16

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 43:53

We dig into Sysdig's Jade Puffer report, the so-called first agentic ransomware, and argue about whether the evidence actually proves an LLM was driving the attack or if it's just a well-trained script wearing an agent costume. We walk through the four signals Sysdig points to, including self-narrating code, fast failure recovery, and a reused Bitcoin address, and push back on how strong that proof really is. We also talk about what this does to the threat model now that attackers don't need a human in the loop to adapt on the fly. And yes, the exploited CVE was sitting unpatched since 2025. 

🚀 Does adaptive malware change who you're defending against, or just how fast they move?

FOLLOW OUR SOCIAL MEDIA:

âžœTwitter: @SecTablePodcast
âžœLinkedIn: The Security Table Podcast
âžœYouTube: The Security Table YouTube Channel

Thanks for Listening!

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Application Security Podcast Artwork

The Application Security Podcast

Chris Romeo and Robert Hurlbut