UnHacked the podcast with hosts Justin Shelley, Bryan Lachapelle, and Mario Zaki.
The first fully autonomous AI ransomware attack just happened. No humans needed once the trigger was pulled.
An LLM broke into a company's network, mapped it, deployed ransomware, and encrypted the drive in a 30-minute window, all without a human touching the keyboard after launch. Security firm Sysdig caught it and named it Jade Puffer. In this episode, Justin Shelley, Mario Zaki (Mazteck IT), and Joshua Holloway (70i Technologies) break down exactly what happened, and why the scarier headline ("AI attacks on its own!") isn't actually true.
The real story is more useful than the hype: a human still had to find the target, buy or steal credentials, and point the AI at a known vulnerability that had been public for over a year, running on default signing keys that hadn't been changed since 2020. Once it had the ammunition, AI did the rest faster than any human team could respond, which means the old "we'll notice and react" playbook no longer works. The guys also unpack why the attacker's own ransomware botched the payout (the encryption key was never stored, so paying wouldn't have gotten the data back), and why backups getting detected and blocked mid-attack proves immutable, disconnected backups aren't optional anymore.
Halfway through, Josh shares a live horror story: a business owner whose MSP disabled her VPN and locked her out of her own data over a single unpaid invoice, mid-legal-dispute, giving her days to pick a $44,000 "fix it or lose it" quote. It's a gut check on why the IT industry desperately needs accountability, and how business owners can protect themselves before it happens to them.
What you'll learn:
- Why the first fully autonomous AI ransomware attack (Jade Puffer, discovered by Sysdig) still relied on a preventable, year-old unpatched vulnerability
- How attacker response windows have shrunk from hours to under 15 minutes, and what that means for your incident response plan
- Why publishing CVEs actually helps defenders more than attackers, and how to use AI to audit whether your IT vendor is doing what you're paying for
- What it looks like when an MSP holds your data hostage over a billing dispute, and why the IT industry needs real regulation
- Why immutable, network-disconnected backups are now table stakes against AI-driven attacks that can detect and disable normal backups
