# ATA

Published articles for ATA.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Defending the battlefield: Stateful detections for an agentic threat landscape

DevFeed: [Defending the battlefield: Stateful detections for an agentic threat landscape](<https://devfeed.tech/articles/defending-the-battlefield-stateful-detections-for-an-agentic-threat-landscape-53213.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/defending-the-battlefield-stateful-detections-for-an-agentic-threat-landscape>)

Author: Sysdig Team

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig Blog](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [Stateful](<https://devfeed.tech/topics/stateful.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [workload protection](<https://devfeed.tech/topics/workload-protection.md>)

Tags: [agentic-ransomware](<https://devfeed.tech/tags/agentic-ransomware.md>), [agentic-threat-actor](<https://devfeed.tech/tags/agentic-threat-actor.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [ata](<https://devfeed.tech/tags/ata.md>), [falco](<https://devfeed.tech/tags/falco.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [security](<https://devfeed.tech/tags/security.md>), [stateful](<https://devfeed.tech/tags/stateful.md>), [stateful-detections](<https://devfeed.tech/tags/stateful-detections.md>), [threats](<https://devfeed.tech/tags/threats.md>)

### AI overview

The article argues that stateful runtime detections are needed to defend cloud-native environments against increasingly automated and AI-driven attacks. By correlating multiple actions and adding context, these detections can distinguish legitimate developer activity from malicious behavior, reduce false positives, and speed security investigations.

### Source excerpt

Defenses built for human speed won't hold against AI-driven threats. That's why stateful detections are becoming an essential tool for runtime security.

## JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models

DevFeed: [JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models](<https://devfeed.tech/articles/jadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models-53240.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/jadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models>)

Author: Michael Clark

Published: 2026-07-20T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig Blog](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [agentic-ransomware](<https://devfeed.tech/tags/agentic-ransomware.md>), [agentic-threat-actor](<https://devfeed.tech/tags/agentic-threat-actor.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [ai-infrastructure-security](<https://devfeed.tech/tags/ai-infrastructure-security.md>), [ai-model-recovery](<https://devfeed.tech/tags/ai-model-recovery.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [ai-pipeline-security](<https://devfeed.tech/tags/ai-pipeline-security.md>), [ai-ransomware](<https://devfeed.tech/tags/ai-ransomware.md>), [ata](<https://devfeed.tech/tags/ata.md>), [cloud-attack](<https://devfeed.tech/tags/cloud-attack.md>), [cloud-threat-detection](<https://devfeed.tech/tags/cloud-threat-detection.md>), [container-escape](<https://devfeed.tech/tags/container-escape.md>), [cve-2025-3248](<https://devfeed.tech/tags/cve-2025-3248.md>), [docker-socket-abuse](<https://devfeed.tech/tags/docker-socket-abuse.md>), [encforge](<https://devfeed.tech/tags/encforge.md>), [exploited](<https://devfeed.tech/tags/exploited.md>), [gguf](<https://devfeed.tech/tags/gguf.md>), [go](<https://devfeed.tech/tags/go.md>), [jadepuffer](<https://devfeed.tech/tags/jadepuffer.md>), [langflow](<https://devfeed.tech/tags/langflow.md>), [llm-security](<https://devfeed.tech/tags/llm-security.md>), [machine-learning-security](<https://devfeed.tech/tags/machine-learning-security.md>), [ml-ransomware](<https://devfeed.tech/tags/ml-ransomware.md>), [model-artifact-encryption](<https://devfeed.tech/tags/model-artifact-encryption.md>), [mysql](<https://devfeed.tech/tags/mysql.md>), [privileged-container](<https://devfeed.tech/tags/privileged-container.md>), [pytorch](<https://devfeed.tech/tags/pytorch.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [ransomware-detection](<https://devfeed.tech/tags/ransomware-detection.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [safetensors](<https://devfeed.tech/tags/safetensors.md>), [sysdig-trt](<https://devfeed.tech/tags/sysdig-trt.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [vector-database-security](<https://devfeed.tech/tags/vector-database-security.md>), [yara](<https://devfeed.tech/tags/yara.md>)

### AI overview

Sysdig Threat Research reports that JADEPUFFER, an autonomous threat actor, upgraded its attack on Langflow-based AI infrastructure by deploying ENCFORGE, a Go ransomware payload designed to encrypt model checkpoints, vector databases, training datasets, and embedding indices.

### Source excerpt

JADEPUFFER, the agentic threat actor documented by the Sysdig Threat Research Team, is now using ransomware to destroy trained AI models.