Security · 6h ago
New ENCFORGE Ransomware Targets AI Model Files in Langflow Attack
Researchers at Sysdig linked a second attack on a Langflow server to JADEPUFFER, an AI-agent-driven operator. The operator deployed ENCFORGE, a Go ransomware that encrypts model weights, vector indexes, and training datasets. The attack highlights growing threats to AI infrastructure files.
Meridian48 take
The targeting of AI model files underscores a shift in ransomware tactics, but the attack's reliance on a previously compromised server suggests limited novelty beyond the file type focus.
Read the full reporting
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack →
The Hacker News
ransomwareai-security