importantSYS.SOURCE: The Hacker News• 2026-07-21T13:04:32+05:30
ENCFORGE Ransomware Exploits Langflow RCE Vulnerability to Encrypt AI Model Files
A new ransomware called ENCFORGE is exploiting a remote code execution (RCE) vulnerability in Langflow to encrypt AI model files, including model weights and training datasets. The attack leverages CVE-2025-3248, with the ransomware using AES-256-CTR encryption and targeting specific AI infrastructure components.
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.
The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.
The entry
*** END OF TRANSMISSION ***