Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations utilizing Langflow AI orchestration
Incident: Deployment of ENCFORGE ransomware via an unauthenticated RCE vulnerability in Langflow.
Impact: Encryption and loss of critical AI model weights, vector databases, and training datasets.
Attacker: JADEPUFFER
Analysis: The threat actor JADEPUFFER is exploiting a critical RCE vulnerability in Langflow (CVE-2025-3248) to deploy a new Go-based ransomware called ENCFORGE. This malware specifically targets AI-centric artifacts, including PyTorch checkpoints and GGUF models, using a targeted list of approximately 180 extensions. The payload uses AES-256-CTR and RSA-2048 encryption to paralyze AI training pipelines and inference capabilities.
Recommendations: Update Langflow to version 1.3.0 or later immediately to patch CVE-2025-3248; Maintain offline or immutable snapshots of model weights and vector indexes; Monitor for mass .locked file creation in directories containing AI model artifacts
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source