New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

July 21, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations utilizing Langflow AI orchestration
Incident: Deployment of ENCFORGE ransomware via an unauthenticated RCE vulnerability in Langflow.
Impact: Encryption and loss of critical AI model weights, vector databases, and training datasets.
Attacker: JADEPUFFER
Analysis: The threat actor JADEPUFFER is exploiting a critical RCE vulnerability in Langflow (CVE-2025-3248) to deploy a new Go-based ransomware called ENCFORGE. This malware specifically targets AI-centric artifacts, including PyTorch checkpoints and GGUF models, using a targeted list of approximately 180 extensions. The payload uses AES-256-CTR and RSA-2048 encryption to paralyze AI training pipelines and inference capabilities.
Recommendations: Update Langflow to version 1.3.0 or later immediately to patch CVE-2025-3248; Maintain offline or immutable snapshots of model weights and vector indexes; Monitor for mass .locked file creation in directories containing AI model artifacts
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *