CVE Tools

JadePuffer agentic attacks now target AI model data with ransomware

BleepingComputerBy Bill Toulas

IncidentJadePuffer

Our summary

A new variant of the JadePuffer ransomware, now using a custom tool named EncForge, is targeting AI infrastructure by encrypting critical assets like training datasets and model checkpoints. The threat actor exploited a vulnerability in Langflow (CVE-2025-3248) to gain access and deploy ransomware designed specifically for AI environments. This development highlights the growing risk of ransomware tailored to disrupt machine learning operations.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store