CVE Tools

JadePuffer returns with ransomware built to target AI models and infrastructure

Help Net SecurityBy Zeljka Zorz

Reported exploitedLangflowJadePufferAI infrastructure

Our summary

Threat actor JadePuffer has returned with ENCFORGE, a new ransomware specifically designed to attack AI and machine learning infrastructure. This follows an earlier campaign where the group used an AI agent to exploit a known vulnerability (CVE-2025-3248) in Langflow, leading to database encryption and destruction. Researchers have confirmed that the same operator is now deploying ENCFORGE, which targets over 180 file types related to AI models, datasets, and configurations. The ransomware was successfully deployed after initial attempts failed, highlighting the evolving tactics of this threat actor. Experts warn that encrypting production AI models can lead to costly recovery efforts, urging organizations to patch exposed systems and harden their environments.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store