Skip to content
Agentic AI Security Hub
Back to feed
Severity: CriticalIncidentData exfiltration

New ransomware variant targets AI model artifacts in Langflow infrastructure compromise

Global

Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.

Researchers identified a second attack on Langflow infrastructure linked to JADEPUFFER, an AI-agent-driven threat actor. The attacker deployed ENCFORGE, a newly discovered Go-based ransomware specifically designed to encrypt AI model weights, vector indexes, training datasets, and other AI-related files across affected systems.

What to do

Isolate Langflow instances and AI model repositories from the internet, and validate file integrity of all model weights and training datasets against clean backups.

#ransomware#AI infrastructure#Langflow#model compromise#JADEPUFFER#ENCFORGE