Severity: CriticalIncidentData exfiltration
New ransomware variant targets AI model artifacts in Langflow infrastructure compromise
Global
Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.
Researchers identified a second attack on Langflow infrastructure linked to JADEPUFFER, an AI-agent-driven threat actor. The attacker deployed ENCFORGE, a newly discovered Go-based ransomware specifically designed to encrypt AI model weights, vector indexes, training datasets, and other AI-related files across affected systems.
What to do
Isolate Langflow instances and AI model repositories from the internet, and validate file integrity of all model weights and training datasets against clean backups.
Mapped framework pillars
Sources
#ransomware#AI infrastructure#Langflow#model compromise#JADEPUFFER#ENCFORGE
