Agentic Hacker Exploits Langflow RCE to Encrypt AI and Machine-Learning Infrastructure
ID: ada6cd95-8c88-5d33-bb2d-1ec33704ea8a
STIX ID: report--ada6cd95-8c88-5d33-bb2d-1ec33704ea8a
Feed Name: Cyber Press
**Executive summary:** JADEPUFFER has escalated from database extortion to a targeted ransomware campaign against AI/ML infrastructure by exploiting Langflow RCE (CVE-2025-3248) to deploy a UPX-packed Go ransomware (ENCFORGE/lockd) that encrypts model checkpoints, vector DBs, datasets and other AI artifacts, harvests cloud credentials, abuses exposed Docker sockets for host access, and uses known extortion contact and project strings enabling detection; immediate patching to Langflow 1.3.0+ or blocking the validation endpoint and restricting network access is recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
