logo

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

ID: 672e5f96-8493-5d93-b856-983fe18ba4fe

STIX ID: report--672e5f96-8493-5d93-b856-983fe18ba4fe

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-21

Date Updated: 2026-07-22

...
...

Sysdig researchers observed JADEPUFFER, an AI-agent-driven threat operator, exploiting a Langflow RCE to deploy ENCFORGE — a compiled Go ransomware engineered to encrypt AI model weights, vector indexes, training datasets, and Langflow pipeline definitions — representing a targeted escalation that threatens AI-dependent organizations; the report details the attack chain, technical profile, affected targets, and mitigation steps including patching, isolation, and offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.