logo

JadePuffer returns with ransomware built to target AI models and infrastructure

ID: 94aadbc2-82ba-5eaf-9211-6f322a6cc303

STIX ID: report--94aadbc2-82ba-5eaf-9211-6f322a6cc303

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Zeljka Zorz

...
...

JadePuffer, an operator using an LLM-powered AI agent, exploited a Langflow vulnerability (CVE-2025-3248) to pivot into production infrastructure and deploy ENCFORGE — a Go-based ransomware designed to target AI/ML artifacts (model checkpoints, vector DBs, training datasets, embedding indices). Researchers observed credential extraction, replay for lateral access, rapid adaptation by the agent, and a focus on assets that are costly or impossible to fully restore; defenders are advised to patch internet-exposed AI orchestration tools, harden container environments, and protect model artifacts and API keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.