JadePuffer returns with ransomware built to target AI models and infrastructure
ID: 94aadbc2-82ba-5eaf-9211-6f322a6cc303
STIX ID: report--94aadbc2-82ba-5eaf-9211-6f322a6cc303
Feed Name: Help Net Security
JadePuffer, an operator using an LLM-powered AI agent, exploited a Langflow vulnerability (CVE-2025-3248) to pivot into production infrastructure and deploy ENCFORGE — a Go-based ransomware designed to target AI/ML artifacts (model checkpoints, vector DBs, training datasets, embedding indices). Researchers observed credential extraction, replay for lateral access, rapid adaptation by the agent, and a focus on assets that are costly or impossible to fully restore; defenders are advised to patch internet-exposed AI orchestration tools, harden container environments, and protect model artifacts and API keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
