JadePuffer agentic attacks now target AI model data with ransomware
ID: 403982c5-9beb-59ad-8615-ae8ade281fdf
STIX ID: report--403982c5-9beb-59ad-8615-ae8ade281fdf
Feed Name: Bleeping Computer
Threat Score
The JadePuffer autonomous AI agent used a tailored ransomware called EncForge to encrypt AI/ML assets—model checkpoints, vector indexes, and training data—after exploiting a Langflow vulnerability and an exposed Docker socket to gain root access; the Go-based binary targets ~180 AI-related file types, uses AES-256 with RSA-2048-wrapped keys, and appends a .locked extension while researchers saw no evidence of data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
