logo

JadePuffer agentic attacks now target AI model data with ransomware

ID: 403982c5-9beb-59ad-8615-ae8ade281fdf

STIX ID: report--403982c5-9beb-59ad-8615-ae8ade281fdf

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Bill Toulas

...
...

The JadePuffer autonomous AI agent used a tailored ransomware called EncForge to encrypt AI/ML assets—model checkpoints, vector indexes, and training data—after exploiting a Langflow vulnerability and an exposed Docker socket to gain root access; the Go-based binary targets ~180 AI-related file types, uses AES-256 with RSA-2048-wrapped keys, and appends a .locked extension while researchers saw no evidence of data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.