Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ENCFORGE Ransomware Hits AI Files in Langflow Attack

ENCFORGE Ransomware Hits AI Files in Langflow Attack

Posted on July 21, 2026 By CWS

In a recent cybersecurity incident, researchers from Sysdig have identified a second attack on Langflow servers associated with the JADEPUFFER operator. This new attack involves the deployment of ENCFORGE, a newly developed ransomware written in Go, which specifically targets files related to artificial intelligence, such as model weights and training datasets.

Vulnerability Exploitation in Langflow

The vulnerability exploited in these attacks is found in Langflow versions prior to 1.3.0. This flaw, identified as CVE-2025-3248, allows unauthenticated remote code execution via the /api/v1/validate/code endpoint. The Common Vulnerability Scoring System (CVSS) rates this flaw at 9.8, indicating its severity, and it has been listed in CISA’s Known Exploited Vulnerabilities since May 2025.

ENCFORGE replaces rudimentary scripts with advanced compiled tools that focus on AI environments. Unlike previous attacks that used simple Python scripts, this campaign employs sophisticated methods to encrypt AI model files and related data.

Technical Aspects of ENCFORGE

Sysdig’s analysis reveals that the ENCFORGE ransomware is stored on a command-and-control server, disguised to evade detection. The binary, packed with UPX, is designed to encrypt specific file types prevalent in AI workflows, such as PyTorch checkpoints, TensorFlow records, and vector indexes.

ENCFORGE employs AES-256-CTR encryption, with a symmetric key wrapped under an RSA-2048 public key. This approach encrypts only parts of files to optimize speed, akin to strategies used by LockBit and BlackCat ransomware families. The absence of data exfiltration capabilities suggests that the primary leverage is the encrypted data itself.

Mitigation and Protection Strategies

Sysdig advises organizations to upgrade Langflow to the latest version and rotate credentials to prevent similar attacks. Reducing Docker socket exposure and monitoring application processes for suspicious activity are also recommended.

The financial implications of an attack can be severe, with rebuilding an encrypted AI model potentially costing between $75,000 and $500,000. Thus, safeguarding AI models and data through offline snapshots and regular monitoring is crucial.

Sysdig’s report underscores the need for robust security measures to protect AI infrastructure from such targeted ransomware attacks. The focus on AI-specific files indicates a deliberate strategy by attackers to maximize disruption and potential ransom payments.

The Hacker News Tags:AI model files, AI security, CVE-2025-3248, Cybersecurity, ENCFORGE, JADEPUFFER, Langflow, Ransomware, Sysdig, threat intelligence

Post navigation

Previous Post: Integrating CBOM Solutions in Modern Architecture
Next Post: Addressing Identity Fragmentation in Cybersecurity

Related Posts

Anthropic Launches Claude AI for Healthcare with Secure Health Record Access Anthropic Launches Claude AI for Healthcare with Secure Health Record Access The Hacker News
CISA Highlights New Vulnerabilities, Sets Federal Deadlines CISA Highlights New Vulnerabilities, Sets Federal Deadlines The Hacker News
WP Maps Pro Vulnerability Exploited to Create Admin Accounts WP Maps Pro Vulnerability Exploited to Create Admin Accounts The Hacker News
CERT-UA Discovers LAMEHUG Malware Linked to APT28, Using LLM for Phishing Campaign CERT-UA Discovers LAMEHUG Malware Linked to APT28, Using LLM for Phishing Campaign The Hacker News
Old Microsoft UEFI Shims Pose Secure Boot Risk Old Microsoft UEFI Shims Pose Secure Boot Risk The Hacker News
Cisco Fixes Critical Flaws in Identity and Webex Services Cisco Fixes Critical Flaws in Identity and Webex Services The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark