Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ENCFORGE Ransomware Hits AI Files in Langflow Attack

ENCFORGE Ransomware Hits AI Files in Langflow Attack

Posted on July 21, 2026 By CWS

In a recent cybersecurity incident, researchers from Sysdig have identified a second attack on Langflow servers associated with the JADEPUFFER operator. This new attack involves the deployment of ENCFORGE, a newly developed ransomware written in Go, which specifically targets files related to artificial intelligence, such as model weights and training datasets.

Vulnerability Exploitation in Langflow

The vulnerability exploited in these attacks is found in Langflow versions prior to 1.3.0. This flaw, identified as CVE-2025-3248, allows unauthenticated remote code execution via the /api/v1/validate/code endpoint. The Common Vulnerability Scoring System (CVSS) rates this flaw at 9.8, indicating its severity, and it has been listed in CISA’s Known Exploited Vulnerabilities since May 2025.

ENCFORGE replaces rudimentary scripts with advanced compiled tools that focus on AI environments. Unlike previous attacks that used simple Python scripts, this campaign employs sophisticated methods to encrypt AI model files and related data.

Technical Aspects of ENCFORGE

Sysdig’s analysis reveals that the ENCFORGE ransomware is stored on a command-and-control server, disguised to evade detection. The binary, packed with UPX, is designed to encrypt specific file types prevalent in AI workflows, such as PyTorch checkpoints, TensorFlow records, and vector indexes.

ENCFORGE employs AES-256-CTR encryption, with a symmetric key wrapped under an RSA-2048 public key. This approach encrypts only parts of files to optimize speed, akin to strategies used by LockBit and BlackCat ransomware families. The absence of data exfiltration capabilities suggests that the primary leverage is the encrypted data itself.

Mitigation and Protection Strategies

Sysdig advises organizations to upgrade Langflow to the latest version and rotate credentials to prevent similar attacks. Reducing Docker socket exposure and monitoring application processes for suspicious activity are also recommended.

The financial implications of an attack can be severe, with rebuilding an encrypted AI model potentially costing between $75,000 and $500,000. Thus, safeguarding AI models and data through offline snapshots and regular monitoring is crucial.

Sysdig’s report underscores the need for robust security measures to protect AI infrastructure from such targeted ransomware attacks. The focus on AI-specific files indicates a deliberate strategy by attackers to maximize disruption and potential ransom payments.

The Hacker News Tags:AI model files, AI security, CVE-2025-3248, Cybersecurity, ENCFORGE, JADEPUFFER, Langflow, Ransomware, Sysdig, threat intelligence

Post navigation

Previous Post: Integrating CBOM Solutions in Modern Architecture
Next Post: Addressing Identity Fragmentation in Cybersecurity

Related Posts

ShadowSilk Hits 36 Government Targets in Central Asia and APAC Using Telegram Bots ShadowSilk Hits 36 Government Targets in Central Asia and APAC Using Telegram Bots The Hacker News
SolarWinds Fixes Major Flaws in Serv-U Software SolarWinds Fixes Major Flaws in Serv-U Software The Hacker News
Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks The Hacker News
Python-Based WhatsApp Worm Spreads Eternidade Stealer Across Brazilian Devices Python-Based WhatsApp Worm Spreads Eternidade Stealer Across Brazilian Devices The Hacker News
Key Insights from Gartner’s Guardian Agents Guide Key Insights from Gartner’s Guardian Agents Guide The Hacker News
Critical PHP Composer Vulnerabilities Patched Critical PHP Composer Vulnerabilities Patched The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion
  • Android AI Agents Vulnerable to Covert Code Execution
  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion
  • Android AI Agents Vulnerable to Covert Code Execution
  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark