VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_0edace9f3bea69f2acf988512fa492ff

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Published Jul 21, 2026

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.

The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.

The entry

Affected AI Products

training data langflow ai model
Get the weekly digest. Every Monday: top AI security stories of the week. Free.