CuraSec

Act archived

ENCFORGE Ransomware Targets AI Infrastructure via Langflow RCE

2026-07-21 12:43 UTC · The Hacker News · read the source ↗ #ransomware#langflow#ai-security
  • Engineer — Act: Active exploitation of a Langflow RCE is being used to deploy Go-based ransomware that encrypts model weights, vector indexes, and training data. If you run Langflow, patch or network-isolate it immediately and review Sysdig’s full JADEPUFFER report for host-level IOCs to audit your AI infrastructure.
  • SOC/IR — Act: A named operator (JADEPUFFER) has been caught in a second confirmed intrusion deploying ENCFORGE ransomware via Langflow; pull Sysdig’s IOC set and hunt for anomalous Go process execution or bulk file encryption activity on hosts running Langflow or adjacent AI pipeline components.
  • Leader — Learn: ENCFORGE is the first documented ransomware purpose-built to destroy AI model assets rather than generic data, signaling that AI infrastructure is becoming a distinct extortion target worth adding to the risk register ahead of broader AI investment discussions.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.