CyberSecurity News
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
AI summary
Researchers at Sysdig have identified a new ransomware called ENCFORGE, which is used by the JADEPUFFER operator to target AI model files. ENCFORGE is a compiled Go ransomware that encrypts various AI infrastructure files, including model weights, vector indexes, and training datasets, across the host filesystem. This discovery is linked to a second attack on a Langflow server, where JADEPUFFER was previously documented. The ENCFORGE ransomware is specifically designed to target these sensitive AI files. The attack is associated with a remote code execution exploit on the Langflow server.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

