Back to Intel

Intel Node

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

criticalransomware2026-07-21T07:34:32+00:00source excerpt
ransomwarevulnerability

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.

Read Original Source