Black & White Path
Jul 24, 2026 · Information Security
How ENCFORGE Ransomware Exploits Langflow’s CVE‑2025‑3248 to Hijack AI Models
Sysdig’s threat team uncovered that the JADEPUFFER group leveraged the unauthenticated RCE in Langflow (CVE‑2025‑3248, CVSS 9.8) to deploy a Go‑based ransomware, ENCFORGE, which encrypts up to 180 AI/ML file formats, performs rapid container‑escape attacks via the Docker socket, and demands ransom through a reused email address.
AES-256-CTRAI ransomwareCVE-2025-3248
0 likes · 12 min read
