Tagged articles

AI ransomware

3 articles · Page 1 of 1
Black & White Path
Black & White Path
Jul 24, 2026 · Information Security

How ENCFORGE Ransomware Exploits Langflow’s CVE‑2025‑3248 to Hijack AI Models

Sysdig’s threat team uncovered that the JADEPUFFER group leveraged the unauthenticated RCE in Langflow (CVE‑2025‑3248, CVSS 9.8) to deploy a Go‑based ransomware, ENCFORGE, which encrypts up to 180 AI/ML file formats, performs rapid container‑escape attacks via the Docker socket, and demands ransom through a reused email address.

AES-256-CTRAI ransomwareCVE-2025-3248
0 likes · 12 min read
How ENCFORGE Ransomware Exploits Langflow’s CVE‑2025‑3248 to Hijack AI Models
Black & White Path
Black & White Path
Jul 10, 2026 · Information Security

JadePuffer: Inside the World’s First Fully Agentic AI Ransomware

JadePuffer, the first ransomware fully driven by a large language model, exploited a CVE‑2025‑3248 flaw in exposed Langflow instances to gain initial access, autonomously performed reconnaissance, credential theft, lateral movement, persistence, and encrypted MySQL/Nacos data, demonstrating rapid self‑healing and highlighting new defensive challenges.

AI ransomwareCloud securityDatabase Security
0 likes · 18 min read
JadePuffer: Inside the World’s First Fully Agentic AI Ransomware