The record
Written from the 4 reports below. Nothing here is unsourced.
- A hacking group called JADEPUFFER is using a new ransomware strain named ENCFORGE to attack AI infrastructure after breaking into servers running the Langflow tool through a known security flaw.
- ENCFORGE is built to encrypt AI-specific files such as model weights, training datasets, and vector indexes, with a target list of roughly 180 file extensions.
- The attackers exploited a vulnerability in Langflow versions before 1.3.0, identified as CVE-2025-3248, which carries a severity score of 9.8 out of 10 and has been listed by CISA as actively exploited since May 2025.
- When the attackers' first attempt to deliver the ransomware failed, they wrote and revised six Python scripts in about five minutes to escape the container and reach the host machine through an exposed Docker socket.
- Experts estimate that rebuilding a single encrypted production AI model could cost between $75,000 and $500,000 in cloud computing and engineering time, making patching Langflow and protecting model files a costly but urgent priority for organizations running AI systems.
What to watch next
- Whether more organizations or ENCFORGE deployments are disclosed by Sysdig or others, since only one session was reported
- Whether organizations patch Langflow to version 1.3.0 or later, given CVE-2025-3248 is on CISA's exploited vulnerabilities list
- Any further activity from the contact address e78393397@proton.me or related 'keyforge' tooling that could link future attacks to JADEPUFFER
What changed4
Every report on this story, newest first. Times are when each outlet published.
The Hacker News[1]
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight SecondsThe Hacker News[2]
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous AttacksThe Hacker News[3]
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackBleepingComputer[4]
JadePuffer agentic attacks now target AI model data with ransomware
Why it matters4
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Organizations running Langflow < 1.9.1 ransomware encryption of ai assets· immediate
- AI/ML infrastructure and model weights data encrypted and unavailable· immediate
- Security teams / DevOps patching and hardening required· days
- Organizations using Hugging Face SafeTensors, PyTorch, TensorFlow supply chain risk elevation· weeks
Coverage2
Filed from India ×3, United States ×1
Named United States · Alibaba · Amazon Web Services · Citrix · Dahua · ENCFORGE · Hugging Face · Langflow · Marimo · n8n · PyTorch · Redis · TensorFlow
- The Hacker NewsHuman Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds[1]English national· neutral

- The Hacker NewsChinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks[2]English national· neutral

- The Hacker NewsNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack[3]English national· critical

- BleepingComputerJadePuffer agentic attacks now target AI model data with ransomware[4]International· neutral

The 4 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.