[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYMFwBp-OrRdTdWgb_KRoESnPn7VJzGvTXsU3IgqxwO8":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"be143fd1-efb3-4bb0-ac34-65c1e582f505","JadePuffer agentic attacks now target AI model data with ransomware","jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware-f57be7","The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]","The JadePuffer threat actor has upgraded its autonomous AI agent with new ransomware called EncForge, specifically designed to target AI and ML infrastructure. This malware encrypts AI assets like training datasets, vector databases, and model checkpoints, potentially causing significant financial damage and weeks of downtime for affected organizations.","JadePuffer ransomware targets AI model data with new EncForge malware.","JadePuffer agentic attacks now target AI model data with ransomware By Bill Toulas July 20, 2026 05:08 PM 0 The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. JadePuffer was disclosed earlier this month as an agentic threat actor (ATA) capable of running autonomously through the stages of a ransomware attack, from initial access to data encryption. Cloud security company Sysdig says that the AI agent adapted to technical difficulties in real time and optimized the intrusion mechanism to find the correct fix in less than a minute. Latest attack In a report today, Sysdig says that the attacker returned to the previously breached Langflow instance vulnerable to CVE-2025-3248 with the Go-based EncForge ransomware \"built specifically for AI and machine learning (ML) infrastructure.\" \"The binary targets approximately 180 file extensions, with a deliberately broad sweep of the modern AI\u002FML stack, including model checkpoints, vector databases, training datasets, and embedding indices in nearly every current format,\" Sysdig says. After gaining access and searching for cloud credentials, API tokens, and reachable internal services, the threat actor discovered an exposed Docker socket that provided root-level control. When the initial attempt to download the ransomware payload failed, the operator iteratively developed and deployed six Python scripts over just five minutes, with the final one (deploy.py v2) solving the delivery issues. “deploy.py v2 is the completed payload: a fully autonomous pipeline that discovers the target PID, copies ENCFORGE across the namespace boundary via procfs, runs a try-mode scan, launches the live encryption pass, and then counts .locked files to verify execution,” Sysdig explained. EncForce ransomware The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including: AI model checkpoints Hugging Face SafeTensors files PyTorch and TensorFlow models GGUF and GGML weights FAISS vector indexes Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor. EncForce uses the AES-256 algorithm in counter mode to encrypt files in a hybrid scheme, where the symmetric key is secured with an RSA-2048 public key. To improve performance, the malware encrypts only selected portions of each file rather than the entire contents. Encrypted files are appended with the .locked extension, and a ransom note is dropped to notify the victim of the attack, stating that a unique identifier has been assigned. The EncForce ransom noteSource: Sysdig The researchers found no evidence that JadePuffer exfiltrated any data during the intrusion, and EncForge itself does not appear to include a data-stealing mechanism. Analysis of the Linux variant revealed the presence of Windows anti-recovery functions such as shadow copy deletion and boot recovery disabling. A macOS version, although hinted in the code, remains unconfirmed. Sysdig comments that encryption of model weights, training datasets, and vector indexes could cost organizations weeks or even months of training and fine-tuning, with financial damages estimated between $75,000 and $500,000 per model, depending on its size and purpose. Defense suggestions include applying available security updates, most notably Langflow version 1.3.0 or later, restricting Docket socket access, running Langflow containers as non-root, and applying filesystem-level access controls to model weight directories. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: JadePuffer ransomware used AI agent to automate entire attackAI-built ransomware toolkit automates EDR evasion, AD discoveryHugging Face warns an autonomous AI agent hacked its networkOpenAI temporarily relaxes GPT-5.6 Sol usage limitsClaude Fable 5 stays free for paid users until July 19 as Anthropic buys more time","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fjadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F07\u002F20\u002Fpuffer.jpg","2026-07-20T21:08:02+00:00","2026-07-20T22:00:09.459557+00:00",8,[18,21,24,27],{"name":19,"type":20},"JadePuffer","threat_actor",{"name":22,"type":23},"Langflow","product",{"name":25,"type":26},"AI","technology",{"name":28,"type":26},"Machine Learning","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":29,"icon":31,"name":32,"slug":33},null,"Malware","malware",[35,40,45,47],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"7d8b5ab8-ea0b-4ced-ae97-ec251b86993a","Ransomware","ransomware",{"category":41},{"id":42,"icon":31,"name":43,"slug":44},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":46},{"id":29,"icon":31,"name":32,"slug":33},{"category":48},{"id":49,"icon":31,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53],{"type":54,"value":55,"context":56},"cve","CVE-2025-3248","Vulnerability exploited by JadePuffer in Langflow instance."]