Back to all lessons
Awareness Lessons
3 months ago

ENCFORGE Ransomware Exploits Unpatched Langflow RCE to Encrypt AI Assets

The JADEPUFFER threat actor is actively exploiting CVE-2025-3248, a critical remote code execution vulnerability in older versions of Langflow, to deploy the ENCFORGE ransomware against AI infrastructure. This attack is particularly damaging because it specifically targets high-value AI assets — model weights and training datasets — which are often irreplaceable and represent enormous investment in compute and data. The root cause is straightforward: organizations running unpatched, internet-facing Langflow instances gave attackers a trivial entry point requiring no credentials. This incident highlights that AI development platforms carry the same exposure risks as any other internet-facing service and must be included in standard patch and vulnerability management programs.

Tactical Insight

Immediate actions

  • Patch all Langflow instances to the latest version to remediate CVE-2025-3248 immediately.
  • Restrict public internet access to Langflow endpoints by placing them behind a VPN or zero-trust access gateway.
  • Audit and disable any unnecessary or unauthenticated API endpoints exposed by AI development platforms.

Long-term improvements

  • Integrate AI development tools (Langflow, MLflow, etc.) into your formal vulnerability management and asset inventory program.
  • Implement immutable, air-gapped backups of AI model weights and training datasets to enable recovery without paying ransom.
  • Apply network segmentation to isolate AI infrastructure from production systems and other sensitive environments.

Detection measures

  • Deploy file integrity monitoring on directories containing AI model files to alert on unexpected mass encryption or renaming activity (e.g., `.locked` extension).
  • Monitor Langflow and AI platform logs for anomalous API calls, unusual process spawning, or outbound connections indicative of ransomware staging.
  • Establish behavioral detection rules in your EDR/SIEM for Go-based binaries executing bulk file encryption patterns.