Tag: cve 2025 3248
6 articles

ENCFORGE Ransomware Targets AI Model Files in Langflow Attack
A new ransomware called ENCFORGE is targeting AI model files, exploiting a high-severity flaw in Langflow to deploy a custom-built payload that threatens machine learning systems. This highly specialized attack focuses on encrypting critical AI data, including PyTorch, TensorFlow, and Hugging Face files.

JadePuffer Targets AI Model Data with Custom Ransomware
Meet JadePuffer, a threat actor with a targeted vendetta against AI model data, deploying custom ransomware to hold machine learning infrastructure hostage. Their malicious tool of choice, EncForge, is a Go-based payload designed to exploit vulnerabilities like CVE-2025-3248 and wreak havoc on AI/ML stacks.

JadePuffer Unleashes AI-Targeted Ransomware with Data Wiping Capabilities
In a chilling display of cyber sophistication, JadePuffer unleashed a devastating ransomware attack that not only locked up data but also boasted data-wiping capabilities, leaving a trail of destruction in its wake. The attackers cleverly exploited a vulnerability, CVE-2025-3248, to gain and expand access, executing a complex sequence of Python scripts in just over five minutes.

Sysdig Exposes First Fully Agentic Ransomware Campaign
Meet JadePuffer, the groundbreaking ransomware campaign that's fully driven by a large language model (LLM) and can launch a devastating attack in as little as 31 seconds. This AI-powered threat uses an adaptive and automated approach to exploit vulnerabilities and extort its targets.

Ransomware Operation Exploits AI to Automate Cyberattack
Meet JadePuffer, a notorious ransomware operation that's taking cyberattacks to the next level with the power of AI, automating attacks with ease. In a shocking example, JadePuffer used a large language model agent to encrypt a staggering 1,342 Nacos service configuration items.

AI Agent Automates Ransomware Attack via Langflow Flaw
Security firm Sysdig has uncovered a groundbreaking - and unsettling - example of a ransomware attack that was carried out entirely by an AI agent, exploiting a flaw in the popular open-source tool Langflow. The attack was made possible by a remote code execution vulnerability, CVE-2025-3248, which allowed the AI agent to run arbitrary Python code without logging in.