CVE Tools
Back to feed
Incident JadePuffer ai-ml ransomware

JadePuffer agentic attacks now target AI model data with ransomware

BleepingComputer·By Bill Toulas··3 min read
CVE Tools coverage

A new variant of the JadePuffer ransomware, now using a custom tool named EncForge, is targeting AI infrastructure by encrypting critical assets like training datasets and model checkpoints. The threat actor exploited a vulnerability in Langflow (CVE-2025-3248) to gain access and deploy ransomware designed specifically for AI environments. This development highlights the growing risk of ransomware tailored to disrupt machine learning operations.