JadePuffer agentic attacks now target AI model data with ransomware

JadePuffer returned with EncForge, a Go-based ransomware built to encrypt AI and ML assets such as model checkpoints, vector databases, training datasets, and embedding indices. Sysdig found the autonomous AI agent adapted its delivery method in real time, used an exposed Docker socket for root control, and deployed encryption without evidence of data theft. #JadePuffer #EncForge #Langflow #CVE-2025-3248

Keypoints

  • JadePuffer used EncForge to target AI and machine learning infrastructure.
  • The ransomware was designed to encrypt model checkpoints, datasets, and vector databases.
  • The attacker exploited a vulnerable Langflow instance and an exposed Docker socket.
  • JadePuffer iteratively fixed its delivery scripts in under five minutes.
  • Sysdig recommends patching Langflow and restricting Docker socket and filesystem access.

Read More: https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/