generative AI for data analysis

When AI Models Become the Target, Ransomware Takes a Darker Turn

When the same attacker breaks into the same server twice, the second visit should never bring a weapon built specifically for what you keep there.

4 min readVentureBeat
When AI Models Become the Target, Ransomware Takes a Darker Turn

**Our Take: The Threat Isn't the Model. It's the Assumption That It's Safe.**

Here is the part that should worry you: The attacker didn't break in differently the second time. They walked through the same open door, on the same server, and swapped a clumsy Python script for a compiled weapon aimed directly at your AI assets. Sysdig's team watched JADEPUFFER return in July with ENCFORGE, a locker built to destroy trained weights, not steal them. The entry point, a missing-authentication flaw in Langflow's code-validation endpoint, never changed. The payload did. That is not a story about a clever hack. That is a story about an adversary who learned what your organization actually values and then built a tool to erase it.

If you think your backup plan covers this, read the math. Restoring a database costs a weekend of transactions. Restoring a fine-tuned model costs everything learned since Friday, none of it stored as rows to replay. Sysdig puts direct recovery for a production-ready fine-tuned model between $75,000 and $500,000, per model, and teams keep several variants on shared storage. The ransomware encrypts regions of file types like `.gguf` and `.safetensors`, specifically targeting the artifacts that define your current AI capability. Michael Clark, who leads Sysdig's threat research, framed it as destroying "the one thing an organization can't simply restore." He is right. The takeaway is not that you need better antivirus. It is that your model weights are a business asset with a replacement cost, and if they are not in the recovery plan next to the databases, they are not protected.

What makes this campaign different is that it is not opportunistic. Generic ransomware picks up model files by accident because it encrypts everything. ENCFORGE names them. Its extension list includes PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors, FAISS vector indexes, and training data in Parquet and NumPy. An attacker who writes that knows whose machines these are. And because the binary carries no network code, no leak site, and no payment portal, the only pressure is making files unusable. In the first campaign, the encryption key was generated at random, printed to the console once, and never saved. That made the payload a wiper wearing a ransom note. Paying was never an option. The goal was destruction, not profit.

Here is what we would tell a reader who asks what to do this week. First, get every internet-reachable Langflow instance onto the current supported release. The vendor fixed this flaw in 1.3.0, and CISA added it to the Known Exploited Vulnerabilities catalog in May 2025. The attacker came back in July 2026, more than fourteen months later. As Ivanti's Mike Riemer put it, if a patch is not applied within 72 hours, it is open to exploit. Fourteen months is not a lapse; it is a decision. Second, get the Docker socket out of application containers. The agent found it at `/var/run/docker.sock`, used it to escape the container, and built a working host escape in five minutes and 24 seconds. Third, rotate every credential the host could reach. The first campaign harvested OpenAI, Anthropic, and cloud credentials within seconds. Patching does not revoke what already left.

The detail to watch is the next 30 days. CISA has now added five Langflow flaws to the KEV catalog, two of them this month, including CVE-2026-0770, an unauthenticated path to root code execution on the same validate endpoint. That is not a coincidence. That is a pattern. The attacker needed under three weeks to go from improvised Python to a compiled locker. Your response should not take fourteen months. The question is not whether they will come back. It is whether your model artifacts are protected well enough to survive the third visit.

From VentureBeat

The same attacker broke into the same internet-facing Langflow server twice, and the second time brought ransomware built to destroy trained AI models. Sysdig's Threat Research Team documented the first campaign on July 1 and the second on July 20. The entry point never changed, but the payload changed completely.

Read the original at VentureBeat