INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Langflow RCE Attack Targets AI Model Files

| 2026-07-21 07:34 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The Langflow ransomware campaign has escalated to a new level of sophistication, with the deployment of an updated version of ENCFORGE, a previously unknown and highly targeted ransomware designed to encrypt AI model files. The attackers have also demonstrated their ability to exploit vulnerabilities in popular software, including Docker and Nacos, making them more difficult to detect and mitigate. As a result, organizations must take immediate action to upgrade Langflow to the latest supported version and ensure that all containers are properly secured against future attacks.
Technical Mitigations AI-generated
* Use secure coding practices, such as input validation and error handling, to prevent exploitation of vulnerabilities like CVE-2025-3248. * Implement a least privilege access model for AI agents and models, limiting their access to sensitive data and infrastructure. * Regularly update and patch dependencies, including libraries and frameworks used by AI models, to ensure that known vulnerabilities are addressed. * Monitor and detect suspicious activity related to AI assets, such as encryption or deletion of files, to identify potential threats early on.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

de•••••.py
ll•••••.cpp
do•••••.sock
e7•••@pr•••.•••
8cb0c2••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ea7822••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BlackCatBlackCat CVE-2025-3248CVE-2025-3248 CVE-2026-33017CVE-2026-33017 CVE-2026-55255CVE-2026-55255
Target & Sectors
Global Scope
Incident Timeline
‎May 5, 2025
Threat actors used a known exploited vulnerability in the JadePuffer AI Model to target systems.
vulnerability CVE-2025-3248
vulnerability CVSS score of 9.8
attribution CVE-2025
attribution CVSS
tactic T1588.006 - Vulnerabilities
‎May 2025
Threat actors used CVE-2025-3248 to target a Container Escape Built in Real Time using the JadePuffer AI Model Ransomware Attacks.
attribution CVE-2025-3248
tactic T1588.006 - Vulnerabilities
attribution Container Escape Built in Real Time Entry
attribution CISA
attribution Known Exploited
‎March 25, 2026
Threat actors used stolen data from a prominent AI model to launch JadePuffer ransomware attacks on multiple organizations.
‎July 7, 2026
Threat actors used a previously unknown Langflow vulnerability in the JadePuffer AI Model Ransomware Attack.
infrastructure 1.3.0
vulnerability CVE-2025-3248
attribution CVE-2025
infrastructure 1.9.1
vulnerability CVE-2026-33017
vulnerability CVE-2026-55255
infrastructure 1.9.0
attribution KEV
attribution RCE
attribution KEV March 25, 2026
general_metric 25 KEV March
general_metric 2026 KEV March
‎2026/07/20
Ransomware attackers used CVE-2025-3248 to target the previously breached Langflow instance.
tactic Ransomware
organisation CVE-2025-3248
organisation Sysdig
organisation ML
‎July 20
JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary targeting roughly 180 file extensions.
tactic Ransomware
organisation UPX
data_breach 180 file extensions
organisation the Sysdig Threat Research Team
organisation TRT
‎2026/07/21
JadePuffer, an agentic threat actor capable of running autonomously through the stages of a ransomware attack from initial access to data encryption.
organisation UPX
organisation PyTorch
organisation TensorFlow
organisation Hugging Face SafeTensors
organisation GGUF
organisation GGML
organisation LoRA
organisation EncForce
data_breach 180 file extensions
organisation LLM
organisation Tor
organisation JADEPUFFER
infrastructure 1.3.0
organisation Docket
organisation The Hacker News
organisation Langflow RCE
organisation Docker
organisation ENCFORGE
infrastructure 1.9.1
organisation The ENCFORGE Payload Researchers
organisation NumPy
organisation HuggingFace SafeTensors
organisation TFRecord
organisation AES-256-CTR
organisation LockBit
organisation GCP
organisation PID
organisation GPU
financial $75,000 model
organisation YARA
organisation Rotate
organisation Keep
organisation Threat Research Team
organisation Sysdig
organisation AI/ML
infrastructure Linux
infrastructure Windows
infrastructure Macos
organisation API
organisation EDR
Tactical Metrics
Metrics
infrastructure
‎1.3.0
Software Version
Metrics
infrastructure
‎1.9.1
Software Version
Metrics
infrastructure
‎1.9.0
Software Version
Metrics
financial
75,000
Model
Metrics
data_breach
180
File Extensions
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Intelligence Sources
Infosecurity-Magazine 2026-07-20