Command Palette
Search for a command to run...

ENCFORGE Ransomware Encrypts AI Model Weights via Langflow Flaw Rated 9.8

techcybersecurityaiai-governanceai-legal-safetyai-infrastructure 1 posts · 1 accounts

A new ransomware campaign dubbed ENCFORGE is targeting artificial intelligence infrastructure by encrypting model weights, vector indexes, and training data. The attacks deploy via a critical vulnerability in the Langflow framework, tracked as CVE-2025-3248 and rated 9.8 by the Common Vulnerability Scoring System.

Experts have linked the malware to the same group behind a previous agentic attack. The Langflow flaw was already listed on the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, confirming active use in the field.

From the sources (1 posts)

@thehackersnews

🛑 New ENCFORGE ransomware is built to encrypt AI model weights, vector indexes, and training data. Deployed via Langflow CVE-2025-3248 (CVSS 9.8, CISA KEV). Experts link it to the same operator from the earlier agentic attack. Learn how t

Preview built on a synthetic news corpus (16 weeks, Apr–Jul 2026). Impact calls are model reads, not price data.

About Archive