AI ransomware makes recovery a first-order risk
The same internet-facing Langflow server was compromised twice in July 2026, but the second intrusion changed what a ransomware incident against AI infrastructure can cost. Sysdig’s Threat Research Team documented the first campaign on July 1 and the second on July 20. Both entered through the same known Langflow vulnerability. In under three weeks, however, the attacker moved from improvised Python-based encryption to a compiled locker designed around trained models and other AI artifacts.
That progression matters because the later payload deliberately selected assets whose reconstruction can be expensive or impossible through ordinary restoration. Michael Clark, who leads Sysdig’s threat research team, described the target as “the one thing an organization can’t simply restore.” The attacker Sysdig tracks as JADEPUFFER needed no new intrusion technique to reach it. Familiar weaknesses were enough to deliver ransomware built for the AI systems attached to an exposed framework.
Those targeted assets change the recovery assumption because conventional restoration can recover known data, while trained artifacts also embody computation and engineering work. Model weights, checkpoints, adapters, vector indexes and training datasets carry different recovery costs because some of their value comes from training work that a storage snapshot alone cannot recreate. The JADEPUFFER case shows how quickly an ordinary application compromise can become deliberate destruction of those assets.
ENCFORGE was built to make AI assets unusable
The first compromise already showed destructive behavior, although its technique was comparatively improvised. Sysdig found that JADEPUFFER encrypted 1,342 Alibaba Nacos configuration items using MySQL’s own encryption function and then dropped the tables. When the attacker returned to the same Langflow server, Sysdig found that the payload was ENCFORGE, a compiled Go program that searched roughly 180 file extensions. Its selection makes the AI-specific objective concrete.
That selection includes PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors weights, GGUF files, FAISS vector indexes, and training data stored in Parquet and NumPy formats. GGUF underpins most local LLM deployments, so encrypting those files can directly disable deployed models. The program’s option for appending additional formats even uses LoRA adapters, which store lightweight model fine-tuning changes, and legacy GGML weights as its example. Those choices show deliberate knowledge of artifacts used across AI development and deployment.
The locker creates pressure through destructive encryption rather than data theft. ENCFORGE contains no network code, and Sysdig found no outbound connection behavior, leak site or payment portal. The intrusion agent harvested credentials before the locker ran, while ENCFORGE itself has no mechanism for sending files out. Both campaigns used the same Proton Mail address in their ransom notes, part of the evidence Sysdig used to connect them to JADEPUFFER.
That destructive approach depends on making large files unusable quickly. ENCFORGE encrypts regions within files instead of processing every byte, using AES-256-CTR with a key generated for each run and wrapped with an embedded RSA-2048 key. Established ransomware families use partial encryption because large files can be disabled much faster this way. AI weights and datasets can be large, making that optimization directly useful against the files ENCFORGE selects.
The first campaign also shows why a ransom demand does not guarantee a usable recovery mechanism. Its encryption key was randomly generated, displayed once in the console and never stored, so the attacker retained no key that could later restore the encrypted material. Payment therefore could not produce decryption in that campaign. ENCFORGE uses a different key scheme, so the campaigns also show that the attacker changed its implementation between intrusions.
The observed ENCFORGE activity gives defenders signatures for that implementation. Sysdig observed an active encryption pass and released a YARA rule, a pattern-based rule used to identify matching malicious files, plus hashes for both binaries. Neither hash had antivirus coverage when Sysdig analyzed them. Sysdig sells cloud-security products and benefits commercially when organizations invest in detecting this kind of threat, so its telemetry and detection material should be read with that interest in view.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
The attacker’s advantage was speed
The route into this environment began with CVE-2025-3248, a missing-authentication vulnerability in Langflow’s code-validation endpoint. A reachable user could make the endpoint execute Python, earning the vulnerability a CVSS score of 9.8. CISA put it in the Known Exploited Vulnerabilities, or KEV, catalog on May 5, 2025; KEV is CISA’s list of vulnerabilities known to be exploited in the wild. Federal agencies faced a May 26 remediation deadline, and Langflow 1.3.0 contained the fix.
By the time JADEPUFFER returned in July 2026, that exposure had persisted for more than 14 months after the KEV listing. The same server had also already been publicly documented as compromised. The chronology separates execution speed from vulnerability novelty because a long-known and patched flaw still provided the initial code execution. What followed shows how rapidly automation can turn that foothold into a deeper compromise.
Once it had code execution, the intrusion agent searched the host for cloud keys, API tokens and connection strings, then tried those credentials against internal database and cache services. During that process, it found /var/run/docker.sock, the Unix socket through which local software can control Docker. Access to the Docker socket is functionally equivalent to root access because a process that controls Docker can manipulate containers and their relationship with the host. That discovery gave the attacker a possible route beyond the Langflow container.
The first attempt to use that route failed when the agent could not download the ransomware binary from command-and-control infrastructure. Sysdig observed that it changed its approach and generated six Python scripts through Langflow, with each script correcting a problem encountered by its predecessor. Five minutes and 24 seconds after starting that sequence, it had produced a working host escape. The speed came from repeatedly adapting the next action to the previous failure.
The final script turned that adaptation into host-level execution. It used the Docker API to identify the host process ID, copied the ransomware binary across the namespace boundary and executed the encryption. It then counted files to check that the operation had succeeded. Sysdig observed the same rapid correction in the earlier campaign on a smaller problem, with the agent diagnosing a failed login and fixing it in 31 seconds.
That compressed sequence is what Sam Evans, then CISO at Clearwater Analytics, connected to incident severity. “In security, it’s all about dwell time,” he told VentureBeat, arguing that a longer-lived intrusion expands the blast radius and raises the probability that an event becomes material. Agentized execution, in which software agents carry out a sequence of actions with limited continuous human input, creates the inverse pressure for defenders because an attacker can complete more consequential work during a short period of access. A response process designed around human operating speed consequently has less time to interrupt the sequence.
The same compression creates an operational problem for defenders, according to Heath Renfrow, co-founder and CISO of breach-recovery firm Fenix24. When agents reduce hours of operator work to minutes, “defenders lose valuable time,” he told Infosecurity Magazine. That difference affects patching, detection and containment because several decisions that once required an operator to inspect a failure and manually try the next action can happen in one continuous run. Fenix24 sells breach-recovery services, so it has a commercial interest in organizations treating faster incidents and recovery readiness as material risks.
The evidence supports a human-directed operating model with automated activity after initial setup. TechCrunch reported on July 6 that the first operation still depended on a person to select the target and establish the infrastructure, while Sysdig could not determine where the root credentials originated. After that direction, activity could continue without someone continuously working at a keyboard. Security teams therefore have to interrupt the observed sequence regardless of whether they classify the operation as “AI-driven.”
That sequence also depended on familiar weaknesses farther down the chain. During the first campaign, JADEPUFFER forged a Nacos administrator token using a default signing key that had been public since 2020. It exploited CVE-2021-29441, a Nacos authentication bypass Alibaba had patched in 2021, and encountered a MinIO object store configured with minioadmin:minioadmin. Sysdig counted more than 600 payloads that depended on known misconfigurations or vulnerabilities for which patches already existed.
The second campaign added the exposed Docker socket to the same pattern of weaknesses. Existing flaws, leaked or weak credentials, internal services and powerful local interfaces could be combined rapidly after the first foothold, without requiring a sequence of new zero-days. That combination matters for patch prioritization because machine-speed assembly raises the consequence of weaknesses organizations may already treat as routine backlog. A single old exposure can become the starting point for several fast pivots.
That speed also underlies the patching window described by Riemer, Ivanti SVP Network Security Group and Field CISO. “If I release a patch and a customer doesn’t patch within 72 hours of that release, they’re open to exploit, because that’s how fast they can now do it,” he said, while noting that most customers need a week to patch manually. A seven-day operating process is already mismatched with the three-day exposure window he describes; an instance left vulnerable for more than 14 months sits much farther outside it. Ivanti sells security and infrastructure software and therefore benefits commercially when customers prioritize faster patching, which is relevant context for its executive’s 72-hour framing.
Once credentials are available, the same sequence also reduces the protection provided by the external boundary. Riemer described attackers obtaining access that functions like a legitimate “house key” after vendors harden obvious external entry paths. Services presumed safe because “they don’t sit out directly on the internet, and they’re behind a protection barrier” can still become reachable through a compromised workload and its credentials. The JADEPUFFER sequence demonstrates that mechanism: initial Langflow execution led into internal services and then to host-level control.
Why an AI model changes the recovery math
That host-level control becomes a different business problem when the encrypted files embody expensive training work. Restore a database from a Friday snapshot and the direct gap is the weekend’s transactions, which may exist elsewhere as records that can be replayed. Restore Friday’s checkpoint for a fine-tuned model and everything the model learned after Friday is absent. There are no equivalent transactional rows that simply reproduce the later model state.
The missing trained state has a direct reconstruction cost. Sysdig estimates that directly recovering one production-ready fine-tuned model can cost between $75,000 and $500,000. The estimate combines cloud GPU charges across the repeated training runs required to reach a usable result with the engineering time behind that work. The range applies per model, while teams can keep several variants on shared storage, so ransomware reaching that location can turn reconstruction into a significant compute and labor expense.
That expense can grow when the artifacts required for reconstruction share the same failure domain. When the training dataset and model weights live on the same compromised host, model reconstruction cannot start until the dataset itself has been recovered or rebuilt. Checkpoints, weights and training data therefore have recovery relationships that infrastructure teams need to represent explicitly. A backup policy that classifies trained artifacts as outputs that can always be regenerated effectively makes retraining part of the recovery plan.
Once retraining is part of the plan, its cost gives finance a way to evaluate the exposure. Kayne McGladrey, an IEEE Senior Member with an identity-security background, told VentureBeat that companies “should be focused on business risks rather than some, you know, cybersecurity risk,” because financial loss is what leads organizations to budget for action and preventive controls. A $75,000-to-$500,000 reconstruction range gives a CFO a concrete exposure to compare with the cost of storage, isolation and tested recovery. That comparison turns model recovery into a budgetable resilience decision.
The first JADEPUFFER campaign makes recoverability especially important because its randomly generated encryption key was never retained. Recovery in that incident could not depend on paying for a decryptor, so the organization needed another path to the encrypted material. When trained artifacts have material replacement costs, their recoverability has to be designed before an incident. The planning question is which trained state the organization must be able to restore and what inputs that restoration requires.
AI-security guidance emphasizes integrity while ransomware adds availability
Existing AI-security guidance already treats data protection as a serious problem, and ENCFORGE adds a recovery question about availability. In May 2025, the NSA Artificial Intelligence Security Center, CISA and FBI published “AI Data Security,” co-sealed with authorities in the U.K., Australia and New Zealand. The guidance is the most authoritative on the subject and identifies three prominent risks: the data supply chain, maliciously modified data and data drift. Those risks concern the integrity of information that feeds and shapes AI systems.
ENCFORGE adds the complementary question of whether model artifacts and supporting data remain available and recoverable after deliberate encryption. That availability problem extends the operational emphasis while leaving the integrity concerns intact. For teams responsible for resilience, AI data security consequently includes the ability to restore the trained state on which production depends. Integrity determines whether that state can be trusted; availability determines whether the organization can use or recover it.
The exposure extends beyond one repeatedly unpatched server
The repeatedly compromised server is one case, while Langflow has a broader exposed footprint. VentureBeat reported in June that roughly 7,000 Langflow instances were internet-accessible, most of them in North America. Such instances can contain provider API keys and cloud credentials as well as live connections to vector stores, which are among the assets ENCFORGE was designed to encrypt. Exposure of the orchestration layer can therefore create a path toward systems containing higher-value AI material.
That footprint sits alongside a wider Langflow vulnerability record. CISA had placed five Langflow flaws in its KEV catalog, including two added during July 2026. On July 7, it added CVE-2026-55255, a cross-tenant bypass through which any authenticated user on a shared instance could execute another tenant’s flows using that tenant’s credentials. Langflow’s maintainers rated the vulnerability 9.9 and fixed it in version 1.9.1.
The next KEV addition showed another route through the validation endpoint. CISA added CVE-2026-0770 on July 21; discovered by Trend Micro and rated 9.8, the vulnerability provides an unauthenticated path to root code execution through the exec_globals parameter on the same validation endpoint used by JADEPUFFER. KEVIntel recorded exploitation beginning June 27, with more than 220 attempts from 64 addresses. Founder Ryan Dewhurst told BleepingComputer that observed payloads moved beyond reconnaissance to seek AWS credentials and container metadata; federal agencies faced a July 24 remediation deadline.
Those exposures reinforce Riemer’s warning about placing security-sensitive applications on an internet boundary. “When you put your security at the edge of your network, you’re inviting the entire world in to the edge of your network,” he said. For an AI framework, the consequences can extend through stored credentials and connected infrastructure after the exposed service is breached. Internet reachability therefore has to be assessed alongside what the framework can reach in turn.
That reach becomes harder to govern when organizations also have unmanaged AI agents. A Cloud Security Alliance survey of 418 professionals, commissioned by Token Security, found that 82% had discovered AI agents nobody knew about, while 65% had dealt with an agent-related incident during the previous year. The findings indicate unmanaged-agent exposure and show that security teams may be granting powerful machine-operated identities without maintaining a complete inventory of them. Token Security sells identity-security technology and commissioned the survey, so it benefits commercially from greater concern about unmanaged agent identities.
The permissions attached to those identities can amplify the same speed problem seen in JADEPUFFER. McGladrey traces part of the issue to the long-standing practice of copying one employee’s access profile when provisioning another user, a habit organizations are now extending to agents. An agent “does whatever it needs to do to get its job done,” he said, and at scale and speed it can use more permissions than its task requires. Excess privilege becomes more consequential when actions happen rapidly because a compromised or misdirected agent can exercise those permissions across systems before manual intervention.
As those incidents become visible, the technical problem also becomes an executive one. Evans said boards respond to a newly reported ransomware campaign by asking, “What are we doing about this?” and that an AI component raises the level of concern. A useful answer has to connect that concern to the observed mechanisms: exposed software, credentials, excessive privileges, host access and recoverability. Those mechanisms give security and infrastructure teams concrete areas in which to reduce the exposure.
Recovery readiness makes model artifacts explicit
The near-term response uses existing security controls, starting with the exposed application. Every internet-reachable Langflow deployment should move to the current supported release, followed by a review of historical /api/v1/validate/code requests for exec_globals patterns. Installing a patch closes an entry point, while the historical review addresses the possibility that exploitation occurred before remediation. The two actions answer different parts of the same exposure.
Once the application is patched, container privilege needs equally direct treatment because the Docker socket created JADEPUFFER’s route toward the host. Langflow operates without needing to create containers, so its application container should run without the Docker socket. Where an architecture genuinely requires a socket mount, access should pass through a proxy restricted to the calls the application needs. Removing general Docker control breaks the specific path used in the host escape.
With host privilege constrained, recovery plans need to name model-artifact paths explicitly. Teams should maintain immutable snapshots of checkpoints, vector indexes and training data and test that those snapshots can actually be restored. Training data should also reside away from the host that holds model weights, reducing the chance that one destructive event removes both the artifact and the material required to reconstruct it. That design turns model recovery into a tested engineering process with known inputs.
The same recovery process has to account for credentials that may survive the original compromise. The first campaign obtained OpenAI, Anthropic and cloud credentials within seconds, so patching Langflow afterward cannot revoke material already captured by the attacker. Every credential the host could reach should be rotated, provider keys should be removed from the runtime, and replacements should be delivered through a secrets manager. Those steps contain access that may remain useful after the vulnerable entry point has been closed.
Detection can then focus directly on the destructive behavior ENCFORGE produces. Teams can alert on bulk creation of .locked files in directories containing .gguf, .safetensors, .ckpt or .faiss files, alongside using Sysdig’s published YARA rule and hashes. Those signals place model weights, checkpoints and vector indexes inside the monitored recovery inventory as assets whose sudden encryption is an incident condition. Training data belongs in that same inventory because recovery of the trained model can depend on it.
Recap
JADEPUFFER does not require executives to assume that AI-powered ransomware will replace conventional attacks. Its significance is more immediate: automation can compress familiar attack chains into minutes, while ransomware aimed at model weights, checkpoints and training data can make recovery materially more expensive. Old vulnerabilities, exposed services and excessive privileges become more consequential when attackers can chain them quickly.
For business leaders, that changes how AI assets should appear in resilience planning. A production model is not simply another file to back up. Its recoverability may depend on training data, checkpoints, engineering knowledge, compute capacity and credentials that sit across several systems. If rebuilding that state costs $75,000 to $500,000 per model, recovery time and reconstruction cost belong in the same business-impact analysis as other critical systems.
The practical test is whether the organization can restore a trusted model without relying on the compromised environment or a ransomware decryptor. That means knowing which AI artifacts are business-critical, isolating immutable copies, protecting the data needed to reconstruct them, limiting the privileges of AI infrastructure and rotating credentials after a compromise. Those controls are familiar, but the assets and timelines they protect are changing.
The executive question is therefore broader than whether AI ransomware is a new threat category. It is whether existing security and recovery processes still match the speed of the attack and the replacement cost of the assets now at risk.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


