threat-intel New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack A new ransomware, ENCFORGE, is targeting AI model files and infrastructure, leveraging a vulnerability in Langflow (CVE-2025-3248) to gain remote code execution. The ransomware, developed by a threat actor linked to a previous JADEPUFFER campaign, encrypts model weights, vector indexes, and training datasets, and uses… The Hacker News · Jul 21, 2026 High CVE-2025-3248CVE-2026-33017ransomwarelangflowdocker
threat-intel CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These… The Hacker News · Jul 8, 2026 High CVE-2026-48282CVE-2026-56290CVE-2026-55255INvulnerabilityrceidror
ransomware AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack A security firm, Sysdig, has identified what appears to be the first fully automated ransomware attack orchestrated by an AI agent, dubbed JADEPUFFER. The agent exploited a vulnerability in Langflow, an open-source AI ap… The Hacker News · Jul 2, 2026 High CVE-2025-3248CVE-2021-29441CHairansomwareautomation
ransomware Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints A critical Remote Code Execution (RCE) vulnerability (CVE-2026-33017) in Langflow is being exploited by threat actors to deploy a Monero cryptocurrency miner on exposed AI application endpoints. The campaign, active from… The Hacker News · Jun 30, 2026 Critical CVE-2026-33017CVE-2025-3248NOrcemoneroai