New ransomware targets AI model weights and can't even collect the ransom
Source:
ventureBeat
July 27, 2026 · 00:00
The same attacker broke into the same internet-facing Langflow server twice, and the second time brought ransomware built to destroy trained AI models. Sysdig's Threat Research Team documented the first campaign on July 1 and the second on July 20. The entry point never changed, but the payload changed completely.Both ran through CVE-2025-3248, a missing-authentication flaw in Langflow's code-validation endpoint that lets anyone reaching the server execute Python on it. In the first, the agent improvised, encrypting 1,342 Alibaba Nacos configuration items with MySQL's own encryption function and dropping the tables. In the second, it staged ENCFORGE, a compiled Go binary sweeping roughly 180 file extensions.ENCFORGE was built for AI assets, not adapted to themWhat gives the design away is …
The original article opens on the publisher's website.
More from Automotive
View topic →Larry Page’s flying car company Pivotal loses its CEO
techcrunch
Sep 1, 2026 · 16:59
SEC proposes transfer agent rule, sets event to figure out round-the-clock U.S. trading
coinDesk
Sep 1, 2026 · 16:55
The Range Rover Electric: Specs, Price, Availability
wired
Sep 1, 2026 · 16:01
Android stuck in Safe Mode? Here's how to turn it off
engadget
Sep 1, 2026 · 16:00
How to change the background on iPhone Messages
engadget
Sep 1, 2026 · 15:30
Countries mentioned