ENCFORGE ransomware encrypting AI models after exploiting a Langflow remote code execution vulnerability

A newly discovered ransomware called ENCFORGE is targeting AI infrastructure by exploiting critical vulnerabilities in Langflow. Attackers use remote code execution (RCE) flaws to gain access and encrypt valuable AI assets, including model weights, vector databases, and training datasets, disrupting AI operations and recovery.

Fake Claude Code Installer Spreads Fileless .NET Infostealer via SEO PoisoningFake Claude Code Installer Spreads Fileless .NET Infostealer via SEO Poisoning

The ransomware uses advanced encryption techniques to lock AI-related files, leaving victims unable to access critical models and data. Researchers observed the attackers leveraging exposed Docker configurations and privileged containers to escape application environments and execute the ransomware directly on host systems.

Organizations should immediately update Langflow to the latest version, rotate exposed credentials, secure Docker environments, and maintain offline backups of AI assets. Continuous endpoint monitoring and proactive threat detection are essential to defend AI infrastructure against evolving ransomware attacks.


NPAV EDR On-Premise, help protect AI workloads from ransomware, advanced threats, and unauthorized access.