Switch language한국어
Back to the list

Ransomware hits Langflow, can't collect ransom | VentureBeat

TL;DR AI

Key summary

2 min read
  1. A Langflow server was attacked twice through the same vulnerability, CVE-2025-3248.

  2. The second campaign deployed ENCFORGE, a Go-based ransomware strain focused on destroying AI model files and training assets.

  3. Targets include PyTorch and TensorFlow checkpoints, SafeTensors, GGUF, FAISS, and other high-value ML artifacts.

  4. The malware encrypts and deletes data without exfiltration or a payment path, making recovery far harder and sometimes impossible.

  5. The case shows ransomware is shifting from generic encryption to deliberate destruction of AI-specific assets.

Read the original