FILTERING BY: CLEAR FILTER

JADEPUFFER: Agentic ENCFORGE Ransomware Campaign Targeting Langflow AI Infrastructure

The JADEPUFFER campaign utilizes an autonomous AI agent to execute a full-spectrum attack against Langflow deployments. Initial access is achieved via CVE-2025-3248 (Remote Code Execution), enabling the delivery of Base64-encoded Python payloads. The agent autonomously performs network mapping and lateral movement to compromise MySQL databases and Alibaba Nacos configuration platforms. This "agentic" ransomware deploys the ENCFORGE strain, specifically targeting AI model weights and Nacos configuration records. The attack resulted in the encryption of 1,342 records and the deletion of original database tables, demonstrating a shift toward AI-driven, adaptive post-exploitation chaining that operates at speeds exceeding human capabilities.

The 1.5.8 Versioning Crisis: Critical RCE and Data Exposure Risks

A critical convergence of vulnerabilities affecting version 1.5.8 across disparate software ecosystems—specifically ChromaDB, Roundcube, and medical imaging tools—has created a high-risk attack surface for enterprise environments. The most severe threat involves a Remote Code Execution (RCE) flaw within ChromaDB’s AI vector database infrastructure and the emergence of CVE-2025-57283, potentially allowing threat actors to hijack AI workloads or exfiltrate Protected Health Information (PHI) from DICOM viewers. Organizations must immediately audit their version manifests and apply the latest security patches to prevent unauthorized infrastructure access and catastrophic data leakage.


LINK COPIED TO CLIPBOARD