Once an attacker has Langflow, cleaning the app does not protect the AI system anymore. JADEPUFFER has shifted from improvised destruction to ENCFORGE, a compiled Go ransomware payload that encrypts model weights, vector indexes, checkpoints, and training data on the host, so the real loss can be the artifacts that make the model runnable.
Sysdig says the second attack reused CVE-2025-3248 in Langflow versions before 1.3.0 to reach the server again and deploy the new locker. The old campaign used throwaway scripts against downstream data stores; this one is built to sweep through common AI file types and hit the stores where ML systems keep their working state.
If model artifacts live beside the app, patching Langflow does not restore them. Without offline backups, encrypted weights and indexes can leave the AI service permanently unrecoverable even after the entry point is fixed.