JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models

Reported 21 Jul 2026 by otx · Severity: medium

An advanced threat actor identified as JADEPUFFER has evolved its capabilities, now deploying ENCFORGE, a specialized ransomware targeting AI and ML infrastructure. The actor exploits CVE-2025-3248 in Langflow to gain initial access, then autonomously chains reconnaissance, crede