Ransomware hits Langflow, can't collect ransom | VentureBeat

TL;DR AI
2 min readKey summary
A Langflow server was attacked twice through the same vulnerability, CVE-2025-3248.
The second campaign deployed ENCFORGE, a Go-based ransomware strain focused on destroying AI model files and training assets.
Targets include PyTorch and TensorFlow checkpoints, SafeTensors, GGUF, FAISS, and other high-value ML artifacts.
The malware encrypts and deletes data without exfiltration or a payment path, making recovery far harder and sometimes impossible.
The case shows ransomware is shifting from generic encryption to deliberate destruction of AI-specific assets.
