An agentic hacking tool first spotted earlier this month is now targeting AI model data with new ransomware designed to destroy specially trained models.

Cloud security firm Sysdig said “agentic threat actor” JADEPUFFER was exploiting a vulnerability (CVE-2025-3248) in AI applications framework Langflow to deploy ransomware that wipes AI model artifacts.

In a blog post, Senior Director of Threat Research Michael Clark said the compiled, UPX-packed Go ransomware “targets approximately 180 file extensions, with a deliberately broad sweep of the modern AI/ML stack, including model checkpoints, vector databases, training datasets, and embedding indices in nearly every current format.”

Get the full story: Subscribe for free

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

Subscribe now

Already a member? Sign in