CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

JadePuffer agentic attacks now target AI model data with ransomware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2870

As cited

Copy frozen at (site build).

ransomware

JadePuffer agentic attacks now target AI model data with ransomware

JadePuffer, an autonomous AI agent, has been updated with a custom malware tool named EncForge designed to encrypt AI-specific assets including training datasets, vector databases, and model checkpoints. This development represents an expansion of the threat beyond general systems to infrastructure critical to machine learning operations.

Why it matters: Organizations running AI/ML workloads need to assess their backup and recovery procedures for model data and training datasets, as this ransomware targets assets not always protected by traditional endpoint defense strategies.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

JadePuffer agentic attacks now target AI model data with ransomware

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

JadePuffer agentic attacks now target AI model data with ransomware

The artificial intelligence (AI) agent JadePuffer has been updated with a custom malware strain named EncForge. EncForge encrypts AI assets such as training datasets, vector databases, and model checkpoints. Organizations using machine‑learning pipelines should review their defenses and monitor for EncForge indicators.

Why it matters: AI developers and data science teams risk losing access to training data, model checkpoints, and vector databases due to EncForge encryption, so they should verify backup integrity and deploy detection rules for this malware.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary