A new strain of ransomware, dubbed ENCFORGE, has been discovered targeting artificial intelligence (AI) model files through a vulnerability in Langflow, a popular video editing software. This attack highlights the increasing sophistication of cyber threats and the need for organizations to prioritize AI-powered security measures.
ENCFORGE leverages a remote code execution (RCE) flaw in Langflow, which allows attackers to inject malicious code into vulnerable systems. The malware then searches for specific AI model files, such as those used in deep learning tasks, and encrypts them using the Advanced Encryption Standard (AES). Once encrypted, victims are presented with a ransom demand in exchange for decryption keys.
The affected software, Langflow, is widely used by video editors, digital artists, and other creatives. The attack’s focus on AI model files suggests that ENCFORGE is designed to target organizations in the tech industry, where such models are commonly employed. The use of RCE exploits also implies that attackers have gained unauthorized access to vulnerable systems.
Langflow’s developers have confirmed the existence of the vulnerability and are working on a patch release. However, the attack demonstrates the potential risks associated with AI model files, which can contain sensitive information and critical infrastructure data. As AI technology continues to advance, organizations must adapt their security strategies to account for these emerging threats.
ENCFORGE’s use of AES encryption also underscores the importance of robust backup procedures and data recovery plans. With many organizations relying on cloud-based services or centralized storage solutions, ensuring that critical files are regularly backed up can help mitigate the impact of ransomware attacks like ENCFORGE.
Ultimately, ENCFORGE serves as a reminder that AI-powered security measures must be integrated into an organization’s overall defense strategy. By combining traditional security practices with AI-driven threat detection and response, companies can better protect themselves against evolving cyber threats.
Source: The Hacker News — 2026-07-21