The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
JadePuffer was disclosed earlier this month as an agentic threat actor (ATA) capable of running autonomously through the stages of a ransomware attack, from initial access to data encryption.
Cloud security company Sysdig says that the AI agent adapted to technical difficulties in real time and optimized the intrusion mechanism to find the correct fix in less than a minute.
Latest attack
In a report today, Sysdig says that the attacker returned to the previously breached Langflow instance vulnerable to CVE-2025-3248 with the Go-based EncForge ransomware "built specifically for AI and machine learning (ML) infrastructure."









