| Mobile Web

Ransomware targeting AI models emerges, encrypting training weights and raising recovery cost concerns

U.S. security firm Sysdig said the same attacker breached an internet-exposed Langflow server twice, using AI-focused ransomware called ENCFORGE in the second attack. The intrusions exploited a Langflow authentication bypass flaw to run arbitrary Python code and later evolved to encrypt AI assets. ENCFORGE selectively encrypts model checkpoints, vector indexes and training data. Sysdig estimated rebuilding a fine-tuned production model could cost $75,000 to $500,000.