cd /news/ai-safety/agentic-hacker-using-ransomware-to-d… · home topics ai-safety article
[ARTICLE · art-66831] src=thestack.technology ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Agentic hacker using ransomware to destroy AI models

Cloud security firm Sysdig reported that an agentic threat actor named JADEPUFFER is exploiting a vulnerability (CVE-2025-3248) in AI framework Langflow to deploy ransomware that destroys AI model artifacts. The ransomware targets approximately 180 file extensions across the AI/ML stack, including model checkpoints, vector databases, training datasets, and embedding indices, according to Sysdig Senior Director of Threat Research Michael Clark.

read1 min views2 publishedJul 21, 2026
Agentic hacker using ransomware to destroy AI models
Image: Thestack (auto-discovered)

An agentic hacking tool first spotted earlier this month is now targeting AI model data with new ransomware designed to destroy specially trained models.

Cloud security firm Sysdig said “agentic threat actor” JADEPUFFER was exploiting a vulnerability ( CVE-2025-3248) in AI applications framework Langflow to deploy ransomware that wipes AI model artifacts.

In a blog post, Senior Director of Threat Research Michael Clark said the compiled, UPX-packed Go ransomware “targets approximately 180 file extensions, with a deliberately broad sweep of the modern AI/ML stack, including model checkpoints, vector databases, training datasets, and embedding indices in nearly every current format.”

Get the full story: Subscribe for free #

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

[Subscribe now](https://www.thestack.technology/membership/)

Already a member? [Sign in](https://www.thestack.technology/signin/)
── more in #ai-safety 4 stories · sorted by recency
── more on @sysdig 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/agentic-hacker-using…] indexed:0 read:1min 2026-07-21 ·