Agentic hacker using ransomware to destroy AI models Cloud security firm Sysdig reported that an agentic threat actor named JADEPUFFER is exploiting a vulnerability (CVE-2025-3248) in AI framework Langflow to deploy ransomware that destroys AI model artifacts. The ransomware targets approximately 180 file extensions across the AI/ML stack, including model checkpoints, vector databases, training datasets, and embedding indices, according to Sysdig Senior Director of Threat Research Michael Clark. Security /tag/security/ An agentic hacking tool first spotted earlier this month is now targeting AI model data with new ransomware designed to destroy specially trained models. Cloud security firm Sysdig said “agentic threat actor” JADEPUFFER was exploiting a vulnerability CVE-2025-3248 https://www.cve.org/CVERecord?id=CVE-2025-3248&ref=thestack.technology in AI applications framework Langflow to deploy ransomware that wipes AI model artifacts. In a blog post, Senior Director of Threat Research Michael Clark said the compiled, UPX-packed Go ransomware “targets approximately 180 file extensions, with a deliberately broad sweep of the modern AI/ML stack, including model checkpoints, vector databases, training datasets, and embedding indices in nearly every current format.” Get the full story: Subscribe for free Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events. Subscribe now https://www.thestack.technology/membership/ Already a member? Sign in https://www.thestack.technology/signin/