New ransomware targets AI model weights and can't even collect the ransom
The same attacker broke into the same internet-facing Langflow server twice, and the second time brought ransomware built to destroy trained AI models. Sysdig's Threat Research Team documented the first campaign on July 1 and the second on July 20 . The entry point never changed, but the payload changed completely. Both ran through CVE-2025-3248 , a missing-authentication flaw in Langflow's code-validation endpoint that lets anyone reaching the server execute Python on it. In the first, the agen
This article was published on VentureBeat (venturebeat.com). Read the full article on the original source:
Read full article on VentureBeat