CVE-2025-3248
-
New ENCFORGE ransomware targets AI files after Langflow breach
Researchers said a Langflow flaw let an operator deploy ENCFORGE ransomware against AI files, including model weights and vector indexes, after a host breakout through Docker. The report found no exfiltration code and no victim count.
-
Sysdig says AI agent ran ransomware attack through patched Langflow flaw
Sysdig says an AI agent carried out a ransomware attack from start to finish after exploiting a patched Langflow flaw, stealing credentials and encrypting a production database. The report says the case shows how exposed software and weak defaults can be chained automatically.
-
New Flodrix Botnet Exploits Vulnerabilities in Langflow Framework
A new botnet campaign exploiting vulnerabilities in the Langflow framework has emerged, allowing attackers to deploy the Flodrix malware. Cybersecurity experts emphasize the urgency of addressing this critical security flaw.



