The bottom line: JadePuffer now uses specialized ransomware to encrypt AI assets and force organizations to pay ransom.
The autonomous AI agent malware JadePuffer has been enhanced with the encryption tool EncForge, which specifically targets AI infrastructures. Affected are training data, vector databases, and model checkpoints.
The autonomous AI agent JadePuffer has expanded its attack arsenal: the threat tool EncForge specifically encrypts AI infrastructure such as training datasets, vector databases, and model checkpoints. These assets are critical to the operation of machine learning systems and are difficult to reconstruct.
For CISOs, this represents a new attack surface. Traditional endpoint and network defenses often fail to detect agent-driven attacks, particularly when they run on specialized ML infrastructures. The ransomware deliberately targets the most valuable and hardest-to-replace components.
Protective measures should include versioning and offline backups of training data and models, access controls on storage systems, and monitoring of agent-based processes. Segmentation of ML infrastructure from the standard network reduces the risk of contamination.
Source: www.bleepingcomputer.com · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 of the EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.