New ransomware targets AI model weights and can’t even collect the ransom
The same attacker broke into the same internet-facing Langflow server twice, and the second time brought ransomware built to destroy trained AI models. Sysdig’s Threat Research Team documented the first campaign on July 1 and the second on July 20. The entry point never changed, but the payload changed completely. Both ran through CVE-2025-3248, a …
New ransomware targets AI model weights and can’t even collect the ransom Read More »









