A reported JADEPUFFER-linked operation points to a blunt shift in extortion tactics: AI models and training data are being treated as high-value damage, not just files to encrypt.
A reported JADEPUFFER intrusion tied to Langflow CVE-2025-3248 shows how extortion crews can focus on the artifacts that keep machine-learning systems operational.
A second attack on the same Langflow server was linked to JADEPUFFER, with ENCFORGE observed targeting AI-related files that support model operations.