Ransomware built for AI weights signals a shift in attacker incentives
Sysdig's Threat Research Team documented two intrusions through the same exposed Langflow server, fourteen months apart. The first ran improvised Python against configuration files. The second brought ENCFORGE, a compiled Go binary whose extension list was written for AI infrastructure specifically. PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors