Extortion contact reused from prior AI-agent-executed campaign: Same identifier (Source: Help Net Security (July 21, 2026))
A Ransomware Strain Built for Model Weights, Not Web Servers
JadePuffer, the threat actor previously linked to an extortion operation executed end-to-end by an AI agent, is now deploying ENCFORGE — ransomware purpose-built to target AI and machine learning infrastructure rather than conventional web servers. The extortion contact embedded in ENCFORGE matches the one used in the earlier, AI-agent-run campaign, according to reporting from Help Net Security on July 21, 2026. That reuse is the clearest signal available right now: the same operator moved from extorting organizations with an AI agent to building ransomware that treats AI infrastructure itself as the asset worth encrypting.
The Monitoring Gap Nobody Priced In
Vulnerability tracking infrastructure built over the last decade was designed around web applications, operating systems, and network appliances. As of July 16, 2026, the CISA Known Exploited Vulnerabilities catalog holds 1,647 entries — and none of them are categorized as AI model-serving or ML pipeline infrastructure, because that asset class largely did not exist as a named category when the catalog's schema was built. EPSS, the companion scoring system that estimates exploitation likelihood, currently rates 100 vulnerabilities above the 0.7 high-risk threshold industry-wide. Model weights, inference endpoints, and training pipelines sit outside both counts, not because they are inherently safer, but because the accounting was never built for them.
Where WebPulse's Lens Ends
WebPulse's own detection scope illustrates the same boundary from a different angle. The platform has scanned 466K+ detected sites across 25 web frameworks, identified through HTML and HTTP signatures — a lens built for the front-end and server layer of the web, not for the model-serving and training infrastructure sitting behind it. None of that scan corpus touches AI/ML infrastructure directly, and that is precisely the point: ENCFORGE targets a layer that framework-level monitoring, vulnerability catalogs, and exploitation scoring systems were not built to see. This is a live instance of a pattern this publication has tracked through 2026 — AI does not just introduce new attack techniques, it introduces new categories of asset that existing security accounting has not caught up to yet.
A New Line Item for Risk Registers
For organizations running model training or inference infrastructure, ENCFORGE is a concrete data point rather than a forecast: a documented ransomware family, from a documented actor, aimed at a documented category of infrastructure. Budget owners evaluating security coverage for 2026 have a narrow, factual question to answer — whether AI and ML systems appear anywhere in the vulnerability tracking, patching, and incident-response processes that already cover web and network assets. Right now, for most organizations, the answer is that they do not, and the reason is not organizational negligence — it is that the tooling and catalogs those processes rely on have not yet built a line item for this asset class.


