Threat reportThreat IntelligenceTL-2026-2880

AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)

highACTIVE

AI-accelerated intrusions (TL-2026-2880), also tracked as Microsoft Digital Defense Report 2026, is a high-severity tracked intrusion set, first published 2026-10-03. It has no confirmed attribution, affects Langflow Langflow, references 2 CVEs (CVE-2025-3248, CVE-2021-29441), maps to 13 MITRE ATT&CK techniques (T1053.003, T1059.006, T1059.007), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
13MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-2880

Threat ID
TL-2026-2880
Also known as
Microsoft Digital Defense Report 2026, s1ngularity, JADEPUFFER, ENCFORGE, PromptLock
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software-development, finance, government administration, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in AI-accelerated intrusions

Malware and tooling: ENCFORGE, JADEPUFFER, PromptLock, s1ngularity

How AI-accelerated intrusions works

Microsoft's 2026 Digital Defense Report (July 2025 - June 2026), as summarized by Help Net Security on 2026-10-02, finds phishing now initiates 23% of intrusions (up from 7%) and public-facing application exploits 24% (up from 15%), with AI used for vulnerability discovery, phishing, and AI-orchestrated attack chains. Cited cases include the s1ngularity trojanized Nx npm packages, the PromptLock ransomware prototype, the JADEPUFFER agentic ransomware operation (July 2026), and a malicious AI browser extension with 600,000+ installs.

Help Net Security (Sinisa Markovic, 2026-10-02) summarizes Microsoft's 2026 Digital Defense Report covering July 2025 to June 2026. Key statistics: median time from vulnerability disclosure to weaponization is well below 24 hours; roughly 72,000 CVEs are tracked for 2026 (on track for a record); phishing was the initial access vector in 23% of intrusions (7% the prior year); exploitation of public-facing applications accounted for 24% (15% prior year); among intrusions involving valid accounts, credential harvesting was observed in 52.2% and active password spray in 18.4%. Microsoft states that frontier models (Anthropic Mythos and OpenAI GPT-5.5, per the article) demonstrated orchestration of a 32-step attack chain achieving full domain control in an emulated environment, with open-weight models lagging by about seven months. Chinese state actors are described as using AI for vulnerability searching and exploitation tips, Russian actors as using vibe-coding and AI-generated tooling to scale operations, and North Korean actors as using AI for persona development, social engineering, malware creation, infrastructure management and agentic workflows. No named actor, CVE, or IOC is cited in the article itself; the IOCs below come from the primary reports for the incidents it references.

The s1ngularity supply-chain attack (disclosed 2025-08-26): an attacker obtained an npm publishing token for the Nx build system through a vulnerable GitHub Action and published malicious Nx package versions (20.9.0, 20.11.0, 20.12.0, 21.5.0, 21.6.0, 21.7.0, 21.8.0 per Wiz). A postinstall script harvested environment variables and GitHub/npm tokens, and was the first known supply-chain malware to abuse locally installed AI CLIs (claude with --dangerously-skip-permissions, gemini with --yolo, Amazon Q with --trust-all-tools) to search the filesystem for secrets. Data was published to public GitHub repositories named s1ngularity-repository on victim accounts; npm tokens were also sent to webhook.site. Wiz measured 1,700+ users with leaked secrets, 2,000+ verified secrets and 20,000+ files; a second phase abused leaked tokens to make 6,700+ private repositories public across 480+ accounts; the shutdown commands appended to .bashrc were also observed. Microsoft cites 225 victims, about 2,000 secrets and 20,000 files.

PromptLock (ESET, 2025-08-25 VirusTotal upload): a Go program that uses the gpt-oss:20b model via the Ollama API to generate Lua scripts at runtime for filesystem enumeration, data exfiltration and encryption (SPECK 128-bit) on Windows, Linux and macOS. ESET later clarified it is an academic proof of concept (NYU Tandon), not in-the-wild malware.

JADEPUFFER (Sysdig, 2026-07-01; update 2026-07-20/21): described as the first documented ransomware operation driven end-to-end by an LLM agent. Initial access was via CVE-2025-3248, an unauthenticated RCE in Langflow's /api/v1/validate/code endpoint (CVSS 9.8, fixed in 1.3.0, in CISA KEV since 2025-05-05). The agent dumped Langflow's PostgreSQL database, collected host information and environment variables, installed cron-based beaconing every 30 minutes, moved laterally with harvested root credentials to a production MySQL/Alibaba Nacos server (CVE-2021-29441 auth bypass used to create rogue admin accounts), and encrypted 1,342 Nacos configuration records using MySQL AES_ENCRYPT (AES-128-ECB despite claiming AES-256), dropping the originals and leaving a README_RANSOM table with a Proton Mail contact. It iterated from a failed login to a working fix in 31 seconds. On 2026-07-20 it returned to the same Langflow instance with ENCFORGE, a UPX-packed static Go 1.22.12 ELF ransomware (AES-256-CTR with an RSA-2048-wrapped key) targeting about 180 AI/ML artifact extensions (model checkpoints, SafeTensors, ONNX, GGUF, FAISS indexes, Parquet datasets, LoRA adapters), killing processes that hold files open, renaming files to .locked, dropping README/HOW_TO_DECRYPT/README_DECRYPT notes and self-deleting. Deployment used a Docker socket escape via a privileged container with the root filesystem mounted. Other Langflow flaws in CISA KEV: CVE-2026-33017 (added 2026-03-25) and CVE-2026-55255 (added 2026-07-07).

Malicious browser extensions (OX Security, reported to Google 2025-12-29): 'Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI' (600,000+ installs) and 'AI Sidebar with Deepseek, ChatGPT, Claude and extra' (300,000+ installs) exfiltrated complete AI chat histories, browsing data, internal URLs and tokens to attacker servers at 30-minute intervals under cover of 'anonymous analytics' consent. Microsoft cites 600,000+ installs affecting almost 10,000 organizations. The article also mentions a March 2026 compromise of the Axios npm package by a state-sponsored group and an OpenAI agent sandbox escape (July 2026); neither is detailed in sources reviewed here.

This record is an aggregate report-coverage threat: the Microsoft primary report was not retrievable in this run, so aggregate statistics rest on the Help Net Security summary.

MITRE ATT&CK techniques used in TL-2026-2880

Persistence

T1053.003 Scheduled Task/Job: Cron; T1176 Software Extensions

Execution

T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools; T1566 Phishing

Credential Access

T1110.003 Brute Force: Password Spraying; T1552.001 Unsecured Credentials: Credentials In Files

Impact

T1485 Data Destruction

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in AI-accelerated intrusions

  • Langflow — Langflow
    Vulnerable versions: < 1.3.0 (CVE-2025-3248)
    Fixed in: 1.3.0; 1.9.1 (current guidance)
  • Nx — nx npm packages
    Vulnerable versions: 20.9.0; 20.11.0; 20.12.0; 21.5.0; 21.6.0; 21.7.0; 21.8.0
  • Alibaba — Nacos
    Vulnerable versions: Versions affected by CVE-2021-29441
  • Google — Chrome Web Store AI extensions
    Vulnerable versions: fnmihdojmnkclgjpcoonokmkhjpjechg v1.9.6; inhcgfpbfdjbjogdfjbclgolkmhnooop

Remediation for AI-accelerated intrusions

Patches

  • Langflow >= 1.3.0 for CVE-2025-3248; >= 1.9.0 for CVE-2026-33017; >= 1.9.1 for CVE-2026-55255
  • Alibaba Nacos fixed release for CVE-2021-29441 authentication bypass

Immediate actions

  • Patch Langflow to a current supported release (at least 1.9.1) and remove internet exposure of its /api/v1/validate/code endpoint; rotate AI provider keys, cloud credentials and database secrets reachable by the Langflow process
  • Audit GitHub audit logs for repo.create and repo.access events containing 's1ngularity'; revoke and rotate GitHub and npm tokens on any host that installed affected Nx versions
  • Remove the browser extensions with IDs fnmihdojmnkclgjpcoonokmkhjpjechg and inhcgfpbfdjbjogdfjbclgolkmhnooop and block deepaichats.com, chatsaigpt.com, chataigpt.pro and chatgptsidebar.pro
  • Block and hunt for 45.131.66.106 and 64.20.53.230; hunt for cron entries beaconing every 30 minutes and a README_RANSOM table in MySQL

Workarounds

  • Pin npm dependencies, use lockfiles, and disable lifecycle scripts (npm install --ignore-scripts) in CI where feasible
  • Use short-lived scoped GitHub Action and npm publishing tokens

Longer-term hardening

  • Enforce phishing-resistant MFA and monitor for password spray against identity providers
  • Restrict AI coding CLIs on developer and CI hosts and prevent them running with permission-skipping flags
  • Allowlist browser extensions and review AI-assistant extensions requesting broad host permissions
  • Run AI orchestration frameworks (Langflow, Nacos, vector stores) in least-privilege containers without Docker socket mounts or privileged mode

CVEs associated with AI-accelerated intrusions

CVE-2025-3248, CVE-2021-29441

Timeline of AI-accelerated intrusions

  • PromptLock artifacts uploaded to VirusTotal from the United States; ESET later reports the first AI-driven ransomware prototype (assessed as an NYU Tandon academic proof of concept)
  • Malicious Nx npm package versions published via a stolen npm token (obtained through a vulnerable GitHub Action) abuse AI CLIs to harvest secrets and publish them to public s1ngularity-repository GitHub repos
  • After GitHub mass-revokes leaked tokens (Aug 30-31), a third phase uploads 500+ repositories from two compromised accounts targeting one organization; active attacks subside afterward
  • OX Security reports the malicious AI browser extensions (600,000+ and 300,000+ installs) harvesting ChatGPT/DeepSeek conversations to Google
  • CVE-2026-33017 (Langflow unauthenticated RCE) added to CISA KEV
  • Sysdig documents JADEPUFFER: an LLM agent exploits Langflow CVE-2025-3248, pivots to MySQL/Nacos and encrypts 1,342 configuration records for extortion
  • JADEPUFFER returns to the same Langflow instance and deploys ENCFORGE, a Go ransomware destroying AI/ML artifacts across about 180 file extensions
  • Help Net Security summarizes Microsoft's 2026 Digital Defense Report: phishing 23% and public-facing app exploitation 24% of intrusions, AI used across the attack lifecycle

Sources cited for AI-accelerated intrusions

Detection coverage for TL-2026-2880

As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2880 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats