Threat reportThreat IntelligenceTL-2026-2880
AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)
AI-accelerated intrusions (TL-2026-2880), also tracked as Microsoft Digital Defense Report 2026, is a high-severity tracked intrusion set, first published 2026-10-03. It has no confirmed attribution, affects Langflow Langflow, references 2 CVEs (CVE-2025-3248, CVE-2021-29441), maps to 13 MITRE ATT&CK techniques (T1053.003, T1059.006, T1059.007), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 13MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-2880
- Threat ID
- TL-2026-2880
- Also known as
- Microsoft Digital Defense Report 2026, s1ngularity, JADEPUFFER, ENCFORGE, PromptLock
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, finance, government administration, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in AI-accelerated intrusions
Malware and tooling: ENCFORGE, JADEPUFFER, PromptLock, s1ngularity
How AI-accelerated intrusions works
Microsoft's 2026 Digital Defense Report (July 2025 - June 2026), as summarized by Help Net Security on 2026-10-02, finds phishing now initiates 23% of intrusions (up from 7%) and public-facing application exploits 24% (up from 15%), with AI used for vulnerability discovery, phishing, and AI-orchestrated attack chains. Cited cases include the s1ngularity trojanized Nx npm packages, the PromptLock ransomware prototype, the JADEPUFFER agentic ransomware operation (July 2026), and a malicious AI browser extension with 600,000+ installs.
Help Net Security (Sinisa Markovic, 2026-10-02) summarizes Microsoft's 2026 Digital Defense Report covering July 2025 to June 2026. Key statistics: median time from vulnerability disclosure to weaponization is well below 24 hours; roughly 72,000 CVEs are tracked for 2026 (on track for a record); phishing was the initial access vector in 23% of intrusions (7% the prior year); exploitation of public-facing applications accounted for 24% (15% prior year); among intrusions involving valid accounts, credential harvesting was observed in 52.2% and active password spray in 18.4%. Microsoft states that frontier models (Anthropic Mythos and OpenAI GPT-5.5, per the article) demonstrated orchestration of a 32-step attack chain achieving full domain control in an emulated environment, with open-weight models lagging by about seven months. Chinese state actors are described as using AI for vulnerability searching and exploitation tips, Russian actors as using vibe-coding and AI-generated tooling to scale operations, and North Korean actors as using AI for persona development, social engineering, malware creation, infrastructure management and agentic workflows. No named actor, CVE, or IOC is cited in the article itself; the IOCs below come from the primary reports for the incidents it references.
The s1ngularity supply-chain attack (disclosed 2025-08-26): an attacker obtained an npm publishing token for the Nx build system through a vulnerable GitHub Action and published malicious Nx package versions (20.9.0, 20.11.0, 20.12.0, 21.5.0, 21.6.0, 21.7.0, 21.8.0 per Wiz). A postinstall script harvested environment variables and GitHub/npm tokens, and was the first known supply-chain malware to abuse locally installed AI CLIs (claude with --dangerously-skip-permissions, gemini with --yolo, Amazon Q with --trust-all-tools) to search the filesystem for secrets. Data was published to public GitHub repositories named s1ngularity-repository on victim accounts; npm tokens were also sent to webhook.site. Wiz measured 1,700+ users with leaked secrets, 2,000+ verified secrets and 20,000+ files; a second phase abused leaked tokens to make 6,700+ private repositories public across 480+ accounts; the shutdown commands appended to .bashrc were also observed. Microsoft cites 225 victims, about 2,000 secrets and 20,000 files.
PromptLock (ESET, 2025-08-25 VirusTotal upload): a Go program that uses the gpt-oss:20b model via the Ollama API to generate Lua scripts at runtime for filesystem enumeration, data exfiltration and encryption (SPECK 128-bit) on Windows, Linux and macOS. ESET later clarified it is an academic proof of concept (NYU Tandon), not in-the-wild malware.
JADEPUFFER (Sysdig, 2026-07-01; update 2026-07-20/21): described as the first documented ransomware operation driven end-to-end by an LLM agent. Initial access was via CVE-2025-3248, an unauthenticated RCE in Langflow's /api/v1/validate/code endpoint (CVSS 9.8, fixed in 1.3.0, in CISA KEV since 2025-05-05). The agent dumped Langflow's PostgreSQL database, collected host information and environment variables, installed cron-based beaconing every 30 minutes, moved laterally with harvested root credentials to a production MySQL/Alibaba Nacos server (CVE-2021-29441 auth bypass used to create rogue admin accounts), and encrypted 1,342 Nacos configuration records using MySQL AES_ENCRYPT (AES-128-ECB despite claiming AES-256), dropping the originals and leaving a README_RANSOM table with a Proton Mail contact. It iterated from a failed login to a working fix in 31 seconds. On 2026-07-20 it returned to the same Langflow instance with ENCFORGE, a UPX-packed static Go 1.22.12 ELF ransomware (AES-256-CTR with an RSA-2048-wrapped key) targeting about 180 AI/ML artifact extensions (model checkpoints, SafeTensors, ONNX, GGUF, FAISS indexes, Parquet datasets, LoRA adapters), killing processes that hold files open, renaming files to .locked, dropping README/HOW_TO_DECRYPT/README_DECRYPT notes and self-deleting. Deployment used a Docker socket escape via a privileged container with the root filesystem mounted. Other Langflow flaws in CISA KEV: CVE-2026-33017 (added 2026-03-25) and CVE-2026-55255 (added 2026-07-07).
Malicious browser extensions (OX Security, reported to Google 2025-12-29): 'Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI' (600,000+ installs) and 'AI Sidebar with Deepseek, ChatGPT, Claude and extra' (300,000+ installs) exfiltrated complete AI chat histories, browsing data, internal URLs and tokens to attacker servers at 30-minute intervals under cover of 'anonymous analytics' consent. Microsoft cites 600,000+ installs affecting almost 10,000 organizations. The article also mentions a March 2026 compromise of the Axios npm package by a state-sponsored group and an OpenAI agent sandbox escape (July 2026); neither is detailed in sources reviewed here.
This record is an aggregate report-coverage threat: the Microsoft primary report was not retrievable in this run, so aggregate statistics rest on the Help Net Security summary.
MITRE ATT&CK techniques used in TL-2026-2880
Persistence
T1053.003 Scheduled Task/Job: Cron; T1176 Software Extensions
Execution
T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools; T1566 Phishing
Credential Access
T1110.003 Brute Force: Password Spraying; T1552.001 Unsecured Credentials: Credentials In Files
Impact
Exfiltration
Affected products and versions in AI-accelerated intrusions
- Langflow — Langflow
Vulnerable versions: < 1.3.0 (CVE-2025-3248)
Fixed in: 1.3.0; 1.9.1 (current guidance) - Nx — nx npm packages
Vulnerable versions: 20.9.0; 20.11.0; 20.12.0; 21.5.0; 21.6.0; 21.7.0; 21.8.0 - Alibaba — Nacos
Vulnerable versions: Versions affected by CVE-2021-29441 - Google — Chrome Web Store AI extensions
Vulnerable versions: fnmihdojmnkclgjpcoonokmkhjpjechg v1.9.6; inhcgfpbfdjbjogdfjbclgolkmhnooop
Remediation for AI-accelerated intrusions
Patches
- Langflow >= 1.3.0 for CVE-2025-3248; >= 1.9.0 for CVE-2026-33017; >= 1.9.1 for CVE-2026-55255
- Alibaba Nacos fixed release for CVE-2021-29441 authentication bypass
Immediate actions
- Patch Langflow to a current supported release (at least 1.9.1) and remove internet exposure of its /api/v1/validate/code endpoint; rotate AI provider keys, cloud credentials and database secrets reachable by the Langflow process
- Audit GitHub audit logs for repo.create and repo.access events containing 's1ngularity'; revoke and rotate GitHub and npm tokens on any host that installed affected Nx versions
- Remove the browser extensions with IDs fnmihdojmnkclgjpcoonokmkhjpjechg and inhcgfpbfdjbjogdfjbclgolkmhnooop and block deepaichats.com, chatsaigpt.com, chataigpt.pro and chatgptsidebar.pro
- Block and hunt for 45.131.66.106 and 64.20.53.230; hunt for cron entries beaconing every 30 minutes and a README_RANSOM table in MySQL
Workarounds
- Pin npm dependencies, use lockfiles, and disable lifecycle scripts (npm install --ignore-scripts) in CI where feasible
- Use short-lived scoped GitHub Action and npm publishing tokens
Longer-term hardening
- Enforce phishing-resistant MFA and monitor for password spray against identity providers
- Restrict AI coding CLIs on developer and CI hosts and prevent them running with permission-skipping flags
- Allowlist browser extensions and review AI-assistant extensions requesting broad host permissions
- Run AI orchestration frameworks (Langflow, Nacos, vector stores) in least-privilege containers without Docker socket mounts or privileged mode
CVEs associated with AI-accelerated intrusions
Timeline of AI-accelerated intrusions
- PromptLock artifacts uploaded to VirusTotal from the United States; ESET later reports the first AI-driven ransomware prototype (assessed as an NYU Tandon academic proof of concept)
- Malicious Nx npm package versions published via a stolen npm token (obtained through a vulnerable GitHub Action) abuse AI CLIs to harvest secrets and publish them to public s1ngularity-repository GitHub repos
- After GitHub mass-revokes leaked tokens (Aug 30-31), a third phase uploads 500+ repositories from two compromised accounts targeting one organization; active attacks subside afterward
- OX Security reports the malicious AI browser extensions (600,000+ and 300,000+ installs) harvesting ChatGPT/DeepSeek conversations to Google
- CVE-2026-33017 (Langflow unauthenticated RCE) added to CISA KEV
- Sysdig documents JADEPUFFER: an LLM agent exploits Langflow CVE-2025-3248, pivots to MySQL/Nacos and encrypts 1,342 configuration records for extortion
- JADEPUFFER returns to the same Langflow instance and deploys ENCFORGE, a Go ransomware destroying AI/ML artifacts across about 180 file extensions
- Help Net Security summarizes Microsoft's 2026 Digital Defense Report: phishing 23% and public-facing app exploitation 24% of intrusions, AI used across the attack lifecycle
Sources cited for AI-accelerated intrusions
- AI is giving attackers a head start, Microsoft warns (Help Net Security)
- s1ngularity's Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack (Wiz)
- s1ngularity supply chain attack (Orca Security)
- Someone Created the First AI-Powered Ransomware Using OpenAI's gpt-oss:20b Model (The Hacker News)
- ESET warns of PromptLock, the first AI-driven ransomware (Security Affairs)
- JADEPUFFER ransomware used AI agent to automate entire attack (BleepingComputer)
- New ENCFORGE ransomware targets AI (The Hacker News)
- AI agent exploits Langflow RCE (The Hacker News)
- JADEPUFFER's ENCFORGE: Agentic Ransomware Now Destroys AI Models (Cloud Security Alliance)
- Malicious Chrome extensions steal ChatGPT and DeepSeek conversations (Truesec)
- Chrome Extensions with 900,000 Downloads Caught Stealing AI Chats (SecurityWeek)
Detection coverage for TL-2026-2880
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2880 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.