# AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)

> Microsoft's 2026 Digital Defense Report (July 2025 - June 2026), as summarized by Help Net Security on 2026-10-02, finds phishing now initiates 23% of intrusions (up from 7%) and public-facing application exploits 24% (up from 15%), with AI used for vulnerability discovery, phishing, and AI-orchestrated attack chains. Cited cases include the s1ngularity trojanized Nx npm packages, the PromptLock ransomware prototype, the JADEPUFFER agentic ransomware operation (July 2026), and a malicious AI browser extension with 600,000+ installs.

- **Published:** 2026-10-03T00:00:00Z
- **Last reviewed:** 2026-10-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2880
- **ID:** TL-2026-2880
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-3248, CVE-2021-29441

## Description

Help Net Security (Sinisa Markovic, 2026-10-02) summarizes Microsoft's 2026 Digital Defense Report covering July 2025 to June 2026. Key statistics: median time from vulnerability disclosure to weaponization is well below 24 hours; roughly 72,000 CVEs are tracked for 2026 (on track for a record); phishing was the initial access vector in 23% of intrusions (7% the prior year); exploitation of public-facing applications accounted for 24% (15% prior year); among intrusions involving valid accounts, credential harvesting was observed in 52.2% and active password spray in 18.4%. Microsoft states that frontier models (Anthropic Mythos and OpenAI GPT-5.5, per the article) demonstrated orchestration of a 32-step attack chain achieving full domain control in an emulated environment, with open-weight models lagging by about seven months. Chinese state actors are described as using AI for vulnerability searching and exploitation tips, Russian actors as using vibe-coding and AI-generated tooling to scale operations, and North Korean actors as using AI for persona development, social engineering, malware creation, infrastructure management and agentic workflows. No named actor, CVE, or IOC is cited in the article itself; the IOCs below come from the primary reports for the incidents it references.

The s1ngularity supply-chain attack (disclosed 2025-08-26): an attacker obtained an npm publishing token for the Nx build system through a vulnerable GitHub Action and published malicious Nx package versions (20.9.0, 20.11.0, 20.12.0, 21.5.0, 21.6.0, 21.7.0, 21.8.0 per Wiz). A postinstall script harvested environment variables and GitHub/npm tokens, and was the first known supply-chain malware to abuse locally installed AI CLIs (claude with --dangerously-skip-permissions, gemini with --yolo, Amazon Q with --trust-all-tools) to search the filesystem for secrets. Data was published to public GitHub repositories named s1ngularity-repository on victim accounts; npm tokens were also sent to webhook.site. Wiz measured 1,700+ users with leaked secrets, 2,000+ verified secrets and 20,000+ files; a second phase abused leaked tokens to make 6,700+ private repositories public across 480+ accounts; the shutdown commands appended to .bashrc were also observed. Microsoft cites 225 victims, about 2,000 secrets and 20,000 files.

PromptLock (ESET, 2025-08-25 VirusTotal upload): a Go program that uses the gpt-oss:20b model via the Ollama API to generate Lua scripts at runtime for filesystem enumeration, data exfiltration and encryption (SPECK 128-bit) on Windows, Linux and macOS. ESET later clarified it is an academic proof of concept (NYU Tandon), not in-the-wild malware.

JADEPUFFER (Sysdig, 2026-07-01; update 2026-07-20/21): described as the first documented ransomware operation driven end-to-end by an LLM agent. Initial access was via CVE-2025-3248, an unauthenticated RCE in Langflow's /api/v1/validate/code endpoint (CVSS 9.8, fixed in 1.3.0, in CISA KEV since 2025-05-05). The agent dumped Langflow's PostgreSQL database, collected host information and environment variables, installed cron-based beaconing every 30 minutes, moved laterally with harvested root credentials to a production MySQL/Alibaba Nacos server (CVE-2021-29441 auth bypass used to create rogue admin accounts), and encrypted 1,342 Nacos configuration records using MySQL AES_ENCRYPT (AES-128-ECB despite claiming AES-256), dropping the originals and leaving a README_RANSOM table with a Proton Mail contact. It iterated from a failed login to a working fix in 31 seconds. On 2026-07-20 it returned to the same Langflow instance with ENCFORGE, a UPX-packed static Go 1.22.12 ELF ransomware (AES-256-CTR with an RSA-2048-wrapped key) targeting about 180 AI/ML artifact extensions (model checkpoints, SafeTensors, ONNX, GGUF, FAISS indexes, Parquet datasets, LoRA adapters), killing processes that hold files open, renaming files to .locked, dropping README/HOW_TO_DECRYPT/README_DECRYPT notes and self-deleting. Deployment used a Docker socket escape via a privileged container with the root filesystem mounted. Other Langflow flaws in CISA KEV: CVE-2026-33017 (added 2026-03-25) and CVE-2026-55255 (added 2026-07-07).

Malicious browser extensions (OX Security, reported to Google 2025-12-29): 'Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI' (600,000+ installs) and 'AI Sidebar with Deepseek, ChatGPT, Claude and extra' (300,000+ installs) exfiltrated complete AI chat histories, browsing data, internal URLs and tokens to attacker servers at 30-minute intervals under cover of 'anonymous analytics' consent. Microsoft cites 600,000+ installs affecting almost 10,000 organizations. The article also mentions a March 2026 compromise of the Axios npm package by a state-sponsored group and an OpenAI agent sandbox escape (July 2026); neither is detailed in sources reviewed here.

This record is an aggregate report-coverage threat: the Microsoft primary report was not retrievable in this run, so aggregate statistics rest on the Help Net Security summary.

## MITRE ATT&CK

- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools
- T1110.003 Brute Force: Password Spraying
- T1552.001 Unsecured Credentials: Credentials In Files
- T1078 Valid Accounts
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1059.006 Command and Scripting Interpreter: Python
- T1053.003 Scheduled Task/Job: Cron
- T1176 Software Extensions
- T1071.001 Application Layer Protocol: Web Protocols
- T1567 Exfiltration Over Web Service
- T1485 Data Destruction

## Sources

- [AI is giving attackers a head start, Microsoft warns (Help Net Security)](https://www.helpnetsecurity.com/2026/10/02/ai-cybersecurity-threats-microsoft-report/)
- [s1ngularity's Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack (Wiz)](https://wiz.io/blog/s1ngularitys-aftermath)
- [s1ngularity supply chain attack (Orca Security)](https://orca.security/resources/blog/s1ngularity-supply-chain-attack/)
- [Someone Created the First AI-Powered Ransomware Using OpenAI's gpt-oss:20b Model (The Hacker News)](https://thehackernews.com/2025/08/someone-created-first-ai-powered.html)
- [ESET warns of PromptLock, the first AI-driven ransomware (Security Affairs)](https://securityaffairs.com/181595/malware/eset-warns-of-promptlock-the-first-ai-driven-ransomware.html)
- [JADEPUFFER ransomware used AI agent to automate entire attack (BleepingComputer)](https://bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack)
- [New ENCFORGE ransomware targets AI (The Hacker News)](https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html)
- [AI agent exploits Langflow RCE (The Hacker News)](https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html)
- [JADEPUFFER's ENCFORGE: Agentic Ransomware Now Destroys AI Models (Cloud Security Alliance)](https://labs.cloudsecurityalliance.org/research/csa-research-note-jadepuffer-agentic-ransomware-ai-models-20)
- [Malicious Chrome extensions steal ChatGPT and DeepSeek conversations (Truesec)](https://www.truesec.com/hub/blog/chrome-extension-steal-chatgpt-and-deepseek-conversations)
- [Chrome Extensions with 900,000 Downloads Caught Stealing AI Chats (SecurityWeek)](https://www.securityweek.com/chrome-extensions-with-900000-downloads-caught-stealing-ai-chats/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2880
