How AI is reshaping the threat landscape, and what our Q1 2026 data shows (part one)
ID: afb91b38-9443-5f0f-86c8-48277881eda1
STIX ID: report--afb91b38-9443-5f0f-86c8-48277881eda1
Feed Name: Expel Blog
Threat Score
AI is not producing new attack primitives but is being abused as bait and a delivery vehicle in Q1 2026: ChatGPT Stealer (malicious browser extensions) and InstallFix (fake install pages/ClickFix) dominated incidents, ClickFix-based social-engineering overtook binary execution as the top delivery method (43.7%), browser extensions and credential weaponization rose, macOS infostealers gained prominence, and an Axios npm supply-chain compromise produced measurable cloud impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
