logo

How AI is reshaping the threat landscape, and what our Q1 2026 data shows (part one)

ID: afb91b38-9443-5f0f-86c8-48277881eda1

STIX ID: report--afb91b38-9443-5f0f-86c8-48277881eda1

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2026-04-30

Date Updated: 2026-05-01

...
...

AI is not producing new attack primitives but is being abused as bait and a delivery vehicle in Q1 2026: ChatGPT Stealer (malicious browser extensions) and InstallFix (fake install pages/ClickFix) dominated incidents, ClickFix-based social-engineering overtook binary execution as the top delivery method (43.7%), browser extensions and credential weaponization rose, macOS infostealers gained prominence, and an Axios npm supply-chain compromise produced measurable cloud impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.