Find notable cyber news and cases, enriched with sources, timelines, and signals.

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on compromise. The share of cases that began with phishing rose to just over half, up from one-third in the previous quarter. Other recurring entry paths included exploitation of public-facing applications and drive-by compromise.

Related Happenings

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

Microsoft Teams OAuth phishing campaign targeting 120 organizations

Campaign
H score30 First: 30.07.2026 15:00 Last: 30.07.2026 15:00 Sources 1

About this happening: A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...

UAT-11764 QR code phishing campaign against organizations

Campaign
H score29 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

How related: The campaign, which is described as persistent and was ongoing as of late June 2026, uses auto-generated victim-tailored PDF documents which contain QR codes that direct victims to adversary-controlled Microsoft 365 credential harvesting pages.

About this happening: A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...

Kratos ecosystem shift changes threat-actor operations

Threat Actor Meta
H score39 First: 22.07.2026 02:07 Last: 22.07.2026 02:07 Sources 1

About this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...

Timeline

  1. 28.07.2026 03:00 2 articles · 10d ago

    Cisco Talos reports phishing as the dominant initial access vector

    Technical Analysis Update

    Cisco Talos published an Incident Response Trends report showing that phishing accounted for the initial attack vector in just over half of incidents investigated during March to June 2026, rising from one-third in the previous quarter. The analysis also highlighted a persistent QR code phishing campaign attributed to UAT-11764 that targeted organizations with victim-tailored PDF files leading to Microsoft 365 credential-harvesting pages, then used stolen credentials for inbox-rule creation and follow-on phishing.

    Show sources