CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3332

As cited

Copy frozen at (site build).

threat intel

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Cisco Talos Incident Response released Q2 2026 trend data showing phishing rose to over half of all engagements, with attackers using QR codes in PDFs and trusted cloud platforms to evade email gateways. Authentication abuse incidents doubled to 65 percent of engagements, featuring adversary-in-the-middle proxies, session-token theft, and MFA fatigue attacks. Ransomware comprised 20 percent of incidents and increasingly leveraged legitimate remote management tools like MeshAgent and Zoho Assist for stealthy persistence.

Why it matters: Security teams must immediately implement QR code filtering in email, deploy phishing-resistant MFA, monitor for suspicious inbox rules and SharePoint activity, and enforce strict controls on remote management tools, as these are now primary attack vectors affecting organizations across industries.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Cisco Talos Incident Response reported that phishing increased to over half of all Q2 2026 engagements, with attackers using QR codes in PDFs and trusted cloud platforms to evade email gateways. Authentication abuse incidents nearly doubled to 65 percent of engagements, driven by adversary-in-the-middle proxies, session-token theft, and multifactor authentication (MFA) fatigue attacks, while ransomware operators leveraged legitimate remote monitoring and management (RMM) tools like MeshAgent and Zoho Assist. A persistent campaign dubbed UAT-11764 targeted Australian organizations with QR code phishing since April 2026, harvesting Microsoft 365 credentials and weaponizing SharePoint and email for lateral spread.

Why it matters: Security teams must immediately block QR codes in PDF attachments, enforce phishing-resistant MFA on cloud email accounts, and monitor for suspicious inbox rules and SharePoint activity, as attackers are successfully bypassing traditional gateways and MFA through multiple techniques. Organizations using RMM tools should implement strict behavior-based monitoring and administrative binary controls to detect stealthy ransomware lateral movement. Identity and access control practitioners should prioritize detection of MFA fatigue, device-code phishing, and token persistence mechanisms exploited by phishing-as-a-service platforms like ARToken.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Cisco Talos Incident Response reported that phishing increased to over half of all Q2 2026 engagements, with attackers using QR codes in PDFs and trusted cloud platforms to evade email gateways. Authentication abuse incidents nearly doubled to 65 percent of engagements, driven by adversary-in-the-middle proxies, session-token theft, and multifactor authentication (MFA) fatigue attacks, while ransomware operators leveraged legitimate remote monitoring and management (RMM) tools like MeshAgent and Zoho Assist. A persistent campaign dubbed UAT-11764 targeted Australian organizations with QR code phishing since April 2026, harvesting Microsoft 365 credentials and weaponizing SharePoint and email for lateral spread.

Why it matters: Security teams must immediately block QR codes in PDF attachments, enforce phishing-resistant MFA on cloud email accounts, and monitor for suspicious inbox rules and SharePoint activity, as attackers are successfully bypassing traditional gateways and MFA through multiple techniques. Organizations using RMM tools should implement strict behavior-based monitoring and administrative binary controls to detect stealthy ransomware lateral movement. Identity and access control practitioners should prioritize detection of MFA fatigue, device-code phishing, and token persistence mechanisms exploited by phishing-as-a-service platforms like ARToken.

VendorsMicrosoftCisco
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary