Find notable cyber news and cases, enriched with sources, timelines, and signals.

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on compromise. The share of cases that began with phishing rose to just over half, up from one-third in the previous quarter. Other recurring entry paths included exploitation of public-facing applications and drive-by compromise.

Related Happenings

UAT-11764 QR code phishing campaign against organizations

Campaign
H score29 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

How related: The campaign, which is described as persistent and was ongoing as of late June 2026, uses auto-generated victim-tailored PDF documents which contain QR codes that direct victims to adversary-controlled Microsoft 365 credential harvesting pages.

About this happening: A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...

Kratos ecosystem shift changes threat-actor operations

Threat Actor Meta
H score39 First: 22.07.2026 02:07 Last: 22.07.2026 02:07 Sources 1

About this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...

23AndMe hit by network compromise

Incident
H score55 First: 16.07.2026 16:47 Last: 16.07.2026 16:47 Sources 1

About this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...

Latest development: 17.07.2026 17:30

23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.

Identity-based access becomes the leading ransomware initial-access trend in 2026

Trend
H score28 First: 15.07.2026 15:45 Last: 15.07.2026 15:45 Sources 1

About this happening: Identity-based attacks became the leading ransomware initial-access trend, raising the risk of credential abuse and legitimate login misuse across affected networks. S...

QR code phishing surged across email threats in Q1 2026

Trend
H score73 First: 05.05.2026 09:35 Last: 05.05.2026 09:35 Sources 1

How related: An example of this, as detailed by researchers, was a QR code phishing campaign which targeted organizations in an effort to harvest login credentials and further propagate the attacks by automatically targeting the victims’ contacts too.

About this happening: QR code phishing remains a growing email threat trend across organizations, with Q1 2026 telemetry showing it as the fastest-growing vector in Microsoft's reportin...

Timeline

  1. 28.07.2026 03:00 2 articles · 15h ago

    Cisco Talos reports phishing as the dominant initial access vector

    Technical Analysis Update

    Cisco Talos published an Incident Response Trends report showing that phishing accounted for the initial attack vector in just over half of incidents investigated during March to June 2026, rising from one-third in the previous quarter. The analysis also highlighted a persistent QR code phishing campaign attributed to UAT-11764 that targeted organizations with victim-tailored PDF files leading to Microsoft 365 credential-harvesting pages, then used stolen credentials for inbox-rule creation and follow-on phishing.

    Show sources