logo

Expel’s Q2 2026 threat report: Identity’s back on top, and Teams phishing isn’t slowing down

ID: 0a92a8a1-904a-53cb-a960-828af8d75702

STIX ID: report--0a92a8a1-904a-53cb-a960-828af8d75702

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2026-08-03

Date Updated: 2026-08-04

ADMIRALTY:B6
...
...

Expel’s Q2 2026 SOC report finds identity attacks rebounding to 68.1% of incidents, endpoint incidents overall declining but spiking in June due to Microsoft Teams phishing that delivers remote access tools with ransomware intent, and cloud incidents driven by misconfigurations, exposed secrets, and a newly observed npm/PyPI supply-chain worm called Mini Shai Hulud; the report indicates active exploitation and increasing attacker success against identities in May–June.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.