Expel’s Q2 2026 threat report: Identity’s back on top, and Teams phishing isn’t slowing down
ID: 0a92a8a1-904a-53cb-a960-828af8d75702
STIX ID: report--0a92a8a1-904a-53cb-a960-828af8d75702
Feed Name: Expel Blog
Threat Score
Expel’s Q2 2026 SOC report finds identity attacks rebounding to 68.1% of incidents, endpoint incidents overall declining but spiking in June due to Microsoft Teams phishing that delivers remote access tools with ransomware intent, and cloud incidents driven by misconfigurations, exposed secrets, and a newly observed npm/PyPI supply-chain worm called Mini Shai Hulud; the report indicates active exploitation and increasing attacker success against identities in May–June.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
