Talos: Attackers Refine Phishing Playbook To Target Critical Infrastructure
ID: dac54ae3-a409-5991-b7c1-f10b321cc4d8
STIX ID: report--dac54ae3-a409-5991-b7c1-f10b321cc4d8
Feed Name: Security Ledger
Cisco Talos' Q2 2026 Incident Response Trends report warns of a sharp increase in phishing (over 50% of engagements) and authentication abuse (65% of engagements), with healthcare, public administration and manufacturing heavily targeted; attackers are using advanced phishing techniques (QR-code embedded PDFs, compromised Microsoft 365/SharePoint, OAuth device-flow abuse), MFA bypass methods, and legitimate cloud/remote-management tools to evade defenses and deploy ransomware and other follow-on activity. Organizations are advised to adopt phishing-resistant MFA, reduce public exposure, improve logging and patch management to mitigate these risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
