Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026
Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than 2 billion phishing threats detected each month during the second quarter of 2026.
Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.
Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than 2 billion phishing threats detected each month during the second quarter of 2026.
Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. ...
Threat actors are increasingly abusing trusted workflows to carry out attacks, according to a new report from Gen Digital.
The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.
A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red ...
By Shikhar Dalela and Jeewan Singh Jalal The operators named the kit themselves. Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called ...
This year National Social Engineering Day falls on Aug. 6. This day is designed to give us an opportunity to remind people that cybercriminals do not always need sophisticated malware, an ...
Researchers at Lexfo are tracking three sophisticated phishing kits that were built using open-source components, primarily based on the publicly available adversary-in-the-middle (AiTM) ...
Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal Most phishing attacks pick a target and commit to a tactic. This one picks the tactic based on the target, which happens ...
Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code phishing ...