Report: Phishing Remains the Primary Initial Access Vector

Phishing is still the top initial access vector, accounting for more than half of cyberattacks observed during Q2 2026, according to a new report from Cisco Talos.

Report: Vishing and Device Code Phishing Are Surging

Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses ...

Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026

Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than 2 billion phishing threats detected each month during the second quarter of 2026.

Warning: Compromised Hotel Routers Send Users to Phishing Sites

Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. ...

Iranian APT Launches AI-Assisted Spear Phishing Attacks

The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.

Why You Can’t Arrest Your Way Out of Youth Cybercrime

Two days at INTERPOL on youth cybercrime, why offender prevention is real police work and why it has to out-recruit rather than out-threaten.

The Blind Spot: How “Bulletproof” Phishing Redirectors Slip Past SEGs

By Shikhar Dalela and Jeewan Singh Jalal The operators named the kit themselves. Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called ...

Inside the OS-Aware Phishing Kit Profiling Your Device

Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal Most phishing attacks pick a target and commit to a tactic. This one picks the tactic based on the target, which happens ...

Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows ...

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code phishing ...