What's Happening?
Phishing attacks have become the dominant method for initial entry in cyber incidents, as reported by Cisco Talos in their Incident Response Trends report for March to June 2026. The report highlights that phishing accounted for over half of the incidents investigated,
marking a significant increase from the previous quarter. Attackers are employing innovative tools and techniques to evade detection, such as QR code phishing campaigns that target organizations to harvest login credentials. These campaigns use auto-generated, victim-tailored PDF documents containing QR codes that lead to adversary-controlled Microsoft 365 credential harvesting pages. The threat actor, identified as UAT-11764, uses methods to bypass traditional email gateway detections and host credential harvesting pages on trusted cloud platforms. Post-compromise actions include creating email inbox rules for defense evasion and using compromised accounts to send further phishing emails.
Why It's Important?
The rise in phishing attacks poses a significant threat to cybersecurity, as these attacks are becoming more sophisticated and harder to detect. The use of trusted platforms like Microsoft 365 and SharePoint to host malicious activities allows attackers to bypass standard security measures, increasing the risk of data breaches and unauthorized access. This trend highlights the need for enhanced security protocols, such as phishing-resistant multi-factor authentication and monitoring for suspicious activities. Organizations must adapt to these evolving threats to protect sensitive information and maintain operational integrity. The increasing complexity of phishing-as-a-service kits further exacerbates the challenge, providing cybercriminals with advanced tools to execute more effective attacks.
What's Next?
Organizations are advised to implement stricter security measures, such as blocking or flagging emails containing QR codes within PDF attachments and enforcing robust multi-factor authentication. Continuous monitoring for unusual inbox rule creation and SharePoint file staging is recommended to detect post-compromise activities. As phishing techniques evolve, cybersecurity professionals must stay vigilant and update their defenses to counteract these sophisticated threats. The development of more advanced anti-phishing technologies and training programs for employees to recognize phishing attempts will be crucial in mitigating the impact of these attacks.











