Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 11 sources · 3 days · First seen · Last updated
Categories: TECHNOLOGY
Corporate phishing defense evolution
Entities: CISOs · IBM Security · Federal Bureau of Investigation · FHNW · G DATA CyberDefense
Overview
By the end of July 2026, the phishing threat landscape intensified. The FBI issued an alert on the Kali365 phishing‑as‑a‑Service platform that hijacks OAuth tokens to maintain persistent access to Microsoft 365 accounts, even bypassing multi‑factor authentication, and advised organizations to block the device‑code flow in conditional‑access policies. Cisco Talos reported that phishing was the initial access vector in more than half of its Q2 2026 engagements, up from one‑third in Q1, noting novel delivery methods such as QR‑code PDFs, device‑code phishing, and AI‑driven attacks. German data showed phishing comprised over 50 % of security incidents in Q2, alongside a rise in ransomware. These developments reinforce earlier observations that static, indicator‑based defenses lag behind fast‑evolving campaigns and that human error remains a primary breach cause. Together with G DATA’s customizable simulation templates and LLM‑driven adaptive training, the new intelligence underscores the need for dynamic, AI‑enhanced detection and continuous employee training to close persistent security gaps.
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [○ 1 SOURCE] The FBI warned that the Kali365 platform hijacks OAuth access and refresh tokens to gain persistent access to Microsoft 365 accounts, bypassing MFA. (FBI warning article)
- [○ 1 SOURCE] Phishing was the initial access vector in over 50 % of Cisco Talos incident engagements in Q2 2026, up from one‑third in Q1. (Cisco Talos research)
- [○ 1 SOURCE] The ARToken phishing‑as‑a‑Service platform exposed more than 80 API endpoints for device‑code phishing and related attacks. (Cisco Talos investigation)
- [○ 1 SOURCE] In Germany, phishing accounted for more than 50 % of all security incidents in Q2 2026. (German security report)
- [○ 1 SOURCE] Ransomware attacks made up just over one‑fifth of the engagements examined by Cisco Talos in Q2 2026. (Cisco Talos research)
- [○ 1 SOURCE] LockBit ransomware‑as‑a‑service group had 194 affiliates between 2022‑2024, with 80 affiliates receiving payment after successful attacks. (Black Hat Europe presentation)
- [○ 1 SOURCE] Common security gaps include outdated access‑control systems, blind‑spot camera placement, weak passwords, lack of equipment maintenance, and limited employee training. (Security best‑practice article)
- [○ 1 SOURCE] Campaign‑based phishing detection is recommended over IOC‑centric approaches to address modern, polymorphic phishing attacks. (Cofense analysis)
Timeline
-
2 days ago
[TECHNOLOGY] 8 sourcesFBI warns of Kali365 phishing-as-a-Service targeting Microsoft 365FBI alerts on Kali365 phishing‑as‑a‑Service targeting Microsoft 365 via OAuth token hijacking; Cisco Talos finds phishing as the primary entry point in Q2 2026; German data shows phishing causing over 50 % of ‑
-
5 days ago
[TECHNOLOGY] 3 sourcesAdvancements in Phishing Awareness Training: G DATA Adds Custom Templates and Researchers Test LLM‑Driven Adaptive ToolsG DATA launches a customizable template editor for its phishing‑simulation platform, while researchers unveil an LLM‑based adaptive training prototype at an IEEE conference.
Sources
arksysinc.com · b2b-cyber-security.de · borncity.com · deutscherpresseindex.de · educba.com · irf.fhnw.ch · presseradar.de · securityjournaluk.com · the-european.eu · welivesecurity.com · yourhome.eu
This summary has been updated 1 time: see revision history