Email threat landscape: Q2 2026 trends and insights
2026-07-26T20:52:18Z•166952093ccb7f352674f1eeef5c5518cde88c4e12a8b289cd00b8a718976415
ACR StealerAI agentsAXA XLAsyncAPIBlack Hat USA 2026CI/CD compromiseClickFixEntra IDMicrosoft Defender ExpertsOAuth abuseShinyHuntersTeams-based social engineeringTycoon2FAauth tokensautomated attack chainscredential theftguest access misconfigurationimport-time payloadincident responseleast privilegenpm supply chainpasskeysphishingsupply chain attacksvishing
What happened
Microsoft Security Blog posts from July 2026 highlight a mixed threat landscape: disruption of the Tycoon2FA phishing platform contributed to declines in some phishing techniques, but threat actors evolved—expanding Teams-based social engineering and using increasingly automated, multi-stage attack chains. Microsoft observed active ACR Stealer campaigns (late Apr–mid Jun 2026) using ClickFix lures to steal browser credentials, auth tokens, and documents. A separate supply-chain compromise of AsyncAPI npm packages abused trusted CI/CD workflows to deliver import-time payloads. Microsoft Threat
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 166952093ccb7f352674f1eeef5c5518cde88c4e12a8b289cd00b8a718976415
- Enrichment time
- 2026-07-26T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.