Email threat landscape: Q2 2026 trends and insights

2026-07-24T20:52:14Z24b7995aeda374a6675b3671b70d43d67fc2c5e1dd0f431878ca092563b39a1d
ACR StealerAXA XLAsyncAPICI/CD compromiseClickFixEntra IDMicrosoft DefenderOAuth abuseShinyHuntersTeams social engineeringTycoon2FAauthentication tokensautomated attacksbrowser credential theftidentity and accessimport-time payload deliveryincident responseleast privilege for AI agentsmulti-stage attacksnpmpasskeysphishingsupply chainthreat intelligence

What happened

Microsoft Security Blog (July 2026) highlights rising supply-chain and OAuth abuse threats alongside evolving phishing tradecraft. Key findings: disruption of the Tycoon2FA phishing platform drove declines in some phishing techniques, but actors shifted to Teams-based social engineering and increasingly automated, multi-stage attack chains; ACR Stealer campaigns (using ClickFix lures) exfiltrate browser credentials, auth tokens, and documents; an AsyncAPI npm supply-chain compromise abused CI/CD/import-time payload delivery to distribute malware; ShinyHunters-linked activity is abusing OAuth,v

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
24b7995aeda374a6675b3671b70d43d67fc2c5e1dd0f431878ca092563b39a1d
Enrichment time
2026-07-24T20:52:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Email threat landscape: Q2 2026 trends and insights · Baitaphish