Email threat landscape: Q2 2026 trends and insights
2026-07-25T14:52:15Z•6af566c51ab881cf858fe4f2536e993c26c73536713f09fdbb151668b027c3ca
ACR StealerAI agentsAsyncAPICI/CD compromiseClickFixDefender ExpertsMicrosoft Entra IDOAuth abuseQ2 2026 trendsShinyHuntersTeams social engineeringTycoon2FAauth tokensbrowser credential theftcredential theftcyber insuranceimport-time payload deliveryincident responseleast privilegemisconfigured guest accessmulti-stage attacksnpm supply chainpasskeysphishingvishing
What happened
Microsoft Security Blog posts from July 2026 highlight Q2 trends and multiple active threat activities: disruption of the Tycoon2FA phishing platform has reduced some phishing techniques but adversaries shifted to Teams-based social engineering and more automated, multi-stage chains. Notable incidents include active ACR Stealer campaigns (late Apr–mid Jun 2026) using ClickFix lures to exfiltrate browser credentials, auth tokens, and sensitive documents; an AsyncAPI npm supply‑chain compromise that abused CI/CD and import‑time payload delivery; and OAuth abuse campaigns with tradecraft linkedto
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 6af566c51ab881cf858fe4f2536e993c26c73536713f09fdbb151668b027c3ca
- Enrichment time
- 2026-07-25T14:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.