Email threat landscape: Q2 2026 trends and insights

2026-07-23T20:52:23Zd3e13a3e48aa915ee926f29a5e6693706ff09737a71b7a918ed078a9a3589223
acr-stealerai-agentsasyncapiautomated-attack-chainsaxa-xlblack-hatclickfixcredential-theftdefender-expertsentra-ididentityimport-time-payloadincident-responseleast-privilegenpm-supply-chainoauth-abusepasskeysphishingsaas-securityshinyhunterssupply-chain-compromiseteams-social-engineeringtoken-thefttycoon2favishing

What happened

Microsoft Security Blog roundup (July 2026): Q2 email threat trends show declines in some phishing techniques after disruption of the Tycoon2FA platform but a shift toward Teams-based social engineering and more automated, multi-stage attacks. Microsoft observed active credential- and token-stealing campaigns (ACR Stealer using ClickFix lures) and a weaponized npm supply-chain compromise (AsyncAPI) delivering import-time payloads. Threat activity also included OAuth abuse and account takeover tradecraft associated with ShinyHunters (vishing, guest access/supply-chain targeting). Microsoft发布s/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
d3e13a3e48aa915ee926f29a5e6693706ff09737a71b7a918ed078a9a3589223
Enrichment time
2026-07-23T20:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.