// 3 CRITICAL · 6 ZERO-DAY · 11 CVE · 7 EXPLOIT IN THE LAST 24H
In Q2 2026, phishing became the leading initial access vector in over half of Cisco Talos Incident Response engagements, up from roughly one-third the prior quarter. Authentication abuse doubled to 65% of engagements, driven by AitM proxies, session-token theft, MFA fatigue, and self-enrolled devices. Ransomware operators Sinobi and Warlock (Storm-2603) weaponized legitimate RMM tools — MeshAgent and Zoho Assist — for stealthy persistence. Healthcare remained the most targeted sector for a second straight quarter at 17% of engagements.

Phishing became the primary initial access vector in the majority of Cisco Talos Incident Response engagements in Q2 2026, accounting for over 50% of cases — up from approximately one-third in the prior quarter. Cisco Talos published the IR Trends Q2 2026 report on July 28, documenting a parallel surge in authentication abuse to 65% of engagements, doubling from 35% in Q1. The data signals a paradigm shift: attackers no longer force systems; they traverse them with valid credentials and legitimate administrative tools repurposed for intrusion.

Key Takeaways
  • Phishing exceeded half of Talos IR engagements in Q2 2026, up from roughly one-third the previous quarter.
  • Authentication abuse jumped to 65% of engagements from 35% in Q1, with MFA bypass via AitM proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices.
  • Ransomware operators Sinobi and Warlock (Storm-2603) used legitimate RMM tools — trojanized MeshAgent and Zoho Assist — for persistent, stealthy access.
  • Healthcare was the most targeted sector for the second consecutive quarter at 17% of engagements, followed by public administration and manufacturing at 14% each.

From 33% to 50%: Phishing Becomes the Majority

The figure is clear and documented: in Q2 2026, phishing represented "over half of all Cisco Talos Incident Response (Talos IR) engagements," according to the official report. The rise from "approximately a third of engagements last quarter" marks an increase of more than 17 percentage points in a single quarter — not a statistical margin.

At the same time, authentication abuse reached 65% of engagements, doubling the 35% seen in Q1 2026. Cisco Talos attributes this acceleration to specific, now-standardized techniques: adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and attacker-enrolled devices. The finding is significant because it shows that multi-factor authentication, in its most common implementations (push notifications, SMS, software-based TOTP), no longer serves as an effective barrier against the attackers documented in the field.

"We also saw a spike in authentication abuse this quarter — observed in 65 percent of engagements compared to 35 percent last quarter — with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices, amongst other methods." — Cisco Talos IR Trends Q2 2026

MeshAgent and Zoho Assist: The Trusted-Tool Paradox

Ransomware incidents accounted for over 20% of engagements in Q2 2026, consistent with the nearly 20% in the prior quarter. Cisco Talos responded to the Sinobi ransomware for the first time, alongside the previously observed Nitrogen and Warlock variants. The technical novelty lies not in quantitative prevalence but in method.

Sinobi employed MeshAgent — a legitimate open-source remote management tool — as its primary command-and-control mechanism. According to the report, the binary was installed as a SYSTEM-level auto-start service with encrypted communication via WebSocket (WSS). This configuration allowed the actor to maintain "undetected access for approximately three days before ransomware deployment," blending malicious traffic with normal administrative activity.

Warlock, attributed to Storm-2603, followed a similar logic by deploying Zoho Assist Unattended Agent for remote control without a logged-in user. Cisco Talos notes it had not previously observed this tool associated with Warlock. In both cases, the issue is not a software vulnerability but the intentional reuse of trusted software against the organization that already uses it or fails to monitor it as a potential vector.

The mechanism is technically elegant for the attacker: signed tools, distributed through legitimate channels, with encrypted communications over standard ports, generate no signature-based alerts. Detection requires monitoring usage behavior, not mere presence.

UAT-11764: The Self-Fueling QR Campaign

Alongside the ransomware incidents, Cisco Talos tracked the QR phishing campaign attributed to actor UAT-11764, active from April 2026 and still operating at the end of June 2026. Targeting favors Australian organizations.

The technique unfolds in sequential stages: PDFs with auto-generated, per-victim QR codes pointing to adversary-controlled Microsoft 365 credential-harvesting pages. After compromise, the actor creates inbox rules to suppress responses, uses SharePoint to host malicious documents, and reuses the compromised mailbox's contact lists to expand the campaign's reach to internal and external targets.

Cisco Talos assesses with "high confidence" that UAT-11764 will continue to exploit this operation, using each newly compromised mailbox as propulsion for the next wave. The model is autocatalytic and resistant to point takedowns: there is no single domain or infrastructure to neutralize, but a network of legitimate mailboxes transformed into relays.

ARToken: Phishing-as-a-Service with 80+ API Endpoints

The report places ARToken in the broader context of PhaaS (Phishing-as-a-Service) platforms that lower the barrier to sophisticated attacks. The ARToken panel exposes over 80 API endpoints and features a React-based dashboard, per the technical details reported by Cisco Talos.

The platform bypasses MFA not by stealing passwords but by abusing the OAuth device authorization flow: the user is tricked into entering a code on an attacker-controlled page, which then obtains a valid session token. Once access is established, ARToken maintains persistence via Primary Refresh Token (PRT) and integrates email access, BEC (Business Email Compromise), and SharePoint exfiltration capabilities. The brief does not specify whether ARToken represents an evolution, a fork, or an affiliate of the previously documented EvilTokens platform, nor does it detail the exact business model.

What to Do Now

Recommendations derive directly from the Talos report and statements by analyst Lexi DiScola on the Talos Takes podcast.

  • Adopt phishing-resistant MFA: Lexi DiScola explicitly cites passkeys, FIDO2, and hardware security keys as "much more effective at stopping these types of attacks," paired with disabling legacy authentication. The shift from push/SMS-based MFA is now a defensive necessity, not an option.
  • Implement behavior-based monitoring on RMM tools: The focus must shift from "is this tool present in the environment?" to "is its use expected right now?" DiScola frames this as monitoring usage behavior rather than mere presence — essential when the line between legitimate and malicious tooling vanishes.
  • Review remote-access baselines: MeshAgent, Zoho Assist, and analogous tools must have documented usage policies, an up-to-date inventory, and centralized logging. The absence of an accurate asset inventory renders compromise invisible.
  • Strengthen control over OAuth and device code flow: Platforms like ARToken exploit legitimate OAuth flows; defense requires session monitoring, proactive revocation of suspicious tokens, and restrictions on app consent.

The healthcare sector, at 17% of engagements for a second straight quarter, and public administration at 14% demand priority attention: zero tolerance for downtime makes them prime targets, and the three-day persistence documented for Sinobi indicates reaction time is compressed beyond traditional margins.

The most disturbing finding in the report is not a single zero-day exploit, but the normalization of techniques that require no software vulnerabilities: stolen credentials, repurposed legitimate tools, abused OAuth flows. Perimeter security, conceived as a blocklist of known threats, has ceased to function as an exclusive model. The boundary is no longer between inside and outside, but between legitimate and malicious use of what is already inside.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. blog.talosintelligence.com
  2. talostakes.talosintelligence.com
  3. talosintelligence.com