The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Talos Takes
Talos Takes artwork

Q2 Talos IR Trends: Phishing and authentication abuse spike

Talos Takes · 2026-07-29 · 16 min

0:00--:--

Key moments - from our scoring

Substance score

66 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality12 / 20
Guest Caliber15 / 20
Specificity & Evidence13 / 20
Conversational Craft12 / 20

The Q2 2026 Talos IR Quarterly Report reveals a significant escalation in attack sophistication across multiple vectors. Phishing campaigns now appear in over 50% of engagements, with threat actors deploying creative delivery mechanisms - embedded QR codes in PDFs, malicious links hosted on trusted platforms like SharePoint and Jira - to bypass traditional email gateways. Authentication abuse has surged to 65% of cases, with attackers exploiting push-based MFA through blast attacks and self-service device enrollment to gain legitimate-appearing access. The report also documents emerging threats like Sinobi ransomware and the ARToken platform, a full post-compromise toolkit that democratizes cloud-focused attacks by packaging advanced capabilities for broader threat actor use. Critical gaps in defensive posture include insufficient logging (preventing incident investigation), reliance on signature-based detection when behavior-based monitoring is needed, and overlooked controls like outbound email rate limiting. The report emphasizes phishing-resistant MFA (passkeys, hardware security keys), restricting MFA enrollment, centralizing logs with 90-day retention, and monitoring for suspicious patterns across identity provider logs, domain controllers, and NetFlow data.

Key takeaways

  • →Phishing has doubled in Talos IR engagements to over 50%, leveraging embedded QR codes in PDFs and trusted infrastructure like SharePoint to bypass email filters.
  • →Authentication abuse now affects 65% of incidents; defenders must move beyond checkbox MFA to phishing-resistant alternatives like passkeys and restrict self-service device enrollment.
  • →ARToken platform lowers the barrier to cloud-focused post-compromise attacks by packaging capabilities previously requiring sophisticated actors into a single toolkit accessible to broader threat groups.
  • →Behavior-based monitoring is essential for detecting legitimate tools like Mesh Agent and Zoho Assist when used maliciously outside normal patterns (unusual accounts, geolocation, hours).
  • →Outbound email rate limiting is a simple but highly effective control that can contain compromise spread by preventing attackers from sending thousands of emails from compromised accounts.

Guests

Lexi DiScola

Topics in this episode

Credential harvestingCisco Talos Incident ResponseQ2 2026 Incident Response Quarterly ReportPhishing campaigns with embedded QR codesMFA blastsPhishing-resistant MFA (passkeys, hardware security keys)Mesh AgentZoho AssistSinobi ransomwareWarlock group

Questions this episode answers

Why are phishing campaigns bypassing email gateways despite improved defenses?

Attackers use embedded QR codes in PDFs (bypassing text-parsing filters), host malicious links on trusted platforms like SharePoint and Jira that reputation filters whitelist, and rely on employee trust in legitimate infrastructure to evade traditional email security.

How should organizations stop adversary-in-the-middle attacks targeting MFA?

Implement phishing-resistant MFA like passkeys or hardware security keys, disable legacy authentication, and critically restrict self-service MFA device enrollment so attackers cannot enroll attacker-controlled devices without IT verification.

What are the indicators that attackers are abusing legitimate remote management tools?

Watch for behavior-based anomalies: tools running on unexpected systems, use by unauthorized accounts, activity outside business hours, unexpected geolocation enrollment requests, and suspicious activity following tool use - rather than focusing on the tool itself.

What logs should security teams prioritize if overwhelmed?

Centralize identity provider logs, domain controller logs, endpoint logs, and NetFlow data with minimum 90-day retention, as these are essential to determine how attackers gained access, what they did, and whether they were fully removed.

How effective is outbound email rate limiting at containing ransomware spread?

Highly effective; in multiple Q2 engagements, attackers sent 6,000-7,000 emails from compromised accounts, and rate limiting both contains internal spread and prevents propagation to trusted partner and customer networks.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode delivers concrete, actionable security insights grounded in real IR work: QR code PDFs bypassing email filters, trusted cloud platforms for malicious hosting, phishing-resistant MFA requirements, behavior-based monitoring for legitimate tools, and outbound email rate limiting. However, it relies somewhat on high-level summarization of the report rather than deep exploration - many points are introduced but not fully excavated, and some advice (e.g., 'training employees') borders on platitude.

by having the embedded images, it kind of makes it more difficult for these um security defenses to catch that kind of malicious delivery
Phishing resistant MFA, like pass keys or harper security keys, that coupled together with disabling legacy authentication, that's definitely much more effective at stopping these types of attacks

Originality

12 / 20

The episode covers timely, relevant attack trends (QR codes in PDFs, ARToken platform, legitimate tool abuse) drawn from Talos IR's real case work, which grounds it in practice rather than generic advice. However, the underlying insights - defenders need better logging, MFA isn't enough unless configured correctly, attackers blend in with legitimate traffic - are well-established in the security industry. The framing is competent but not particularly contrarian or first-principles.

attackers actually deployed PDFs that had embedded QR codes
ARToken platform...provides a full toolkit for post-compromise activity

Guest Caliber

15 / 20

Lexi DiScola is the author of Cisco Talos' official quarterly IR report and clearly works as a practitioner on active incident response cases, giving her direct operational credibility. The episode benefits from her hands-on perspective and specific case exposure. However, she is primarily a vendor researcher rather than an independent operator or customer-side security leader, which limits caliber slightly - she speaks from detection/advisory vantage point, not from running security for a major organization.

Lexi DiScola, who is the report's author
Talos IR encountered Sinobi Ransomware for the first time this quarter

Specificity & Evidence

13 / 20

The episode cites specific attack mechanisms (QR code PDFs, Mesh Agent, Zoho Assist, ARToken, Sinobi ransomware) and concrete defensive numbers (90-day log retention, 65% of engagements affected by auth abuse, 6-7k emails from compromised accounts). However, it lacks named victim organizations, specific dollar impacts, timelines, attack group names (except Warlock), and quantified outcome data. Evidence is more granular than pure advice but stops short of deep forensic specificity.

one engagement where the attackers actually deployed PDFs that had embedded QR codes
attackers sending thousands and thousands, sometimes like six, seven thousands of emails from compromised mail losses

Conversational Craft

12 / 20

Amy asks solid clarifying follow-ups ('what are the obvious indicators?' 'what should defenders look for?') and connects threads across topics. However, she rarely pushes back, challenge assumptions, or dig deeper when answers could be probed further. The conversation follows a predictable report-walk-through format with softball-to-moderate questions; there's no genuine disagreement, skepticism, or tough follow-ups that would elevate the dialogue. Host is competent but not particularly sharp or demanding.

what are the specific delivery mechanisms that are allowing these campaigns to bypass these traditional email gateways so effectively?
What should security teams be looking out for?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

attackers13security11legitimate11talos10quarter9tool8report7question7sure7activity7phishing6attacks6attacker6post6compromise6thousands6

Episode notes

In this episode, Amy and analyst Lexi DiScola unpack the trends Talos IR saw on the frontlines in Q2 2026. From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, we explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage. What configuration changes and visibility gaps could be the difference between a minor incident and a full-scale breach? How can you harden your environment with limited resources? Tune into this episode to stay one step ahead of an evolving threat landscape. Talos IR Quarterly Trends Report: Find Talos at Black Hat:

Full transcript

16 min

Transcribed and scored by The B2B Podcast Index.

Welcome to the Talos Takes podcast, where we discuss Talos' latest research and security news. This podcast is for everyone, from the C- suite to the frontlines. Hello everyone, and welcome back to Talos Takes. I'm your host, Amy Ciminnisi.

Today we are looking at the latest Cisco Talos Incident Response Quarterly Report for Q2 2026. I will link it in the show notes below, but the team has seen some pretty significant shifts this quarter. We saw a sharp surge in phishing and authentication abuse, the weaponization of legitimate remote management tools by ransomware operators, the impact of insufficient logging, and so much more. Joining me to break down these trends today is Lexi DiScola, who is the report's author.

We're going to walk through what Talos IR has been seeing on the front lines and more importantly, what security practitioners should be prioritizing to harden their defenses. Lexi, it's great to have you here. Hi, Amy. Thank you so much for having me back.

Yeah, absolutely. So this is a really interesting report. Um, it shows a pretty significant jump in phishing. Uh, it says it appears in over half of all Talos IR engagements, but last report it was just one-third.

You know, beyond just the sheer volume, what are the specific delivery mechanisms that are allowing these campaigns to bypass these traditional email gateways so effectively? Yeah, that's a good question. Uh, so we definitely see these actors continue to change up their delivery tactics to adapt to organizations who are just always improving their defenses. So, for example, this quarter we had one engagement where the attackers actually deployed PDFs that had embedded QR codes.

Um, these links directed to credential harvesting pages, which is something we always see. But that delivery mechanism is pretty unique because these types of PDFs can obviously bypass email filters that parse only text. So by having the embedded images, it kind of makes it more difficult for these um security defenses to catch that kind of malicious delivery. So that was something that was pretty creative.

Something that we consistently see is actors continue to host their malicious infrastructure on sites that are trusted by the victim organization. So this can be, you know, trusted cloud platforms such as SharePoint. This tactic just helps them bypass things like reputation filters and obviously also just appear more legitimate to the victim. Yeah, I remember a few months back, um, there was a blog about, I think, Jira and Confluence being used as delivery mechanisms for phishing links and things like that.

Um, and, you know, for employees who trust these websites so explicitly, that can be really dangerous. For sure. That's why, you know, um, training the human is always one of the most important aspects. You can do so much on the technical front, um, but really training your employees to recognize when something could be malicious makes a huge difference in the long run.

Yeah. Moving on to the authentication abuse, this was something that I found interesting after having read about it in the 2025 year in review so much. It jumped to 65% of our engagements this quarter. Um, it's pretty clear that attackers are consistently bypassing this standard push-based multi-factor authentication.

But for the security teams listening who feel like they have like checked their boxes by enabling MFA, what's the most important configuration change or mindset shift that they need to actually stop these, you know, adversary in the middle session token, you know, based attacks? I think it's a good question because, like you said, it does feel like just checking a box sometimes with MFA. I think the biggest shift is recognizing that not all MFA methods are equally effective. Phishing resistant MFA, like pass keys or harper security keys, that coupled together with disabling legacy authentication, that's definitely much more effective at stopping these types of attacks that you mentioned.

And then something else that's huge, restricting self-service MFA device enrollment. This is really a crucial step security teams can uh can take. This is something we see quarter after quarter, attackers, you know, enrolling their own attacker-controlled device and then using that to appear legitimate, legitimate. So that's a small step, just restricting self-service, saying, you know, if you want to enroll a device, you have to engage with our IT team.

That's something that's um gonna make a huge difference in preventing this activity as well. And so what does that look like, you know, as these attacks are playing out? What are kind of the obvious indicators that something is afoot? Is it a few weeks ago we had had a conversation about, you know, looking at your enrolled devices, making sure that all of those seem legitimate.

What should security teams be looking out for? MFA blasts is a huge thing we've seen, just continuing to send authentication requests until something's approved. So if you see like a, you know, a cluster of MFA requests, um, because something that we'll see is attackers just send, send, send until someone finally is like, yeah, I'll just accept this. I don't want these notifications on my phone anymore.

Um so that's that's an easy way these actors can gain access. But yeah, also with the with the uh um attacker-controlled um enrollment of MFA devices, if you see these requests or enrollments coming from someplace that's not expected in terms of geolocation, if the user is typically located in one place, but these requests are coming from somewhere different, or if it's outside of business hours, something like that. Um, so yeah, just circling back to it's really important to just if you want to have a new device enrolled, you have to physically speak with a human, speak with our IT desk, make sure that this request is legitimate.

So on the topic of ransomware, Talos IR encountered Sinobi. Is that is that how you say it? Sinobi ransomware. Well, I mean your guess is as good as mine.

All right. Well, we encountered Sinobi Ransomware for the first time this quarter. And um, we noticed both them and the Warlock group using tools like Mesh Agent and Zoho Assist to maintain that stealthy access. It's really not surprising that attackers move toward these more legitimate binaries because they help them blend in with normal traffic.

But what should, again, kind of similar to the last question, what should defenders look for to distinguish this authorized traffic from a malicious backdoor? Yeah. So I think that's that's kind of a theme we're seeing here, you know, attackers just trying to blend in with normal activity. I think, you know, specifically for this question, behavior-based monitoring instead of signature-based detection is really key for threats like this.

Basically, not just focusing on, you know, is this tool expected in the environment, but focusing on if its use is expected. So, for example, looking at these tools are running on systems where they shouldn't be, if they're being used by unexpected accounts, if they're running outside of business hours, like I mentioned before, or, you know, obviously if they're being followed by suspicious activity. Because you're right, oftentimes this tool is expected and authorized. Um, so yeah, just really focusing more on the use as opposed to the tool itself.

Um, and I think Joe had said that as much as attackers try to blend in with normal behavior, it's still abnormal behavior. There's still always something that you can see that will I guess more or less give it away. Like it, it might not be obvious, but it will be there. For sure.

Yeah. More nuanced, you know, as attackers develop to organizations' defenses. But I definitely do think, you know, there's always going to be differences in the way attacker is going to use a remote management tool as opposed to a legitimate, you know, MLP. So in this report, you highlighted the ARToken platform.

We actually talked about that on our last episode of Talos Takes. Hint, hint, go listen, everyone. Um, but this platform is so interesting. It provides a full toolkit for post-compromise activity.

It's not just phishing and credential theft. For listeners who didn't catch that episode, can you talk a little bit about how this changes the game for defenders and, you know, what does it mean for how we should be monitoring our environments? Yeah. So as you mentioned, this tool is significant because it goes beyond just stealing credentials.

It gives attackers basically a full toolkit for operating in cloud environments. Um that capability really emphasizes how defenders can't just focus on preventing unauthorized access, but they really also need to watch for things like suspicious token use, unusual cloud activity, changes to user permissions, basically just more of a focus on post-compromise activity because this tool lowers the barrier entry for cloud-focused attacks. That's something I usually was more aligned with more sophisticated actors.

This tool can package more of these advanced post-compromise capabilities into a single platform. A wide range of threat actors can use. So I think we can definitely expect attacks like these to grow in popularity. With the tools that are out there currently, you know, both ones like ARToken and also AI, like it is way easier for people to get into the network.

But like once they're actually in there, do they know what to do next? Are they for a loss? And it seems like ARToken really exactly like it says, like the post-compromise activity is just made so much easier. It's pretty wild.

For sure. I mean, you can give someone a tool, good, but do they know how to use it? I mean, that's the question. I guess we'll see as these uh platforms grow more popular.

Yeah. So something that I think all defenders need to be thinking about right now. Insufficient logging. It was a major weakness this quarter.

It often prevented from identifying how an attacker got in. If a security team is feeling overwhelmed, what are the must-have logs that they should prioritize to make sure that they have visibility? I mean, Amy, that's such a hard question. You know exactly which logs security teams have to keep.

I think the biggest priority is centralizing logs, keeping them long to investigate an incident. So Talos Instant Response typically recommends 90 days of retention. But if you can only prioritize a few sources, I think definitely you start with identity provider logs, domain controller and endpoint logs, NetFlow, post kind of things, because without those, really can be difficult to determine, you know, how an attacker got in, what they did, and if they've been fully removed.

So basically the lesson is you can't investigate what you can't see. So good logging is foundational. Finally, you mentioned that outbound email rate limiting is both simple but highly effective to stop attacks from propagating. You know, once a credential is stolen, attackers get into an account, spam out emails.

Why is this method so overlooked? And does it really how much of a difference can it make in containing that blast radius? So uh we typically, you know, highlight our top security weaknesses each quarter. This didn't fall technically into the top three of the security weaknesses, but it was something I wanted to add to the report because it was something that was prevalent across a number of engagements.

So I thought it was something that was worth mentioning. It's often overlooked to your question because I think organizations tend to focus on preventing initial compromise. And this is kind of like once initial access has been gained, this limits the post-compromise impact. But it really can give defenders more time to detect an incident and also contain it before it spreads.

In terms of how much difference, I mean, it varies, of course, by attack chain, but in a number of engagements this quarter, I mean, we saw attackers sending thousands and thousands, sometimes like six, seven thousands of emails from compromised mail losses to spread the infection. So it definitely can help contain the threat, both you know, internally within an organization, but also to partner in customer networks that are trusted as well. Right. Yeah.

And honestly, like if I were an attacker, this is such an effective way to, you know, spread across a network and maintain persistence. Like, I've I think I remember last uh quarterly trends report, or was that the year in review? Uh, one of the two. Internal phishing was highly popular with attackers.

It's kind of like a golden key. Once you have this trusted um email account, you can just reach out to frequent contacts, to partners, to customers, um, to upper management, you know, and just continue to propagate the attack appearing at legitimate. Usually we see attackers, you know, spoofing legitimate domains or using compromised infrastructure. In this case, really just using an account that appears so legitimate, it's one of the best ways to deceive um the recipient, to blend in with regular traffic, but to spread this attack from just one account to thousands and thousands.

Yeah. And very few people in an organization actually have the need to, you know, be sending out thousands of emails. So it just makes sense. I think that about wraps it up.

Lexi, thanks so much for coming on, sharing all this info with us. Appreciate it. Thank you so much for having me. Looking forward to next time.

If you want to hear more about the incidents we responded to directly from the Talos IR folks, we will be doing another Tales from the Frontlines webinar in August. So watch our socials and the newsletter for that registration link. If you're going to Black Hat, be sure to stop by the Cisco and Splunk booth. We'll be there throughout the conference, and I will share the link to our schedule below.

Thanks for tuning in, and until next time, stay safe out there.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • FortiBleed Attacks: Turning Fortinet Firewalls into Credential StealersSecure AF · on Credential harvesting34 / 100

More from Talos Takes

All episodes →
  • From evasion to detection: A guide to analyzing COM-based threats90 / 100
  • Patching in the dark: Managing unknown threats in complex environments58 / 100
  • When synthetic logs don’t lie: Generating coherent attack stories for better detection85 / 100
  • The trust paradox: How attackers weaponize legitimate SaaS platforms94 / 100
  • It's not you, it's your printer: State-sponsored and phishing threats in 202586 / 100
Explore the best B2B Engineering & DevTools podcasts →
All Talos Takes episodes →