The Cisco Talos Incident Response (Talos IR) report for this quarter highlights a significant surge in phishing and authentication abuse. Phishing remains the primary initial access vector, appearing in over half of all engagements, with attackers increasingly utilizing QR code-embedded PDFs and trusted cloud platforms to bypass traditional email security. Authentication abuse rose sharply to 65 percent of engagements, as adversaries successfully bypassed multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, and MFA fatigue.
Ransomware accounted for 20 percent of incidents, featuring the emergence of Sinobi ransomware and new tactics from the Warlock group. Attackers are increasingly weaponizing legitimate remote monitoring and management (RMM) tools, such as MeshAgent and Zoho Assist, to maintain stealthy persistence. The report also details the ARToken phishing-as-a-service platform, which offers advanced toolkits for Microsoft 365 account compromise and post-exploitation. Top targeted sectors included healthcare, public administration, and manufacturing due to their critical need for operational uptime.
To counter these evolving threats, Talos IR recommends moving toward phishing-resistant MFA like FIDO2/WebAuthn and strengthening centralized logging to a minimum 90-day retention period. Organizations are also urged to prioritize robust patch management for internet-facing infrastructure and implement strict outbound email thresholds to disrupt the propagation of compromised mailboxes.
Top comments (0)