惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
MyScale Blog
MyScale Blog
Recent Announcements
Recent Announcements
N
Netflix TechBlog - Medium
GbyAI
GbyAI
Vercel News
Vercel News
The GitHub Blog
The GitHub Blog
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Visual Studio Blog
Martin Fowler
Martin Fowler
腾讯CDC
大猫的无限游戏
大猫的无限游戏
aimingoo的专栏
aimingoo的专栏
云风的 BLOG
云风的 BLOG
J
Java Code Geeks
WordPress大学
WordPress大学
P
Proofpoint News Feed
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
有赞技术团队
有赞技术团队
人人都是产品经理
人人都是产品经理
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
As email phishing evolves, malicious attachments decline ...
Eric Geller · 2026-05-01 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

A new Microsoft report also describes the collapse of a once-dominant tool for generating phishing websites with fake CAPTCHAs.

Published May 1, 2026

Login information attached to large hook hanging in front of computer keyboard.

Getty Images

Dive Brief:

  • Phishing attacks using QR codes to direct victims to malicious links surged in the first quarter of 2026, Microsoft said in a threat report published on Thursday.
  • Email-based phishing attacks overwhelmingly used malicious links rather than attachments during the first three months of the year, reflecting the greater range of delivery options for externally hosted threats.
  • A major phishing-as-a-service (PhaaS) platform is significantly diminished after recent attempts to choke off its infrastructure, the company said.

Dive Insight:

The growth in QR-code phishing attacks is one of the most striking findings in Microsoft Threat Intelligence’s Q1 2026 report, which analyzes the 8.3 billion email-based phishing attacks that the company detected between January and March.

In January, 7.6 million threats used QR codes, but by March, it was 18.7 million, a 146% increase. That jump made QR-code phishing “the fastest-growing attack vector” during the quarter, Microsoft said.

“By embedding malicious URLs within image-based QR codes in the body of an email or within the contents of an attachment,” researchers explained, “threat actors attempt to exploit the limitations of text-based scanning engines and redirect victims to phishing sites on unmanaged mobile devices.”

Malware delivery web pages using fake CAPTCHA security checks also surged in Q1, largely driven by a massive increase in March after month-to-month declines in both January and February. The 11.9 million attacks using CAPTCHAs in March represented “the highest volume observed over the last year,” Microsoft said.

The PhaaS platform Tycoon2FA used to dominate CAPTCHA-based attacks, but after a global takedown involving law enforcement agencies, tech companies and security vendors, its influence has waned significantly. “At the end of 2025, more than three-quarters of CAPTCHA-gated phishing sites were hosted on Tycoon2FA infrastructure,” Microsoft said in its report. “This share decreased significantly over the course of the first three months of 2026, falling to just 41% in March.”

But Microsoft attributed Tycoon2FA’s decline to more than just the coordinated takedown campaign. “The broadening of CAPTCHA-gated phishing sites being used by an increasing number of threat actors and phishing kits, combined with the overall surge in volume, indicates that this technique is becoming a more entrenched component of the phishing playbook rather than a specialty of a small number of tools.”

By far the most common objective of email-based phishing attacks in Q1 was to steal login credentials. That has been true for months, but the share of attacks focused on credential theft grew in Q1, from 89% in January to 94% in March.

At the same time, traditional attachment-based malware delivery has almost become an afterthought — it represented just 5% to 6% of attacks in Q1, with the vast majority of attacks using phishing websites or “locally loaded spoofed sign-in screens.”