惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
量子位
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
Y
Y Combinator Blog
Vercel News
Vercel News
云风的 BLOG
云风的 BLOG
宝玉的分享
宝玉的分享
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
Microsoft Security Blog
Microsoft Security Blog
B
Blog
Last Week in AI
Last Week in AI
有赞技术团队
有赞技术团队
博客园 - 聂微东
腾讯CDC
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
J
Java Code Geeks

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Phishing — sometimes with AI’s help — topped initial-acce...
Eric Geller · 2026-04-22 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

Hackers can now spin up fake login pages without writing a single line of code.

Published April 22, 2026

Login information attached to large hook hanging in front of computer keyboard.

Getty Images

Dive Brief:

  • Phishing was the most common way hackers breached their targets in the first quarter of 2026, after nearly a year out of the top spot, Cisco’s Talos threat intelligence team said in a report published on Wednesday.
  • Nearly 20% of Cisco’s incident-response engagements involved the preliminary stages of a ransomware attack, according to the report — significantly lower than in the first two quarters of 2025, when it was 50%.
  • Cisco also said it saw hackers using AI to improve phishing attacks.

Dive Insight:

Cisco described a credential-harvesting scheme in which attackers used the Softr AI platform to build a website that mimicked the Outlook Web Access login page. Cisco said this was “the first time we have documented the use of a specific AI tool by an adversary in a phishing campaign.” The company said it was fairly confident that attackers have been using Softr for credential-harvesting websites since May 2023 “and have done so with increasing frequency to date.”

The hackers could even have connected their fake login page to a third-party service like Google Sheets for automatic collection of stolen credentials, complete with notifications every time someone tried to log in — all without writing a single line of code.

“This incident demonstrates how AI tools can lower the barrier to entry for less sophisticated actors and/or accelerate the speed of phishing and credential-harvesting campaigns,” Cisco researchers wrote.

Government agencies and health-care organizations tied for the most common targets in the first quarter of 2026, according to the report. The government sector first claimed the top spot in Cisco’s data in Q3 2025 and has held it since then. Government agencies, which often are underfunded and full of outdated equipment, “may have access to sensitive data as well as a low downtime tolerance,” Cisco said, “making them attractive to financially motivated and espionage-focused threat groups.”

After the government and health-care sectors, the most common targets were in the professional, scientific and technical-services sector, the report said.

Deficient multifactor authentication was the most common security weakness leading to intrusions in the first quarter, according to Cisco, which said 35% of its engagements involved that problem. Sometimes, MFA wasn’t turned on; other times, it was active but misconfigured.

“Adversaries were able to bypass MFA by registering new devices to previously compromised accounts, and in one instance, by configuring Outlook clients to connect directly to Exchange servers, circumventing MFA requirements,” researchers wrote. “Addressing these weaknesses, especially by restricting self-service MFA enrollment and enforcing strong, centralized authentication policies, is essential to reducing risk and strengthening organizational resilience.”

Other common problems that Cisco saw in Q1 included vulnerable internet-facing infrastructure (25% of engagements) and inadequate logging capabilities (18%).