惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
B
Blog RSS Feed
美团技术团队
博客园 - 【当耐特】
C
Check Point Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
M
MIT News - Artificial intelligence
aimingoo的专栏
aimingoo的专栏
J
Java Code Geeks
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 司徒正美
T
Tailwind CSS Blog
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
N
Netflix TechBlog - Medium
Vercel News
Vercel News
P
Proofpoint News Feed
IT之家
IT之家
I
InfoQ
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
As email phishing evolves, malicious attachments decline ...
Eric Geller · 2026-05-01 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

A new Microsoft report also describes the collapse of a once-dominant tool for generating phishing websites with fake CAPTCHAs.

Published May 1, 2026

Login information attached to large hook hanging in front of computer keyboard.

Getty Images

Dive Brief:

  • Phishing attacks using QR codes to direct victims to malicious links surged in the first quarter of 2026, Microsoft said in a threat report published on Thursday.
  • Email-based phishing attacks overwhelmingly used malicious links rather than attachments during the first three months of the year, reflecting the greater range of delivery options for externally hosted threats.
  • A major phishing-as-a-service (PhaaS) platform is significantly diminished after recent attempts to choke off its infrastructure, the company said.

Dive Insight:

The growth in QR-code phishing attacks is one of the most striking findings in Microsoft Threat Intelligence’s Q1 2026 report, which analyzes the 8.3 billion email-based phishing attacks that the company detected between January and March.

In January, 7.6 million threats used QR codes, but by March, it was 18.7 million, a 146% increase. That jump made QR-code phishing “the fastest-growing attack vector” during the quarter, Microsoft said.

“By embedding malicious URLs within image-based QR codes in the body of an email or within the contents of an attachment,” researchers explained, “threat actors attempt to exploit the limitations of text-based scanning engines and redirect victims to phishing sites on unmanaged mobile devices.”

Malware delivery web pages using fake CAPTCHA security checks also surged in Q1, largely driven by a massive increase in March after month-to-month declines in both January and February. The 11.9 million attacks using CAPTCHAs in March represented “the highest volume observed over the last year,” Microsoft said.

The PhaaS platform Tycoon2FA used to dominate CAPTCHA-based attacks, but after a global takedown involving law enforcement agencies, tech companies and security vendors, its influence has waned significantly. “At the end of 2025, more than three-quarters of CAPTCHA-gated phishing sites were hosted on Tycoon2FA infrastructure,” Microsoft said in its report. “This share decreased significantly over the course of the first three months of 2026, falling to just 41% in March.”

But Microsoft attributed Tycoon2FA’s decline to more than just the coordinated takedown campaign. “The broadening of CAPTCHA-gated phishing sites being used by an increasing number of threat actors and phishing kits, combined with the overall surge in volume, indicates that this technique is becoming a more entrenched component of the phishing playbook rather than a specialty of a small number of tools.”

By far the most common objective of email-based phishing attacks in Q1 was to steal login credentials. That has been true for months, but the share of attacks focused on credential theft grew in Q1, from 89% in January to 94% in March.

At the same time, traditional attachment-based malware delivery has almost become an afterthought — it represented just 5% to 6% of attacks in Q1, with the vast majority of attacks using phishing websites or “locally loaded spoofed sign-in screens.”