← Back to Feed

You were onto something with “It’s the Climb,” Miley

July 30, 2026 · Talos Intelligence · Severity: MEDIUM

Talos Intelligence's Q2 2026 Incident Response Trends report reveals a sharp rise in authentication abuse and advanced phishing tactics, with phishing accounting for over half of all engagements. Attackers are exploiting QR codes and platforms like ARToken to bypass multi-factor authentication (MFA), while ransomware groups abuse legitimate tools like MeshAgent and Zoho Assist for stealthy access. These tactics allow threat actors to blend malicious activity with normal traffic, particularly targeting healthcare and public administration sectors, where downtime is critical. The report urges organizations to adopt phishing-resistant MFA (e.g., FIDO2 or hardware keys), implement behavior-based monitoring to detect unauthorized tool usage, and enforce strict logging and patching protocols. Separately, authorities are investigating a coordinated cyberattack against over 30 Minnesota water systems, and hacked public Wi-Fi gateways have been weaponized to harvest corporate credentials. These incidents underscore the need for robust defenses against evolving threats.

You were onto something with “It’s the Climb,” Miley

Welcome to this week’s edition of the Threat Source newsletter. 

For my fianceé’s 30th birthday, I took her on a weekend trip to Shenandoah National Park – a favorite of ours since we went to a wedding there several years back. We’ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that’s largely considered the most difficult in Virginia. 

I've always been warned that at the beginning and end, you hate Old Rag. For the first 2.6 miles, you’re hiking a steep climb on a dirt road, with lots of switchbacks, and plenty of places where you turn a corner and groan, because there’s an even steeper section ahead. This part was pretty torturous, because 1) I felt like my heart was going to explode out of my chest, 2) I couldn’t breathe, and 3) several times, there was a family we passed as they were taking a break, then WE took a break and THEY passed US, and so on and so forth. So awkward. 

Finally, we reached the fun part: a mile-long rock scramble, where you're squeezing through (and down) narrow rock crevices, cramming your boots to desperately find any leverage to propel yourself upward, and using all your upper body strength to control your descent. This was definitely the most fun part, although my hands and knees were sore by the end.

After hiking for hours, you reach the top and realize it was all worth it, because the summit has a a spectacular vie—

You were onto something with “It’s the Climb,” Miley

... That’s what we get for being excited to hike in overcast weather. Well, at least the way back down is fun— oh wait, four miles downward on a fire trail, crushing your toes in the front of your hiking boots? Yike. 

It may sound like I’m complaining a lot about this hike, but it was genuinely the most fun one that I’ve done to date. By the time I was freshly showered and drinking an iced coffee in Culpeper, I was gushing about when we’d go back. 

There’s a really good tie-in to cybersecurity somewhere here. Ah, got it. 

Everyone has had those uphill hike phases with the endless documentation, patching, and alerts that keep you up at night. You’re waiting for the misery to end and hoping that around the next corner, you’ll see a sign that you’re almost out of the woods. Bruised and out of breath, you finally arrive at the exciting parts: a complex project that finally comes together, the thrill of stopping an attack, or a feeling of pride when someone you're mentoring gets a new certification. Maybe the payoff is something completely unexpected.

Those moments definitely don’t erase the exhaustion — you're still sore and bruised, and will be for days — but they do remind you why you started in the first place. 

The one big thing 

Talos released our Q2 2026 Incident Response Trends report, which showed a massive spike in authentication abuse and sophisticated phishing tactics. Phishing drove over half of all engagements, with attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-factor authentication (MFA). Additionally, ransomware operators are increasingly weaponizing legitimate remote management tools like MeshAgent and Zoho Assist to establish stealthy, persistent access. 

Why do I care? 

Standard email gateways and basic MFA are no longer enough to stop adversaries from bypassing traditional defenses. By abusing legitimate administrative tools and trusted cloud infrastructure, threat actors can easily blend malicious traffic with normal network activity to remain undetected before deploying ransomware. Furthermore, the continued targeting of health care and public administration highlights a deliberate focus on organizations with zero tolerance for downtime. 

So now what? 

Organizations must transition from push- and SMS-based MFA to phishing-resistant methods like FIDO2 or hardware security keys. Defenders should also shift to behavior-based monitoring, specifically hunting for unauthorized instances of administrative tools. Finally, configure centralized logging with at least 90 days of retention, enforce strict outbound email thresholds, and prioritize patching internet-exposed infrastructure.  

Read the full report for a deeper dive into this quarter's trends and observed MITRE ATT&CK techniques. 

Top security headlines of the week 

Authorities investigating a coordinated cyber attack against Minnesota water systems 
Federal and state authorities are investigating what they call a coordinated cyberattack over two days against operational technology at more than 30 community water systems in Minnesota. (Cybersecurity Dive

Hacked public Wi-Fi gateways used to harvest corporate credentials 
As part of the attacks, the hackers modified the DNS configurations of the compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure for credential theft. (SecurityWeek

Default Azure Automation setting enables cross-tenant identity takeover 
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, and cloud workloads. (DarkReading

Public proof-of-concept released for exploited Check Point SmartConsole authentication bypass 
The vulnerability is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. (The Hacker News

Can’t get enough Talos? 

The TTP: Built for IT. Used by attackers 
In this episode of The Talos Threat Perspective, Hazel, Craig and Joe explore how attackers are abusing legitimate Remote Monitoring and Management software, trusted services

Key Takeaways

  • Cybersecurity requires persistence and facing difficult challenges head-on.
  • The journey of improving security is as important as the end goal.
  • Regular assessments and continuous effort are key to staying secure.
☕ Buy a Coffee