chiprook
← Security
SecurityOctober 3, 2026, 08:11

Microsoft: phishing that bypasses MFA hits 23% of intrusions

Microsoft's 2026 Digital Defense Report covering July 2025 to June 2026 says phishing was the initial access vector in 23% of intrusions, up from 7% a year earlier. Adversary-in-the-middle kits account for 44.6% of phishing techniques, and 87.7% of phishing intrusions involved credential or session harvesting.

Microsoft: phishing that bypasses MFA hits 23% of intrusions
#Microsoft#Defender
Read next
Security

Microsoft disrupts EvilTokens phishing service that hit 12,000 accounts

Security

Cisco ISE authentication bypass CVE-2026-76460: what defenders need to do now

Security

TrustSink: rogue external MFA provider steals passwords in Microsoft Entra logins

Security

dev.to hit by phishing comments posing as "DEV Support"