Lead Research Note
Vishing Is a Control-Plane Problem, Not an Awareness Statistic
When a caller can reset a password or enroll a new authenticator, the help desk is operating an identity control plane and needs controls designed accordingly.
Category
Longer-form research notes, measurement studies, and periodic threat briefs.
Lead Research Note
When a caller can reset a password or enroll a new authenticator, the help desk is operating an identity control plane and needs controls designed accordingly.
Field Analysis
Google's 2026 public-sector M-Trends brief says vishing reached 11 percent of global infections, sharpening the case for stronger help-desk recovery and device-enrollment controls.
Read more:Google CloudMicrosoft Security Blog
Field Analysis
Vendor headlines about AI phishing blend volume, effectiveness, and survey sentiment into single numbers. Defenders need to separate those measurements to instrument the threat honestly.
Field Analysis
Copy Fail, Dirty Frag, and ssh-keysign-pwn show why local Linux privilege escalation still belongs in phishing and infrastructure-defense planning.
Read more:CERT-EUDirty Frag
Field Analysis
Phishing-resistant authentication reduces token theft risk, but account recovery, device replacement, and exception handling can reintroduce phishable paths.
Read more:CISAMicrosoft Security Blog
Field Analysis
Microsoft's Q1 2026 email threat review shows link-based phishing dominance, QR code growth, CAPTCHA-gated flows, and persistent business email compromise pressure.
Read more:Microsoft Security Blog
Field Analysis
QR phishing programs are easier to understand when teams measure scan context, report timing, landing-page behavior, and control coverage instead of only counting delivered messages.
Read more:Microsoft Security BlogCISA
Field Analysis
OAuth app grants accumulate over time, and stale consent can become a hidden access path when vendors, users, or integrations are later compromised.
Read more:Microsoft LearnThe Hacker News
Field Analysis
Healthcare organizations are experiencing clustered phishing campaigns aligned to regional staffing and patient billing cycles.
Read more:The Hacker NewsCISA
Field Analysis
Security leaders are expanding phishing KPIs beyond user clicks to include reporting speed, containment time, and repeat exposure risk.
Read more:Microsoft Security Blog