Security · 1h ago
Cisco Talos details M365 token theft and RMM-based ransomware attacks
Cisco Talos IR observed two major attack chains in Q2 2026: one steals Microsoft 365 tokens via QR code phishing and OAuth device-code abuse, bypassing MFA; the other uses trojanized remote management tools like MeshAgent to achieve SYSTEM persistence and deploy ransomware across domains via GPO. The report highlights how attackers increasingly abuse legitimate tools and authentication flows to evade detection.
Meridian48 take
The report underscores a shift toward token theft and living-off-the-land tactics, making traditional perimeter defenses less effective against these sophisticated, multi-stage attacks.
Read the full reporting
Cisco Talos IR Q2 2026: Observed Attack Chains of M365 Token Compromise and RMM-Disguised Ransomware →
DEV Community
m365-token-theftrmm-ransomware