Microsoft Email Threat Landscape Report Q2, 2026

Microsoft have just released their email threat landscape report for Q2, 2026. Without a doubt, phishing is still the number one threat vector, with Microsoft detecting 7.6 billion email-based phishing threats in the quarter, with credential phishing remaining the dominant objective behind malicious payloads.

Of these malicious payloads 38% were html attachments, and 27% were contained within PDFs. Realistically, imo there isn't really a reason why an organisation should allow html through its email filters, if you assess the attachments coming through your organisation, I doubt you would see even 0.5% of attachments containing html attachments, so a good quick win would be to block these attachments along with rar and other non standard extensions at your email gateway.

You can access the report here: https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/

#danweis #boardroomcyber #nexon #hackproofyourself #phishing #microsoft #threatlandscape #cyberattacks

Next
Next

CISA Adds Four Vulnerabilities to the KEV Catalog