Dev.to
7/29/2026

Cisco Talos IR Q2 2026: Observed Attack Chains of M365 Token Compromise and RMM-Disguised Ransomware
Short summary
Cisco Talos Q2 2026 incident response report details two major attack chains: one steals M365 tokens via QR code PDF phishing and OAuth device-code flows, then self-propagates through inbox rules and SharePoint; the other abuses legitimate RMM tools for SYSTEM persistence and domain-wide ransomware via GPO. The report maps full attack chains, detection signals for EDR/IdPs/email admins, and mitigation recommendations.
- •M365 token theft via QR code phishing and OAuth device-code bypasses MFA
- •RMM tools (MeshAgent, Zoho Assist) abused for persistence and ransomware deployment
- •Detection signals span email admins, IdPs, and EDR tools with mitigation guidance
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



