INTEL_REPORT
Cisco Talos Blog · published 4/22/2026, 10:00:34 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined. Phishing has not been the top vertical for initial access since Q2 2025. Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements wher…
https://blog.talosintelligence.com/ir-trends-q1-2026
sha256:2c8e95fc5f775e50e6b25fad2d370936e9f9d6722ff9d7e2e902c67b200996a6
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.