Threats · 137 days ago
No-Code Phishing Pages Reclaim Exchange Credentials Phishing is back at the top because attackers no longer need custom code to steal Exchange credentials. The standard response still treats phishing as a lure problem, but this case shows the real shift: no-code AI builders can now generate convincing OWA login pages and wire stolen credentials to external storage with almost no technical effort.
Cisco Talos said phishing accounted for over a third of initial-access engagements in Q1 2026, with public administration and health care tied as the most targeted sectors at 24 percent each. Talos also documented the first confirmed use of Softr in a phishing engagement, where attackers built a page that mimicked Microsoft Exchange and Outlook Web Access and used form templates and vibe coding features to collect credentials.
The risk is not just better-looking phishing. It is faster, cheaper credential harvesting that can be repeated at scale by less skilled actors, and the same no-code tooling can keep lowering the barrier as adoption grows.
Timeline Sources 6 sources covering this story
The Register Security May 1
Most phishing now uses AI, says KnowBe4
: KnowBe4 says 86% of phishing it tracked used AI, and inboxes are only the start
The Register Security Apr 30
Most phishing now uses AI, says KnowBe4
: KnowBe4 says 86% of phishing it tracked used AI, and inboxes are only the start
Proofpoint Apr 28
AI-Era Threats Spread Beyond Email Into SaaS, Collaboration Apps, and AI Assistants
Proofpoint’s annual survey of 1,453 security professionals shows that organizations hit by an AI incident saw threats appear across every collaboration channel, not just the inbox.
Dark Reading Apr 24
AI Phishing Is No. 1 With a Bullet for Cyberattackers
Companies are seeing a significant influx of AI-powered phishing, as cyberattackers progress from small campaigns to 1-to-1 personalized attacks.
Cybersecurity Dive Apr 22
Phishing — sometimes with AI’s help — topped initial-access methods in Q1, Cisco says
Hackers can now spin up fake login pages without writing a single line of code.
Talos Intelligence Apr 22
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
Phishing has not been the top vertical for initial access since Q2 2025.
Help Net Security Apr 22
Phishing reclaims the top initial access spot, attackers experiment with AI tools - Help Net Security
Phishing tops initial access vectors in Q1 2026 as public sector attacks persist.
Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-05-01
Editions Related stories
Threats · 137 days ago
No-Code Phishing Pages Reclaim Exchange Credentials Phishing is back at the top because attackers no longer need custom code to steal Exchange credentials. The standard response still treats phishing as a lure problem, but this case shows the real shift: no-code AI builders can now generate convincing OWA login pages and wire stolen credentials to external storage with almost no technical effort.
Cisco Talos said phishing accounted for over a third of initial-access engagements in Q1 2026, with public administration and health care tied as the most targeted sectors at 24 percent each. Talos also documented the first confirmed use of Softr in a phishing engagement, where attackers built a page that mimicked Microsoft Exchange and Outlook Web Access and used form templates and vibe coding features to collect credentials.
The risk is not just better-looking phishing. It is faster, cheaper credential harvesting that can be repeated at scale by less skilled actors, and the same no-code tooling can keep lowering the barrier as adoption grows.
Timeline Sources 6 sources covering this story
The Register Security May 1
Most phishing now uses AI, says KnowBe4
: KnowBe4 says 86% of phishing it tracked used AI, and inboxes are only the start
The Register Security Apr 30
Most phishing now uses AI, says KnowBe4
: KnowBe4 says 86% of phishing it tracked used AI, and inboxes are only the start
Proofpoint Apr 28
AI-Era Threats Spread Beyond Email Into SaaS, Collaboration Apps, and AI Assistants
Proofpoint’s annual survey of 1,453 security professionals shows that organizations hit by an AI incident saw threats appear across every collaboration channel, not just the inbox.
Dark Reading Apr 24
AI Phishing Is No. 1 With a Bullet for Cyberattackers
Companies are seeing a significant influx of AI-powered phishing, as cyberattackers progress from small campaigns to 1-to-1 personalized attacks.
Cybersecurity Dive Apr 22
Phishing — sometimes with AI’s help — topped initial-access methods in Q1, Cisco says
Hackers can now spin up fake login pages without writing a single line of code.
Talos Intelligence Apr 22
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
Phishing has not been the top vertical for initial access since Q2 2025.
Help Net Security Apr 22
Phishing reclaims the top initial access spot, attackers experiment with AI tools - Help Net Security
Phishing tops initial access vectors in Q1 2026 as public sector attacks persist.
Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-05-01
Editions Related stories