Has mobile become AI’s new frontline?
Mobile devices have become AI's new frontline. Discover how embedded AI, mobile apps and limited visibility are influencing enterprise AI governance and cybersecurity.
Read More
We used to fight the phishing fight before the click. If people could spot the lure and move on without clicking the link, everything would be OK. But recent reports from Zscaler ThreatLabz and ANY.RUN show that this model of defence isn’t enough anymore. Because the danger can now begin after the click – in encrypted web sessions and at a speed that leaves security teams with very little time to respond.
Zscaler's 2026 research into phishing and initial access highlights just how much phishing has evolved. In 2025, 87% of blocked malicious activity was delivered over HTTPS, while 95.2% of all blocked phishing attempts (around 1.2 billion hits) travelled through encrypted channels.
The implication is that now, phishing can lead to compromise through encrypted web sessions, making malicious activity far harder to distinguish from legitimate traffic.
Many organisations still focus phishing defences on the inbox. Email security filters malicious messages, awareness training encourages users not to click, and multi-factor authentication (MFA) provides another layer of protection.
But a growing number of phishing campaigns use adversary-in-the-middle techniques and session interception to bypass traditional credential-based defences. Rather than simply stealing passwords, attackers are increasingly targeting authenticated sessions themselves.
ANY.RUN's Q1 2026 risk research backs up this trend. Sneaky2FA detections increased by 76.8%, while EvilProxy activity grew by 17.7% – demonstrating continued investment in phishing kits designed to defeat MFA.
According to ANY.RUN’s report, the median time to living-off-the-land execution was just 16 seconds, while the median time to persistence was 21 seconds.
That leaves very little time for security teams to investigate before an attacker has established a foothold. And this fundamentally changes what phishing defence means. If attackers can move from initial access to native Windows tools within seconds and establish persistence less than half a minute later, traditional post-click investigation will probably happen too late.
ANY.RUN also recorded a 17.4% increase in PowerShell abuse and a 58.4% rise in JavaScript-based LOLBAS activity. So rather than relying solely on bespoke malware, attackers are exploiting legitimate administrative tools that blend into everyday system activity – which makes detecting malicious behaviour significantly more difficult, and reduces the window available for defenders to respond.
The real phishing challenge now lies in what happens immediately after someone has clicked a malicious link. Organisations may now have just a few seconds to detect, contain and interrupt an attack before initial access becomes a far more serious compromise.
Learn from the world’s leading cybersecurity practitioners at Black Hat MEA 2026, and implement tools and processes to protect against evolving threats. Register now.
Join the newsletter to receive the latest updates in your inbox.
Mobile devices have become AI's new frontline. Discover how embedded AI, mobile apps and limited visibility are influencing enterprise AI governance and cybersecurity.
Read More
Why cybersecurity still needs real-world classrooms
Read More
Research from 687 IT and security leaders shows that deeper AI adoption leads to more incidents, making governance a critical cybersecurity priority.
Read More