Why Secure Web Gateways Miss Modern Browser Attacks
Secure web gateways inspect traffic. Modern browsers assemble applications. Attackers exploit the difference between what crosses the network and what finally appears, runs, or leaves the device.
Secto Security Lab
Threat research, security engineering, and practical guidance for protecting modern work in the browser.
Latest intelligence
Secure web gateways inspect traffic. Modern browsers assemble applications. Attackers exploit the difference between what crosses the network and what finally appears, runs, or leaves the device.
For years, defenders assumed malicious activity came from malicious infrastructure. That assumption is now broken, and attackers know it.
January 2026 reporting showed attackers skipping lookalike domains entirely and sending phishing that appeared to come from the victim's own organization. The enabling factors were weak mail routing and permissive spoof handling.
A January 2026 campaign abused Microsoft Teams guest invitations to send official-looking billing alerts from legitimate Microsoft infrastructure. The lure did not ask for a click. It asked the victim to call.
January 2026 reporting on a KONNI-linked campaign showed a phishing chain aimed at developers and engineering teams, using project documents, Discord-hosted ZIP files, LNK execution, and an AI-written PowerShell backdoor.
The April 2026 W3LL takedown was not just about one phishing kit. It exposed how credential theft, MFA bypass, stolen accounts, and business email fraud have become a managed marketplace.
A recent payroll-diversion campaign against Canadian employees shows how poisoned search results, adversary-in-the-middle phishing, hidden inbox rules, and HR workflow abuse can turn one login into a stolen paycheck.
Recent VENOM phishing campaigns show why QR phishing keeps evolving. The attack targets executives, renders QR codes from Unicode blocks instead of image files, and moves victims from email to mobile before credential theft begins.
Recent device code phishing campaigns turned a niche device-authorization abuse path into a practical MFA-bypass workflow. The real change is not just better lures. It is that attackers now generate device codes in real time, which makes the attack far easier to scale.
The March 2026 disruption of Tycoon2FA was important, but the bigger takeaway is what the platform proved: session theft and MFA bypass are now available as a subscription service. That changes the scale and economics of enterprise phishing.
TA416's latest campaigns are a useful reminder that state-linked phishing does not stay fixed for long. The group's mission stayed stable, but its delivery chains kept changing, from fake challenge pages to OAuth abuse and newer downloader methods tied to current geopolitical events.
The new Microsoft phishing problem is not just the fake login page. It is the trusted redirect that gets users there. OAuth prompts, consent screens, and legitimate identity-provider hops are now being used as a browser handoff into phishing and adversary-in-the-middle flows.