Secto Security Lab

Insights from the Frontlines

Deep dives into threat research, security engineering, and the evolving landscape of Microsoft 365 protection.

Why Secure Web Gateways Miss Modern Browser Attacks
Network Security
Jul 31, 2026
10 min read

Why Secure Web Gateways Miss Modern Browser Attacks

Secure web gateways inspect traffic. Modern browsers assemble applications. Attackers exploit the difference between what crosses the network and what finally appears, runs, or leaves the device.

Yaamini Barathi Mohan
Why IP-Based Filtering Is No Longer Enough
Network Security
Jun 10, 2026
8 min read

Why IP-Based Filtering Is No Longer Enough

IP-based filtering was once a reliable way to control access and block threats. Modern attack patterns have made it a weak anchor. Here is why identity and browser context now carry more weight than the IP address alone.

Secto Research
The Email From Yourself: When Routing Mistakes Make Phishing Look Internal
Domain Spoofing
Apr 22, 2026
9 min read

The Email From Yourself: When Routing Mistakes Make Phishing Look Internal

January 2026 reporting showed attackers skipping lookalike domains entirely and sending phishing that appeared to come from the victim's own organization. The enabling factors were weak mail routing and permissive spoof handling.

Secto Research
The Teams Invite That Wants a Phone Call
Collaboration Phishing
Apr 22, 2026
8 min read

The Teams Invite That Wants a Phone Call

A January 2026 campaign abused Microsoft Teams guest invitations to send official-looking billing alerts from legitimate Microsoft infrastructure. The lure did not ask for a click. It asked the victim to call.

Secto Research
KONNI, Blockchain Lures, and the Developer as a Phishing Target
Developer Spear Phishing
Apr 22, 2026
10 min read

KONNI, Blockchain Lures, and the Developer as a Phishing Target

January 2026 reporting on a KONNI-linked campaign showed a phishing chain aimed at developers and engineering teams, using project documents, Discord-hosted ZIP files, LNK execution, and an AI-written PowerShell backdoor.

Secto Research
W3LLSTORE Is Gone. The Phishing Marketplace Model Is Not
Phishing-as-a-Service
Apr 15, 2026
8 min read

W3LLSTORE Is Gone. The Phishing Marketplace Model Is Not

The April 2026 W3LL takedown was not just about one phishing kit. It exposed how credential theft, MFA bypass, stolen accounts, and business email fraud have become a managed marketplace.

Secto Research
Payroll Pirate Phishing: When Search Ads Lead to Stolen Salaries
AiTM
Apr 15, 2026
8 min read

Payroll Pirate Phishing: When Search Ads Lead to Stolen Salaries

A recent payroll-diversion campaign against Canadian employees shows how poisoned search results, adversary-in-the-middle phishing, hidden inbox rules, and HR workflow abuse can turn one login into a stolen paycheck.

Secto Research
VENOM and the QR Code That Was Not an Image
QR Phishing
Apr 15, 2026
7 min read

VENOM and the QR Code That Was Not an Image

Recent VENOM phishing campaigns show why QR phishing keeps evolving. The attack targets executives, renders QR codes from Unicode blocks instead of image files, and moves victims from email to mobile before credential theft begins.

Secto Research
Device Code Phishing After EvilToken: The 15-Minute Window Is Gone
MFA Bypass
Apr 7, 2026
7 min read

Device Code Phishing After EvilToken: The 15-Minute Window Is Gone

Recent device code phishing campaigns turned a niche device-authorization abuse path into a practical MFA-bypass workflow. The real change is not just better lures. It is that attackers now generate device codes in real time, which makes the attack far easier to scale.

Secto Research
Tycoon2FA Is Down. The Session-Theft Problem Is Not
AiTM
Apr 7, 2026
8 min read

Tycoon2FA Is Down. The Session-Theft Problem Is Not

The March 2026 disruption of Tycoon2FA was important, but the bigger takeaway is what the platform proved: session theft and MFA bypass are now available as a subscription service. That changes the scale and economics of enterprise phishing.

Secto Research
TA416's New Delivery Chains: State Phishing That Tracks the News Cycle
State-Sponsored Phishing
Apr 7, 2026
8 min read

TA416's New Delivery Chains: State Phishing That Tracks the News Cycle

TA416's latest campaigns are a useful reminder that state-linked phishing does not stay fixed for long. The group's mission stayed stable, but its delivery chains kept changing, from fake challenge pages to OAuth abuse and newer downloader methods tied to current geopolitical events.

Secto Research
Trusted Redirects: OAuth as a Phishing Handoff
Phishing / AiTM
Mar 16, 2026
8 min read

Trusted Redirects: OAuth as a Phishing Handoff

The new Microsoft phishing problem is not just the fake login page. It is the trusted redirect that gets users there. OAuth prompts, consent screens, and legitimate identity-provider hops are now being used as a browser handoff into phishing and adversary-in-the-middle flows.

Secto Research
GhostFrame and the Failure of HTML-Only Phishing Detection
Browser-Based Phishing
Mar 16, 2026
8 min read

GhostFrame and the Failure of HTML-Only Phishing Detection

GhostFrame is a useful wake-up call because it does not just hide phishing behind a new domain or a better lure. It hides the real credential-harvesting experience inside the browser's rendering path, leaving many source-only inspections looking at the wrong thing.

Secto Research
GenAI Cloned Login Pages and the 30-Second Phish
Cloned Login Pages
Mar 16, 2026
8 min read

GenAI Cloned Login Pages and the 30-Second Phish

The important change in GenAI-enabled phishing is not better email copy. It is the collapse in time and effort required to produce a convincing login page. Okta's 2025 reporting showed attackers using GenAI web-building tools to generate polished sign-in clones in roughly thirty seconds.

Secto Research
Adversary-in-the-Middle (AiTM): The MFA Bypass Threat Every Org Must Understand
AiTM
Jul 8, 2025
8 min read

Adversary-in-the-Middle (AiTM): The MFA Bypass Threat Every Org Must Understand

Imagine your CEO receives a perfectly legitimate Microsoft 365 login page. Everything looks normal. They enter their credentials, complete the MFA prompt, and continue with their day.

Secto Research
The SEG Blind Spot: How Attackers Bypass Your Gateway via Direct-Send to Microsoft 365
SEG Bypass
Oct 24, 2025
9 min read

The SEG Blind Spot: How Attackers Bypass Your Gateway via Direct-Send to Microsoft 365

A sophisticated phishing tactic is gaining traction: attackers are delivering internal-looking emails directly to Microsoft 365 mailboxes, completely bypassing Secure Email Gateways (SEGs) like Proofpoint or Mimecast.

Secto Research
Executing Adversary-in-the-Middle (AiTM) in Okta-Flows: And How Secto Stops It
AiTM
Nov 15, 2025
8 min read

Executing Adversary-in-the-Middle (AiTM) in Okta-Flows: And How Secto Stops It

In today's enterprise identity architecture, Okta often acts as the identity provider (IdP) for Microsoft Entra ID federated sign-ins. When a user authenticates through an Okta-integrated browser flow, a session is established and tokens are issued, which are then reused across Microsoft 365 web applications with no additional prompts.

Secto Research
The "ClickFix" Trap: How Attackers Trick Users into Hacking Themselves
Social Engineering
Dec 20, 2025
7 min read

The "ClickFix" Trap: How Attackers Trick Users into Hacking Themselves

The landscape of phishing and social engineering is shifting. Attackers are moving away from just trying to steal credentials via fake login pages and are increasingly focused on immediate payload delivery. The newest, and particularly insidious, trend is the "ClickFix" attack.

Secto Research
Beyond the Email Gateway: Why Your Inbox is the Wrong Place to Fight Phishing
Email Security
Dec 26, 2025
10 min read

Beyond the Email Gateway: Why Your Inbox is the Wrong Place to Fight Phishing

For decades, the corporate approach to cybersecurity has relied on a simple medieval concept: the castle and moat. We build strong perimeter defenses: firewalls, antivirus, and, crucially, Secure Email Gateways (SEGs) to keep the bad things out.

Secto Research
Understanding Browser-in-the-Middle vs Attacker-in-the-Middle
AiTM
Dec 26, 2025
12 min read

Understanding Browser-in-the-Middle vs Attacker-in-the-Middle

Traditional phishing was simple: send a fake login page, steal a password, log in. Multi-factor authentication (MFA) made that much harder… so attackers evolved. Modern attackers are increasingly using Adversary-in-the-Middle (AiTM) and Browser-in-the-Middle (BitM) techniques.

Secto Research