[{"data":1,"prerenderedAt":3624},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"trust-badges":226,"blog/browser-threat-landscape-mid-year-update-2026":247},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https://pushsecurity.com/resources/browser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"w6hfy8mvbuk",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Do you know how much AI is in your workforce? Find out August 20th.\u003C/p>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Save your seat →\u003C/p>","https://pushsecurity.com/webinar/shadow-ai",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-4u2enr9kxy9","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1786155414606,"kYgMv6WsbvfmlOUYqR2SFwGzw6e2",{"breakpoints":99,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"ha0nugfu5jw",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"k4ufee9ob7","/customer-stories/inductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"1og4b784sda",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","/resources/browser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"3kc79f54k2z","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"b31wehs83eq",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[227,231,235,239,243],{"title":228,"logo":229,"createdDate":230},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":232,"logo":233,"createdDate":234},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":236,"logo":237,"createdDate":238},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":240,"logo":241,"createdDate":242},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":244,"logo":245,"createdDate":246},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,{"id":248,"title":249,"authorsCollection":250,"content":260,"extension":1670,"faqItemsCollection":1671,"faqTitle":59,"featured":6,"hashTags":59,"meta":1673,"metaTitle":1674,"ogImage":59,"publishedDate":1675,"relatedBlogPostsCollection":1676,"slug":3601,"stem":3602,"subtitle":59,"summary":3603,"synopsis":3613,"sys":3614,"tagsCollection":3617,"__hash__":3623},"blog/blog/browser-threat-landscape-mid-year-update-2026.json","Browser threat landscape: mid-year update 2026",{"items":251},[252],{"fullName":253,"firstName":254,"jobTitle":255,"socialLinks":256,"profilePicture":258},"Dan Green","Dan","Threat Research",[257],"https://www.linkedin.com/in/daniel-g-/",{"url":259},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"json":261,"links":1581},{"nodeType":262,"data":263,"content":264},"document",{},[265,274,278,288,320,336,345,376,491,533,542,597,628,634,637,645,652,660,677,732,738,745,764,770,777,783,790,796,803,809,817,860,891,910,941,949,980,1011,1042,1050,1057,1076,1130,1161,1169,1187,1230,1233,1241,1248,1255,1273,1279,1286,1401,1444,1452,1471,1478,1481,1489,1496,1539,1546,1549,1556,1563],{"nodeType":266,"data":267,"content":268},"paragraph",{},[269],{"nodeType":270,"value":271,"marks":272,"data":273},"text","Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.",[],{},{"nodeType":275,"data":276,"content":277},"hr",{},[],{"nodeType":279,"data":280,"content":281},"heading-1",{},[282],{"nodeType":270,"value":283,"marks":284,"data":287},"The SLH playbook becomes the industry standard",[285],{"type":286},"bold",{},{"nodeType":266,"data":289,"content":290},{},[291,295,304,308,316],{"nodeType":270,"value":292,"marks":293,"data":294},"Criminals associated with \"The Com,\" broadly known as the ",[],{},{"nodeType":296,"data":297,"content":299},"hyperlink",{"uri":298},"https://pushsecurity.com/blog/scattered-lapsus-hunters",[300],{"nodeType":270,"value":301,"marks":302,"data":303},"Scattered Lapsus$ Hunters",[],{},{"nodeType":270,"value":305,"marks":306,"data":307}," collective, have spent the past three years establishing a playbook ",[],{},{"nodeType":296,"data":309,"content":311},{"uri":310},"https://pushsecurity.com/blog/analyzing-the-instructure-breach",[312],{"nodeType":270,"value":313,"marks":314,"data":315},"focused on identity compromise and cloud data theft",[],{},{"nodeType":270,"value":317,"marks":318,"data":319}," for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).",[],{},{"nodeType":266,"data":321,"content":322},{},[323,327,332],{"nodeType":270,"value":324,"marks":325,"data":326},"Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, ",[],{},{"nodeType":270,"value":328,"marks":329,"data":331},"SLH-affiliated groups are responsible for roughly 70%",[330],{"type":286},{},{"nodeType":270,"value":333,"marks":334,"data":335},".",[],{},{"nodeType":337,"data":338,"content":344},"embedded-entry-block",{"target":339},{"sys":340},{"id":341,"type":342,"linkType":343},"3hODobO3VJr3LvbXkzso8I","Link","Entry",[],{"nodeType":266,"data":346,"content":347},{},[348,352,360,364,372],{"nodeType":270,"value":349,"marks":350,"data":351},"The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in ",[],{},{"nodeType":296,"data":353,"content":355},{"uri":354},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams",[356],{"nodeType":270,"value":357,"marks":358,"data":359},"tricking help desks into performing account resets",[],{},{"nodeType":270,"value":361,"marks":362,"data":363},". This year, they've switched to using voice-based lures in tandem with ",[],{},{"nodeType":296,"data":365,"content":367},{"uri":366},"https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign",[368],{"nodeType":270,"value":369,"marks":370,"data":371},"browser-based phishing payloads",[],{},{"nodeType":270,"value":373,"marks":374,"data":375}," — usually impersonating IT staff under the guise of \"setting up passkeys.\"",[],{},{"nodeType":266,"data":377,"content":378},{},[379,383,391,395,403,407,415,419,427,431,439,443,451,455,463,467,475,479,487],{"nodeType":270,"value":380,"marks":381,"data":382},"The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: ",[],{},{"nodeType":296,"data":384,"content":386},{"uri":385},"https://www.securityweek.com/panera-bread-data-breach-linked-to-shinyhunters-sso-campaign/",[387],{"nodeType":270,"value":388,"marks":389,"data":390},"Panera Bread",[],{},{"nodeType":270,"value":392,"marks":393,"data":394}," (~14M records), ",[],{},{"nodeType":296,"data":396,"content":398},{"uri":397},"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/",[399],{"nodeType":270,"value":400,"marks":401,"data":402},"Match Group",[],{},{"nodeType":270,"value":404,"marks":405,"data":406}," (Hinge, Tinder, OkCupid; 10M+ records), ",[],{},{"nodeType":296,"data":408,"content":410},{"uri":409},"https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft",[411],{"nodeType":270,"value":412,"marks":413,"data":414},"Betterment",[],{},{"nodeType":270,"value":416,"marks":417,"data":418}," (~20M records), ",[],{},{"nodeType":296,"data":420,"content":422},{"uri":421},"https://www.bleepingcomputer.com/news/security/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions/",[423],{"nodeType":270,"value":424,"marks":425,"data":426},"Odido",[],{},{"nodeType":270,"value":428,"marks":429,"data":430}," (6.2M Dutch telecom customers with BSNs and IBANs exposed), ",[],{},{"nodeType":296,"data":432,"content":434},{"uri":433},"https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/",[435],{"nodeType":270,"value":436,"marks":437,"data":438},"ADT",[],{},{"nodeType":270,"value":440,"marks":441,"data":442}," (5.5M records), ",[],{},{"nodeType":296,"data":444,"content":446},{"uri":445},"https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/",[447],{"nodeType":270,"value":448,"marks":449,"data":450},"Charter Communications",[],{},{"nodeType":270,"value":452,"marks":453,"data":454}," (4.9M accounts), ",[],{},{"nodeType":296,"data":456,"content":458},{"uri":457},"https://www.theregister.com/2026/04/24/shinyhunters_claim_cruise_giant_carnivals/",[459],{"nodeType":270,"value":460,"marks":461,"data":462},"Carnival Corporation",[],{},{"nodeType":270,"value":464,"marks":465,"data":466}," (6M records), and",[],{},{"nodeType":296,"data":468,"content":470},{"uri":469},"https://www.theregister.com/2026/04/28/pitney_bowes_is_the_latest/",[471],{"nodeType":270,"value":472,"marks":473,"data":474}," Pitney Bowes",[],{},{"nodeType":270,"value":476,"marks":477,"data":478}," (8.2M emails per HIBP). ",[],{},{"nodeType":296,"data":480,"content":482},{"uri":481},"https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/",[483],{"nodeType":270,"value":484,"marks":485,"data":486},"Optimizely",[],{},{"nodeType":270,"value":488,"marks":489,"data":490}," is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.",[],{},{"nodeType":266,"data":492,"content":493},{},[494,498,506,510,518,522,530],{"nodeType":270,"value":495,"marks":496,"data":497},"Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal ",[],{},{"nodeType":296,"data":499,"content":501},{"uri":500},"https://pushsecurity.com/blog/device-code-phishing",[502],{"nodeType":270,"value":503,"marks":504,"data":505},"device code phishing",[],{},{"nodeType":270,"value":507,"marks":508,"data":509}," campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like ",[],{},{"nodeType":296,"data":511,"content":513},{"uri":512},"https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift",[514],{"nodeType":270,"value":515,"marks":516,"data":517},"Salesloft, Drift, and GainSight",[],{},{"nodeType":270,"value":519,"marks":520,"data":521}," and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since ",[],{},{"nodeType":296,"data":523,"content":525},{"uri":524},"https://claude.ai/cowork/local_70b7ac94-7f15-42f9-8a3c-3e0b9e989eda#oauth-supply-chain-attacks",[526],{"nodeType":270,"value":527,"marks":528,"data":529},"repeated at scale",[],{},{"nodeType":270,"value":333,"marks":531,"data":532},[],{},{"nodeType":534,"data":535,"content":536},"heading-2",{},[537],{"nodeType":270,"value":538,"marks":539,"data":541},"Copycats and nation-state adoption",[540],{"type":286},{},{"nodeType":266,"data":543,"content":544},{},[545,549,557,561,569,573,581,585,593],{"nodeType":270,"value":546,"marks":547,"data":548},"Wider groups are now running the SLH playbook independently. ",[],{},{"nodeType":296,"data":550,"content":552},{"uri":551},"https://hackread.com/pink-extortion-microsoft-365-cloud-data-vishing-scams/",[553],{"nodeType":270,"value":554,"marks":555,"data":556},"Pink",[],{},{"nodeType":270,"value":558,"marks":559,"data":560}," (the latest rebrand in the",[],{},{"nodeType":296,"data":562,"content":564},{"uri":563},"https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments",[565],{"nodeType":270,"value":566,"marks":567,"data":568}," BlackFile",[],{},{"nodeType":270,"value":570,"marks":571,"data":572},"-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. ",[],{},{"nodeType":296,"data":574,"content":576},{"uri":575},"https://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/",[577],{"nodeType":270,"value":578,"marks":579,"data":580},"Helix",[],{},{"nodeType":270,"value":582,"marks":583,"data":584}," also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. ",[],{},{"nodeType":296,"data":586,"content":588},{"uri":587},"https://www.bleepingcomputer.com/news/security/kongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches/",[589],{"nodeType":270,"value":590,"marks":591,"data":592},"KongTuke",[],{},{"nodeType":270,"value":594,"marks":595,"data":596},", an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.",[],{},{"nodeType":266,"data":598,"content":599},{},[600,604,612,616,624],{"nodeType":270,"value":601,"marks":602,"data":603},"It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used ",[],{},{"nodeType":296,"data":605,"content":607},{"uri":606},"https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",[608],{"nodeType":270,"value":609,"marks":610,"data":611},"compromised hotel and conference Wi-Fi gateways",[],{},{"nodeType":270,"value":613,"marks":614,"data":615}," to direct victims to AiTM, ClickFix, and device code phishing pages. And ",[],{},{"nodeType":296,"data":617,"content":619},{"uri":618},"https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/",[620],{"nodeType":270,"value":621,"marks":622,"data":623},"Google Threat Intelligence mapped",[],{},{"nodeType":270,"value":625,"marks":626,"data":627}," a dozen Chinese-language PhaaS platforms with real-time MFA interception.",[],{},{"nodeType":337,"data":629,"content":633},{"target":630},{"sys":631},{"id":632,"type":342,"linkType":343},"6q2NwH6Q4DJE7RNeYheIvJ",[],{"nodeType":275,"data":635,"content":636},{},[],{"nodeType":279,"data":638,"content":639},{},[640],{"nodeType":270,"value":641,"marks":642,"data":644},"Phishing infrastructure has reached an industrial scale",[643],{"type":286},{},{"nodeType":266,"data":646,"content":647},{},[648],{"nodeType":270,"value":649,"marks":650,"data":651},"The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.",[],{},{"nodeType":534,"data":653,"content":654},{},[655],{"nodeType":270,"value":656,"marks":657,"data":659},"Device code phishing goes mainstream",[658],{"type":286},{},{"nodeType":266,"data":661,"content":662},{},[663,667,673],{"nodeType":270,"value":664,"marks":665,"data":666},"We're tracking a huge spike in ",[],{},{"nodeType":296,"data":668,"content":669},{"uri":500},[670],{"nodeType":270,"value":503,"marks":671,"data":672},[],{},{"nodeType":270,"value":674,"marks":675,"data":676}," since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.",[],{},{"nodeType":266,"data":678,"content":679},{},[680,684,692,696,704,708,716,720,728],{"nodeType":270,"value":681,"marks":682,"data":683},"What began with ",[],{},{"nodeType":296,"data":685,"content":687},{"uri":686},"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/",[688],{"nodeType":270,"value":689,"marks":690,"data":691},"Storm-2372's nation-state campaigns",[],{},{"nodeType":270,"value":693,"marks":694,"data":695}," in August 2024 has proliferated through criminal kits like ",[],{},{"nodeType":296,"data":697,"content":699},{"uri":698},"https://thehackernews.com/2026/05/the-new-phishing-click-how-oauth-consent.html",[700],{"nodeType":270,"value":701,"marks":702,"data":703},"EvilTokens",[],{},{"nodeType":270,"value":705,"marks":706,"data":707}," (340+ organizations in its first five weeks), ",[],{},{"nodeType":296,"data":709,"content":711},{"uri":710},"https://www.huntress.com/blog/kali365-device-code-phishing-kit",[712],{"nodeType":270,"value":713,"marks":714,"data":715},"Kali365",[],{},{"nodeType":270,"value":717,"marks":718,"data":719}," (which earned an FBI public advisory), ",[],{},{"nodeType":296,"data":721,"content":723},{"uri":722},"https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/",[724],{"nodeType":270,"value":725,"marks":726,"data":727},"ARToken",[],{},{"nodeType":270,"value":729,"marks":730,"data":731},", DEBULL, Forg365, and many more.",[],{},{"nodeType":337,"data":733,"content":737},{"target":734},{"sys":735},{"id":736,"type":342,"linkType":343},"7G6ytXRQPWatOyYarqgMK2",[],{"nodeType":266,"data":739,"content":740},{},[741],{"nodeType":270,"value":742,"marks":743,"data":744},"The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.",[],{},{"nodeType":266,"data":746,"content":747},{},[748,752,760],{"nodeType":270,"value":749,"marks":750,"data":751},"Established AiTM vendors like Tycoon 2FA have ",[],{},{"nodeType":296,"data":753,"content":755},{"uri":754},"https://pushsecurity.com/blog/device-code-phishing/",[756],{"nodeType":270,"value":757,"marks":758,"data":759},"added device code phishing",[],{},{"nodeType":270,"value":761,"marks":762,"data":763}," alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.",[],{},{"nodeType":337,"data":765,"content":769},{"target":766},{"sys":767},{"id":768,"type":342,"linkType":343},"3urXbEwK0OSjXQ7lOMDEoc",[],{"nodeType":266,"data":771,"content":772},{},[773],{"nodeType":270,"value":774,"marks":775,"data":776},"When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.",[],{},{"nodeType":337,"data":778,"content":782},{"target":779},{"sys":780},{"id":781,"type":342,"linkType":343},"4ipTS2U4HE1VLSLmA6DJgB",[],{"nodeType":266,"data":784,"content":785},{},[786],{"nodeType":270,"value":787,"marks":788,"data":789},"PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.",[],{},{"nodeType":337,"data":791,"content":795},{"target":792},{"sys":793},{"id":794,"type":342,"linkType":343},"3UDzUCCizPJhXp3SsoZuSK",[],{"nodeType":266,"data":797,"content":798},{},[799],{"nodeType":270,"value":800,"marks":801,"data":802},"And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.",[],{},{"nodeType":337,"data":804,"content":808},{"target":805},{"sys":806},{"id":807,"type":342,"linkType":343},"3SPsKzwBNxl4d9QRukBtwt",[],{"nodeType":534,"data":810,"content":811},{},[812],{"nodeType":270,"value":813,"marks":814,"data":816},"PhaaS platform evolution and evasion",[815],{"type":286},{},{"nodeType":266,"data":818,"content":819},{},[820,824,832,836,844,848,856],{"nodeType":270,"value":821,"marks":822,"data":823},"The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include ",[],{},{"nodeType":296,"data":825,"content":827},{"uri":826},"https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas",[828],{"nodeType":270,"value":829,"marks":830,"data":831},"Bluekit",[],{},{"nodeType":270,"value":833,"marks":834,"data":835},", ",[],{},{"nodeType":296,"data":837,"content":839},{"uri":838},"https://abnormal.ai/blog/blacksite-aitm-phishing-kit-cloaked-gg",[840],{"nodeType":270,"value":841,"marks":842,"data":843},"Blacksite and Cloaked.gg",[],{},{"nodeType":270,"value":845,"marks":846,"data":847}," — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and ",[],{},{"nodeType":296,"data":849,"content":851},{"uri":850},"https://threatactix.com/2026/07/02/a-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations/",[852],{"nodeType":270,"value":853,"marks":854,"data":855},"WackoGinx",[],{},{"nodeType":270,"value":857,"marks":858,"data":859},", a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.",[],{},{"nodeType":266,"data":861,"content":862},{},[863,867,875,879,887],{"nodeType":270,"value":864,"marks":865,"data":866},"Sneaky 2FA changes have also been documented, with what ",[],{},{"nodeType":296,"data":868,"content":870},{"uri":869},"https://zerobec.com/blog/sneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay",[871],{"nodeType":270,"value":872,"marks":873,"data":874},"ZeroBEC calls \"route polymorphism\"",[],{},{"nodeType":270,"value":876,"marks":877,"data":878}," (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting ",[],{},{"nodeType":296,"data":880,"content":882},{"uri":881},"https://blog.barracuda.com/2026/06/29/email-threat-radar-june-2026",[883],{"nodeType":270,"value":884,"marks":885,"data":886},"split-click buttons and blob URLs",[],{},{"nodeType":270,"value":888,"marks":889,"data":890}," designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page). ",[],{},{"nodeType":266,"data":892,"content":893},{},[894,898,906],{"nodeType":270,"value":895,"marks":896,"data":897},"The speed of technique adoption across these platforms is itself accelerating. ",[],{},{"nodeType":296,"data":899,"content":901},{"uri":900},"https://sublime.security/blog/flowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation/",[902],{"nodeType":270,"value":903,"marks":904,"data":905},"FlowerStorm adopted",[],{},{"nodeType":270,"value":907,"marks":908,"data":909}," KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.",[],{},{"nodeType":266,"data":911,"content":912},{},[913,917,925,929,937],{"nodeType":270,"value":914,"marks":915,"data":916},"At the same time, target surfaces are expanding: ",[],{},{"nodeType":296,"data":918,"content":920},{"uri":919},"https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/",[921],{"nodeType":270,"value":922,"marks":923,"data":924},"Datadog documented",[],{},{"nodeType":270,"value":926,"marks":927,"data":928}," an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of ",[],{},{"nodeType":296,"data":930,"content":932},{"uri":931},"https://pushsecurity.com/blog/mfa-downgrade-attacks",[933],{"nodeType":270,"value":934,"marks":935,"data":936},"MFA downgrade",[],{},{"nodeType":270,"value":938,"marks":939,"data":940}," in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.",[],{},{"nodeType":534,"data":942,"content":943},{},[944],{"nodeType":270,"value":945,"marks":946,"data":948},"ClickFix as a service",[947],{"type":286},{},{"nodeType":266,"data":950,"content":951},{},[952,956,964,968,976],{"nodeType":270,"value":953,"marks":954,"data":955},"ClickFix has also continued to industrialize. ",[],{},{"nodeType":296,"data":957,"content":959},{"uri":958},"https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/",[960],{"nodeType":270,"value":961,"marks":962,"data":963},"Sekoia documented",[],{},{"nodeType":270,"value":965,"marks":966,"data":967}," the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers ",[],{},{"nodeType":296,"data":969,"content":971},{"uri":970},"https://kqlquery.com/posts/clickfix-gift-that-keeps-on-giving/",[972],{"nodeType":270,"value":973,"marks":974,"data":975},"mapped approximately 3,000 live ClickFix payloads",[],{},{"nodeType":270,"value":977,"marks":978,"data":979}," being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.",[],{},{"nodeType":266,"data":981,"content":982},{},[983,987,995,999,1007],{"nodeType":270,"value":984,"marks":985,"data":986},"The technique has also expanded cross-platform, with Unit 42 documenting ",[],{},{"nodeType":296,"data":988,"content":990},{"uri":989},"https://www.bleepingcomputer.com/news/security/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer/",[991],{"nodeType":270,"value":992,"marks":993,"data":994},"macOS ClickFix variants",[],{},{"nodeType":270,"value":996,"marks":997,"data":998}," that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over ",[],{},{"nodeType":296,"data":1000,"content":1002},{"uri":1001},"https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/",[1003],{"nodeType":270,"value":1004,"marks":1005,"data":1006},"700 Ghost CMS sites were compromised",[],{},{"nodeType":270,"value":1008,"marks":1009,"data":1010}," to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.",[],{},{"nodeType":266,"data":1012,"content":1013},{},[1014,1018,1026,1030,1038],{"nodeType":270,"value":1015,"marks":1016,"data":1017},"Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: ",[],{},{"nodeType":296,"data":1019,"content":1021},{"uri":1020},"https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html",[1022],{"nodeType":270,"value":1023,"marks":1024,"data":1025},"BlueNoroff",[],{},{"nodeType":270,"value":1027,"marks":1028,"data":1029}," targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and ",[],{},{"nodeType":296,"data":1031,"content":1033},{"uri":1032},"https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/",[1034],{"nodeType":270,"value":1035,"marks":1036,"data":1037},"Famous Chollima",[],{},{"nodeType":270,"value":1039,"marks":1040,"data":1041}," embedding ClickFix in multi-stage fake job interviews.",[],{},{"nodeType":534,"data":1043,"content":1044},{},[1045],{"nodeType":270,"value":1046,"marks":1047,"data":1049},"Vishing as a payload delivery mechanism",[1048],{"type":286},{},{"nodeType":266,"data":1051,"content":1052},{},[1053],{"nodeType":270,"value":1054,"marks":1055,"data":1056},"Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.",[],{},{"nodeType":266,"data":1058,"content":1059},{},[1060,1064,1072],{"nodeType":270,"value":1061,"marks":1062,"data":1063},"When Push researchers ",[],{},{"nodeType":296,"data":1065,"content":1067},{"uri":1066},"https://pushsecurity.com/blog/inside-criminal-phishing-panel/",[1068],{"nodeType":270,"value":1069,"marks":1070,"data":1071},"infiltrated the phishing panels",[],{},{"nodeType":270,"value":1073,"marks":1074,"data":1075}," linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.",[],{},{"nodeType":266,"data":1077,"content":1078},{},[1079,1083,1091,1095,1103,1107,1115,1119,1127],{"nodeType":270,"value":1080,"marks":1081,"data":1082},"The financial scale is now quantifiable: ",[],{},{"nodeType":296,"data":1084,"content":1086},{"uri":1085},"https://www.darkreading.com/cyberattacks-data-breaches/silent-ransom-us-law-firms-extortion-attacks",[1087],{"nodeType":270,"value":1088,"marks":1089,"data":1090},"Luna Moth",[],{},{"nodeType":270,"value":1092,"marks":1093,"data":1094}," (Silent Ransom Group), a ",[],{},{"nodeType":296,"data":1096,"content":1098},{"uri":1097},"https://www.crowdstrike.com/en-us/adversaries/chatty-spider/",[1099],{"nodeType":270,"value":1100,"marks":1101,"data":1102},"Russia-linked Conti spinoff",[],{},{"nodeType":270,"value":1104,"marks":1105,"data":1106}," operating independently of the Com, has extracted ",[],{},{"nodeType":296,"data":1108,"content":1110},{"uri":1109},"https://www.theinsurer.com/ti/news/exclusive-weil-gotshal-paid-double-digit-millions-in-suppression-payment-to-luna-2026-05-27/",[1111],{"nodeType":270,"value":1112,"marks":1113,"data":1114},"up to $48 million",[],{},{"nodeType":270,"value":1116,"marks":1117,"data":1118}," from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the ",[],{},{"nodeType":296,"data":1120,"content":1122},{"uri":1121},"https://www.ic3.gov/CSA/2026/260526.pdf",[1123],{"nodeType":270,"value":1124,"marks":1125,"data":1126},"FBI issuing a dedicated flash alert",[],{},{"nodeType":270,"value":333,"marks":1128,"data":1129},[],{},{"nodeType":266,"data":1131,"content":1132},{},[1133,1137,1145,1149,1157],{"nodeType":270,"value":1134,"marks":1135,"data":1136},"The infrastructure behind these campaigns is industrializing independently. ",[],{},{"nodeType":296,"data":1138,"content":1140},{"uri":1139},"https://www.okta.com/blog/threat-intelligence/behind-the-scenes-of-a-vishing-operation/",[1141],{"nodeType":270,"value":1142,"marks":1143,"data":1144},"Okta obtained access to Work Panel",[],{},{"nodeType":270,"value":1146,"marks":1147,"data":1148},", a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately ",[],{},{"nodeType":296,"data":1150,"content":1152},{"uri":1151},"https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor",[1153],{"nodeType":270,"value":1154,"marks":1155,"data":1156},"documented a dedicated Teams-vishing initial access broker",[],{},{"nodeType":270,"value":1158,"marks":1159,"data":1160}," operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.",[],{},{"nodeType":534,"data":1162,"content":1163},{},[1164],{"nodeType":270,"value":1165,"marks":1166,"data":1168},"OAuth supply chain attacks",[1167],{"type":286},{},{"nodeType":266,"data":1170,"content":1171},{},[1172,1176,1183],{"nodeType":270,"value":1173,"marks":1174,"data":1175},"The OAuth supply chain dimension has also continued to produce confirmed victims. The ",[],{},{"nodeType":296,"data":1177,"content":1178},{"uri":512},[1179],{"nodeType":270,"value":1180,"marks":1181,"data":1182},"Salesloft/Drift supply chain attack",[],{},{"nodeType":270,"value":1184,"marks":1185,"data":1186}," in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.",[],{},{"nodeType":266,"data":1188,"content":1189},{},[1190,1194,1202,1206,1214,1218,1226],{"nodeType":270,"value":1191,"marks":1192,"data":1193},"In 2026, the ",[],{},{"nodeType":296,"data":1195,"content":1197},{"uri":1196},"https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/",[1198],{"nodeType":270,"value":1199,"marks":1200,"data":1201},"Anodot compromise",[],{},{"nodeType":270,"value":1203,"marks":1204,"data":1205}," cascaded through to Vimeo, Rockstar Games, and Zara. The ",[],{},{"nodeType":296,"data":1207,"content":1209},{"uri":1208},"https://pushsecurity.com/blog/unpacking-the-vercel-breach/",[1210],{"nodeType":270,"value":1211,"marks":1212,"data":1213},"Context.ai → Vercel",[],{},{"nodeType":270,"value":1215,"marks":1216,"data":1217}," breach followed the same structural pattern. And the ",[],{},{"nodeType":296,"data":1219,"content":1221},{"uri":1220},"https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/",[1222],{"nodeType":270,"value":1223,"marks":1224,"data":1225},"Klue/Icarus breach",[],{},{"nodeType":270,"value":1227,"marks":1228,"data":1229}," in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.",[],{},{"nodeType":275,"data":1231,"content":1232},{},[],{"nodeType":279,"data":1234,"content":1235},{},[1236],{"nodeType":270,"value":1237,"marks":1238,"data":1240},"AI is a force multiplier for attackers",[1239],{"type":286},{},{"nodeType":266,"data":1242,"content":1243},{},[1244],{"nodeType":270,"value":1245,"marks":1246,"data":1247},"Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.",[],{},{"nodeType":266,"data":1249,"content":1250},{},[1251],{"nodeType":270,"value":1252,"marks":1253,"data":1254},"The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits. ",[],{},{"nodeType":266,"data":1256,"content":1257},{},[1258,1262,1270],{"nodeType":270,"value":1259,"marks":1260,"data":1261},"You can see more examples of these kits under the hood in our blog post ",[],{},{"nodeType":296,"data":1263,"content":1265},{"uri":1264},"https://pushsecurity.com/blog/inside-criminal-phishing-panel",[1266],{"nodeType":270,"value":1267,"marks":1268,"data":1269},"infiltrating a criminal phishing panel. ",[],{},{"nodeType":270,"value":21,"marks":1271,"data":1272},[],{},{"nodeType":337,"data":1274,"content":1278},{"target":1275},{"sys":1276},{"id":1277,"type":342,"linkType":343},"01mOiserRBXraawXwQyJNm",[],{"nodeType":266,"data":1280,"content":1281},{},[1282],{"nodeType":270,"value":1283,"marks":1284,"data":1285},"Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability. ",[],{},{"nodeType":1287,"data":1288,"content":1289},"unordered-list",{},[1290,1313,1334,1357,1379],{"nodeType":1291,"data":1292,"content":1293},"list-item",{},[1294],{"nodeType":266,"data":1295,"content":1296},{},[1297,1301,1309],{"nodeType":270,"value":1298,"marks":1299,"data":1300},"The first major device code phishing kit identified in the wild, EvilTokens, ",[],{},{"nodeType":296,"data":1302,"content":1304},{"uri":1303},"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign",[1305],{"nodeType":270,"value":1306,"marks":1307,"data":1308},"heavily used Railway",[],{},{"nodeType":270,"value":1310,"marks":1311,"data":1312},", a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes. ",[],{},{"nodeType":1291,"data":1314,"content":1315},{},[1316],{"nodeType":266,"data":1317,"content":1318},{},[1319,1323,1330],{"nodeType":270,"value":1320,"marks":1321,"data":1322},"Kali365's E2 edition includes an AI-powered BEC module that ",[],{},{"nodeType":296,"data":1324,"content":1325},{"uri":710},[1326],{"nodeType":270,"value":1327,"marks":1328,"data":1329},"uses Claude Sonnet",[],{},{"nodeType":270,"value":1331,"marks":1332,"data":1333}," to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.",[],{},{"nodeType":1291,"data":1335,"content":1336},{},[1337],{"nodeType":266,"data":1338,"content":1339},{},[1340,1343,1353],{"nodeType":270,"value":21,"marks":1341,"data":1342},[],{},{"nodeType":296,"data":1344,"content":1346},{"uri":1345},"https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html",[1347],{"nodeType":270,"value":1348,"marks":1349,"data":1352},"Rapid7's analysis of an exposed server",[1350],{"type":1351},"underline",{},{"nodeType":270,"value":1354,"marks":1355,"data":1356}," containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.",[],{},{"nodeType":1291,"data":1358,"content":1359},{},[1360],{"nodeType":266,"data":1361,"content":1362},{},[1363,1367,1375],{"nodeType":270,"value":1364,"marks":1365,"data":1366},"Three independent operators were ",[],{},{"nodeType":296,"data":1368,"content":1370},{"uri":1369},"https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html",[1371],{"nodeType":270,"value":1372,"marks":1373,"data":1374},"found running kits from public GitHub forks",[],{},{"nodeType":270,"value":1376,"marks":1377,"data":1378}," with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain. ",[],{},{"nodeType":1291,"data":1380,"content":1381},{},[1382],{"nodeType":266,"data":1383,"content":1384},{},[1385,1389,1397],{"nodeType":270,"value":1386,"marks":1387,"data":1388},"The tooling itself is starting to embed AI as a product feature — ",[],{},{"nodeType":296,"data":1390,"content":1392},{"uri":1391},"https://www.varonis.com/blog/dolphin-x-stealer",[1393],{"nodeType":270,"value":1394,"marks":1395,"data":1396},"Dolphin X",[],{},{"nodeType":270,"value":1398,"marks":1399,"data":1400},", a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.",[],{},{"nodeType":266,"data":1402,"content":1403},{},[1404,1408,1416,1420,1428,1432,1440],{"nodeType":270,"value":1405,"marks":1406,"data":1407},"AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a ",[],{},{"nodeType":296,"data":1409,"content":1411},{"uri":1410},"https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",[1412],{"nodeType":270,"value":1413,"marks":1414,"data":1415},"malicious Claude.ai Artifact impersonating a download portal",[],{},{"nodeType":270,"value":1417,"marks":1418,"data":1419}," drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the ",[],{},{"nodeType":296,"data":1421,"content":1423},{"uri":1422},"https://pushsecurity.com/blog/llmshare-malvertising-campaign/",[1424],{"nodeType":270,"value":1425,"marks":1426,"data":1427},"LLMShare attack pattern",[],{},{"nodeType":270,"value":1429,"marks":1430,"data":1431}," we documented in May. A second campaign, ",[],{},{"nodeType":296,"data":1433,"content":1435},{"uri":1434},"https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering",[1436],{"nodeType":270,"value":1437,"marks":1438,"data":1439},"MacSync",[],{},{"nodeType":270,"value":1441,"marks":1442,"data":1443},", used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.",[],{},{"nodeType":534,"data":1445,"content":1446},{},[1447],{"nodeType":270,"value":1448,"marks":1449,"data":1451},"But the core techniques aren't changing",[1450],{"type":286},{},{"nodeType":266,"data":1453,"content":1454},{},[1455,1459,1467],{"nodeType":270,"value":1456,"marks":1457,"data":1458},"AI compresses the bottom layers of the ",[],{},{"nodeType":296,"data":1460,"content":1462},{"uri":1461},"https://pushsecurity.com/blog/the-pyramid-of-pain-in-the-ai-era/",[1463],{"nodeType":270,"value":1464,"marks":1465,"data":1466},"Pyramid of Pain",[],{},{"nodeType":270,"value":1468,"marks":1469,"data":1470}," (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.",[],{},{"nodeType":266,"data":1472,"content":1473},{},[1474],{"nodeType":270,"value":1475,"marks":1476,"data":1477},"A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.",[],{},{"nodeType":275,"data":1479,"content":1480},{},[],{"nodeType":279,"data":1482,"content":1483},{},[1484],{"nodeType":270,"value":1485,"marks":1486,"data":1488},"What this means for defenders",[1487],{"type":286},{},{"nodeType":266,"data":1490,"content":1491},{},[1492],{"nodeType":270,"value":1493,"marks":1494,"data":1495},"Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.",[],{},{"nodeType":1287,"data":1497,"content":1498},{},[1499,1509,1519,1529],{"nodeType":1291,"data":1500,"content":1501},{},[1502],{"nodeType":266,"data":1503,"content":1504},{},[1505],{"nodeType":270,"value":1506,"marks":1507,"data":1508},"For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.",[],{},{"nodeType":1291,"data":1510,"content":1511},{},[1512],{"nodeType":266,"data":1513,"content":1514},{},[1515],{"nodeType":270,"value":1516,"marks":1517,"data":1518},"For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.",[],{},{"nodeType":1291,"data":1520,"content":1521},{},[1522],{"nodeType":266,"data":1523,"content":1524},{},[1525],{"nodeType":270,"value":1526,"marks":1527,"data":1528},"For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.",[],{},{"nodeType":1291,"data":1530,"content":1531},{},[1532],{"nodeType":266,"data":1533,"content":1534},{},[1535],{"nodeType":270,"value":1536,"marks":1537,"data":1538},"For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.",[],{},{"nodeType":266,"data":1540,"content":1541},{},[1542],{"nodeType":270,"value":1543,"marks":1544,"data":1545},"As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.",[],{},{"nodeType":275,"data":1547,"content":1548},{},[],{"nodeType":266,"data":1550,"content":1551},{},[1552],{"nodeType":270,"value":1553,"marks":1554,"data":1555},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":266,"data":1557,"content":1558},{},[1559],{"nodeType":270,"value":1560,"marks":1561,"data":1562},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":266,"data":1564,"content":1565},{},[1566,1569,1578],{"nodeType":270,"value":21,"marks":1567,"data":1568},[],{},{"nodeType":296,"data":1570,"content":1572},{"uri":1571},"https://pushsecurity.com/demo/",[1573],{"nodeType":270,"value":1574,"marks":1575,"data":1577},"Book a live demo to learn more.",[1576],{"type":1351},{},{"nodeType":270,"value":21,"marks":1579,"data":1580},[],{},{"entries":1582},{"hyperlink":1583,"inline":1584,"block":1585},[],[],[1586,1594,1616,1621,1647,1653,1659,1663],{"sys":1587,"__typename":1588,"title":1589,"caption":1589,"layoutMode":59,"file":1590},{"id":341},"Image"," Public breaches and campaigns with a browser and identity-related breach vector in 2026.",{"url":1591,"width":1592,"height":1593},"https://images.ctfassets.net/y1cdw1ablpvd/7DDf4WnfcZa3U9C6Leyu14/f6b7e43f663a387ed7238e4a47e4e215/image2.png",1999,1125,{"sys":1595,"__typename":1596,"content":1597,"name":1615,"title":59},{"id":632},"InsightTextBlockComponent",{"json":1598},{"nodeType":262,"data":1599,"content":1600},{},[1601,1608],{"nodeType":266,"data":1602,"content":1603},{},[1604],{"nodeType":270,"value":1605,"marks":1606,"data":1607},"\"The Com\" affiliates increasingly set the playbook for other criminal groups, and even nation-state operators. It might not always be super sophisticated, but they've proven the playbook works. And from the APT's perspective, why burn an exploit if you can achieve the same with a phish kit?",[],{},{"nodeType":266,"data":1609,"content":1610},{},[1611],{"nodeType":270,"value":1612,"marks":1613,"data":1614},"\n",[],{},"Browser attacks update IB1",{"sys":1617,"__typename":1588,"title":1618,"caption":1618,"layoutMode":59,"file":1619},{"id":736},"Detections by device code phishing kit. Kits are multiplying and fragmenting each month, with a long tail of kits not named here.",{"url":1620,"width":1592,"height":1593},"https://images.ctfassets.net/y1cdw1ablpvd/3VgSTD544VehTl3THm4zpa/dd7e8610c29b283f38a3fa17a0614c90/image1.png",{"sys":1622,"__typename":1596,"content":1623,"name":1646,"title":59},{"id":768},{"json":1624},{"nodeType":262,"data":1625,"content":1626},{},[1627],{"nodeType":266,"data":1628,"content":1629},{},[1630,1634,1642],{"nodeType":270,"value":1631,"marks":1632,"data":1633},"Tycoon is a particularly notable example because following a public takedown of its AiTM infrastructure, some recent reports have ",[],{},{"nodeType":296,"data":1635,"content":1637},{"uri":1636},"https://cybersecuritynews.com/top-10-phishing-kits-used-by-hackers/",[1638],{"nodeType":270,"value":1639,"marks":1640,"data":1641},"Tycoon detections dropping",[],{},{"nodeType":270,"value":1643,"marks":1644,"data":1645},", but we're finding that actually Tycoon device code attacks in particular have bounced back in our detections. ",[],{},"Browser attacks update IB2",{"sys":1648,"__typename":1588,"title":1649,"caption":1649,"layoutMode":59,"file":1650},{"id":781},"Push Security detections by phishing kit, April-June 2026",{"url":1651,"width":1592,"height":1652},"https://images.ctfassets.net/y1cdw1ablpvd/71NeNdtXc5hbJrhfypTFS1/b7159dc73169225ff36bbbdf75d7b059/image3.png",1082,{"sys":1654,"__typename":1655,"title":1656,"arcadeDemoUrl":1657,"playText":1658},{"id":794},"ArcadeDemo","Tycoon2FA Device Code Phishing","https://demo.arcade.software/SPNMxNkoyY5vTMPPlqWS?embed","30 secs",{"sys":1660,"__typename":1655,"title":1661,"arcadeDemoUrl":1662,"playText":1658},{"id":807},"Device code phishing to AITM fallback","https://demo.arcade.software/6qbvBCrv9ncUnwSv7kQJ?embed",{"sys":1664,"__typename":1588,"title":1665,"caption":1665,"layoutMode":59,"file":1666},{"id":1277},"Verbose phishing kit comments (a clear sign of AI involvement).",{"url":1667,"width":1668,"height":1669},"https://images.ctfassets.net/y1cdw1ablpvd/2XOX0xzOxsmBKUuQbup47x/a624c2141879f9238704167a35fdeb39/Screenshot_2026-05-07_at_12.53.27.png",1100,1332,"json",{"items":1672},[],{},"How browser attacks are evolving in 2026 so far","2026-08-10T00:00:00.000Z",{"items":1677},[1678,2307,2743],{"__typename":1679,"sys":1680,"content":1682,"title":2289,"synopsis":2290,"hashTags":59,"publishedDate":2291,"slug":2292,"tagsCollection":2293,"authorsCollection":2303},"BlogPosts",{"id":1681},"4NY2NbkAPucFOJY45yrrrE",{"json":1683},{"data":1684,"content":1685,"nodeType":262},{},[1686,1693,1700,1707,1713,1754,1757,1765,1772,1780,1824,1830,1837,1843,1846,1854,1861,1869,1876,1883,1899,1907,1932,1939,1945,1952,1960,1975,2003,2009,2027,2033,2041,2048,2073,2080,2087,2094,2100,2103,2111,2118,2125,2144,2152,2159,2167,2190,2202,2205,2213,2220,2227,2234,2254,2257,2263,2269],{"data":1687,"content":1688,"nodeType":266},{},[1689],{"data":1690,"marks":1691,"value":1692,"nodeType":270},{},[],"Employees have been self-adopting apps, creating unmanaged accounts, and introducing third-party software dependencies into their organizations for years, and the core problem hasn't changed: unmanaged software expanding your attack surface without your knowledge.",{"data":1694,"content":1695,"nodeType":266},{},[1696],{"data":1697,"marks":1698,"value":1699,"nodeType":270},{},[],"But the rate at which employees are signing up for AI tools is unprecedented, and the depth of interconnectivity those tools demand is fundamentally different from traditional shadow SaaS. ",{"data":1701,"content":1702,"nodeType":266},{},[1703],{"data":1704,"marks":1705,"value":1706,"nodeType":270},{},[],"AI tools aren't just standalone apps that employees sign into — they're increasingly used as agents that drive other applications, pulling data from one platform, acting on another — they are becoming a core that other apps are integrating to, and that users are integrating with their wider SaaS stack. It’s becoming a focal integration point for app access and functionality in a way that's more comparable to an enterprise cloud platform than a typical SaaS tool. ",{"data":1708,"content":1712,"nodeType":337},{"target":1709},{"sys":1710},{"id":1711,"type":342,"linkType":343},"4jsomkKmK7Vjijo8UkCQkf",[],{"data":1714,"content":1715,"nodeType":266},{},[1716,1720,1728,1732,1737,1741,1750],{"data":1717,"marks":1718,"value":1719,"nodeType":270},{},[],"The industry data backs this up. The ",{"data":1721,"content":1723,"nodeType":296},{"uri":1722},"https://www.verizon.com/business/resources/reports/dbir/",[1724],{"data":1725,"marks":1726,"value":1727,"nodeType":270},{},[],"Verizon DBIR 2026",{"data":1729,"marks":1730,"value":1731,"nodeType":270},{},[]," reports that ",{"data":1733,"marks":1734,"value":1736,"nodeType":270},{},[1735],{"type":286},"45% of employees are now regular AI users on corporate devices",{"data":1738,"marks":1739,"value":1740,"nodeType":270},{},[],", up from 15% the year before. ",{"data":1742,"content":1744,"nodeType":296},{"uri":1743},"https://omdia.tech.informa.com/",[1745],{"data":1746,"marks":1747,"value":1749,"nodeType":270},{},[1748],{"type":1351},"Omdia's 2026 browser security research",{"data":1751,"marks":1752,"value":1753,"nodeType":270},{},[]," presents a stronger picture, finding that 92% allow employees to use public GenAI applications. However, given that the typical company policy sanctions a small number of approved tools, this means everything else employees are using is unsanctioned by default. In other words: every organization in the survey had unsanctioned AI usage.",{"data":1755,"content":1756,"nodeType":275},{},[],{"data":1758,"content":1759,"nodeType":279},{},[1760],{"data":1761,"marks":1762,"value":1764,"nodeType":270},{},[1763],{"type":286},"The state of shadow AI, using Push data",{"data":1766,"content":1767,"nodeType":266},{},[1768],{"data":1769,"marks":1770,"value":1771,"nodeType":270},{},[],"We analyzed a snapshot of AI activity across Push customers during an average week in April 2026. We wanted to make sure it captured actual activity, not just historical data on apps that were added once and no longer used.",{"data":1773,"content":1774,"nodeType":266},{},[1775],{"data":1776,"marks":1777,"value":1779,"nodeType":270},{},[1778],{"type":286},"The numbers paint a picture that most security teams will find uncomfortable.",{"data":1781,"content":1782,"nodeType":266},{},[1783,1787,1792,1796,1801,1805,1810,1814,1820],{"data":1784,"marks":1785,"value":1786,"nodeType":270},{},[],"The average organization has ",{"data":1788,"marks":1789,"value":1791,"nodeType":270},{},[1790],{"type":286},"16 unique AI apps",{"data":1793,"marks":1794,"value":1795,"nodeType":270},{},[]," in active use, ",{"data":1797,"marks":1798,"value":1800,"nodeType":270},{},[1799],{"type":286},"17 unique AI browser extensions",{"data":1802,"marks":1803,"value":1804,"nodeType":270},{},[],", and ",{"data":1806,"marks":1807,"value":1809,"nodeType":270},{},[1808],{"type":286},"17 unique AI OAuth integrations",{"data":1811,"marks":1812,"value":1813,"nodeType":270},{},[]," connected into just Google Workspace and Microsoft 365 — with some organizations reaching as high as 40 unique AI apps, 163 AI extensions, and 55 OAuth connections to AI apps respectively. At the other end, the smallest organization with the ",{"data":1815,"marks":1816,"value":1819,"nodeType":270},{},[1817],{"type":1818},"italic","lowest",{"data":1821,"marks":1822,"value":1823,"nodeType":270},{},[]," adoption level is actively using two. ",{"data":1825,"content":1829,"nodeType":337},{"target":1826},{"sys":1827},{"id":1828,"type":342,"linkType":343},"2AfeiHub5kyZN8wuf6CJch",[],{"data":1831,"content":1832,"nodeType":266},{},[1833],{"data":1834,"marks":1835,"value":1836,"nodeType":270},{},[],"If most organizations have sanctioned one or two core AI assistants/platforms for business use, the gap between what's approved and what's actually happening is significant.",{"data":1838,"content":1842,"nodeType":337},{"target":1839},{"sys":1840},{"id":1841,"type":342,"linkType":343},"2hsKQ9DEspflhmtR0bE7QY",[],{"data":1844,"content":1845,"nodeType":275},{},[],{"data":1847,"content":1848,"nodeType":279},{},[1849],{"data":1850,"marks":1851,"value":1853,"nodeType":270},{},[1852],{"type":286},"Understanding the four categories of shadow AI",{"data":1855,"content":1856,"nodeType":266},{},[1857],{"data":1858,"marks":1859,"value":1860,"nodeType":270},{},[],"Shadow SaaS has always been a problem, but in the context of AI apps there are four categories of shadow IT that security teams need to understand, because each one introduces a different kind of risk and requires a different approach to tackling it.",{"data":1862,"content":1863,"nodeType":534},{},[1864],{"data":1865,"marks":1866,"value":1868,"nodeType":270},{},[1867],{"type":286},"Shadow AI apps",{"data":1870,"content":1871,"nodeType":266},{},[1872],{"data":1873,"marks":1874,"value":1875,"nodeType":270},{},[],"Shadow apps are AI tools that employees have signed up to and are using for business purposes without approval. This is the most visible dimension of the problem, and the one most people think of when they hear \"shadow AI\" — an employee pastes sensitive internal documents into ChatGPT, uploads confidential files to an AI assistant, or uses an unapproved coding tool to generate production code.",{"data":1877,"content":1878,"nodeType":266},{},[1879],{"data":1880,"marks":1881,"value":1882,"nodeType":270},{},[],"All of that is sensitive data leaving the organization through channels the security team can't see - and often accessible using personal accounts that can be compromised on personal devices or workstations. ",{"data":1884,"content":1885,"nodeType":266},{},[1886,1890,1895],{"data":1887,"marks":1888,"value":1889,"nodeType":270},{},[],"The 2026 DBIR's data loss prevention analysis underscores the scale — shadow AI is now the ",{"data":1891,"marks":1892,"value":1894,"nodeType":270},{},[1893],{"type":286},"third most common non-malicious insider action",{"data":1896,"marks":1897,"value":1898,"nodeType":270},{},[]," in DLP data, a 4x increase year-over-year. Across 858,000+ DLP events targeting GenAI tools, the most common data types being submitted were source code (28%), images (16%), structured data (14%), documents (13%), and PDFs (10%). That's not employees asking ChatGPT to fix their grammar — it's core intellectual property, production code, and internal documentation flowing into platforms the security team has no visibility into. But shadow apps themselves are only the most obvious part of the problem.",{"data":1900,"content":1901,"nodeType":534},{},[1902],{"data":1903,"marks":1904,"value":1906,"nodeType":270},{},[1905],{"type":286},"Shadow tenants",{"data":1908,"content":1909,"nodeType":266},{},[1910,1914,1919,1923,1928],{"data":1911,"marks":1912,"value":1913,"nodeType":270},{},[],"Even when an organization has approved an AI tool — say, an enterprise ChatGPT deployment — employees frequently access the same app with personal accounts, creating shadow tenants that sit entirely outside organizational control. The DBIR found that ",{"data":1915,"marks":1916,"value":1918,"nodeType":270},{},[1917],{"type":286},"67% of GenAI users on corporate devices are using non-corporate accounts",{"data":1920,"marks":1921,"value":1922,"nodeType":270},{},[],", and our own data shows that ",{"data":1924,"marks":1925,"value":1927,"nodeType":270},{},[1926],{"type":286},"38% of file uploads to AI tools are made from shadow accounts",{"data":1929,"marks":1930,"value":1931,"nodeType":270},{},[]," rather than approved organizational ones.",{"data":1933,"content":1934,"nodeType":266},{},[1935],{"data":1936,"marks":1937,"value":1938,"nodeType":270},{},[],"When an organization approves Claude, ChatGPT, or another core AI platform, you typically also approve the OAuth integration and browser extension for core apps (e.g. M365, Google Workspace, and so on). When that integration is approved, it is approved for all tenants — not just your corporate tenant. ",{"data":1940,"content":1944,"nodeType":337},{"target":1941},{"sys":1942},{"id":1943,"type":342,"linkType":343},"3Rvw0n28AYIM3FQXtHyafD",[],{"data":1946,"content":1947,"nodeType":266},{},[1948],{"data":1949,"marks":1950,"value":1951,"nodeType":270},{},[],"This means that even if you've deployed enterprise controls around your sanctioned AI tools — DLP policies, retention settings, admin oversight — more than a third of the file uploads hitting AI tools are bypassing those controls entirely because they're happening through personal accounts on corporate devices.",{"data":1953,"content":1954,"nodeType":534},{},[1955],{"data":1956,"marks":1957,"value":1959,"nodeType":270},{},[1958],{"type":286},"Shadow extensions",{"data":1961,"content":1962,"nodeType":266},{},[1963,1967,1971],{"data":1964,"marks":1965,"value":1966,"nodeType":270},{},[],"Many AI tools come with a browser extension counterpart, and there's a large ecosystem of third-party AI extensions that offer everything from writing assistance to automated data extraction. The average organization in our dataset has ",{"data":1968,"marks":1969,"value":1800,"nodeType":270},{},[1970],{"type":286},{"data":1972,"marks":1973,"value":1974,"nodeType":270},{},[]," deployed across its workforce, with the highest we observed reaching 163 — and since each of those average 17 different extensions may be installed by multiple employees, the actual number of individual extension installs across the organization is much higher still.",{"data":1976,"content":1977,"nodeType":266},{},[1978,1982,1990,1994,1999],{"data":1979,"marks":1980,"value":1981,"nodeType":270},{},[],"The extension dimension is particularly concerning because most extensions operate with significant privilege inside the browser — they can read and modify page content, access cookies and session tokens, and interact with virtually every web application an employee uses. As we detailed in our recent analysis of ",{"data":1983,"content":1985,"nodeType":296},{"uri":1984},"https://pushsecurity.com/blog/why-browser-extension-risk-scoring-wont-predict-your-next-breach/",[1986],{"data":1987,"marks":1988,"value":1989,"nodeType":270},{},[],"browser extension risk scoring",{"data":1991,"marks":1992,"value":1993,"nodeType":270},{},[],", at least ",{"data":1995,"marks":1996,"value":1998,"nodeType":270},{},[1997],{"type":286},"46.76% of all extensions across Push customers have the permission combinations needed to perform account takeover with no user interaction",{"data":2000,"marks":2001,"value":2002,"nodeType":270},{},[],", and the extensions involved in every major supply chain breach of the past 18 months scored as normal or low-risk beforehand.",{"data":2004,"content":2008,"nodeType":337},{"target":2005},{"sys":2006},{"id":2007,"type":342,"linkType":343},"3z4JOMALI52xoOXZkzPHLD",[],{"data":2010,"content":2011,"nodeType":266},{},[2012,2016,2023],{"data":2013,"marks":2014,"value":2015,"nodeType":270},{},[],"AI extensions add a specific wrinkle to this problem: many are branded to look like official companions to well-known AI tools but are actually third-party creations with no affiliation to the original vendor. They're not necessarily malicious at the point of installation, but they're exactly the kind of extension that's likely to be ",{"data":2017,"content":2018,"nodeType":296},{"uri":1984},[2019],{"data":2020,"marks":2021,"value":2022,"nodeType":270},{},[],"acquired and weaponized",{"data":2024,"marks":2025,"value":2026,"nodeType":270},{},[]," down the line — and in the meantime, they're collecting data that their permissions entitle them to (which, in most cases, means everything the user can see in their browser).",{"data":2028,"content":2032,"nodeType":337},{"target":2029},{"sys":2030},{"id":2031,"type":342,"linkType":343},"6K3z67rohss6H3lCsSn12B",[],{"data":2034,"content":2035,"nodeType":534},{},[2036],{"data":2037,"marks":2038,"value":2040,"nodeType":270},{},[2039],{"type":286},"Shadow integrations",{"data":2042,"content":2043,"nodeType":266},{},[2044],{"data":2045,"marks":2046,"value":2047,"nodeType":270},{},[],"The fourth dimension — and arguably the most dangerous — is shadow integrations: OAuth connections between AI tools and core enterprise apps that aren't known or approved by the security team. Even if an organization has approved an AI tool for standalone use, plugging that tool directly into Google Workspace, Microsoft 365, Salesforce, or any other one of the dozen or so SaaS apps in a typical user’s work stack is a fundamentally different risk decision, because it creates a persistent, programmatic bridge between your environment and a third party.",{"data":2049,"content":2050,"nodeType":266},{},[2051,2055,2060,2064,2069],{"data":2052,"marks":2053,"value":2054,"nodeType":270},{},[],"On average, we see ",{"data":2056,"marks":2057,"value":2059,"nodeType":270},{},[2058],{"type":286},"17 unique AI app OAuth integrations per organization",{"data":2061,"marks":2062,"value":2063,"nodeType":270},{},[]," in ",{"data":2065,"marks":2066,"value":2068,"nodeType":270},{},[2067],{"type":1818},"just",{"data":2070,"marks":2071,"value":2072,"nodeType":270},{},[]," Google Workspace and Microsoft 365 (to be clear: this number excludes the dozens of downstream apps the AI assistants are integrated with as well), with the highest reaching 55. Each of those represents a unique AI product that has been granted OAuth access — the total number of individual consent grants across users is larger, because popular integrations get authorized by multiple employees independently.",{"data":2074,"content":2075,"nodeType":266},{},[2076],{"data":2077,"marks":2078,"value":2079,"nodeType":270},{},[],"The actual number of AI-related OAuth connections across the full SaaS estate is considerably higher again, because AI tools that automate workflows need to be connected to be useful — pulling data from one app, analyzing it in another, presenting results in a third.",{"data":2081,"content":2082,"nodeType":266},{},[2083],{"data":2084,"marks":2085,"value":2086,"nodeType":270},{},[],"MCP connections use OAuth to achieve this interconnectivity in the same way, and AI coding agents create a particularly concentrated version of the risk: a single agent configuration can hold OAuth tokens for Jira, Confluence, Salesforce, GitHub, and more, meaning that compromising one agent — whether through prompt injection, a malicious repository config, or a supply chain attack on an MCP server — yields persistent, broadly scoped tokens for every service it was connected to, tokens that survive session restarts and generate audit log entries indistinguishable from legitimate user activity.",{"data":2088,"content":2089,"nodeType":266},{},[2090],{"data":2091,"marks":2092,"value":2093,"nodeType":270},{},[],"It's also worth noting that OAuth blast radius is almost always larger than organizations expect. A single well-permissioned user can expose secrets, dashboards, and internal tooling without tenant-wide admin access. And every new AI tool an employee connects makes the web of abusable permissions a little wider.",{"data":2095,"content":2099,"nodeType":337},{"target":2096},{"sys":2097},{"id":2098,"type":342,"linkType":343},"4SnzJ9T93gHzFIUASx7Yb3",[],{"data":2101,"content":2102,"nodeType":275},{},[],{"data":2104,"content":2105,"nodeType":279},{},[2106],{"data":2107,"marks":2108,"value":2110,"nodeType":270},{},[2109],{"type":286},"Why shadow AI needs a different solution to shadow SaaS",{"data":2112,"content":2113,"nodeType":266},{},[2114],{"data":2115,"marks":2116,"value":2117,"nodeType":270},{},[],"The reason it's worth distinguishing between these four dimensions isn't academic. Each one requires a different control, and addressing one doesn't solve the others.",{"data":2119,"content":2120,"nodeType":266},{},[2121],{"data":2122,"marks":2123,"value":2124,"nodeType":270},{},[],"Blocking unsanctioned AI apps does nothing for the personal accounts accessing approved ones, and neither addresses the average 17 different AI extensions running with broad browser permissions, let alone the dozens of OAuth integrations that have already been granted persistent access to core enterprise apps — and even auditing OAuth in Google Workspace and Microsoft 365, where the controls are relatively mature, leaves the broader SaaS estate unaddressed, where admin tooling is inconsistent and visibility is limited.",{"data":2126,"content":2127,"nodeType":266},{},[2128,2132,2140],{"data":2129,"marks":2130,"value":2131,"nodeType":270},{},[],"The tooling gap compounds the policy gap. ",{"data":2133,"content":2135,"nodeType":296},{"uri":2134},"https://pushsecurity.com/blog/7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market/",[2136],{"data":2137,"marks":2138,"value":2139,"nodeType":270},{},[],"Omdia found",{"data":2141,"marks":2142,"value":2143,"nodeType":270},{},[]," that 58% of organizations rely on secure web gateways to secure GenAI usage — but an SWG can tell you that a user visited ChatGPT, not whether they pasted your source code into the prompt. That link between knowing where data went and knowing what the user actually did is the fundamental visibility gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":2145,"content":2146,"nodeType":534},{},[2147],{"data":2148,"marks":2149,"value":2151,"nodeType":270},{},[2150],{"type":286},"Advice for security teams",{"data":2153,"content":2154,"nodeType":266},{},[2155],{"data":2156,"marks":2157,"value":2158,"nodeType":270},{},[],"The principles behind managing shadow AI are the same ones that have governed shadow SaaS and software supply chain management for years: default-deny where feasible, comprehensive inventory where it isn't, and continuous monitoring for changes that signal increased risk. But it's vital that teams act fast to stop the snowball.",{"data":2160,"content":2161,"nodeType":266},{},[2162],{"data":2163,"marks":2164,"value":2166,"nodeType":270},{},[2165],{"type":286},"That starts with visibility into which AI tools employees are actually using and which accounts they're using to access them — without that baseline, every other control is built on assumptions.",{"data":2168,"content":2169,"nodeType":266},{},[2170,2175,2179,2186],{"data":2171,"marks":2172,"value":2174,"nodeType":270},{},[2173],{"type":286},"Extensions",{"data":2176,"marks":2177,"value":2178,"nodeType":270},{},[]," need the same ",{"data":2180,"content":2181,"nodeType":296},{"uri":1984},[2182],{"data":2183,"marks":2184,"value":2185,"nodeType":270},{},[],"default-deny allowlisting approach",{"data":2187,"marks":2188,"value":2189,"nodeType":270},{},[]," that has been best practice for software management elsewhere: build a complete inventory, allowlist what's vetted, block everything else, and monitor the approved set for changes that precede weaponization.",{"data":2191,"content":2192,"nodeType":266},{},[2193,2198],{"data":2194,"marks":2195,"value":2197,"nodeType":270},{},[2196],{"type":286},"OAuth",{"data":2199,"marks":2200,"value":2201,"nodeType":270},{},[]," demands the most urgency, because each unmanaged integration is a persistent trust relationship that survives password resets and MFA changes — adopt default-deny for consent grants in your primary enterprise apps, routinely audit what's already connected, and critically extend that visibility beyond Google and Microsoft to the broader SaaS estate where the controls are weaker and the sprawl is harder to track.",{"data":2203,"content":2204,"nodeType":275},{},[],{"data":2206,"content":2207,"nodeType":279},{},[2208],{"data":2209,"marks":2210,"value":2212,"nodeType":270},{},[2211],{"type":286},"Browser visibility and control is key to de-risking AI adoption",{"data":2214,"content":2215,"nodeType":266},{},[2216],{"data":2217,"marks":2218,"value":2219,"nodeType":270},{},[],"AI usage is fundamentally browser-based activity — every LLM interaction, every prompt containing sensitive data, every AI agent authorization, every OAuth consent grant happens inside a browser session — which makes the browser the natural control point for AI governance across the workforce. ",{"data":2221,"content":2222,"nodeType":266},{},[2223],{"data":2224,"marks":2225,"value":2226,"nodeType":270},{},[],"Push tracks AI app usage and login security across the workforce, inventories and controls AI browser extensions, monitors and blocks OAuth consent flows across any app (not just the primary enterprise platforms), and gives security teams a single view of the full shadow AI picture across all four dimensions.",{"data":2228,"content":2229,"nodeType":266},{},[2230],{"data":2231,"marks":2232,"value":2233,"nodeType":270},{},[],"Shadow AI isn't a problem that will age well if ignored. Every week that passes without visibility adds more apps, more extensions, more integrations, and more potential breach paths into the environment — and as the Vercel breach demonstrated, it only takes one forgotten OAuth grant to turn an employee's idle curiosity into an organization-wide incident.",{"data":2235,"content":2236,"nodeType":266},{},[2237,2241,2250],{"data":2238,"marks":2239,"value":2240,"nodeType":270},{},[],"Learn more about how you can tackle ",{"data":2242,"content":2244,"nodeType":296},{"uri":2243},"https://pushsecurity.com/uc/shadow-ai",[2245],{"data":2246,"marks":2247,"value":2249,"nodeType":270},{},[2248],{"type":1351},"Shadow AI",{"data":2251,"marks":2252,"value":2253,"nodeType":270},{},[]," with Push. ",{"data":2255,"content":2256,"nodeType":275},{},[],{"data":2258,"content":2259,"nodeType":266},{},[2260],{"data":2261,"marks":2262,"value":1553,"nodeType":270},{},[],{"data":2264,"content":2265,"nodeType":266},{},[2266],{"data":2267,"marks":2268,"value":1560,"nodeType":270},{},[],{"data":2270,"content":2271,"nodeType":266},{},[2272,2276,2285],{"data":2273,"marks":2274,"value":2275,"nodeType":270},{},[],"Book a ",{"data":2277,"content":2279,"nodeType":296},{"uri":2278},"https://pushsecurity.com/demo",[2280],{"data":2281,"marks":2282,"value":2284,"nodeType":270},{},[2283],{"type":1351},"live demo",{"data":2286,"marks":2287,"value":2288,"nodeType":270},{},[]," to learn more.","Shadow AI: what Push data reveals about the scale of the problem","AI adoption has been a genuine force multiplier for Shadow IT to the point that it may have surpassed the problem of wider Shadow SaaS. ","2026-05-28T00:00:00.000Z","what-push-data-reveals-about-the-state-of-shadow-ai",{"items":2294},[2295,2299],{"sys":2296,"name":2298},{"id":2297},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"sys":2300,"name":2302},{"id":2301},"3pjES4THCIfSAwhGdNwBcy","Browser security",{"items":2304},[2305],{"fullName":253,"firstName":254,"jobTitle":255,"profilePicture":2306},{"url":259},{"__typename":1679,"sys":2308,"content":2310,"title":2721,"synopsis":2722,"hashTags":59,"publishedDate":2723,"slug":2724,"tagsCollection":2725,"authorsCollection":2735},{"id":2309},"4fUZAVpkaksHImeoT8jp0f",{"json":2311},{"nodeType":262,"data":2312,"content":2313},{},[2314,2321,2328,2335,2342,2349,2369,2376,2383,2390,2396,2399,2406,2425,2431,2447,2463,2479,2495,2502,2509,2516,2522,2529,2536,2543,2550,2556,2576,2591,2598,2605,2612,2619,2626,2633,2639,2646,2653,2660,2667,2674,2681,2688,2695,2702],{"nodeType":266,"data":2315,"content":2316},{},[2317],{"nodeType":270,"value":2318,"marks":2319,"data":2320},"Every security engineer has a version of this ritual. ",[],{},{"nodeType":266,"data":2322,"content":2323},{},[2324],{"nodeType":270,"value":2325,"marks":2326,"data":2327},"A new campaign hits the news, and you already hear the question coming, “Are we covered?”",[],{},{"nodeType":266,"data":2329,"content":2330},{},[2331],{"nodeType":270,"value":2332,"marks":2333,"data":2334},"So you read the writeup and quickly do the calculus on whether you can extract meaningful data, something to base a behavioral detection around — or not.",[],{},{"nodeType":266,"data":2336,"content":2337},{},[2338],{"nodeType":270,"value":2339,"marks":2340,"data":2341},"Then the choice is: Send the IOCs you can identify to your blocklists and move on for now, or try to dig deeper. The limitations of the first choice are clear; so are the challenges of the second.",[],{},{"nodeType":266,"data":2343,"content":2344},{},[2345],{"nodeType":270,"value":2346,"marks":2347,"data":2348},"That’s the uncomfortable gap between “We’re aware of this threat” and “We have strong detections around it.”",[],{},{"nodeType":266,"data":2350,"content":2351},{},[2352,2356,2365],{"nodeType":270,"value":2353,"marks":2354,"data":2355},"Because you already know that the IOCs for a novel browser-based attack are likely outdated the moment you block them. And in the case of a ",[],{},{"nodeType":296,"data":2357,"content":2359},{"uri":2358},"https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/",[2360],{"nodeType":270,"value":2361,"marks":2362,"data":2364},"new technique observed by Microsoft",[2363],{"type":1351},{},{"nodeType":270,"value":2366,"marks":2367,"data":2368}," earlier this year, you’d be right.",[],{},{"nodeType":266,"data":2370,"content":2371},{},[2372],{"nodeType":270,"value":2373,"marks":2374,"data":2375},"In March, Push’s AI agents took a close look at that Microsoft intel, which details a discovered campaign built around a novel OAuth redirect abuse technique used to deliver users to phishing pages under the cover of trusted services’ OAuth flows. ",[],{},{"nodeType":266,"data":2377,"content":2378},{},[2379],{"nodeType":270,"value":2380,"marks":2381,"data":2382},"What we found was indicative of how these attacks rapidly evolve: No matches for the published IOCs across our install base. But a few months later, we got a true positive. Except it was for new lures, new variants, and different IOCs. What hadn’t changed was the underlying attack delivery technique, and that’s what we used to detect a new campaign on Push customer estates.",[],{},{"nodeType":266,"data":2384,"content":2385},{},[2386],{"nodeType":270,"value":2387,"marks":2388,"data":2389},"In this article, we’ll walk through this example as a case study of how agentic threat hunting helps us go beyond IOCs to extract durable behavioral indicators that close the gap between “We’re aware of this threat” and “We’re covered.”",[],{},{"nodeType":337,"data":2391,"content":2395},{"target":2392},{"sys":2393},{"id":2394,"type":342,"linkType":343},"6X7yXNdchH1Qp2tNKRAyVP",[],{"nodeType":275,"data":2397,"content":2398},{},[],{"nodeType":279,"data":2400,"content":2401},{},[2402],{"nodeType":270,"value":2403,"marks":2404,"data":2405},"The intel: Novel abuse of OAuth redirects as a phishing delivery mechanism",[],{},{"nodeType":266,"data":2407,"content":2408},{},[2409,2413,2421],{"nodeType":270,"value":2410,"marks":2411,"data":2412},"The technique ",[],{},{"nodeType":296,"data":2414,"content":2415},{"uri":2358},[2416],{"nodeType":270,"value":2417,"marks":2418,"data":2420},"Microsoft documented",[2419],{"type":1351},{},{"nodeType":270,"value":2422,"marks":2423,"data":2424}," back in March is an interesting one. It doesn't steal tokens or abuse consent flows. Instead, it weaponizes the OAuth error-handling path itself — turning trusted identity provider domains into a delivery mechanism for phishing and malware.",[],{},{"nodeType":337,"data":2426,"content":2430},{"target":2427},{"sys":2428},{"id":2429,"type":342,"linkType":343},"486pfUpMxx15vJupxuiePn",[],{"nodeType":266,"data":2432,"content":2433},{},[2434,2438,2443],{"nodeType":270,"value":2435,"marks":2436,"data":2437},"Here's how it works. The attacker registers a malicious application in an actor-controlled tenant, pointing its redirect URI at attacker infrastructure. They craft an authorization URL using ",[],{},{"nodeType":270,"value":2439,"marks":2440,"data":2442},"prompt=none",[2441],{"type":286},{},{"nodeType":270,"value":2444,"marks":2445,"data":2446}," (forcing silent authentication) and an intentionally invalid scope, which guarantees an OAuth error. ",[],{},{"nodeType":266,"data":2448,"content":2449},{},[2450,2454,2459],{"nodeType":270,"value":2451,"marks":2452,"data":2453},"The identity provider — Microsoft Entra ID, Google Workspace, or any OAuth-compliant service — handles that error the way the spec says it should: By redirecting the browser to the application's registered redirect URI. The user clicks a link that begins at ",[],{},{"nodeType":270,"value":2455,"marks":2456,"data":2458},"login.microsoftonline.com",[2457],{"type":286},{},{"nodeType":270,"value":2460,"marks":2461,"data":2462},", passes through a legitimate authentication endpoint, and lands on an attacker-controlled page.",[],{},{"nodeType":266,"data":2464,"content":2465},{},[2466,2470,2475],{"nodeType":270,"value":2467,"marks":2468,"data":2469},"Importantly, no token is stolen during the redirect. The OAuth flow is the delivery vehicle, not the compromise mechanism. What happens ",[],{},{"nodeType":270,"value":2471,"marks":2472,"data":2474},"after",[2473],{"type":1818},{},{"nodeType":270,"value":2476,"marks":2477,"data":2478}," the redirect — phishing, malware download, credential harvesting — is where the actual attack occurs.",[],{},{"nodeType":266,"data":2480,"content":2481},{},[2482,2486,2491],{"nodeType":270,"value":2483,"marks":2484,"data":2485},"This technique is also successful because conventional URL filtering sees a legitimate authentication domain, not a phishing destination. The redirect is standards-compliant behavior, and the initial URL carries the domain reputation of a trusted identity provider — which means the usual defenses at the network layer don't fire. (No TI or domain-based detection service in the world would raise a ",[],{},{"nodeType":270,"value":2487,"marks":2488,"data":2490},"microsoft.com",[2489],{"type":286},{},{"nodeType":270,"value":2492,"marks":2493,"data":2494}," domain as suspicious!)",[],{},{"nodeType":266,"data":2496,"content":2497},{},[2498],{"nodeType":270,"value":2499,"marks":2500,"data":2501},"With this intel, Push’s agents now had some useful fodder to hunt for.",[],{},{"nodeType":279,"data":2503,"content":2504},{},[2505],{"nodeType":270,"value":2506,"marks":2507,"data":2508},"Hunting from intel: How we developed a behavioral detection",[],{},{"nodeType":266,"data":2510,"content":2511},{},[2512],{"nodeType":270,"value":2513,"marks":2514,"data":2515},"It started with ingestion. When the Microsoft blog was published, Push's TI aggregation agent flagged it as relevant to our detection surface — the technique abuses OAuth redirect behavior observable in the browser, which maps directly to the metadata that Push's browser agent captures.",[],{},{"nodeType":337,"data":2517,"content":2521},{"target":2518},{"sys":2519},{"id":2520,"type":342,"linkType":343},"26saWWXsyFAZrsrfspGwaF",[],{"nodeType":266,"data":2523,"content":2524},{},[2525],{"nodeType":270,"value":2526,"marks":2527,"data":2528},"The Push intel agent understands not to hunt for IOCs, but rather to think in terms of durable behaviors. It understands the telemetry available to the Push browser extension, and then compares that to the telemetry it would expect to be able to extract for a given technique, before deciding what to hunt for.",[],{},{"nodeType":266,"data":2530,"content":2531},{},[2532],{"nodeType":270,"value":2533,"marks":2534,"data":2535},"In this case, the intel agent extracted two distinct behavioral elements from the research to look for: the OAuth redirect technique and the page users land on after the error.",[],{},{"nodeType":266,"data":2537,"content":2538},{},[2539],{"nodeType":270,"value":2540,"marks":2541,"data":2542},"That extraction step is where surface-level details can become technique-driven hunts. Microsoft's article listed specific client IDs, redirect URLs, and PowerShell command patterns — indicators that are useful for retrospective hunting but will rotate as the campaign evolves. ",[],{},{"nodeType":266,"data":2544,"content":2545},{},[2546],{"nodeType":270,"value":2547,"marks":2548,"data":2549},"The pipeline's job was to identify what wouldn't change: The behavioral mechanics of abusing the OAuth error redirect path as a delivery mechanism, independent of which domains, client IDs, or post-redirect payloads the attacker chose to use. This is the Pyramid of Pain principle in practice: Hunt for the technique, not the indicator, because techniques are genuinely hard for attackers to change.",[],{},{"nodeType":337,"data":2551,"content":2555},{"target":2552},{"sys":2553},{"id":2554,"type":342,"linkType":343},"7qUVlKVjHMkabu0MJ1S7gC",[],{"nodeType":266,"data":2557,"content":2558},{},[2559,2563,2572],{"nodeType":270,"value":2560,"marks":2561,"data":2562},"Next, the agents verified what they already knew from Push’s internal TTP knowledge base. In this case, the agents understood the well-known technique of ",[],{},{"nodeType":296,"data":2564,"content":2566},{"uri":2565},"https://owasp.org/www-community/attacks/open_redirect",[2567],{"nodeType":270,"value":2568,"marks":2569,"data":2571},"open redirects",[2570],{"type":1351},{},{"nodeType":270,"value":2573,"marks":2574,"data":2575},", where attackers leverage redirects to deliver users to a malicious page. The example originally published by Microsoft was a novel variation of that — abusing a trusted service and the open redirect technique via a legitimate OAuth error workflow to deliver a multi-stage phishing attack.",[],{},{"nodeType":266,"data":2577,"content":2578},{},[2579,2583,2587],{"nodeType":270,"value":2580,"marks":2581,"data":2582},"AI models’ deep knowledge of web programming and frameworks is a particular strength here, because they understand which OAuth redirect behavior is normal and common across diverse scenarios, and can pinpoint which elements will be the strongest signal to hunt for malicious behavior. The agents immediately recognized that hunting for ",[],{},{"nodeType":270,"value":2439,"marks":2584,"data":2586},[2585],{"type":286},{},{"nodeType":270,"value":2588,"marks":2589,"data":2590}," would be too noisy, as legitimate apps regularly use silent token refresh.",[],{},{"nodeType":266,"data":2592,"content":2593},{},[2594],{"nodeType":270,"value":2595,"marks":2596,"data":2597},"In this case, the approach was simply to find all the instances where a user hit an OAuth error page, and then landed on a login page afterward. Normal behavior for error states would be to return an error response — not send the user on to a page with a password form field or a CAPTCHA. That’s highly suspicious.",[],{},{"nodeType":266,"data":2599,"content":2600},{},[2601],{"nodeType":270,"value":2602,"marks":2603,"data":2604},"The agents then built behavioral queries targeting both behavioral attributes of the attack, and validated them across Push's install base. ",[],{},{"nodeType":266,"data":2606,"content":2607},{},[2608],{"nodeType":270,"value":2609,"marks":2610,"data":2611},"When agents first looked in March, the hunts returned no true positives — the specific campaign Microsoft documented wasn’t active against Push customers at that time.",[],{},{"nodeType":266,"data":2613,"content":2614},{},[2615],{"nodeType":270,"value":2616,"marks":2617,"data":2618},"But the query logic was sound — precise enough to avoid false positives, broad enough to catch technique variants without relying on the specific IOCs that Microsoft documented. So the pipeline promoted it to a live query — a continuing detection that would surface any future instances of the technique across the customer base.",[],{},{"nodeType":279,"data":2620,"content":2621},{},[2622],{"nodeType":270,"value":2623,"marks":2624,"data":2625},"The hunt pays off: A new variant, completely different IOCs",[],{},{"nodeType":266,"data":2627,"content":2628},{},[2629],{"nodeType":270,"value":2630,"marks":2631,"data":2632},"In June, the query fired. A single user at a single customer had been targeted, but with a completely different scenario. ",[],{},{"nodeType":337,"data":2634,"content":2638},{"target":2635},{"sys":2636},{"id":2637,"type":342,"linkType":343},"7uXgOzxemy1PaJLhUa1txV",[],{"nodeType":266,"data":2640,"content":2641},{},[2642],{"nodeType":270,"value":2643,"marks":2644,"data":2645},"Where the Microsoft-documented example used lures presented as document-sharing links, Teams meeting recordings, or password resets, and the abused trusted service was a Microsoft login link used to trigger the OAuth error, the Push-observed attack chain used different elements. However, the behavioral technique at the core was the same.",[],{},{"nodeType":266,"data":2647,"content":2648},{},[2649],{"nodeType":270,"value":2650,"marks":2651,"data":2652},"In this case, the user clicked a link in a service desk ticket, triggering an OAuth flow that used a redirect URL with parameters designed to make it look like a Grammarly link. After hitting the OAuth error, the user was redirected to a page with a CAPTCHA, and then redirected again to a second page behind a Cloudflare Turnstile that was running a phish kit. While examining the phishing page, Push’s agents found a net-new phish kit that they later added additional detections for. ",[],{},{"nodeType":266,"data":2654,"content":2655},{},[2656],{"nodeType":270,"value":2657,"marks":2658,"data":2659},"Roughly a day after the Push detection fired, Google Safe Browsing flagged both domains as phishing domains. But when the user was first targeted, neither domain had been flagged. In this case, the user exited the redirect flow before entering any credentials.",[],{},{"nodeType":266,"data":2661,"content":2662},{},[2663],{"nodeType":270,"value":2664,"marks":2665,"data":2666},"It’s important to note that this phishing technique also bypasses other controls based on network content pattern analysis or domain-based detections. For example, a network proxy is designed to look for malicious webpages based on known-bad IOCs like domains or page content that contains known-bad script files. This technique uses a dynamic obfuscated Javascript blob that unpacks and loads the webpage on the client side after checking to see if it’s running in a live browser environment, evading proxy-based analysis.",[],{},{"nodeType":266,"data":2668,"content":2669},{},[2670],{"nodeType":270,"value":2671,"marks":2672,"data":2673},"The query now serves as another early-warning flag designed to be broad enough to catch other interesting new variants of this TTP.",[],{},{"nodeType":279,"data":2675,"content":2676},{},[2677],{"nodeType":270,"value":2678,"marks":2679,"data":2680},"Why technique-level detection pays dividends",[],{},{"nodeType":266,"data":2682,"content":2683},{},[2684],{"nodeType":270,"value":2685,"marks":2686,"data":2687},"This example demonstrates the value of behavioral detection. By focusing on technique extraction, we can stay a step ahead of attack evolution, identifying other contexts and campaigns that use the same behavioral technique, without relying on stale IOCs.",[],{},{"nodeType":266,"data":2689,"content":2690},{},[2691],{"nodeType":270,"value":2692,"marks":2693,"data":2694},"For customers, this means no one has to distil the threat intel report into behavioral elements, spend time crafting detections, or work to eliminate false positives. The Push agents do all that automatically, delivering a compounding benefit the more they learn. ",[],{},{"nodeType":266,"data":2696,"content":2697},{},[2698],{"nodeType":270,"value":2699,"marks":2700,"data":2701},"Customers get a fully operationalized threat-hunting and detection engineering capability; and the Push knowledge base itself expands with each new hunt, getting better at identifying emerging threats.",[],{},{"nodeType":266,"data":2703,"content":2704},{},[2705,2709,2717],{"nodeType":270,"value":2706,"marks":2707,"data":2708},"If you'd like to see how Push's detection pipeline would work in your environment, ",[],{},{"nodeType":296,"data":2710,"content":2711},{"uri":2278},[2712],{"nodeType":270,"value":2713,"marks":2714,"data":2716},"book a demo",[2715],{"type":1351},{},{"nodeType":270,"value":2718,"marks":2719,"data":2720}," with our team.",[],{},"From IOCs to TTPs: An agentic threat hunting case study","How Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources.","2026-07-31T00:00:00.000Z","from-iocs-to-ttps-an-agentic-threat-hunting-case-study",{"items":2726},[2727,2731],{"sys":2728,"name":2730},{"id":2729},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":2732,"name":2734},{"id":2733},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":2736},[2737],{"fullName":2738,"firstName":2739,"jobTitle":2740,"profilePicture":2741},"Kelly Davenport","Kelly","Product Team",{"url":2742},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1679,"sys":2744,"content":2746,"title":3587,"synopsis":3588,"hashTags":59,"publishedDate":3589,"slug":3590,"tagsCollection":3591,"authorsCollection":3597},{"id":2745},"211Dd0EIrXPOFpvRgs0fEE",{"json":2747},{"data":2748,"content":2749,"nodeType":262},{},[2750,2769,2788,2807,2813,2816,2824,2831,2838,2845,2852,2860,2863,2871,2878,2885,2892,2898,2906,2925,2932,2939,2955,2963,2994,3010,3017,3048,3056,3087,3094,3102,3120,3127,3134,3140,3147,3155,3173,3180,3199,3206,3209,3217,3224,3312,3319,3335,3338,3368,3387,3394,3401,3404,3412,3431,3438,3445,3462,3465,3473,3480,3513,3520,3537,3556,3562,3565,3572],{"data":2751,"content":2752,"nodeType":266},{},[2753,2757,2765],{"data":2754,"marks":2755,"value":2756,"nodeType":270},{},[],"When we released the ",{"data":2758,"content":2760,"nodeType":296},{"uri":2759},"https://pushsecurity.com/blog/saas-attack-techniques/",[2761],{"data":2762,"marks":2763,"value":2764,"nodeType":270},{},[],"SaaS attack matrix",{"data":2766,"marks":2767,"value":2768,"nodeType":270},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":2770,"content":2771,"nodeType":266},{},[2772,2776,2784],{"data":2773,"marks":2774,"value":2775,"nodeType":270},{},[],"A year later, we ",{"data":2777,"content":2779,"nodeType":296},{"uri":2778},"https://pushsecurity.com/blog/the-saas-attack-matrix-one-year-on/",[2780],{"data":2781,"marks":2782,"value":2783,"nodeType":270},{},[],"reviewed what had changed",{"data":2785,"marks":2786,"value":2787,"nodeType":270},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":2789,"content":2790,"nodeType":266},{},[2791,2795,2803],{"data":2792,"marks":2793,"value":2794,"nodeType":270},{},[],"Today, we're re-releasing the matrix as the ",{"data":2796,"content":2798,"nodeType":296},{"uri":2797},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/",[2799],{"data":2800,"marks":2801,"value":2802,"nodeType":270},{},[],"Browser & Identity Attacks Matrix",{"data":2804,"marks":2805,"value":2806,"nodeType":270},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":2808,"content":2812,"nodeType":337},{"target":2809},{"sys":2810},{"id":2811,"type":342,"linkType":343},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":2814,"content":2815,"nodeType":275},{},[],{"data":2817,"content":2818,"nodeType":279},{},[2819],{"data":2820,"marks":2821,"value":2823,"nodeType":270},{},[2822],{"type":286},"Why the scope needed to change",{"data":2825,"content":2826,"nodeType":266},{},[2827],{"data":2828,"marks":2829,"value":2830,"nodeType":270},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":2832,"content":2833,"nodeType":266},{},[2834],{"data":2835,"marks":2836,"value":2837,"nodeType":270},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":2839,"content":2840,"nodeType":266},{},[2841],{"data":2842,"marks":2843,"value":2844,"nodeType":270},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":2846,"content":2847,"nodeType":266},{},[2848],{"data":2849,"marks":2850,"value":2851,"nodeType":270},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":2853,"content":2854,"nodeType":266},{},[2855],{"data":2856,"marks":2857,"value":2859,"nodeType":270},{},[2858],{"type":286},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":2861,"content":2862,"nodeType":275},{},[],{"data":2864,"content":2865,"nodeType":279},{},[2866],{"data":2867,"marks":2868,"value":2870,"nodeType":270},{},[2869],{"type":286},"The technique landscape has transformed",{"data":2872,"content":2873,"nodeType":266},{},[2874],{"data":2875,"marks":2876,"value":2877,"nodeType":270},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":2879,"content":2880,"nodeType":266},{},[2881],{"data":2882,"marks":2883,"value":2884,"nodeType":270},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":2886,"content":2887,"nodeType":266},{},[2888],{"data":2889,"marks":2890,"value":2891,"nodeType":270},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":2893,"content":2897,"nodeType":337},{"target":2894},{"sys":2895},{"id":2896,"type":342,"linkType":343},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":2899,"content":2900,"nodeType":534},{},[2901],{"data":2902,"marks":2903,"value":2905,"nodeType":270},{},[2904],{"type":286},"AiTM phishing has become the default phishing method",{"data":2907,"content":2908,"nodeType":266},{},[2909,2913,2921],{"data":2910,"marks":2911,"value":2912,"nodeType":270},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":2914,"content":2916,"nodeType":296},{"uri":2915},"https://pushsecurity.com/blog/2025-top-phishing-trends/",[2917],{"data":2918,"marks":2919,"value":2920,"nodeType":270},{},[],"62% of phishing detected by Microsoft",{"data":2922,"marks":2923,"value":2924,"nodeType":270},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":2926,"content":2927,"nodeType":266},{},[2928],{"data":2929,"marks":2930,"value":2931,"nodeType":270},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":2933,"content":2934,"nodeType":266},{},[2935],{"data":2936,"marks":2937,"value":2938,"nodeType":270},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":2940,"content":2941,"nodeType":266},{},[2942,2946,2951],{"data":2943,"marks":2944,"value":2945,"nodeType":270},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":2947,"marks":2948,"value":2950,"nodeType":270},{},[2949],{"type":286},"442% year-over-year increase",{"data":2952,"marks":2953,"value":2954,"nodeType":270},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":2956,"content":2957,"nodeType":534},{},[2958],{"data":2959,"marks":2960,"value":2962,"nodeType":270},{},[2961],{"type":286},"ClickFix is the top reported initial access vector",{"data":2964,"content":2965,"nodeType":266},{},[2966,2970,2978,2982,2990],{"data":2967,"marks":2968,"value":2969,"nodeType":270},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":2971,"content":2973,"nodeType":296},{"uri":2972},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf",[2974],{"data":2975,"marks":2976,"value":2977,"nodeType":270},{},[],"most common initial access vector in 2025",{"data":2979,"marks":2980,"value":2981,"nodeType":270},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":2983,"content":2985,"nodeType":296},{"uri":2984},"https://www.crowdstrike.com/explore/2026-global-threat-report",[2986],{"data":2987,"marks":2988,"value":2989,"nodeType":270},{},[],"563% increase",{"data":2991,"marks":2992,"value":2993,"nodeType":270},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":2995,"content":2996,"nodeType":266},{},[2997,3001,3006],{"data":2998,"marks":2999,"value":3000,"nodeType":270},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":3002,"marks":3003,"value":3005,"nodeType":270},{},[3004],{"type":286},"4 in 5 ClickFix payloads",{"data":3007,"marks":3008,"value":3009,"nodeType":270},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":3011,"content":3012,"nodeType":266},{},[3013],{"data":3014,"marks":3015,"value":3016,"nodeType":270},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":3018,"content":3019,"nodeType":266},{},[3020,3024,3032,3036,3044],{"data":3021,"marks":3022,"value":3023,"nodeType":270},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":3025,"content":3027,"nodeType":296},{"uri":3026},"https://pushsecurity.com/blog/installfix/",[3028],{"data":3029,"marks":3030,"value":3031,"nodeType":270},{},[],"InstallFix",{"data":3033,"marks":3034,"value":3035,"nodeType":270},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":3037,"content":3039,"nodeType":296},{"uri":3038},"https://pushsecurity.com/blog/consentfix/",[3040],{"data":3041,"marks":3042,"value":3043,"nodeType":270},{},[],"ConsentFix",{"data":3045,"marks":3046,"value":3047,"nodeType":270},{},[]," was a genuinely novel development.",{"data":3049,"content":3050,"nodeType":534},{},[3051],{"data":3052,"marks":3053,"value":3055,"nodeType":270},{},[3054],{"type":286},"Browser-native ClickFix: ConsentFix",{"data":3057,"content":3058,"nodeType":266},{},[3059,3063,3071,3075,3083],{"data":3060,"marks":3061,"value":3062,"nodeType":270},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":3064,"content":3066,"nodeType":296},{"uri":3065},"https://pushsecurity.com/blog/consentfix-debrief/",[3067],{"data":3068,"marks":3069,"value":3070,"nodeType":270},{},[],"traced to APT29",{"data":3072,"marks":3073,"value":3074,"nodeType":270},{},[]," and has since been ",{"data":3076,"content":3078,"nodeType":296},{"uri":3077},"https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit/",[3079],{"data":3080,"marks":3081,"value":3082,"nodeType":270},{},[],"commercialized on criminal forums",{"data":3084,"marks":3085,"value":3086,"nodeType":270},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":3088,"content":3089,"nodeType":266},{},[3090],{"data":3091,"marks":3092,"value":3093,"nodeType":270},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":3095,"content":3096,"nodeType":534},{},[3097],{"data":3098,"marks":3099,"value":3101,"nodeType":270},{},[3100],{"type":286},"Attackers have pivoted to authorization attacks to get around login controls",{"data":3103,"content":3104,"nodeType":266},{},[3105,3109,3116],{"data":3106,"marks":3107,"value":3108,"nodeType":270},{},[],"Authorization attacks like device code phishing have seen a ",{"data":3110,"content":3111,"nodeType":296},{"uri":754},[3112],{"data":3113,"marks":3114,"value":3115,"nodeType":270},{},[],"37.5x increase",{"data":3117,"marks":3118,"value":3119,"nodeType":270},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":3121,"content":3122,"nodeType":266},{},[3123],{"data":3124,"marks":3125,"value":3126,"nodeType":270},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":3128,"content":3129,"nodeType":266},{},[3130],{"data":3131,"marks":3132,"value":3133,"nodeType":270},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":3135,"content":3139,"nodeType":337},{"target":3136},{"sys":3137},{"id":3138,"type":342,"linkType":343},"2WPb41lNRajdpt5pogQg8M",[],{"data":3141,"content":3142,"nodeType":266},{},[3143],{"data":3144,"marks":3145,"value":3146,"nodeType":270},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":3148,"content":3149,"nodeType":534},{},[3150],{"data":3151,"marks":3152,"value":3154,"nodeType":270},{},[3153],{"type":286},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":3156,"content":3157,"nodeType":266},{},[3158,3162,3169],{"data":3159,"marks":3160,"value":3161,"nodeType":270},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":3163,"content":3164,"nodeType":296},{"uri":1984},[3165],{"data":3166,"marks":3167,"value":3168,"nodeType":270},{},[],"Cyberhaven compromise",{"data":3170,"marks":3171,"value":3172,"nodeType":270},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":3174,"content":3175,"nodeType":266},{},[3176],{"data":3177,"marks":3178,"value":3179,"nodeType":270},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":3181,"content":3182,"nodeType":266},{},[3183,3187,3195],{"data":3184,"marks":3185,"value":3186,"nodeType":270},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":3188,"content":3189,"nodeType":296},{"uri":1984},[3190],{"data":3191,"marks":3192,"value":3194,"nodeType":270},{},[3193],{"type":1351},"most malicious extensions didn't start out malicious",{"data":3196,"marks":3197,"value":3198,"nodeType":270},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":3200,"content":3201,"nodeType":266},{},[3202],{"data":3203,"marks":3204,"value":3205,"nodeType":270},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":3207,"content":3208,"nodeType":275},{},[],{"data":3210,"content":3211,"nodeType":279},{},[3212],{"data":3213,"marks":3214,"value":3216,"nodeType":270},{},[3215],{"type":286},"The evolution is playing out in public breaches",{"data":3218,"content":3219,"nodeType":266},{},[3220],{"data":3221,"marks":3222,"value":3223,"nodeType":270},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":3225,"content":3226,"nodeType":1287},{},[3227,3248,3270,3290],{"data":3228,"content":3229,"nodeType":1291},{},[3230],{"data":3231,"content":3232,"nodeType":266},{},[3233,3237,3244],{"data":3234,"marks":3235,"value":3236,"nodeType":270},{},[],"When ",{"data":3238,"content":3240,"nodeType":296},{"uri":3239},"https://pushsecurity.com/blog/scattered-lapsus-hunters/",[3241],{"data":3242,"marks":3243,"value":301,"nodeType":270},{},[],{"data":3245,"marks":3246,"value":3247,"nodeType":270},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.",{"data":3249,"content":3250,"nodeType":1291},{},[3251],{"data":3252,"content":3253,"nodeType":266},{},[3254,3258,3266],{"data":3255,"marks":3256,"value":3257,"nodeType":270},{},[],"When the same collective launched ",{"data":3259,"content":3261,"nodeType":296},{"uri":3260},"https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign/",[3262],{"data":3263,"marks":3264,"value":3265,"nodeType":270},{},[],"AiTM phishing campaigns",{"data":3267,"marks":3268,"value":3269,"nodeType":270},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":3271,"content":3272,"nodeType":1291},{},[3273],{"data":3274,"content":3275,"nodeType":266},{},[3276,3279,3286],{"data":3277,"marks":3278,"value":3236,"nodeType":270},{},[],{"data":3280,"content":3281,"nodeType":296},{"uri":3038},[3282],{"data":3283,"marks":3284,"value":3285,"nodeType":270},{},[],"APT29 deployed ConsentFix",{"data":3287,"marks":3288,"value":3289,"nodeType":270},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":3291,"content":3292,"nodeType":1291},{},[3293],{"data":3294,"content":3295,"nodeType":266},{},[3296,3300,3308],{"data":3297,"marks":3298,"value":3299,"nodeType":270},{},[],"The ",{"data":3301,"content":3303,"nodeType":296},{"uri":3302},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[3304],{"data":3305,"marks":3306,"value":3307,"nodeType":270},{},[],"Snowflake breach",{"data":3309,"marks":3310,"value":3311,"nodeType":270},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.",{"data":3313,"content":3314,"nodeType":266},{},[3315],{"data":3316,"marks":3317,"value":3318,"nodeType":270},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":3320,"content":3321,"nodeType":266},{},[3322,3326,3331],{"data":3323,"marks":3324,"value":3325,"nodeType":270},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":3327,"marks":3328,"value":3330,"nodeType":270},{},[3329],{"type":286},"29 minutes",{"data":3332,"marks":3333,"value":3334,"nodeType":270},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":3336,"content":3337,"nodeType":275},{},[],{"data":3339,"content":3340,"nodeType":279},{},[3341,3346,3352,3357,3363],{"data":3342,"marks":3343,"value":3345,"nodeType":270},{},[3344],{"type":286},"Sidenote: why we're looking at attacks ",{"data":3347,"marks":3348,"value":3351,"nodeType":270},{},[3349,3350],{"type":1818},{"type":286},"in",{"data":3353,"marks":3354,"value":3356,"nodeType":270},{},[3355],{"type":286}," the browser, not ",{"data":3358,"marks":3359,"value":3362,"nodeType":270},{},[3360,3361],{"type":1818},{"type":286},"on",{"data":3364,"marks":3365,"value":3367,"nodeType":270},{},[3366],{"type":286}," the browser",{"data":3369,"content":3370,"nodeType":266},{},[3371,3375,3383],{"data":3372,"marks":3373,"value":3374,"nodeType":270},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":3376,"content":3378,"nodeType":296},{"uri":3377},"https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review",[3379],{"data":3380,"marks":3381,"value":3382,"nodeType":270},{},[],"historic low of 9%",{"data":3384,"marks":3385,"value":3386,"nodeType":270},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":3388,"content":3389,"nodeType":266},{},[3390],{"data":3391,"marks":3392,"value":3393,"nodeType":270},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":3395,"content":3396,"nodeType":266},{},[3397],{"data":3398,"marks":3399,"value":3400,"nodeType":270},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":3402,"content":3403,"nodeType":275},{},[],{"data":3405,"content":3406,"nodeType":279},{},[3407],{"data":3408,"marks":3409,"value":3411,"nodeType":270},{},[3410],{"type":286},"What hasn't changed",{"data":3413,"content":3414,"nodeType":266},{},[3415,3419,3427],{"data":3416,"marks":3417,"value":3418,"nodeType":270},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":3420,"content":3422,"nodeType":296},{"uri":3421},"https://github.com/pushsecurity/saas-attacks",[3423],{"data":3424,"marks":3425,"value":3426,"nodeType":270},{},[],"GitHub",{"data":3428,"marks":3429,"value":3430,"nodeType":270},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":3432,"content":3433,"nodeType":266},{},[3434],{"data":3435,"marks":3436,"value":3437,"nodeType":270},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":3439,"content":3440,"nodeType":266},{},[3441],{"data":3442,"marks":3443,"value":3444,"nodeType":270},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":3446,"content":3447,"nodeType":266},{},[3448,3452,3459],{"data":3449,"marks":3450,"value":3451,"nodeType":270},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":3453,"content":3455,"nodeType":296},{"uri":3454},"https://github.com/pushsecurity/browser-identity-attacks-matrix",[3456],{"data":3457,"marks":3458,"value":3426,"nodeType":270},{},[],{"data":3460,"marks":3461,"value":333,"nodeType":270},{},[],{"data":3463,"content":3464,"nodeType":275},{},[],{"data":3466,"content":3467,"nodeType":279},{},[3468],{"data":3469,"marks":3470,"value":3472,"nodeType":270},{},[3471],{"type":286},"Looking ahead",{"data":3474,"content":3475,"nodeType":266},{},[3476],{"data":3477,"marks":3478,"value":3479,"nodeType":270},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":3481,"content":3482,"nodeType":1287},{},[3483,3493,3503],{"data":3484,"content":3485,"nodeType":1291},{},[3486],{"data":3487,"content":3488,"nodeType":266},{},[3489],{"data":3490,"marks":3491,"value":3492,"nodeType":270},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":3494,"content":3495,"nodeType":1291},{},[3496],{"data":3497,"content":3498,"nodeType":266},{},[3499],{"data":3500,"marks":3501,"value":3502,"nodeType":270},{},[],"ClickFix has spawned fully browser-native variants.",{"data":3504,"content":3505,"nodeType":1291},{},[3506],{"data":3507,"content":3508,"nodeType":266},{},[3509],{"data":3510,"marks":3511,"value":3512,"nodeType":270},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":3514,"content":3515,"nodeType":266},{},[3516],{"data":3517,"marks":3518,"value":3519,"nodeType":270},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":3521,"content":3522,"nodeType":266},{},[3523,3527,3534],{"data":3524,"marks":3525,"value":3526,"nodeType":270},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":3528,"content":3529,"nodeType":296},{"uri":2797},[3530],{"data":3531,"marks":3532,"value":3533,"nodeType":270},{},[],"explore the matrix here",{"data":3535,"marks":3536,"value":333,"nodeType":270},{},[],{"data":3538,"content":3539,"nodeType":266},{},[3540,3544,3552],{"data":3541,"marks":3542,"value":3543,"nodeType":270},{},[],"You can also read our recent ",{"data":3545,"content":3547,"nodeType":296},{"uri":3546},"https://pushsecurity.com/thank-you/browser-attacks-report",[3548],{"data":3549,"marks":3550,"value":3551,"nodeType":270},{},[],"browser attack techniques report",{"data":3553,"marks":3554,"value":3555,"nodeType":270},{},[]," for more information.",{"data":3557,"content":3561,"nodeType":337},{"target":3558},{"sys":3559},{"id":3560,"type":342,"linkType":343},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":3563,"content":3564,"nodeType":275},{},[],{"data":3566,"content":3567,"nodeType":266},{},[3568],{"data":3569,"marks":3570,"value":3571,"nodeType":270},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":3573,"content":3574,"nodeType":266},{},[3575,3578,3584],{"data":3576,"marks":3577,"value":2275,"nodeType":270},{},[],{"data":3579,"content":3580,"nodeType":296},{"uri":2278},[3581],{"data":3582,"marks":3583,"value":2284,"nodeType":270},{},[],{"data":3585,"marks":3586,"value":2288,"nodeType":270},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":3592},[3593,3595],{"sys":3594,"name":2730},{"id":2729},{"sys":3596,"name":2734},{"id":2733},{"items":3598},[3599],{"fullName":253,"firstName":254,"jobTitle":255,"profilePicture":3600},{"url":259},"browser-threat-landscape-mid-year-update-2026","blog/browser-threat-landscape-mid-year-update-2026",{"json":3604},{"data":3605,"content":3606,"nodeType":262},{},[3607],{"data":3608,"content":3609,"nodeType":266},{},[3610],{"data":3611,"marks":3612,"value":3613,"nodeType":270},{},[],"PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.",{"id":3615,"publishedAt":3616},"vLb3RhwYt7Xc6mkX3pWyI","2026-08-10T15:18:45.096Z",{"items":3618},[3619,3621],{"sys":3620,"name":2730},{"id":2729},{"sys":3622,"name":2734},{"id":2733},"dE2Ic-JJP2wpO_RX--2Tx7Plz0nnJ6SdT0UuAl22fGs",1786375404711]