[{"data":1,"prerenderedAt":1395},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":35,"navbar-about-highlight":98,"navbar-resource-highlight":172,"trust-badges":221,"solution-nav":242,"mega-nav":382,"fa-icon-sharp-regular-faFishingRod":383,"fa-icon-solid-faUserSecret":387,"fa-icon-sharp-regular-faLaptopCode":389,"fa-icon-solid-faTabletScreenButton":391,"fa-icon-solid-faThumbsUp":393,"fa-icon-solid-faPlugCircleXmark":395,"fa-icon-sharp-regular-faPuzzlePiece":397,"fa-icon-solid-faFileCircleXmark":399,"fa-icon-solid-faGhost":402,"fa-icon-solid-faQrcode":405,"fa-icon-solid-faCookieBite":407,"fa-icon-sharp-regular-faUserSecret":409,"fa-icon-sharp-regular-faRadar":411,"fa-icon-sharp-regular-faSatelliteDish":413,"fa-icon-sharp-regular-faShieldCheck":415,"fa-icon-sharp-regular-faBrainCircuit":417,"fa-icon-solid-faMobileScreenButton":419,"fa-icon-brands-faChrome":421,"fa-icon-solid-faDisplay":423,"fa-icon-solid-faFilter":425,"fa-icon-solid-faCloudArrowUp":427,"blog\u002Fproduct-release-september-2026":429,"blog-topics":983},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":20,"data":21,"variations":26,"lastUpdated":27,"firstPublished":28,"testRatio":29,"createdBy":30,"lastUpdatedBy":31,"folders":32,"lastUpdateSource":33,"stageModifiedSincePublish":6,"rev":34},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":6,"hasErrors":6,"kind":19},{"medium":16,"small":17,"xsmall":18},768,640,320,"data",[],{"link":22,"text":23,"type":24,"url":25},{},"Get the latest stats and analysis on browser-based attacks","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks",{},1790775413052,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],null,"jcbbqqvm3g",{"createdBy":36,"createdDate":37,"data":38,"folders":86,"id":87,"lastUpdated":88,"lastUpdatedBy":36,"meta":89,"modelId":92,"name":93,"published":13,"query":94,"testRatio":29,"variations":95,"firstPublished":96,"stageModifiedSincePublish":6,"lastUpdateSource":33,"rev":97},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":39,"text":40,"url":41,"blocks":42,"state":82},"ewrererw","testrfesssssssssss","",[43,71],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":61},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":33},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56,"styleVariant":59,"showMonsters":60},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Shadow AI monsters are lurking in the dark! Bust them all in our retro-inspired arcade game.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Press start &gt;&gt;\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-busters","arcade",true,{"large":62},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67,"marginTop":68,"marginBottom":68,"fontSize":69,"fontWeight":70},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":72,"@type":44,"tagName":73,"properties":74,"responsiveStyles":77},"builder-pixel-93e2thmj145","img",{"src":75,"aria-hidden":76,"alt":41,"width":66,"height":66},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true",{"large":78},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},"block","hidden","none",{"deviceSize":83,"location":84},"large",{"path":41,"query":85},{},[],"fd266d0172cc47429be7ad10f48c99ad",1789552629325,{"breakpoints":90,"hasAutosaves":60,"hasErrors":6,"hasLinks":6,"kind":91},{"medium":16,"small":17,"xsmall":18},"component","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"tiwljfnf8hi",[99,135],{"createdBy":30,"createdDate":100,"data":101,"folders":124,"id":125,"lastUpdated":126,"lastUpdatedBy":30,"meta":127,"modelId":129,"name":130,"published":13,"query":131,"stageModifiedSincePublish":6,"testRatio":29,"variations":132,"firstPublished":133,"rev":134},1776247359804,{"link":102,"testimonial":103,"testimonialLink":123,"type":106},{},{"@type":104,"id":105,"model":106,"value":107},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":108,"folders":109,"createdDate":110,"id":105,"name":111,"modelId":112,"published":13,"data":113,"variations":117,"lastUpdated":118,"firstPublished":119,"testRatio":29,"createdBy":36,"lastUpdatedBy":36,"meta":120,"rev":122},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":114,"jobTitle":115,"quote":111,"image":116},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":19,"breakpoints":121,"hasAutosaves":60},{"small":17,"medium":16},"ue7thebx49m","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":128,"hasAutosaves":6,"kind":19},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"epu8b0ds9lh",{"createdBy":30,"createdDate":136,"data":137,"folders":164,"id":165,"lastUpdated":166,"lastUpdatedBy":30,"meta":167,"modelId":129,"name":162,"published":13,"query":169,"stageModifiedSincePublish":6,"testRatio":29,"variations":170,"firstPublished":171,"rev":134},1776255761419,{"description":138,"image":139,"link":140,"testimonial":143,"title":162,"type":163},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":141,"url":142},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":104,"id":144,"model":106,"value":145},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":146,"folders":147,"createdDate":148,"id":144,"name":149,"modelId":112,"published":13,"data":150,"variations":156,"lastUpdated":157,"firstPublished":158,"testRatio":29,"createdBy":36,"lastUpdatedBy":30,"meta":159,"rev":161},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":151,"jobTitle":152,"author":153,"qoute":41,"quote":154,"image":155},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":19,"breakpoints":160,"hasAutosaves":60},{"small":17,"medium":16},"nmcm8jiq6v","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":168,"hasAutosaves":6,"kind":19},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[173,200],{"createdBy":30,"createdDate":174,"data":175,"folders":190,"id":191,"lastUpdated":192,"lastUpdatedBy":31,"meta":193,"modelId":195,"name":162,"published":13,"query":196,"stageModifiedSincePublish":6,"testRatio":29,"variations":197,"firstPublished":198,"lastUpdateSource":33,"rev":199},1776256900280,{"description":176,"image":177,"link":178,"testimonial":181,"title":189,"type":163},"Get the latest stats and analysis","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F06fa3b7b95af409d9aba80cde49f3978",{"text":179,"url":180},"Learn more","\u002Fresources\u002Fbrowser-attacks",{"@type":104,"id":144,"model":106,"value":182},{"query":183,"folders":184,"createdDate":148,"id":144,"name":149,"modelId":112,"published":13,"data":185,"variations":186,"lastUpdated":157,"firstPublished":158,"testRatio":29,"createdBy":36,"lastUpdatedBy":30,"meta":187,"rev":161},[],[],{"video":151,"jobTitle":152,"author":153,"qoute":41,"quote":154,"image":155},{},{"kind":19,"breakpoints":188,"hasAutosaves":60},{"small":17,"medium":16},"Browser attacks in 2026",[],"1f429607996e4e5fae8fe3f9b9610e55",1790780300911,{"breakpoints":194,"hasAutosaves":6,"hasErrors":6,"kind":19},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"j8r2yp34e9",{"createdBy":30,"createdDate":201,"data":202,"folders":212,"id":213,"lastUpdated":214,"lastUpdatedBy":30,"meta":215,"modelId":195,"name":217,"published":13,"query":218,"stageModifiedSincePublish":6,"testRatio":29,"variations":219,"firstPublished":220,"rev":199},1776256949234,{"link":203,"testimonial":204,"testimonialLink":123,"type":106},{},{"@type":104,"id":105,"model":106,"value":205},{"query":206,"folders":207,"createdDate":110,"id":105,"name":111,"modelId":112,"published":13,"data":208,"variations":209,"lastUpdated":118,"firstPublished":119,"testRatio":29,"createdBy":36,"lastUpdatedBy":36,"meta":210,"rev":122},[],[],{"author":114,"jobTitle":115,"quote":111,"image":116},{},{"kind":19,"breakpoints":211,"hasAutosaves":60},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":216,"hasAutosaves":6,"kind":19},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[222,226,230,234,238],{"title":223,"logo":224,"createdDate":225},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":227,"logo":228,"createdDate":229},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":231,"logo":232,"createdDate":233},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":235,"logo":236,"createdDate":237},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":239,"logo":240,"createdDate":241},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[243,312,357],{"id":244,"label":245,"text":41,"navIcon":246,"items":247},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[248,253,258,263,268,273,278,283,288,292,297,302,307],{"title":249,"text":250,"url":251,"navIcon":252},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":254,"text":255,"url":256,"navIcon":257},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":259,"text":260,"url":261,"navIcon":262},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":264,"text":265,"url":266,"navIcon":267},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":269,"text":270,"url":271,"navIcon":272},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":274,"text":275,"url":276,"navIcon":277},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":279,"text":280,"url":281,"navIcon":282},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":284,"text":285,"url":286,"navIcon":287},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":289,"text":290,"url":291,"navIcon":287},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":293,"text":294,"url":295,"navIcon":296},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":298,"text":299,"url":300,"navIcon":301},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":303,"text":304,"url":305,"navIcon":306},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":308,"text":309,"url":310,"navIcon":311},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":313,"label":314,"text":41,"navIcon":315,"items":316},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[317,322,327,332,337,342,347,352],{"title":318,"text":319,"url":320,"navIcon":321},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":323,"text":324,"url":325,"navIcon":326},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":328,"text":329,"url":330,"navIcon":331},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":333,"text":334,"url":335,"navIcon":336},"Secure shadow IT","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":338,"text":339,"url":340,"navIcon":341},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":343,"text":344,"url":345,"navIcon":346},"Secure BYOD","Extend security to unmanaged devices without MDM.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":348,"text":349,"url":350,"navIcon":351},"Secure Chromebooks","Secure Chromebooks in the enterprise without endpoint agents. Push deploys as a browser extension — phishing detection, credential monitoring, and SaaS visibility via browser extension that works with Chrome OS.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":353,"text":354,"url":355,"navIcon":356},"Data loss prevention","Enforce DLP at the point of interaction in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":358,"label":359,"text":41,"navIcon":360,"items":361},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[362,367,372,377],{"title":363,"text":364,"url":365,"navIcon":366},"Remote browser isolation","Detect attacks that happen inside the browser session.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":368,"text":369,"url":370,"navIcon":371},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":373,"text":374,"url":375,"navIcon":376},"CASB alternative","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":378,"text":379,"url":380,"navIcon":381},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",[],{"w":384,"h":385,"d":386},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":384,"h":385,"d":388},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":385,"d":390},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":384,"h":385,"d":392},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":385,"h":385,"d":394},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":385,"d":396},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":385,"h":385,"d":398},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":400,"h":385,"d":401},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":403,"h":385,"d":404},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":384,"h":385,"d":406},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":385,"h":385,"d":408},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":384,"h":385,"d":410},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":385,"h":385,"d":412},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":385,"h":385,"d":414},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":385,"h":385,"d":416},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":385,"h":385,"d":418},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":403,"h":385,"d":420},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":385,"h":385,"d":422},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":385,"h":385,"d":424},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":385,"h":385,"d":426},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":400,"h":385,"d":428},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"id":430,"title":431,"authorsCollection":432,"content":440,"extension":911,"faqItemsCollection":912,"faqTitle":33,"featured":6,"hashTags":33,"meta":914,"metaTitle":915,"ogImage":33,"postType":916,"publishedDate":917,"relatedBlogPostsCollection":918,"slug":932,"stem":933,"subtitle":33,"summary":934,"synopsis":945,"sys":946,"tagsCollection":949,"topicsCollection":955,"__hash__":982},"blog\u002Fblog\u002Fproduct-release-september-2026.json","Product release: September 2026",{"items":433},[434],{"fullName":435,"firstName":436,"jobTitle":437,"socialLinks":33,"profilePicture":438},"Andy Waugh","Andy","VP Product",{"url":439},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3Rf76rJn6S9inMb4dUnAIJ\u002F0a787f8141d05b95300e2fe77c4493fa\u002FDSC_6868.jpg",{"json":441,"links":865},{"data":442,"content":443,"nodeType":864},{},[444,453,509,516,523,540,547,556,576,582,598,605,612,630,637,644,660,667,686,693,708,719,726,732,751,757,858],{"data":445,"content":446,"nodeType":452},{},[447],{"data":448,"marks":449,"value":450,"nodeType":451},{},[],"What’s new this month:","text","heading-1",{"data":454,"content":455,"nodeType":508},{},[456,468,478,488,498],{"data":457,"content":458,"nodeType":467},{},[459],{"data":460,"content":461,"nodeType":466},{},[462],{"data":463,"marks":464,"value":465,"nodeType":451},{},[],"Block categories of domains","paragraph","list-item",{"data":469,"content":470,"nodeType":467},{},[471],{"data":472,"content":473,"nodeType":466},{},[474],{"data":475,"marks":476,"value":477,"nodeType":451},{},[],"Manage Push controls via the API",{"data":479,"content":480,"nodeType":467},{},[481],{"data":482,"content":483,"nodeType":466},{},[484],{"data":485,"marks":486,"value":487,"nodeType":451},{},[],"AI conversation visibility",{"data":489,"content":490,"nodeType":467},{},[491],{"data":492,"content":493,"nodeType":466},{},[494],{"data":495,"marks":496,"value":497,"nodeType":451},{},[],"Account condition enforcement",{"data":499,"content":500,"nodeType":467},{},[501],{"data":502,"content":503,"nodeType":466},{},[504],{"data":505,"marks":506,"value":507,"nodeType":451},{},[],"And a few other things","unordered-list",{"data":510,"content":511,"nodeType":452},{},[512],{"data":513,"marks":514,"value":515,"nodeType":451},{},[],"Block categories of domains directly in the browser",{"data":517,"content":518,"nodeType":466},{},[519],{"data":520,"marks":521,"value":522,"nodeType":451},{},[],"You can now block categories of domains directly in the browser using Push. ",{"data":524,"content":525,"nodeType":466},{},[526,530,536],{"data":527,"marks":528,"value":529,"nodeType":451},{},[],"You can configure ",{"data":531,"marks":532,"value":535,"nodeType":451},{},[533],{"type":534},"bold","Domain category blocking",{"data":537,"marks":538,"value":539,"nodeType":451},{},[]," to block all AI-related domains, except the ones you allow, prevent employees from visiting sites that violate your acceptable use policy, or block newly registered or known-bad domains.",{"data":541,"content":542,"nodeType":466},{},[543],{"data":544,"marks":545,"value":546,"nodeType":451},{},[],"This is a similar capability to URL filtering tools, but delivered via the Push browser extension, using an AI-powered categorization database.",{"data":548,"content":554,"nodeType":555},{"target":549},{"sys":550},{"id":551,"type":552,"linkType":553},"16ayCgwzfRA4zZE4lQYWs5","Link","Entry",[],"embedded-entry-block",{"data":557,"content":558,"nodeType":466},{},[559,562,573],{"data":560,"marks":561,"value":41,"nodeType":451},{},[],{"data":563,"content":567,"nodeType":572},{"target":564},{"sys":565},{"id":566,"type":552,"linkType":553},"uj983MqFMBjAz3NalDAHv",[568],{"data":569,"marks":570,"value":179,"nodeType":451},{},[571],{"type":534},"entry-hyperlink",{"data":574,"marks":575,"value":41,"nodeType":451},{},[],{"data":577,"content":578,"nodeType":452},{},[579],{"data":580,"marks":581,"value":477,"nodeType":451},{},[],{"data":583,"content":584,"nodeType":466},{},[585,589,594],{"data":586,"marks":587,"value":588,"nodeType":451},{},[],"You can now programmatically configure ",{"data":590,"marks":591,"value":593,"nodeType":451},{},[592],{"type":534},"Controls",{"data":595,"marks":596,"value":597,"nodeType":451},{},[]," in Push via the API.",{"data":599,"content":600,"nodeType":466},{},[601],{"data":602,"marks":603,"value":604,"nodeType":451},{},[],"This allows you to read a control’s complete configuration, create and update control rules, change enforcement modes, adjust employee and app scopes, edit the logic of custom detections, and more.",{"data":606,"content":607,"nodeType":466},{},[608],{"data":609,"marks":610,"value":611,"nodeType":451},{},[],"You may want to use this capability to apply CI\u002FCD workflows to managing Push control configurations. Snapshot every control for backups, drift detection, and restore. Or hook up your SOAR to automate incident response tasks.",{"data":613,"content":614,"nodeType":466},{},[615,618,627],{"data":616,"marks":617,"value":41,"nodeType":451},{},[],{"data":619,"content":621,"nodeType":626},{"uri":620},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002Faudience\u002Fengineering\u002Frest-v1",[622],{"data":623,"marks":624,"value":179,"nodeType":451},{},[625],{"type":534},"hyperlink",{"data":628,"marks":629,"value":41,"nodeType":451},{},[],{"data":631,"content":632,"nodeType":452},{},[633],{"data":634,"marks":635,"value":636,"nodeType":451},{},[],"Get visibility into AI chat interactions",{"data":638,"content":639,"nodeType":466},{},[640],{"data":641,"marks":642,"value":643,"nodeType":451},{},[],"Push can now capture AI chat conversations and stream the telemetry via webhook.",{"data":645,"content":646,"nodeType":466},{},[647,651,656],{"data":648,"marks":649,"value":650,"nodeType":451},{},[],"Use ",{"data":652,"marks":653,"value":655,"nodeType":451},{},[654],{"type":534},"AI conversations ",{"data":657,"marks":658,"value":659,"nodeType":451},{},[],"telemetry to identify unstructured sensitive content that introduces risks to your business or violates your AI usage policy. ",{"data":661,"content":662,"nodeType":466},{},[663],{"data":664,"marks":665,"value":666,"nodeType":451},{},[],"You can tailor the configuration to capture AI chat telemetry for specific browser profiles (e.g. company profiles vs. personal profiles), for specific AI apps, and by user email domain.",{"data":668,"content":669,"nodeType":466},{},[670,674,682],{"data":671,"marks":672,"value":673,"nodeType":451},{},[],"This feature is in early release, so ",{"data":675,"content":677,"nodeType":626},{"uri":676},"mailto:support@pushsecurity.com",[678],{"data":679,"marks":680,"value":681,"nodeType":451},{},[],"contact us",{"data":683,"marks":684,"value":685,"nodeType":451},{},[]," if you’d like to try it out.",{"data":687,"content":688,"nodeType":452},{},[689],{"data":690,"marks":691,"value":692,"nodeType":451},{},[],"Prevent personal logins to corporate apps",{"data":694,"content":695,"nodeType":466},{},[696,700,704],{"data":697,"marks":698,"value":699,"nodeType":451},{},[],"Our latest control, ",{"data":701,"marks":702,"value":497,"nodeType":451},{},[703],{"type":534},{"data":705,"marks":706,"value":707,"nodeType":451},{},[],", allows you to specify the conditions under which users can access apps. For example, you can use this control to prevent personal usage of specific AI apps.",{"data":709,"content":710,"nodeType":466},{},[711,715],{"data":712,"marks":713,"value":497,"nodeType":451},{},[714],{"type":534},{"data":716,"marks":717,"value":718,"nodeType":451},{},[]," also allows you to specify permitted login methods, allowing you to prevent employees from using passwords on certain apps, or use only supported browsers to access apps.",{"data":720,"content":721,"nodeType":466},{},[722],{"data":723,"marks":724,"value":725,"nodeType":451},{},[],"This control currently supports popular AI apps. We’ll add support for more apps over time.",{"data":727,"content":731,"nodeType":555},{"target":728},{"sys":729},{"id":730,"type":552,"linkType":553},"2Gqv7E0xmo4uPlD41p6rvH",[],{"data":733,"content":734,"nodeType":466},{},[735,738,748],{"data":736,"marks":737,"value":41,"nodeType":451},{},[],{"data":739,"content":743,"nodeType":572},{"target":740},{"sys":741},{"id":742,"type":552,"linkType":553},"7zcJe8Xa7XXnfarc7r5gw7",[744],{"data":745,"marks":746,"value":179,"nodeType":451},{},[747],{"type":534},{"data":749,"marks":750,"value":41,"nodeType":451},{},[],{"data":752,"content":753,"nodeType":452},{},[754],{"data":755,"marks":756,"value":507,"nodeType":451},{},[],{"data":758,"content":759,"nodeType":508},{},[760,783,793,816,839],{"data":761,"content":762,"nodeType":467},{},[763],{"data":764,"content":765,"nodeType":466},{},[766,770,780],{"data":767,"marks":768,"value":769,"nodeType":451},{},[],"You can now use the Push admin console in ",{"data":771,"content":775,"nodeType":572},{"target":772},{"sys":773},{"id":774,"type":552,"linkType":553},"1IaJ0oOztt44eQ2opCYNnH",[776],{"data":777,"marks":778,"value":779,"nodeType":451},{},[],"dark mode",{"data":781,"marks":782,"value":41,"nodeType":451},{},[],{"data":784,"content":785,"nodeType":467},{},[786],{"data":787,"content":788,"nodeType":466},{},[789],{"data":790,"marks":791,"value":792,"nodeType":451},{},[],"Push now offers a SentinelOne integration",{"data":794,"content":795,"nodeType":467},{},[796],{"data":797,"content":798,"nodeType":466},{},[799,803,813],{"data":800,"marks":801,"value":802,"nodeType":451},{},[],"You can now configure the help link on ",{"data":804,"content":808,"nodeType":572},{"target":805},{"sys":806},{"id":807,"type":552,"linkType":553},"4i1KWgBfYqtFYlUFRYiGdW",[809],{"data":810,"marks":811,"value":812,"nodeType":451},{},[],"employee-facing banners and block pages",{"data":814,"marks":815,"value":41,"nodeType":451},{},[],{"data":817,"content":818,"nodeType":467},{},[819],{"data":820,"content":821,"nodeType":466},{},[822,825,835],{"data":823,"marks":824,"value":41,"nodeType":451},{},[],{"data":826,"content":830,"nodeType":572},{"target":827},{"sys":828},{"id":829,"type":552,"linkType":553},"73WHwpYAWCnKrIf4SpbuJE",[831],{"data":832,"marks":833,"value":834,"nodeType":451},{},[],"Custom detections",{"data":836,"marks":837,"value":838,"nodeType":451},{},[]," now support internal IPs and hosts in the target scope",{"data":840,"content":841,"nodeType":467},{},[842],{"data":843,"content":844,"nodeType":466},{},[845,849,854],{"data":846,"marks":847,"value":848,"nodeType":451},{},[],"The ",{"data":850,"marks":851,"value":853,"nodeType":451},{},[852],{"type":534},"Events",{"data":855,"marks":856,"value":857,"nodeType":451},{},[]," page now has an updated look and feel, as do inventory tables in the admin console\n\n\n\n\n\n",{"data":859,"content":860,"nodeType":466},{},[861],{"data":862,"marks":863,"value":41,"nodeType":451},{},[],"document",{"entries":866},{"inline":867,"hyperlink":868,"block":895},[],[869,875,880,885,890],{"sys":870,"__typename":871,"title":872,"slug":873,"articleId":874},{"id":566},"HelpArticle","Can Push block domains by category?","can-push-block-domains-by-category",10166,{"sys":876,"__typename":871,"title":877,"slug":878,"articleId":879},{"id":742},"Can Push enforce access conditions for apps?","can-push-enforce-access-conditions-for-apps",10161,{"sys":881,"__typename":871,"title":882,"slug":883,"articleId":884},{"id":774},"How do I enable dark mode for the Push admin console?","how-do-i-enable-dark-mode-for-the-push-admin-console",10165,{"sys":886,"__typename":871,"title":887,"slug":888,"articleId":889},{"id":807},"How do I add custom branding to Push banners and block pages?","how-do-i-add-custom-branding-to-push-banners-and-block-pages",10147,{"sys":891,"__typename":871,"title":892,"slug":893,"articleId":894},{"id":829},"How do I write my own detections?","how-do-i-write-my-own-detections",10155,[896,904],{"sys":897,"__typename":898,"title":899,"caption":33,"layoutMode":33,"file":900},{"id":551},"Image","Domain category block page - KB 10166",{"url":901,"width":902,"height":903},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3M8C2xoW6XaKl8juQ1kOMw\u002F02149254038bb4020b87a9143aaa8e79\u002Fblocked_domain_page.png",2786,1658,{"sys":905,"__typename":898,"title":906,"caption":33,"layoutMode":33,"file":907},{"id":730},"Account condition enforcement banner example - KB 10161",{"url":908,"width":909,"height":910},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F66rjS4c3oMR3HXBDSzOa0K\u002Fe025d98771bb8e86e76fd59bc0c8b59c\u002Faccount_condition_enforcement_banner.png",1999,1295,"json",{"items":913},[],{},"Push Security new product features for September 2026","release-notes","2026-09-29T00:00:00.000Z",{"items":919},[920],{"__typename":921,"sys":922,"title":924,"synopsis":925,"publishedDate":926,"slug":927,"authorsCollection":928},"BlogPosts",{"id":923},"4CnX1gLNvcwsbed1q4kTEj","Product release: May 2026","Here’s what’s new on the Push platform for May 2026.","2026-05-29T00:00:00.000Z","product-release-may-2026",{"items":929},[930],{"firstName":436,"profilePicture":931},{"url":439},"product-release-september-2026","blog\u002Fproduct-release-september-2026",{"json":935},{"data":936,"content":937,"nodeType":864},{},[938],{"data":939,"content":940,"nodeType":466},{},[941],{"data":942,"marks":943,"value":944,"nodeType":451},{},[],"Block domains by category, manage Push controls via API, and more","Here’s what’s new on the Push platform for September 2026.",{"id":947,"publishedAt":948},"4LFYblZ2Sb8fNzGGy6Xe8F","2026-10-02T20:06:02.449Z",{"items":950},[951],{"sys":952,"name":954},{"id":953},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"items":956},[957,962,967,972,977],{"sys":958,"name":960,"slug":961,"tier":45},{"id":959},"topic-dlp","DLP","dlp",{"sys":963,"name":965,"slug":966,"tier":45},{"id":964},"topic-ai-governance","AI governance","ai-governance",{"sys":968,"name":970,"slug":971,"tier":45},{"id":969},"topic-shadow-ai","Shadow AI","shadow-ai",{"sys":973,"name":975,"slug":976,"tier":45},{"id":974},"topic-shadow-saas","Shadow SaaS","shadow-saas",{"sys":978,"name":980,"slug":981,"tier":29},{"id":979},"topic-ai","AI","ai","mxtCAZJ6XoWZy74iZ_R6MygBgEDfitGWIneew8RuiYE",{"id":984,"extension":911,"items":985,"meta":1392,"stem":1393,"__hash__":1394},"blogTopics\u002Fblogtopics.json",[986,992,1001,1007,1016,1025,1034,1043,1052,1061,1070,1079,1087,1096,1105,1112,1118,1127,1136,1144,1153,1162,1171,1180,1189,1198,1207,1216,1225,1234,1242,1251,1259,1267,1276,1285,1294,1303,1312,1320,1326,1331,1340,1349,1357,1366,1375,1384],{"sys":987,"faqItemsCollection":988,"name":980,"slug":981,"tier":29,"intro":990,"faqTitle":33,"postCount":991,"hasPage":60},{"id":979},{"items":989},[],"AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",23,{"sys":993,"faqItemsCollection":995,"name":997,"slug":998,"tier":45,"intro":999,"faqTitle":33,"postCount":1000,"hasPage":60},{"id":994},"topic-ai-attacks",{"items":996},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",24,{"sys":1002,"faqItemsCollection":1003,"name":965,"slug":966,"tier":45,"intro":1005,"faqTitle":33,"postCount":1006,"hasPage":60},{"id":964},{"items":1004},[],"AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",10,{"sys":1008,"faqItemsCollection":1010,"name":1012,"slug":1013,"tier":45,"intro":1014,"faqTitle":33,"postCount":1015,"hasPage":60},{"id":1009},"topic-aitm",{"items":1011},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":1017,"faqItemsCollection":1019,"name":1021,"slug":1022,"tier":45,"intro":1023,"faqTitle":33,"postCount":1024,"hasPage":60},{"id":1018},"topic-bec",{"items":1020},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",5,{"sys":1026,"faqItemsCollection":1028,"name":1030,"slug":1031,"tier":29,"intro":1032,"faqTitle":33,"postCount":1033,"hasPage":60},{"id":1027},"topic-browser-attacks",{"items":1029},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",124,{"sys":1035,"faqItemsCollection":1037,"name":1039,"slug":1040,"tier":45,"intro":1041,"faqTitle":33,"postCount":1042,"hasPage":60},{"id":1036},"topic-browser-extensions",{"items":1038},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":1044,"faqItemsCollection":1046,"name":1048,"slug":1049,"tier":29,"intro":1050,"faqTitle":33,"postCount":1051,"hasPage":60},{"id":1045},"topic-browser-security",{"items":1047},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",130,{"sys":1053,"faqItemsCollection":1055,"name":1057,"slug":1058,"tier":45,"intro":1059,"faqTitle":33,"postCount":1060,"hasPage":60},{"id":1054},"topic-casb",{"items":1056},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":1062,"faqItemsCollection":1064,"name":1066,"slug":1067,"tier":45,"intro":1068,"faqTitle":33,"postCount":1069,"hasPage":60},{"id":1063},"topic-clickfix",{"items":1065},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",41,{"sys":1071,"faqItemsCollection":1073,"name":1075,"slug":1076,"tier":45,"intro":1077,"faqTitle":33,"postCount":1078,"hasPage":60},{"id":1072},"topic-credential-phishing",{"items":1074},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":1080,"faqItemsCollection":1082,"name":303,"slug":1084,"tier":45,"intro":1085,"faqTitle":33,"postCount":1086,"hasPage":60},{"id":1081},"topic-credential-stuffing",{"items":1083},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":1088,"faqItemsCollection":1090,"name":1092,"slug":1093,"tier":29,"intro":1094,"faqTitle":33,"postCount":1095,"hasPage":60},{"id":1089},"topic-detection-and-response",{"items":1091},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",103,{"sys":1097,"faqItemsCollection":1099,"name":1101,"slug":1102,"tier":45,"intro":1103,"faqTitle":33,"postCount":1104,"hasPage":60},{"id":1098},"topic-detection-engineering",{"items":1100},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",43,{"sys":1106,"faqItemsCollection":1108,"name":264,"slug":1110,"tier":45,"intro":1111,"faqTitle":33,"postCount":1000,"hasPage":60},{"id":1107},"topic-device-code-phishing",{"items":1109},[],"device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",{"sys":1113,"faqItemsCollection":1114,"name":960,"slug":961,"tier":45,"intro":1116,"faqTitle":33,"postCount":1117,"hasPage":60},{"id":959},{"items":1115},[],"Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",16,{"sys":1119,"faqItemsCollection":1121,"name":1123,"slug":1124,"tier":45,"intro":1125,"faqTitle":33,"postCount":1126,"hasPage":60},{"id":1120},"topic-edr",{"items":1122},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",26,{"sys":1128,"faqItemsCollection":1130,"name":1132,"slug":1133,"tier":45,"intro":1134,"faqTitle":33,"postCount":1135,"hasPage":60},{"id":1129},"topic-enterprise-browser",{"items":1131},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",9,{"sys":1137,"faqItemsCollection":1139,"name":293,"slug":1141,"tier":45,"intro":1142,"faqTitle":33,"postCount":1143,"hasPage":60},{"id":1138},"topic-ghost-logins",{"items":1140},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":1145,"faqItemsCollection":1147,"name":1149,"slug":1150,"tier":45,"intro":1151,"faqTitle":33,"postCount":1152,"hasPage":60},{"id":1146},"topic-identity-attacks",{"items":1148},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",58,{"sys":1154,"faqItemsCollection":1156,"name":1158,"slug":1159,"tier":29,"intro":1160,"faqTitle":33,"postCount":1161,"hasPage":60},{"id":1155},"topic-identity-security",{"items":1157},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":1163,"faqItemsCollection":1165,"name":1167,"slug":1168,"tier":45,"intro":1169,"faqTitle":33,"postCount":1170,"hasPage":60},{"id":1164},"topic-infostealer",{"items":1166},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",54,{"sys":1172,"faqItemsCollection":1174,"name":1176,"slug":1177,"tier":45,"intro":1178,"faqTitle":33,"postCount":1179,"hasPage":60},{"id":1173},"topic-legitimate-service-abuse",{"items":1175},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":1181,"faqItemsCollection":1183,"name":1185,"slug":1186,"tier":45,"intro":1187,"faqTitle":33,"postCount":1188,"hasPage":60},{"id":1182},"topic-malvertising",{"items":1184},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",32,{"sys":1190,"faqItemsCollection":1192,"name":1194,"slug":1195,"tier":45,"intro":1196,"faqTitle":33,"postCount":1197,"hasPage":60},{"id":1191},"topic-malware-delivery",{"items":1193},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",15,{"sys":1199,"faqItemsCollection":1201,"name":1203,"slug":1204,"tier":45,"intro":1205,"faqTitle":33,"postCount":1206,"hasPage":60},{"id":1200},"topic-mfa",{"items":1202},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":1208,"faqItemsCollection":1210,"name":1212,"slug":1213,"tier":45,"intro":1214,"faqTitle":33,"postCount":1215,"hasPage":60},{"id":1209},"topic-mfa-bypass",{"items":1211},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":1217,"faqItemsCollection":1219,"name":1221,"slug":1222,"tier":45,"intro":1223,"faqTitle":33,"postCount":1224,"hasPage":60},{"id":1218},"topic-non-email-phishing",{"items":1220},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",53,{"sys":1226,"faqItemsCollection":1228,"name":1230,"slug":1231,"tier":45,"intro":1232,"faqTitle":33,"postCount":1233,"hasPage":60},{"id":1227},"topic-oauth-abuse",{"items":1229},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":1235,"faqItemsCollection":1237,"name":1239,"slug":1240,"tier":45,"intro":1241,"faqTitle":33,"postCount":991,"hasPage":60},{"id":1236},"topic-passkeys",{"items":1238},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",{"sys":1243,"faqItemsCollection":1245,"name":1247,"slug":1248,"tier":45,"intro":1249,"faqTitle":33,"postCount":1250,"hasPage":60},{"id":1244},"topic-password-security",{"items":1246},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":1252,"faqItemsCollection":1254,"name":1256,"slug":1257,"tier":45,"intro":1258,"faqTitle":33,"postCount":1069,"hasPage":60},{"id":1253},"topic-phaas",{"items":1255},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",{"sys":1260,"faqItemsCollection":1262,"name":249,"slug":1264,"tier":29,"intro":1265,"faqTitle":33,"postCount":1266,"hasPage":60},{"id":1261},"topic-phishing",{"items":1263},[],"phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",94,{"sys":1268,"faqItemsCollection":1270,"name":1272,"slug":1273,"tier":45,"intro":1274,"faqTitle":33,"postCount":1275,"hasPage":60},{"id":1269},"topic-public-breach",{"items":1271},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":1277,"faqItemsCollection":1279,"name":1281,"slug":1282,"tier":45,"intro":1283,"faqTitle":33,"postCount":1284,"hasPage":60},{"id":1278},"topic-ransomware",{"items":1280},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",14,{"sys":1286,"faqItemsCollection":1288,"name":1290,"slug":1291,"tier":29,"intro":1292,"faqTitle":33,"postCount":1293,"hasPage":60},{"id":1287},"topic-saas-security",{"items":1289},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":1295,"faqItemsCollection":1297,"name":1299,"slug":1300,"tier":45,"intro":1301,"faqTitle":33,"postCount":1302,"hasPage":6},{"id":1296},"topic-security-training",{"items":1298},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":1304,"faqItemsCollection":1306,"name":1308,"slug":1309,"tier":45,"intro":1310,"faqTitle":33,"postCount":1311,"hasPage":60},{"id":1305},"topic-seo-poisoning",{"items":1307},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",8,{"sys":1313,"faqItemsCollection":1315,"name":308,"slug":1317,"tier":45,"intro":1318,"faqTitle":33,"postCount":1319,"hasPage":60},{"id":1314},"topic-session-hijacking",{"items":1316},[],"session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",76,{"sys":1321,"faqItemsCollection":1322,"name":970,"slug":971,"tier":45,"intro":1324,"faqTitle":33,"postCount":1325,"hasPage":60},{"id":969},{"items":1323},[],"Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",21,{"sys":1327,"faqItemsCollection":1328,"name":975,"slug":976,"tier":45,"intro":1330,"faqTitle":33,"postCount":1319,"hasPage":60},{"id":974},{"items":1329},[],"Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",{"sys":1332,"faqItemsCollection":1334,"name":1336,"slug":1337,"tier":45,"intro":1338,"faqTitle":33,"postCount":1339,"hasPage":60},{"id":1333},"topic-siem",{"items":1335},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",20,{"sys":1341,"faqItemsCollection":1343,"name":1345,"slug":1346,"tier":45,"intro":1347,"faqTitle":33,"postCount":1348,"hasPage":60},{"id":1342},"topic-social-engineering",{"items":1344},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",62,{"sys":1350,"faqItemsCollection":1352,"name":1354,"slug":1355,"tier":29,"intro":1356,"faqTitle":33,"postCount":1302,"hasPage":6},{"id":1351},"topic-supply-chain-security",{"items":1353},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":1358,"faqItemsCollection":1360,"name":1362,"slug":1363,"tier":45,"intro":1364,"faqTitle":33,"postCount":1365,"hasPage":60},{"id":1359},"topic-swg",{"items":1361},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":1367,"faqItemsCollection":1369,"name":1371,"slug":1372,"tier":45,"intro":1373,"faqTitle":33,"postCount":1374,"hasPage":60},{"id":1368},"topic-third-party-risk",{"items":1370},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":1376,"faqItemsCollection":1378,"name":1380,"slug":1381,"tier":29,"intro":1382,"faqTitle":33,"postCount":1383,"hasPage":60},{"id":1377},"topic-threat-landscape",{"items":1379},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",50,{"sys":1385,"faqItemsCollection":1387,"name":1389,"slug":1390,"tier":45,"intro":1391,"faqTitle":33,"postCount":1117,"hasPage":60},{"id":1386},"topic-vishing",{"items":1388},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",{},"blogtopics","_ugKLXDXnzBPp-Da6f2JZ34gSqWxWNRSRmZKSLPNpjM",1790972659363]