[{"data":1,"prerenderedAt":11132},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":99,"navbar-resource-highlight":173,"blog-topics":217,"trust-badges":650,"solution-nav":671,"fa-icon-sharp-regular-faFishingRod":806,"fa-icon-solid-faUserSecret":810,"fa-icon-sharp-regular-faLaptopCode":812,"fa-icon-solid-faTabletScreenButton":814,"fa-icon-solid-faThumbsUp":816,"fa-icon-solid-faPlugCircleXmark":818,"fa-icon-sharp-regular-faPuzzlePiece":820,"fa-icon-solid-faFileCircleXmark":822,"fa-icon-solid-faGhost":825,"fa-icon-solid-faQrcode":828,"fa-icon-solid-faCookieBite":830,"fa-icon-sharp-regular-faUserSecret":832,"fa-icon-sharp-regular-faRadar":834,"fa-icon-sharp-regular-faSatelliteDish":836,"fa-icon-sharp-regular-faShieldCheck":838,"fa-icon-sharp-regular-faBrainCircuit":840,"fa-icon-solid-faMobileScreenButton":842,"fa-icon-brands-faChrome":844,"fa-icon-solid-faDisplay":846,"fa-icon-solid-faFilter":848,"fa-icon-solid-faCloudArrowUp":850,"blog-topic-bec":852},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"cu8s1bgrun",{"createdBy":37,"createdDate":38,"data":39,"folders":86,"id":87,"lastUpdated":88,"lastUpdatedBy":37,"meta":89,"modelId":93,"name":94,"published":13,"query":95,"testRatio":31,"variations":96,"firstPublished":97,"stageModifiedSincePublish":6,"lastUpdateSource":60,"rev":98},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":82},"ewrererw","testrfesssssssssss",[43,71],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":61},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":60},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56,"styleVariant":59,"showMonsters":19},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Shadow AI monsters are lurking in the dark! Bust them all in our retro-inspired arcade game.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Press start &gt;&gt;\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-busters","arcade",null,{"large":62},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67,"marginTop":68,"marginBottom":68,"fontSize":69,"fontWeight":70},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":72,"@type":44,"tagName":73,"properties":74,"responsiveStyles":77},"builder-pixel-nmrnkreld9","img",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true",{"large":78},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},"block","hidden","none",{"deviceSize":83,"location":84},"large",{"path":21,"query":85},{},[],"fd266d0172cc47429be7ad10f48c99ad",1789552629325,{"breakpoints":90,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":91,"lastPreviewUrl":92},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fsite.dev.pushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2Cadmin%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests%2CfusionHostingPublish%2CfusionHostingRevokeAiToken&builder.user.role.name=Admin&builder.user.role.id=admin&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"lmu43pypdb",[100,136],{"createdBy":32,"createdDate":101,"data":102,"folders":125,"id":126,"lastUpdated":127,"lastUpdatedBy":32,"meta":128,"modelId":130,"name":131,"published":13,"query":132,"stageModifiedSincePublish":6,"testRatio":31,"variations":133,"firstPublished":134,"rev":135},1776247359804,{"link":103,"testimonial":104,"testimonialLink":124,"type":107},{},{"@type":105,"id":106,"model":107,"value":108},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":109,"folders":110,"createdDate":111,"id":106,"name":112,"modelId":113,"published":13,"data":114,"variations":118,"lastUpdated":119,"firstPublished":120,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":121,"rev":123},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":115,"jobTitle":116,"quote":112,"image":117},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":122,"hasAutosaves":19},{"small":17,"medium":16},"4ryyzlvud4a","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":129,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"83wwox7t9hk",{"createdBy":32,"createdDate":137,"data":138,"folders":165,"id":166,"lastUpdated":167,"lastUpdatedBy":32,"meta":168,"modelId":130,"name":163,"published":13,"query":170,"stageModifiedSincePublish":6,"testRatio":31,"variations":171,"firstPublished":172,"rev":135},1776255761419,{"description":139,"image":140,"link":141,"testimonial":144,"title":163,"type":164},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":142,"url":143},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":105,"id":145,"model":107,"value":146},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":147,"folders":148,"createdDate":149,"id":145,"name":150,"modelId":113,"published":13,"data":151,"variations":157,"lastUpdated":158,"firstPublished":159,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":160,"rev":162},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":152,"jobTitle":153,"author":154,"qoute":21,"quote":155,"image":156},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":161,"hasAutosaves":19},{"small":17,"medium":16},"l3cndi0gnw","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":169,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[174,196],{"createdBy":32,"createdDate":175,"data":176,"folders":186,"id":187,"lastUpdated":188,"lastUpdatedBy":32,"meta":189,"modelId":191,"name":163,"published":13,"query":192,"stageModifiedSincePublish":6,"testRatio":31,"variations":193,"firstPublished":194,"rev":195},1776256900280,{"description":139,"image":140,"link":177,"testimonial":178,"title":163,"type":164},{"text":142,"url":143},{"@type":105,"id":145,"model":107,"value":179},{"query":180,"folders":181,"createdDate":149,"id":145,"name":150,"modelId":113,"published":13,"data":182,"variations":183,"lastUpdated":158,"firstPublished":159,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":184,"rev":162},[],[],{"video":152,"jobTitle":153,"author":154,"qoute":21,"quote":155,"image":156},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":185,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":190,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"xyasj27wu8",{"createdBy":32,"createdDate":197,"data":198,"folders":208,"id":209,"lastUpdated":210,"lastUpdatedBy":32,"meta":211,"modelId":191,"name":213,"published":13,"query":214,"stageModifiedSincePublish":6,"testRatio":31,"variations":215,"firstPublished":216,"rev":195},1776256949234,{"link":199,"testimonial":200,"testimonialLink":124,"type":107},{},{"@type":105,"id":106,"model":107,"value":201},{"query":202,"folders":203,"createdDate":111,"id":106,"name":112,"modelId":113,"published":13,"data":204,"variations":205,"lastUpdated":119,"firstPublished":120,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":206,"rev":123},[],[],{"author":115,"jobTitle":116,"quote":112,"image":117},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":207,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":212,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,{"id":218,"extension":219,"items":220,"meta":647,"stem":648,"__hash__":649},"blogTopics\u002Fblogtopics.json","json",[221,230,239,248,257,266,275,284,293,302,311,320,329,338,347,355,364,373,381,390,399,408,417,426,435,443,452,461,470,479,488,497,505,514,523,532,541,550,559,568,577,586,594,603,611,620,629,638],{"sys":222,"faqItemsCollection":224,"name":226,"slug":227,"tier":31,"intro":228,"faqTitle":60,"postCount":229,"hasPage":19},{"id":223},"topic-ai",{"items":225},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":231,"faqItemsCollection":233,"name":235,"slug":236,"tier":45,"intro":237,"faqTitle":60,"postCount":238,"hasPage":19},{"id":232},"topic-ai-attacks",{"items":234},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",24,{"sys":240,"faqItemsCollection":242,"name":244,"slug":245,"tier":45,"intro":246,"faqTitle":60,"postCount":247,"hasPage":19},{"id":241},"topic-ai-governance",{"items":243},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":249,"faqItemsCollection":251,"name":253,"slug":254,"tier":45,"intro":255,"faqTitle":60,"postCount":256,"hasPage":19},{"id":250},"topic-aitm",{"items":252},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":258,"faqItemsCollection":260,"name":262,"slug":263,"tier":45,"intro":264,"faqTitle":60,"postCount":265,"hasPage":19},{"id":259},"topic-bec",{"items":261},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",5,{"sys":267,"faqItemsCollection":269,"name":271,"slug":272,"tier":31,"intro":273,"faqTitle":60,"postCount":274,"hasPage":19},{"id":268},"topic-browser-attacks",{"items":270},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",124,{"sys":276,"faqItemsCollection":278,"name":280,"slug":281,"tier":45,"intro":282,"faqTitle":60,"postCount":283,"hasPage":19},{"id":277},"topic-browser-extensions",{"items":279},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":285,"faqItemsCollection":287,"name":289,"slug":290,"tier":31,"intro":291,"faqTitle":60,"postCount":292,"hasPage":19},{"id":286},"topic-browser-security",{"items":288},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",130,{"sys":294,"faqItemsCollection":296,"name":298,"slug":299,"tier":45,"intro":300,"faqTitle":60,"postCount":301,"hasPage":19},{"id":295},"topic-casb",{"items":297},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":303,"faqItemsCollection":305,"name":307,"slug":308,"tier":45,"intro":309,"faqTitle":60,"postCount":310,"hasPage":19},{"id":304},"topic-clickfix",{"items":306},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",41,{"sys":312,"faqItemsCollection":314,"name":316,"slug":317,"tier":45,"intro":318,"faqTitle":60,"postCount":319,"hasPage":19},{"id":313},"topic-credential-phishing",{"items":315},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":321,"faqItemsCollection":323,"name":325,"slug":326,"tier":45,"intro":327,"faqTitle":60,"postCount":328,"hasPage":19},{"id":322},"topic-credential-stuffing",{"items":324},[],"Credential stuffing","credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":330,"faqItemsCollection":332,"name":334,"slug":335,"tier":31,"intro":336,"faqTitle":60,"postCount":337,"hasPage":19},{"id":331},"topic-detection-and-response",{"items":333},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",103,{"sys":339,"faqItemsCollection":341,"name":343,"slug":344,"tier":45,"intro":345,"faqTitle":60,"postCount":346,"hasPage":19},{"id":340},"topic-detection-engineering",{"items":342},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",43,{"sys":348,"faqItemsCollection":350,"name":352,"slug":353,"tier":45,"intro":354,"faqTitle":60,"postCount":238,"hasPage":19},{"id":349},"topic-device-code-phishing",{"items":351},[],"Device code phishing","device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",{"sys":356,"faqItemsCollection":358,"name":360,"slug":361,"tier":45,"intro":362,"faqTitle":60,"postCount":363,"hasPage":19},{"id":357},"topic-dlp",{"items":359},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":365,"faqItemsCollection":367,"name":369,"slug":370,"tier":45,"intro":371,"faqTitle":60,"postCount":372,"hasPage":19},{"id":366},"topic-edr",{"items":368},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",26,{"sys":374,"faqItemsCollection":376,"name":378,"slug":379,"tier":45,"intro":380,"faqTitle":60,"postCount":247,"hasPage":19},{"id":375},"topic-enterprise-browser",{"items":377},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",{"sys":382,"faqItemsCollection":384,"name":386,"slug":387,"tier":45,"intro":388,"faqTitle":60,"postCount":389,"hasPage":19},{"id":383},"topic-ghost-logins",{"items":385},[],"Ghost logins","ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":391,"faqItemsCollection":393,"name":395,"slug":396,"tier":45,"intro":397,"faqTitle":60,"postCount":398,"hasPage":19},{"id":392},"topic-identity-attacks",{"items":394},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",58,{"sys":400,"faqItemsCollection":402,"name":404,"slug":405,"tier":31,"intro":406,"faqTitle":60,"postCount":407,"hasPage":19},{"id":401},"topic-identity-security",{"items":403},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":409,"faqItemsCollection":411,"name":413,"slug":414,"tier":45,"intro":415,"faqTitle":60,"postCount":416,"hasPage":19},{"id":410},"topic-infostealer",{"items":412},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",54,{"sys":418,"faqItemsCollection":420,"name":422,"slug":423,"tier":45,"intro":424,"faqTitle":60,"postCount":425,"hasPage":19},{"id":419},"topic-legitimate-service-abuse",{"items":421},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":427,"faqItemsCollection":429,"name":431,"slug":432,"tier":45,"intro":433,"faqTitle":60,"postCount":434,"hasPage":19},{"id":428},"topic-malvertising",{"items":430},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",32,{"sys":436,"faqItemsCollection":438,"name":440,"slug":441,"tier":45,"intro":442,"faqTitle":60,"postCount":363,"hasPage":19},{"id":437},"topic-malware-delivery",{"items":439},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",{"sys":444,"faqItemsCollection":446,"name":448,"slug":449,"tier":45,"intro":450,"faqTitle":60,"postCount":451,"hasPage":19},{"id":445},"topic-mfa",{"items":447},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":453,"faqItemsCollection":455,"name":457,"slug":458,"tier":45,"intro":459,"faqTitle":60,"postCount":460,"hasPage":19},{"id":454},"topic-mfa-bypass",{"items":456},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":462,"faqItemsCollection":464,"name":466,"slug":467,"tier":45,"intro":468,"faqTitle":60,"postCount":469,"hasPage":19},{"id":463},"topic-non-email-phishing",{"items":465},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",53,{"sys":471,"faqItemsCollection":473,"name":475,"slug":476,"tier":45,"intro":477,"faqTitle":60,"postCount":478,"hasPage":19},{"id":472},"topic-oauth-abuse",{"items":474},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":480,"faqItemsCollection":482,"name":484,"slug":485,"tier":45,"intro":486,"faqTitle":60,"postCount":487,"hasPage":19},{"id":481},"topic-passkeys",{"items":483},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",23,{"sys":489,"faqItemsCollection":491,"name":493,"slug":494,"tier":45,"intro":495,"faqTitle":60,"postCount":496,"hasPage":19},{"id":490},"topic-password-security",{"items":492},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":498,"faqItemsCollection":500,"name":502,"slug":503,"tier":45,"intro":504,"faqTitle":60,"postCount":310,"hasPage":19},{"id":499},"topic-phaas",{"items":501},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",{"sys":506,"faqItemsCollection":508,"name":510,"slug":511,"tier":31,"intro":512,"faqTitle":60,"postCount":513,"hasPage":19},{"id":507},"topic-phishing",{"items":509},[],"Phishing","phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",94,{"sys":515,"faqItemsCollection":517,"name":519,"slug":520,"tier":45,"intro":521,"faqTitle":60,"postCount":522,"hasPage":19},{"id":516},"topic-public-breach",{"items":518},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":524,"faqItemsCollection":526,"name":528,"slug":529,"tier":45,"intro":530,"faqTitle":60,"postCount":531,"hasPage":19},{"id":525},"topic-ransomware",{"items":527},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",14,{"sys":533,"faqItemsCollection":535,"name":537,"slug":538,"tier":31,"intro":539,"faqTitle":60,"postCount":540,"hasPage":19},{"id":534},"topic-saas-security",{"items":536},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":542,"faqItemsCollection":544,"name":546,"slug":547,"tier":45,"intro":548,"faqTitle":60,"postCount":549,"hasPage":6},{"id":543},"topic-security-training",{"items":545},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":551,"faqItemsCollection":553,"name":555,"slug":556,"tier":45,"intro":557,"faqTitle":60,"postCount":558,"hasPage":19},{"id":552},"topic-seo-poisoning",{"items":554},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",8,{"sys":560,"faqItemsCollection":562,"name":564,"slug":565,"tier":45,"intro":566,"faqTitle":60,"postCount":567,"hasPage":19},{"id":561},"topic-session-hijacking",{"items":563},[],"Session hijacking","session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",76,{"sys":569,"faqItemsCollection":571,"name":573,"slug":574,"tier":45,"intro":575,"faqTitle":60,"postCount":576,"hasPage":19},{"id":570},"topic-shadow-ai",{"items":572},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":578,"faqItemsCollection":580,"name":582,"slug":583,"tier":45,"intro":584,"faqTitle":60,"postCount":585,"hasPage":19},{"id":579},"topic-shadow-saas",{"items":581},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",75,{"sys":587,"faqItemsCollection":589,"name":591,"slug":592,"tier":45,"intro":593,"faqTitle":60,"postCount":576,"hasPage":19},{"id":588},"topic-siem",{"items":590},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",{"sys":595,"faqItemsCollection":597,"name":599,"slug":600,"tier":45,"intro":601,"faqTitle":60,"postCount":602,"hasPage":19},{"id":596},"topic-social-engineering",{"items":598},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",62,{"sys":604,"faqItemsCollection":606,"name":608,"slug":609,"tier":31,"intro":610,"faqTitle":60,"postCount":549,"hasPage":6},{"id":605},"topic-supply-chain-security",{"items":607},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":612,"faqItemsCollection":614,"name":616,"slug":617,"tier":45,"intro":618,"faqTitle":60,"postCount":619,"hasPage":19},{"id":613},"topic-swg",{"items":615},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":621,"faqItemsCollection":623,"name":625,"slug":626,"tier":45,"intro":627,"faqTitle":60,"postCount":628,"hasPage":19},{"id":622},"topic-third-party-risk",{"items":624},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":630,"faqItemsCollection":632,"name":634,"slug":635,"tier":31,"intro":636,"faqTitle":60,"postCount":637,"hasPage":19},{"id":631},"topic-threat-landscape",{"items":633},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",50,{"sys":639,"faqItemsCollection":641,"name":643,"slug":644,"tier":45,"intro":645,"faqTitle":60,"postCount":646,"hasPage":19},{"id":640},"topic-vishing",{"items":642},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",16,{},"blogtopics","qtNMnplEXowqr6wsMGgTGOB2ggNwhNDP5HHoUK1bdKc",[651,655,659,663,667],{"title":652,"logo":653,"createdDate":654},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":656,"logo":657,"createdDate":658},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":660,"logo":661,"createdDate":662},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":664,"logo":665,"createdDate":666},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":668,"logo":669,"createdDate":670},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[672,736,781],{"id":673,"label":674,"text":21,"navIcon":675,"items":676},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[677,681,686,691,695,700,705,710,715,719,723,728,732],{"title":510,"text":678,"url":679,"navIcon":680},"Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":682,"text":683,"url":684,"navIcon":685},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":687,"text":688,"url":689,"navIcon":690},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":352,"text":692,"url":693,"navIcon":694},"Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":696,"text":697,"url":698,"navIcon":699},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":701,"text":702,"url":703,"navIcon":704},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":706,"text":707,"url":708,"navIcon":709},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":711,"text":712,"url":713,"navIcon":714},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":716,"text":717,"url":718,"navIcon":714},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":386,"text":720,"url":721,"navIcon":722},"Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":724,"text":725,"url":726,"navIcon":727},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":325,"text":729,"url":730,"navIcon":731},"Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":564,"text":733,"url":734,"navIcon":735},"Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":737,"label":738,"text":21,"navIcon":739,"items":740},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[741,746,751,756,761,766,771,776],{"title":742,"text":743,"url":744,"navIcon":745},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":747,"text":748,"url":749,"navIcon":750},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":752,"text":753,"url":754,"navIcon":755},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":757,"text":758,"url":759,"navIcon":760},"Secure shadow IT","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":762,"text":763,"url":764,"navIcon":765},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":767,"text":768,"url":769,"navIcon":770},"Secure BYOD","Extend security to unmanaged devices without MDM.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":772,"text":773,"url":774,"navIcon":775},"Secure Chromebooks","Secure Chromebooks in the enterprise without endpoint agents. Push deploys as a browser extension — phishing detection, credential monitoring, and SaaS visibility via browser extension that works with Chrome OS.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":777,"text":778,"url":779,"navIcon":780},"Data loss prevention","Enforce DLP at the point of interaction in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":782,"label":783,"text":21,"navIcon":784,"items":785},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[786,791,796,801],{"title":787,"text":788,"url":789,"navIcon":790},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":792,"text":793,"url":794,"navIcon":795},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":797,"text":798,"url":799,"navIcon":800},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":802,"text":803,"url":804,"navIcon":805},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":807,"h":808,"d":809},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":807,"h":808,"d":811},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":808,"d":813},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":807,"h":808,"d":815},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":808,"h":808,"d":817},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":808,"d":819},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":808,"h":808,"d":821},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":823,"h":808,"d":824},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":826,"h":808,"d":827},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":807,"h":808,"d":829},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":808,"h":808,"d":831},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":807,"h":808,"d":833},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":808,"h":808,"d":835},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":808,"h":808,"d":837},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":808,"h":808,"d":839},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":808,"h":808,"d":841},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":826,"h":808,"d":843},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":808,"h":808,"d":845},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":808,"h":808,"d":847},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":808,"h":808,"d":849},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":823,"h":808,"d":851},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",[853,3866,7052,7962,10379],{"id":854,"title":855,"authorsCollection":856,"content":864,"extension":219,"faqItemsCollection":1117,"faqTitle":60,"featured":19,"hashTags":60,"meta":1119,"metaTitle":1120,"ogImage":60,"postType":1121,"publishedDate":1122,"relatedBlogPostsCollection":1123,"slug":3824,"stem":3825,"subtitle":60,"summary":3826,"synopsis":3837,"sys":3838,"tagsCollection":3841,"topicsCollection":3847,"__hash__":3865},"blog\u002Fblog\u002Fproofpoint-x-push-partnership-announcement.json","Proofpoint x Push: Why browser security is now a non-negotiable for security teams",{"items":857},[858],{"fullName":859,"firstName":860,"jobTitle":861,"socialLinks":60,"profilePicture":862},"Adam Bateman","Adam","Co-founder \u002F CEO",{"url":863},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3Bt9feB72kxdWlS0hvpldi\u002F904bdb8b20d98e53c574f8be2f60996b\u002FPush_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-20.jpg",{"json":865,"links":1112},{"nodeType":866,"data":867,"content":868},"document",{},[869,888,895,899,908,915,922,929,936,943,952,959,980,988,995,1002,1009,1012,1020,1027,1034,1041,1048,1056,1063,1070,1077,1080,1087,1094],{"nodeType":870,"data":871,"content":872},"paragraph",{},[873,878,884],{"nodeType":874,"value":875,"marks":876,"data":877},"text","We're announcing a partnership with Proofpoint to power ",[],{},{"nodeType":874,"value":879,"marks":880,"data":883},"Proofpoint Advanced Browser Protection ",[881],{"type":882},"bold",{},{"nodeType":874,"value":885,"marks":886,"data":887},"— a new addition to Proofpoint's collaboration security platform that extends protection from the inbox into the browser session. Push provides the real-time behavioral detection, in-session blocking, and browser telemetry that feeds directly into Proofpoint's Threat Protection Workbench, Security Graph, and Investigation Agent.",[],{},{"nodeType":870,"data":889,"content":890},{},[891],{"nodeType":874,"value":892,"marks":893,"data":894},"Proofpoint is one of the biggest names in cybersecurity. They've spent two decades building the most comprehensive picture of how attacks reach people via email. This partnership exists because Proofpoint recognizes that today’s attacks don’t stop at the inbox: they happen inside the browser session. ",[],{},{"nodeType":896,"data":897,"content":898},"hr",{},[],{"nodeType":900,"data":901,"content":902},"heading-1",{},[903],{"nodeType":874,"value":904,"marks":905,"data":907},"Phishing doesn't stop at the inbox anymore",[906],{"type":882},{},{"nodeType":870,"data":909,"content":910},{},[911],{"nodeType":874,"value":912,"marks":913,"data":914},"Email is one of the most heavily defended delivery channels in the enterprise. Enterprise organizations have multiple layers of email security, scanning messages for malicious links, sandboxing attachments, and rewriting URLs. ",[],{},{"nodeType":870,"data":916,"content":917},{},[918],{"nodeType":874,"value":919,"marks":920,"data":921},"But better controls doesn't mean attackers stopped phishing: they adapted.",[],{},{"nodeType":870,"data":923,"content":924},{},[925],{"nodeType":874,"value":926,"marks":927,"data":928},"Push data shows a growing number of malicious payloads now arrive outside of email entirely — via messaging apps, social media, search results, and malvertising.",[],{},{"nodeType":870,"data":930,"content":931},{},[932],{"nodeType":874,"value":933,"marks":934,"data":935},"As email defenses improve, attackers increasingly conceal malicious content during delivery, such as multi-stage redirect chains and conditional loading based on email,  IP and browser checks that prevent the true destination from being revealed until a user interacts with the link. These techniques allow links to appear legitimate during email inspection while exposing malicious content only at the point of interaction, making the browser a critical control point for detecting and stopping modern attacks.",[],{},{"nodeType":870,"data":937,"content":938},{},[939],{"nodeType":874,"value":940,"marks":941,"data":942},"All of this makes it increasingly difficult for traditional time-of-click URL and page analysis to find and block bad before a user has the chance to get phished. ",[],{},{"nodeType":944,"data":945,"content":946},"heading-2",{},[947],{"nodeType":874,"value":948,"marks":949,"data":951},"No matter the delivery vector, the attack plays out in the browser ",[950],{"type":882},{},{"nodeType":870,"data":953,"content":954},{},[955],{"nodeType":874,"value":956,"marks":957,"data":958},"Either way, the attack ends up rendering in the browser session, where the user enters credentials and completes MFA checks, authorizes an OAuth consent grant, copies a malicious command, downloads a file, or installs a malicious extension. That's the moment that determines whether the attack succeeds or fails.",[],{},{"nodeType":870,"data":960,"content":961},{},[962,965,976],{"nodeType":874,"value":21,"marks":963,"data":964},[],{},{"nodeType":966,"data":967,"content":969},"hyperlink",{"uri":968},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",[970],{"nodeType":874,"value":971,"marks":972,"data":975},"Omdia's Browser Management and Security ",[973],{"type":974},"underline",{},{"nodeType":874,"value":977,"marks":978,"data":979},"report puts a number on the consequence: 49% of organizations suffered a confirmed successful browser-based attack in the preceding 12 months, and 88% now rank browser security among their top 5 priorities.",[],{},{"nodeType":900,"data":981,"content":982},{},[983],{"nodeType":874,"value":984,"marks":985,"data":987},"Known-bad blocklists can’t keep up: Real-time behavioral analysis in the browser is the answer",[986],{"type":882},{},{"nodeType":870,"data":989,"content":990},{},[991],{"nodeType":874,"value":992,"marks":993,"data":994},"89% of phishing domains are active for less than two days. Phishing kits rotate infrastructure continuously. Attackers host phishing content on trusted cloud platforms — Azure Blob Storage, Cloudflare Workers, Google-owned domains, and many more — that carry clean reputations by default. A URL that returns \"safe\" at time of delivery tells you very little about what the page will do when the user clicks through an hour later.",[],{},{"nodeType":870,"data":996,"content":997},{},[998],{"nodeType":874,"value":999,"marks":1000,"data":1001},"Push detects attacks by analyzing what the page actually does. Because we operate inside the browser session, we see the page load in real time and how the user interacts with it, including all of the client-side scripting and DOM loading that happens with modern web pages (and is invisible at the network layer). This means we can spot attacks by technique and behavior rather than just looking at things like domains, URLs, or static HTML.",[],{},{"nodeType":870,"data":1003,"content":1004},{},[1005],{"nodeType":874,"value":1006,"marks":1007,"data":1008},"AiTM kits, cloned login pages, Browser-in-the-Browser pop-ups, the ClickFix family of malicious copy-and-paste attacks, device code phishing, malicious OAuth consent grants — our behavioral detection catches them all, regardless of the infrastructure, hosting, or phish kits used. ",[],{},{"nodeType":896,"data":1010,"content":1011},{},[],{"nodeType":900,"data":1013,"content":1014},{},[1015],{"nodeType":874,"value":1016,"marks":1017,"data":1019},"What Push brings to Advanced Browser Protection",[1018],{"type":882},{},{"nodeType":870,"data":1021,"content":1022},{},[1023],{"nodeType":874,"value":1024,"marks":1025,"data":1026},"Push detects and blocks attacks regardless of whether a phishing link arrived via email, social media DM,  a Teams message, a Google search ad, or a compromised website. The delivery channel is irrelevant to Push's detection model — which is the point. ",[],{},{"nodeType":870,"data":1028,"content":1029},{},[1030],{"nodeType":874,"value":1031,"marks":1032,"data":1033},"With Push, no matter where a link is clicked and a page is loaded from, malicious content is detected and blocked in real time, before the user is compromised. Even if a page has never been flagged before, Push analyzes, detects the malicious elements of the page, and blocks access before the user has time to interact with it. Every session and interaction is protected by Push, without any need for sandboxing or latency-inducing remote isolation technology. ",[],{},{"nodeType":870,"data":1035,"content":1036},{},[1037],{"nodeType":874,"value":1038,"marks":1039,"data":1040},"Push's browser telemetry — every page load, credential entry, session event, and OAuth consent — feeds directly into Proofpoint's Threat Protection Workbench and Investigation Agent, giving security teams a unified view from the message that carried the lure through to the credential entered and the session compromised. ",[],{},{"nodeType":870,"data":1042,"content":1043},{},[1044],{"nodeType":874,"value":1045,"marks":1046,"data":1047},"An analyst working in Proofpoint's platform can now follow a single attack end-to-end without stitching together data from disconnected tools and limited data sources, significantly reducing investigation and response times. ",[],{},{"nodeType":900,"data":1049,"content":1050},{},[1051],{"nodeType":874,"value":1052,"marks":1053,"data":1055},"What this means for Proofpoint customers",[1054],{"type":882},{},{"nodeType":870,"data":1057,"content":1058},{},[1059],{"nodeType":874,"value":1060,"marks":1061,"data":1062},"Proofpoint customers get a first-class browser security integration that covers the attacks email security was never architecturally positioned to catch — and delivers that detection data back into the Proofpoint platform. When Push detects and stops an attack for one Proofpoint customer, the data feeds back into the Proofpoint platform to block it everywhere.",[],{},{"nodeType":870,"data":1064,"content":1065},{},[1066],{"nodeType":874,"value":1067,"marks":1068,"data":1069},"For the broader market, the signal here is hard to miss. When a company of Proofpoint's scale — one that has the highest level of visibility into email-based threats — concludes that browser security is a critical piece for threat protection, that's extreme validation for the secure enterprise browser market. Browser security isn't a niche add-on anymore. It's a non-negotiable.",[],{},{"nodeType":870,"data":1071,"content":1072},{},[1073],{"nodeType":874,"value":1074,"marks":1075,"data":1076},"Proofpoint Advanced Browser Protection will be generally available from early 2027. ",[],{},{"nodeType":896,"data":1078,"content":1079},{},[],{"nodeType":870,"data":1081,"content":1082},{},[1083],{"nodeType":874,"value":1084,"marks":1085,"data":1086},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":870,"data":1088,"content":1089},{},[1090],{"nodeType":874,"value":1091,"marks":1092,"data":1093},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":870,"data":1095,"content":1096},{},[1097,1100,1109],{"nodeType":874,"value":21,"marks":1098,"data":1099},[],{},{"nodeType":966,"data":1101,"content":1103},{"uri":1102},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[1104],{"nodeType":874,"value":1105,"marks":1106,"data":1108},"Book a live demo to learn more.",[1107],{"type":974},{},{"nodeType":874,"value":21,"marks":1110,"data":1111},[],{},{"entries":1113},{"hyperlink":1114,"block":1115,"inline":1116},[],[],[],{"items":1118},[],{},"Announcing the Proofpoint and Push Security partnership","company-news","2026-09-29T00:00:00.000Z",{"items":1124},[1125,2019,2514],{"__typename":1126,"sys":1127,"content":1129,"title":1998,"synopsis":1999,"hashTags":60,"publishedDate":2000,"slug":2001,"tagsCollection":2002,"authorsCollection":2011},"BlogPosts",{"id":1128},"62Zyr35VUmijkpupWk3hoD",{"json":1130},{"nodeType":866,"data":1131,"content":1132},{},[1133,1150,1157,1160,1168,1175,1182,1214,1223,1230,1237,1244,1247,1255,1262,1265,1273,1280,1286,1293,1299,1319,1326,1333,1340,1346,1349,1357,1364,1370,1401,1408,1424,1443,1450,1456,1459,1467,1486,1493,1516,1548,1584,1591,1597,1600,1608,1615,1621,1640,1647,1675,1706,1712,1715,1723,1730,1736,1755,1762,1812,1850,1857,1863,1866,1874,1881,1888,1914,1933,1939,1942,1950,1968,1974,1980],{"nodeType":870,"data":1134,"content":1135},{},[1136,1140,1146],{"nodeType":874,"value":1137,"marks":1138,"data":1139},"The view that \"the browser is the new endpoint\" and \"the new battleground for cyber attacks\" is becoming increasingly advocated by security leaders. But what does this ",[],{},{"nodeType":874,"value":1141,"marks":1142,"data":1145},"actually",[1143],{"type":1144},"italic",{},{"nodeType":874,"value":1147,"marks":1148,"data":1149}," mean for security teams? ",[],{},{"nodeType":870,"data":1151,"content":1152},{},[1153],{"nodeType":874,"value":1154,"marks":1155,"data":1156},"In this article, we’re cutting out the jargon to explore what a browser-based attack is, and what’s required for effective detection and response. ",[],{},{"nodeType":896,"data":1158,"content":1159},{},[],{"nodeType":900,"data":1161,"content":1162},{},[1163],{"nodeType":874,"value":1164,"marks":1165,"data":1167},"What is the goal of a browser-based attack?   ",[1166],{"type":882},{},{"nodeType":870,"data":1169,"content":1170},{},[1171],{"nodeType":874,"value":1172,"marks":1173,"data":1174},"First, it’s important to establish what the point of a browser-based attack is.",[],{},{"nodeType":870,"data":1176,"content":1177},{},[1178],{"nodeType":874,"value":1179,"marks":1180,"data":1181},"In most scenarios, attackers don’t think of themselves as attacking your web browser. Their end-goal is to compromise your business apps and data. That means going after the third-party apps and services that are now the backbone of business IT — and therefore the top target for attackers. ",[],{},{"nodeType":870,"data":1183,"content":1184},{},[1185,1189,1198,1202,1210],{"nodeType":874,"value":1186,"marks":1187,"data":1188},"The most common attack path today sees attackers log into third-party services, dump the data, and monetize it through extortion. You need only look at last year’s ",[],{},{"nodeType":966,"data":1190,"content":1192},{"uri":1191},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsnowflake-retro",[1193],{"nodeType":874,"value":1194,"marks":1195,"data":1197},"Snowflake",[1196],{"type":974},{},{"nodeType":874,"value":1199,"marks":1200,"data":1201}," customer breaches that impacted 165+ organizations, or the still-ongoing ",[],{},{"nodeType":966,"data":1203,"content":1205},{"uri":1204},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-instructure-breach",[1206],{"nodeType":874,"value":1207,"marks":1208,"data":1209},"Salesforce attacks",[],{},{"nodeType":874,"value":1211,"marks":1212,"data":1213}," to see the scale of the problem. Identity weaknesses played a material role in almost 90% of Unit 42's investigations, and Google\u002FMandiant reported that identity issues were the initial access vector in 83% of cloud-related incidents.",[],{},{"nodeType":1215,"data":1216,"content":1222},"embedded-entry-block",{"target":1217},{"sys":1218},{"id":1219,"type":1220,"linkType":1221},"5agrVXzEdwALmew2F5SPDp","Link","Entry",[],{"nodeType":870,"data":1224,"content":1225},{},[1226],{"nodeType":874,"value":1227,"marks":1228,"data":1229},"The most logical way to do this is by targeting users of those apps. And because of the changes to working practices, your users are more accessible than ever to external attackers.",[],{},{"nodeType":870,"data":1231,"content":1232},{},[1233],{"nodeType":874,"value":1234,"marks":1235,"data":1236},"Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content (at least, without significantly impeding their ability to do their jobs).",[],{},{"nodeType":870,"data":1238,"content":1239},{},[1240],{"nodeType":874,"value":1241,"marks":1242,"data":1243},"Given that the browser is the place where business apps are accessed and used, it makes sense that attacks are increasingly playing out there too. ",[],{},{"nodeType":896,"data":1245,"content":1246},{},[],{"nodeType":900,"data":1248,"content":1249},{},[1250],{"nodeType":874,"value":1251,"marks":1252,"data":1254},"The 6 key browser-based attacks that security teams need to know about",[1253],{"type":882},{},{"nodeType":870,"data":1256,"content":1257},{},[1258],{"nodeType":874,"value":1259,"marks":1260,"data":1261},"Here's our breakdown of the top 6 browser-based attacks that should be on every security team's radar right now. Check out the videos for 101 explainers!",[],{},{"nodeType":896,"data":1263,"content":1264},{},[],{"nodeType":944,"data":1266,"content":1267},{},[1268],{"nodeType":874,"value":1269,"marks":1270,"data":1272},"1. Phishing for credentials and sessions",[1271],{"type":882},{},{"nodeType":870,"data":1274,"content":1275},{},[1276],{"nodeType":874,"value":1277,"marks":1278,"data":1279},"The most direct way for an attacker to compromise a business application is to phish a user of that app. You might not necessarily think of phishing as a browser-based attack, but that’s exactly what it is today. ",[],{},{"nodeType":1215,"data":1281,"content":1285},{"target":1282},{"sys":1283},{"id":1284,"type":1220,"linkType":1221},"6wn81JTcqktmJSSFfTzNSc",[],{"nodeType":870,"data":1287,"content":1288},{},[1289],{"nodeType":874,"value":1290,"marks":1291,"data":1292},"Phishing tooling and infrastructure has evolved a lot in the past decade, while the changes to business IT means there are both many more vectors for phishing attack delivery, and apps and identities to target. Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration. ",[],{},{"nodeType":1215,"data":1294,"content":1298},{"target":1295},{"sys":1296},{"id":1297,"type":1220,"linkType":1221},"3SrKOgpedLMQRpKIZqUQur",[],{"nodeType":870,"data":1300,"content":1301},{},[1302,1306,1315],{"nodeType":874,"value":1303,"marks":1304,"data":1305},"Whereas phishing was once entirely focused on credential theft, modern phishing attacks see the attacker intercept the victim’s session on the target app, using reverse-proxy Attacker-in-the-Middle kits that are the standard choice for attackers today. This means most forms of MFA can be bypassed, with the exception of passkeys (though attackers are finding ways to work around passkeys using ",[],{},{"nodeType":966,"data":1307,"content":1309},{"uri":1308},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks\u002F",[1310],{"nodeType":874,"value":1311,"marks":1312,"data":1314},"downgrade attacks",[1313],{"type":974},{},{"nodeType":874,"value":1316,"marks":1317,"data":1318},"). ",[],{},{"nodeType":870,"data":1320,"content":1321},{},[1322],{"nodeType":874,"value":1323,"marks":1324,"data":1325},"There are other key differences to be aware of too. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques. The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",[],{},{"nodeType":870,"data":1327,"content":1328},{},[1329],{"nodeType":874,"value":1330,"marks":1331,"data":1332},"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution with the rate that attackers refresh and rotate their phishing infrastructure. ",[],{},{"nodeType":870,"data":1334,"content":1335},{},[1336],{"nodeType":874,"value":1337,"marks":1338,"data":1339},"These changes make phishing more effective than ever, and increasingly difficult to detect and block without being able to observe and analyze web pages that a user interacts with in real time — something only possible with browser-level visibility. ",[],{},{"nodeType":1215,"data":1341,"content":1345},{"target":1342},{"sys":1343},{"id":1344,"type":1220,"linkType":1221},"NHu0Q6ac9mLOPPMoswB8B",[],{"nodeType":896,"data":1347,"content":1348},{},[],{"nodeType":944,"data":1350,"content":1351},{},[1352],{"nodeType":874,"value":1353,"marks":1354,"data":1356},"2. Malicious copy and paste (aka. ClickFix, FileFix, etc.)",[1355],{"type":882},{},{"nodeType":870,"data":1358,"content":1359},{},[1360],{"nodeType":874,"value":1361,"marks":1362,"data":1363},"Since late 2024, attackers have been tricking users into performing malicious actions under the pretext of \"fixing\" an issue for a webpage to load. The most common scenarios relate to \"verifying that you are human,\" styled as a version of the bot protection challenges we're all used to encountering on the internet today. ",[],{},{"nodeType":1215,"data":1365,"content":1369},{"target":1366},{"sys":1367},{"id":1368,"type":1220,"linkType":1221},"4Tp6KL7yz8CdxdKu5ieWMt",[],{"nodeType":870,"data":1371,"content":1372},{},[1373,1377,1385,1389,1397],{"nodeType":874,"value":1374,"marks":1375,"data":1376},"Microsoft's Digital Defense Report identified ClickFix as the ",[],{},{"nodeType":966,"data":1378,"content":1380},{"uri":1379},"https:\u002F\u002Fcdn-dynmedia-1.microsoft.com\u002Fis\u002Fcontent\u002Fmicrosoftcorp\u002Fmicrosoft\u002Fmsc\u002Fdocuments\u002Fpresentations\u002FCSR\u002FMicrosoft-Digital-Defense-Report-2025.pdf",[1381],{"nodeType":874,"value":1382,"marks":1383,"data":1384},"most common initial access vector, accounting for 47% of observed attacks",[],{},{"nodeType":874,"value":1386,"marks":1387,"data":1388},". CrowdStrike recorded a ",[],{},{"nodeType":966,"data":1390,"content":1392},{"uri":1391},"https:\u002F\u002Fwww.crowdstrike.com\u002Fexplore\u002F2026-global-threat-report",[1393],{"nodeType":874,"value":1394,"marks":1395,"data":1396},"563% increase in fake CAPTCHA ClickFix lures",[],{},{"nodeType":874,"value":1398,"marks":1399,"data":1400},". Push's own detection data tells a similar story: ClickFix made up an average of 52% of detections through Q2 2026, surpassing all other browser-based attack categories for the first time.",[],{},{"nodeType":870,"data":1402,"content":1403},{},[1404],{"nodeType":874,"value":1405,"marks":1406,"data":1407},"Traditional ClickFix-style attacks are a hybrid of browser and endpoint targeting. While delivered via the browser, the user copies and runs malicious scripts on their endpoint, targeting a wide range of legitimate, pre-installed system tools that allow commands to be run (Living Off the Land Binaries, or LOLBins). This results in the user installing malicious software on their machine — typically Remote Access Tools (RATs) and infostealer malware.",[],{},{"nodeType":870,"data":1409,"content":1410},{},[1411,1415,1420],{"nodeType":874,"value":1412,"marks":1413,"data":1414},"Notably, ClickFix remains a trap that users fall into rather than something they're targeted with directly. ",[],{},{"nodeType":874,"value":1416,"marks":1417,"data":1419},"4 in 5 ClickFix payloads intercepted by Push are accessed from search engines",[1418],{"type":882},{},{"nodeType":874,"value":1421,"marks":1422,"data":1423}," — the result of compromised sites, malvertising, and SEO poisoning. This naturally means they completely bypass email-based security controls. ",[],{},{"nodeType":870,"data":1425,"content":1426},{},[1427,1431,1439],{"nodeType":874,"value":1428,"marks":1429,"data":1430},"ClickFix continues to spawn new tools and sub-techniques. ClickFix-as-a-Service platforms are achieving 60% victim conversion rates. Payloads are highly variable, with Push capturing 84 distinct command forms targeting 16+ different system binaries. EtherHiding — storing kit configuration on public blockchains — means there's no host to take down and no domain to block. Attackers are also using shared conversations on AI chatbot platforms like ",[],{},{"nodeType":966,"data":1432,"content":1434},{"uri":1433},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign\u002F",[1435],{"nodeType":874,"value":1436,"marks":1437,"data":1438},"ChatGPT and Claude to deliver malware",[],{},{"nodeType":874,"value":1440,"marks":1441,"data":1442}," via pages hosted on trusted, legitimate domains.",[],{},{"nodeType":870,"data":1444,"content":1445},{},[1446],{"nodeType":874,"value":1447,"marks":1448,"data":1449},"These varied delivery mechanisms and payloads make ClickFix tricky for traditional security tools to detect in real time. However, every ClickFix attack and variant happens in the browser with a malicious copy and paste event, which is where browser-based tools like Push have a great opportunity to intercept them.",[],{},{"nodeType":1215,"data":1451,"content":1455},{"target":1452},{"sys":1453},{"id":1454,"type":1220,"linkType":1221},"29Y7nRr39TiUyvAwinYctG",[],{"nodeType":896,"data":1457,"content":1458},{},[],{"nodeType":944,"data":1460,"content":1461},{},[1462],{"nodeType":874,"value":1463,"marks":1464,"data":1466},"3. Authorization phishing",[1465],{"type":882},{},{"nodeType":870,"data":1468,"content":1469},{},[1470,1474,1482],{"nodeType":874,"value":1471,"marks":1472,"data":1473},"While AiTM phishing targets the login — the moment a user proves their identity — a growing class of attacks targets what happens after the login. Instead of stealing a session from the authentication flow, ",[],{},{"nodeType":966,"data":1475,"content":1477},{"uri":1476},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fauthorization-phishing",[1478],{"nodeType":874,"value":1479,"marks":1480,"data":1481},"authorization phishing",[],{},{"nodeType":874,"value":1483,"marks":1484,"data":1485}," abuses OAuth authorization mechanisms — consent grants, device code flows, and token exchanges — to obtain access tokens. The attacker never touches the authentication flow at all, which means every form of MFA, including phishing-resistant passkeys, is irrelevant.",[],{},{"nodeType":870,"data":1487,"content":1488},{},[1489],{"nodeType":874,"value":1490,"marks":1491,"data":1492},"Three techniques currently fall under the authorization phishing umbrella:",[],{},{"nodeType":870,"data":1494,"content":1495},{},[1496,1500,1504,1512],{"nodeType":874,"value":696,"marks":1497,"data":1499},[1498],{"type":882},{},{"nodeType":874,"value":1501,"marks":1502,"data":1503}," sees the victim authorize a third-party app via an OAuth consent grant. This can be an app the attacker has created, or a legitimate SaaS app tenant — you can simply sign up for an account and ",[],{},{"nodeType":966,"data":1505,"content":1507},{"uri":1506},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fopenai-poisoned-tenant-attack",[1508],{"nodeType":874,"value":1509,"marks":1510,"data":1511},"invite targets to your app tenant",[],{},{"nodeType":874,"value":1513,"marks":1514,"data":1515},". Identity providers have substantially hardened their defaults against consent phishing (Microsoft now blocks unverified third-party app consent by default, for example), which is why attackers have increasingly shifted to the next two techniques.",[],{},{"nodeType":870,"data":1517,"content":1518},{},[1519,1523,1527,1535,1539,1544],{"nodeType":874,"value":352,"marks":1520,"data":1522},[1521],{"type":882},{},{"nodeType":874,"value":1524,"marks":1525,"data":1526}," targets a different OAuth flow entirely: the RFC 8628 device authorization grant, originally designed for input-constrained devices like smart TVs. The attacker generates a code, delivers it to the victim via a phishing page, and the victim enters the code on the real identity provider's device login page. Push has tracked a ",[],{},{"nodeType":966,"data":1528,"content":1530},{"uri":1529},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing",[1531],{"nodeType":874,"value":1532,"marks":1533,"data":1534},"37.5x increase in device code phishing attacks",[],{},{"nodeType":874,"value":1536,"marks":1537,"data":1538}," in 2026, with ",[],{},{"nodeType":874,"value":1540,"marks":1541,"data":1543},"30+ distinct kits",[1542],{"type":882},{},{"nodeType":874,"value":1545,"marks":1546,"data":1547}," now offering the technique. Because device code phishing targets apps already consented in the user's tenant (usually first-party Microsoft apps), it sidesteps the consent restrictions that shut down traditional consent phishing.",[],{},{"nodeType":870,"data":1549,"content":1550},{},[1551,1556,1560,1568,1572,1580],{"nodeType":874,"value":1552,"marks":1553,"data":1555},"ConsentFix",[1554],{"type":882},{},{"nodeType":874,"value":1557,"marks":1558,"data":1559}," occupies a middle ground — a ClickFix-OAuth hybrid that targets the standard authorization code grant flow rather than the device code flow. ",[],{},{"nodeType":966,"data":1561,"content":1563},{"uri":1562},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix\u002F",[1564],{"nodeType":874,"value":1565,"marks":1566,"data":1567},"First observed in Russian APT29 campaigns",[],{},{"nodeType":874,"value":1569,"marks":1570,"data":1571},", it has since been ",[],{},{"nodeType":966,"data":1573,"content":1575},{"uri":1574},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-v3-analyzing-a-new-toolkit\u002F",[1576],{"nodeType":874,"value":1577,"marks":1578,"data":1579},"commoditized into criminal tooling",[],{},{"nodeType":874,"value":1581,"marks":1582,"data":1583},".",[],{},{"nodeType":870,"data":1585,"content":1586},{},[1587],{"nodeType":874,"value":1588,"marks":1589,"data":1590},"Preventing malicious OAuth grants requires tight in-app management of user permissions and tenant security settings across every app in the estate. Conditional access policies help, but their effectiveness varies significantly by technique — \"require compliant device\" blocks device code phishing but not ConsentFix, while \"block device code flow\" breaks legitimate use cases like Azure CLI and conference room hardware. Browser-based security tools are well positioned to observe OAuth grants across all apps accessed in the browser — even the ones the security team doesn't manage or know about.",[],{},{"nodeType":1215,"data":1592,"content":1596},{"target":1593},{"sys":1594},{"id":1595,"type":1220,"linkType":1221},"1Fxgll8d4vVwtkGdwIAgkm",[],{"nodeType":896,"data":1598,"content":1599},{},[],{"nodeType":944,"data":1601,"content":1602},{},[1603],{"nodeType":874,"value":1604,"marks":1605,"data":1607},"4. Malicious browser extensions",[1606],{"type":882},{},{"nodeType":870,"data":1609,"content":1610},{},[1611],{"nodeType":874,"value":1612,"marks":1613,"data":1614},"Attackers use malicious extensions to steal data, log keystrokes, and intercept credentials and tokens as they transit the browser. ",[],{},{"nodeType":1215,"data":1616,"content":1620},{"target":1617},{"sys":1618},{"id":1619,"type":1220,"linkType":1221},"5fuigCAUuHxP49KjWgP8SO",[],{"nodeType":870,"data":1622,"content":1623},{},[1624,1628,1636],{"nodeType":874,"value":1625,"marks":1626,"data":1627},"Most malicious extensions didn't start that way — attackers begin with a legitimate extension and bide their time, waiting until install counts reach maximum impact before deploying a malicious update. It's ",[],{},{"nodeType":966,"data":1629,"content":1631},{"uri":1630},"https:\u002F\u002Fsecureannex.com\u002Fblog\u002Fbuying-browser-extensions\u002F",[1632],{"nodeType":874,"value":1633,"marks":1634,"data":1635},"very easy for attackers to buy and add malicious updates",[],{},{"nodeType":874,"value":1637,"marks":1638,"data":1639}," to existing extensions, easily passing extension web store security checks.",[],{},{"nodeType":870,"data":1641,"content":1642},{},[1643],{"nodeType":874,"value":1644,"marks":1645,"data":1646},"There are four common entry paths: phish the developer of a popular extension; offer to buy a widely-installed extension outright; vibe-code your own extension and market it to users; or upload a malicious version and let user browsers auto-update on next launch.",[],{},{"nodeType":870,"data":1648,"content":1649},{},[1650,1654,1659,1663,1671],{"nodeType":874,"value":1651,"marks":1652,"data":1653},"Permissions alone don't indicate risk, since nearly every extension has exploitable ones — ",[],{},{"nodeType":874,"value":1655,"marks":1656,"data":1658},"46.76% of extensions across Push customers have the permission combinations needed for account takeover with no user interaction",[1657],{"type":882},{},{"nodeType":874,"value":1660,"marks":1661,"data":1662},". The most dangerous let attackers intercept sensitive data, credentials, and session tokens in transit. Malicious extensions routinely evade static and sandbox analysis via dynamically compiled, smuggled code, letting them reach official stores and even earn \"Featured\" or \"Verified\" status. AI browser extensions add a further dimension: the ",[],{},{"nodeType":966,"data":1664,"content":1666},{"uri":1665},"https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fresources\u002Freports\u002Fdbir\u002F",[1667],{"nodeType":874,"value":1668,"marks":1669,"data":1670},"Verizon DBIR 2026",[],{},{"nodeType":874,"value":1672,"marks":1673,"data":1674}," found that more than 15% of corporate users had unauthorized AI browser extensions installed — extensions that collect and retain browsing context from internal sites, creating a data exfiltration pathway that operates independently of traditional DLP controls.",[],{},{"nodeType":870,"data":1676,"content":1677},{},[1678,1682,1690,1694,1702],{"nodeType":874,"value":1679,"marks":1680,"data":1681},"Generally, your employees should not be randomly installing browser extensions unless pre-approved by your security team. But the reality is that many organizations have very little visibility of the extensions their employees are using, and the potential risk they're exposed to as a result. Static risk scoring is a ",[],{},{"nodeType":966,"data":1683,"content":1685},{"uri":1684},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-browser-extension-risk-scoring-wont-predict-your-next-breach\u002F",[1686],{"nodeType":874,"value":1687,"marks":1688,"data":1689},"poor predictor of supply chain compromise",[],{},{"nodeType":874,"value":1691,"marks":1692,"data":1693}," — every major breach of the past 18 months involved extensions that scored as low-risk beforehand. A default-deny approach with ",[],{},{"nodeType":966,"data":1695,"content":1697},{"uri":1696},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-extension-management-guide\u002F",[1698],{"nodeType":874,"value":1699,"marks":1700,"data":1701},"allowlisting plus monitoring for change events",[],{},{"nodeType":874,"value":1703,"marks":1704,"data":1705}," is more effective than risk-score-based removal.",[],{},{"nodeType":1215,"data":1707,"content":1711},{"target":1708},{"sys":1709},{"id":1710,"type":1220,"linkType":1221},"6WRUfE4LepAQ35hRz2UlH1",[],{"nodeType":896,"data":1713,"content":1714},{},[],{"nodeType":944,"data":1716,"content":1717},{},[1718],{"nodeType":874,"value":1719,"marks":1720,"data":1722},"5. Credential stuffing and ghost logins",[1721],{"type":882},{},{"nodeType":870,"data":1724,"content":1725},{},[1726],{"nodeType":874,"value":1727,"marks":1728,"data":1729},"Password-based compromise remains one of the leading causes of breaches. This might surprise you if you think that SSO solved credential attacks. ",[],{},{"nodeType":1215,"data":1731,"content":1735},{"target":1732},{"sys":1733},{"id":1734,"type":1220,"linkType":1221},"5RJyr7JbVhUnccMIMsGtnE",[],{"nodeType":870,"data":1737,"content":1738},{},[1739,1743,1751],{"nodeType":874,"value":1740,"marks":1741,"data":1742},"But SSO isn't universal — SAML often costs extra, requires admin setup, and self-adopted apps rarely get configured, while most apps allow simultaneous login methods and don't restrict login methods. The result is ",[],{},{"nodeType":966,"data":1744,"content":1746},{"uri":1745},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-many-vulnerable-identities-do-you-have\u002F",[1747],{"nodeType":874,"value":1748,"marks":1749,"data":1750},"ghost logins",[],{},{"nodeType":874,"value":1752,"marks":1753,"data":1754},": backup credentials outside SSO, invisible to IdP logs, created at adoption and still active unless disabled — gaps that stay hidden since most orgs focus MFA at the IdP layer, not on local app config, until an attacker finds them.",[],{},{"nodeType":870,"data":1756,"content":1757},{},[1758],{"nodeType":874,"value":1759,"marks":1760,"data":1761},"The data supports this. Of the last million logins observed by Push:",[],{},{"nodeType":1763,"data":1764,"content":1765},"unordered-list",{},[1766,1782,1797],{"nodeType":1767,"data":1768,"content":1769},"list-item",{},[1770],{"nodeType":870,"data":1771,"content":1772},{},[1773,1778],{"nodeType":874,"value":1774,"marks":1775,"data":1777},"1 in 4",[1776],{"type":882},{},{"nodeType":874,"value":1779,"marks":1780,"data":1781}," were password logins, not SSO",[],{},{"nodeType":1767,"data":1783,"content":1784},{},[1785],{"nodeType":870,"data":1786,"content":1787},{},[1788,1793],{"nodeType":874,"value":1789,"marks":1790,"data":1792},"2 in 5",[1791],{"type":882},{},{"nodeType":874,"value":1794,"marks":1795,"data":1796}," were not protected by MFA",[],{},{"nodeType":1767,"data":1798,"content":1799},{},[1800],{"nodeType":870,"data":1801,"content":1802},{},[1803,1808],{"nodeType":874,"value":1804,"marks":1805,"data":1807},"1 in 5",[1806],{"type":882},{},{"nodeType":874,"value":1809,"marks":1810,"data":1811}," used a weak, breached, or reused password",[],{},{"nodeType":870,"data":1813,"content":1814},{},[1815,1819,1827,1831,1836,1840,1846],{"nodeType":874,"value":1816,"marks":1817,"data":1818},"And the external sources also paint this picture. ",[],{},{"nodeType":966,"data":1820,"content":1822},{"uri":1821},"https:\u002F\u002Fcf-assets.www.cloudflare.com\u002Fslt3lc6tev37\u002FsWDBUMNVtEJB9ZFLt1dUU\u002F8d69e92de2edfb3bf59e7d21d57e7e1a\u002FCloudflare-2026-threat-report.pdf",[1823],{"nodeType":874,"value":1824,"marks":1825,"data":1826},"Cloudflare's 2026 Threat Report",[],{},{"nodeType":874,"value":1828,"marks":1829,"data":1830}," found that ",[],{},{"nodeType":874,"value":1832,"marks":1833,"data":1835},"63% of all human logins involve credentials already compromised elsewhere",[1834],{"type":882},{},{"nodeType":874,"value":1837,"marks":1838,"data":1839},". And the ",[],{},{"nodeType":966,"data":1841,"content":1842},{"uri":1665},[1843],{"nodeType":874,"value":1668,"marks":1844,"data":1845},[],{},{"nodeType":874,"value":1847,"marks":1848,"data":1849}," found that 50% of ransomware victims had a credential or infostealer event within 95 days prior to the attack, with infostealers surfacing an average of 2,362 breached corporate credentials per month from organizational email domains.",[],{},{"nodeType":870,"data":1851,"content":1852},{},[1853],{"nodeType":874,"value":1854,"marks":1855,"data":1856},"Logins can be observed in the browser — in fact, it's as close to a universal source of truth as you're going to get about how your employees are actually logging in, which apps they're using, and whether MFA is present, enabling security teams to find and fix vulnerable logins before they can be exploited.",[],{},{"nodeType":1215,"data":1858,"content":1862},{"target":1859},{"sys":1860},{"id":1861,"type":1220,"linkType":1221},"1tX9gSZ51VEmXjRliTXuPV",[],{"nodeType":896,"data":1864,"content":1865},{},[],{"nodeType":944,"data":1867,"content":1868},{},[1869],{"nodeType":874,"value":1870,"marks":1871,"data":1873},"6. Session hijacking",[1872],{"type":882},{},{"nodeType":870,"data":1875,"content":1876},{},[1877],{"nodeType":874,"value":1878,"marks":1879,"data":1880},"Session hijacking (aka token replay) allows attackers to bypass the authentication process by taking an already-approved session token that they've stolen from the victim's device or browser, and reusing it in their own browser. This enables them to get around even phishing-resistant authentication controls like passkeys.",[],{},{"nodeType":870,"data":1882,"content":1883},{},[1884],{"nodeType":874,"value":1885,"marks":1886,"data":1887},"This is different to AiTM attacks, which see a new session created via the attacker's reverse-proxy connection to the target app. Sessions can be stolen using a variety of methods, some of which we've already discussed. Malicious browser extensions can extract them from webpages visited by the user, for example. But the most prominent source of stolen tokens is infostealer malware — also the leading source of stolen credentials powering credential stuffing attacks.",[],{},{"nodeType":870,"data":1889,"content":1890},{},[1891,1895,1902,1905,1910],{"nodeType":874,"value":1892,"marks":1893,"data":1894},"As mentioned previously, ClickFix is now the go-to method for delivering malware like infostealers. ClickFix is more detection-resistant than a normal file download, which is more likely to be intercepted and analyzed by controls like a web sandbox before hitting the endpoint and more likely to trigger endpoint alarms during execution. The problem extends beyond managed corporate machines, too: the ",[],{},{"nodeType":966,"data":1896,"content":1897},{"uri":1665},[1898],{"nodeType":874,"value":1899,"marks":1900,"data":1901},"Verizon DBIR 2025",[],{},{"nodeType":874,"value":1828,"marks":1903,"data":1904},[],{},{"nodeType":874,"value":1906,"marks":1907,"data":1909},"46% of infostealer infections that lead to corporate breaches originate on non-managed devices",[1908],{"type":882},{},{"nodeType":874,"value":1911,"marks":1912,"data":1913}," — personal machines, developer workstations, and contractor laptops where EDR is absent.",[],{},{"nodeType":870,"data":1915,"content":1916},{},[1917,1921,1929],{"nodeType":874,"value":1918,"marks":1919,"data":1920},"There's also a less obvious path for session theft. ",[],{},{"nodeType":966,"data":1922,"content":1924},{"uri":1923},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches\u002F",[1925],{"nodeType":874,"value":1926,"marks":1927,"data":1928},"Browser sync features",[],{},{"nodeType":874,"value":1930,"marks":1931,"data":1932}," create a bridge between personal and corporate credential stores, meaning personal account or device compromises can directly lead to corporate breaches — as demonstrated in the Okta incident below, where corporate credentials had been synced to an engineer's personal Google account via Chrome profile sync.",[],{},{"nodeType":1215,"data":1934,"content":1938},{"target":1935},{"sys":1936},{"id":1937,"type":1220,"linkType":1221},"51WVinSAV5wN7mVny7v9QC",[],{"nodeType":896,"data":1940,"content":1941},{},[],{"nodeType":900,"data":1943,"content":1944},{},[1945],{"nodeType":874,"value":1946,"marks":1947,"data":1949},"Conclusion",[1948],{"type":882},{},{"nodeType":870,"data":1951,"content":1952},{},[1953,1957,1964],{"nodeType":874,"value":1954,"marks":1955,"data":1956},"Attacks are increasingly happening in the browser. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams — ",[],{},{"nodeType":966,"data":1958,"content":1959},{"uri":968},[1960],{"nodeType":874,"value":1961,"marks":1962,"data":1963},"according to Omdia",[],{},{"nodeType":874,"value":1965,"marks":1966,"data":1967},", 49% of organizations suffered a successful browser-based attack in the last 12 months, and browser security is now a top-five priority for 88% of organizations. ",[],{},{"nodeType":870,"data":1969,"content":1970},{},[1971],{"nodeType":874,"value":1084,"marks":1972,"data":1973},[],{},{"nodeType":870,"data":1975,"content":1976},{},[1977],{"nodeType":874,"value":1091,"marks":1978,"data":1979},[],{},{"nodeType":870,"data":1981,"content":1982},{},[1983,1987,1995],{"nodeType":874,"value":1984,"marks":1985,"data":1986},"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",[],{},{"nodeType":966,"data":1988,"content":1989},{"uri":1102},[1990],{"nodeType":874,"value":1991,"marks":1992,"data":1994},"book some time with one of our team for a live demo",[1993],{"type":974},{},{"nodeType":874,"value":1581,"marks":1996,"data":1997},[],{},"6 browser-based attacks every security team should be prepared for","What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.","2026-09-15T00:00:00.000Z","6-browser-based-attacks-every-security-team-should-be-prepared-for",{"items":2003},[2004,2008],{"sys":2005,"name":2007},{"id":2006},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":2009,"name":334},{"id":2010},"4ksQNCFeBf8H4QIORqpRLw",{"items":2012},[2013],{"fullName":2014,"firstName":2015,"jobTitle":2016,"profilePicture":2017},"Dan Green","Dan","Threat Research",{"url":2018},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png",{"__typename":1126,"sys":2020,"content":2022,"title":2495,"synopsis":2496,"hashTags":60,"publishedDate":2497,"slug":2498,"tagsCollection":2499,"authorsCollection":2506},{"id":2021},"ThcZepauVfA5fKossdkbm",{"json":2023},{"data":2024,"content":2025,"nodeType":866},{},[2026,2033,2040,2070,2077,2085,2091,2094,2102,2145,2165,2171,2174,2182,2189,2208,2211,2219,2226,2233,2236,2244,2251,2258,2261,2269,2276,2294,2297,2305,2312,2319,2322,2330,2337,2344,2347,2355,2374,2377,2385,2392,2399,2405,2408,2416,2423,2430,2433,2441,2447,2465,2471,2477],{"data":2027,"content":2028,"nodeType":870},{},[2029],{"data":2030,"marks":2031,"value":2032,"nodeType":874},{},[],"Ask a security team where most of their tools are and it's the endpoint, network, or cloud. But ask where their users spend most of their time and it's the browser.",{"data":2034,"content":2035,"nodeType":870},{},[2036],{"data":2037,"marks":2038,"value":2039,"nodeType":874},{},[],"So we got a category: browser security. And when it comes to the best browser security tools, there's a problem. Browser security means three different things depending on who's talking: enterprise browser extensions, enterprise browsers, and remote browser isolation (RBI).",{"data":2041,"content":2042,"nodeType":870},{},[2043,2047,2054,2058,2066],{"data":2044,"marks":2045,"value":2046,"nodeType":874},{},[],"The market reflects that confusion, but the momentum is real. According to ",{"data":2048,"content":2049,"nodeType":966},{"uri":968},[2050],{"data":2051,"marks":2052,"value":2053,"nodeType":874},{},[],"Omdia's 2026 research",{"data":2055,"marks":2056,"value":2057,"nodeType":874},{},[],", browser security is already a top-five priority for 88% of organizations and the top priority for 26%, with 86% having meaningfully increased their browser security spending in response to emerging threats. ",{"data":2059,"content":2061,"nodeType":966},{"uri":2060},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-case-for-best-of-breed-browser-security",[2062],{"data":2063,"marks":2064,"value":2065,"nodeType":874},{},[],"Three browser security startups were acquired",{"data":2067,"marks":2068,"value":2069,"nodeType":874},{},[]," by major platform vendors in 2026 alone — CrowdStrike bought Seraphic, Zscaler absorbed SquareX, and Akamai announced intent to acquire LayerX.",{"data":2071,"content":2072,"nodeType":870},{},[2073],{"data":2074,"marks":2075,"value":2076,"nodeType":874},{},[],"Here's what the browser security market looks like in 2026.",{"data":2078,"content":2079,"nodeType":870},{},[2080],{"data":2081,"marks":2082,"value":2084,"nodeType":874},{},[2083],{"type":882},"The top enterprise browser solutions in 2026 include Push Security, Island, and LayerX.",{"data":2086,"content":2090,"nodeType":1215},{"target":2087},{"sys":2088},{"id":2089,"type":1220,"linkType":1221},"5d35fpWpgIytQhhiABQray",[],{"data":2092,"content":2093,"nodeType":896},{},[],{"data":2095,"content":2096,"nodeType":900},{},[2097],{"data":2098,"marks":2099,"value":2101,"nodeType":874},{},[2100],{"type":882},"1. Push Security – Enterprise browser extension",{"data":2103,"content":2104,"nodeType":870},{},[2105,2109,2117,2121,2129,2133,2141],{"data":2106,"marks":2107,"value":2108,"nodeType":874},{},[],"Push is a browser extension, not a browser, that turns whatever browser your people already use into a detection and response platform for the security team. With no migration, no user disruption, no new browser to manage. It covers ",{"data":2110,"content":2112,"nodeType":966},{"uri":2111},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",[2113],{"data":2114,"marks":2115,"value":2116,"nodeType":874},{},[],"four use cases from a single deployment",{"data":2118,"marks":2119,"value":2120,"nodeType":874},{},[],": detecting and stopping sophisticated browser-based attacks, AI visibility and control, identity and shadow IT security, and DLP and insider investigations. Detections are built on ",{"data":2122,"content":2124,"nodeType":966},{"uri":2123},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-to-avoid-the-browser-security-buyers-trap",[2125],{"data":2126,"marks":2127,"value":2128,"nodeType":874},{},[],"in-house threat research",{"data":2130,"marks":2131,"value":2132,"nodeType":874},{},[]," and operationalized by autonomous agents, so what Push catches is based on attacker techniques and behaviors rather than a blocklist. It ",{"data":2134,"content":2136,"nodeType":966},{"uri":2135},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmaking-the-business-case-for-a-browser-security-solution",[2137],{"data":2138,"marks":2139,"value":2140,"nodeType":874},{},[],"deploys in minutes",{"data":2142,"marks":2143,"value":2144,"nodeType":874},{},[]," across managed and unmanaged devices.",{"data":2146,"content":2147,"nodeType":870},{},[2148,2152,2161],{"data":2149,"marks":2150,"value":2151,"nodeType":874},{},[],"Push detects AiTM and device code phishing kits (",{"data":2153,"content":2155,"nodeType":966},{"uri":2154},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fagentic-threat-hunting-benefits-for-customers",[2156],{"data":2157,"marks":2158,"value":2160,"nodeType":874},{},[2159],{"type":974},"75+ across Tycoon 2FA, Sneaky 2FA, Evilginx, and many others",{"data":2162,"marks":2163,"value":2164,"nodeType":874},{},[],") behaviorally by analyzing page structure and script execution — so detection survives infrastructure rotation. It catches ClickFix-style clipboard injection before the payload executes, detects stolen session tokens via marker injection when they appear in uninstrumented browsers, and monitors OAuth consent flows across 20+ authorization servers. Push is deployed across 3 million browsers worldwide and has been rolled out to 100,000 users in under one hour during normal office hours.",{"data":2166,"content":2170,"nodeType":1215},{"target":2167},{"sys":2168},{"id":2169,"type":1220,"linkType":1221},"ZmRwtfBPVptxTOE6wt1Yq",[],{"data":2172,"content":2173,"nodeType":896},{},[],{"data":2175,"content":2176,"nodeType":900},{},[2177],{"data":2178,"marks":2179,"value":2181,"nodeType":874},{},[2180],{"type":882},"2. Island – Enterprise browser",{"data":2183,"content":2184,"nodeType":870},{},[2185],{"data":2186,"marks":2187,"value":2188,"nodeType":874},{},[],"Island was one of the first to market in the enterprise browser category and still defines it. It replaces current browsers with a managed Chromium fork that gives IT granular control over copy-paste, screenshots, downloads, session recording, and application access — all enforced at the browser level without routing traffic through a proxy. For highly regulated environments where that degree of governance is a requirement, it's a capable platform with real enterprise traction.",{"data":2190,"content":2191,"nodeType":870},{},[2192,2196,2205],{"data":2193,"marks":2194,"value":2195,"nodeType":874},{},[],"It's a full browser replacement, with primary use cases around VDI replacement, contractor access, BYOD governance, and zero-trust network access. Most organizations plan for a ",{"data":2197,"content":2199,"nodeType":966},{"uri":2198},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fenterprise-browser-vs-browser-extension-which-should-your-security-team-choose",[2200],{"data":2201,"marks":2202,"value":2204,"nodeType":874},{},[2203],{"type":974},"phased rollout",{"data":2206,"marks":2207,"value":1581,"nodeType":874},{},[],{"data":2209,"content":2210,"nodeType":896},{},[],{"data":2212,"content":2213,"nodeType":900},{},[2214],{"data":2215,"marks":2216,"value":2218,"nodeType":874},{},[2217],{"type":882},"3. Prisma Browser – Enterprise browser",{"data":2220,"content":2221,"nodeType":870},{},[2222],{"data":2223,"marks":2224,"value":2225,"nodeType":874},{},[],"Formerly Talon, now Palo Alto Networks' enterprise browser and the last-mile enforcement layer of its SASE platform. Prisma Browser is a managed Chromium browser with DLP that inspects the rendered page and zero-trust access controls, designed primarily for contractor, BYOD, and remote worker populations accessing corporate apps from unmanaged devices.",{"data":2227,"content":2228,"nodeType":870},{},[2229],{"data":2230,"marks":2231,"value":2232,"nodeType":874},{},[],"Like Island, it's a browser replacement. It integrates natively with the broader Prisma Access and Cortex stack, feeding browser telemetry into Palo Alto Networks' existing correlation and response workflows.",{"data":2234,"content":2235,"nodeType":896},{},[],{"data":2237,"content":2238,"nodeType":900},{},[2239],{"data":2240,"marks":2241,"value":2243,"nodeType":874},{},[2242],{"type":882},"4. Seraphic Security (CrowdStrike) – Enterprise browser extension",{"data":2245,"content":2246,"nodeType":870},{},[2247],{"data":2248,"marks":2249,"value":2250,"nodeType":874},{},[],"Seraphic works across any browser through an endpoint agent that adds enterprise security without replacing what's deployed. CrowdStrike acquired Seraphic in early 2026 to extend Falcon past the endpoint and into the browser layer, with the stated goal of correlating endpoint and browser telemetry in a single platform.",{"data":2252,"content":2253,"nodeType":870},{},[2254],{"data":2255,"marks":2256,"value":2257,"nodeType":874},{},[],"For existing CrowdStrike customers, the extension into the browser is a natural addition to the Falcon ecosystem. Cross-browser coverage remains a differentiator for mixed environments.",{"data":2259,"content":2260,"nodeType":896},{},[],{"data":2262,"content":2263,"nodeType":900},{},[2264],{"data":2265,"marks":2266,"value":2268,"nodeType":874},{},[2267],{"type":882},"5. LayerX Security (Akamai) – Enterprise browser extension",{"data":2270,"content":2271,"nodeType":870},{},[2272],{"data":2273,"marks":2274,"value":2275,"nodeType":874},{},[],"LayerX is extension-based, focused on real-time DLP and AI governance which captures what happens inside AI tools, flagging sensitive data submissions, and enforcing policy, all without requiring a new browser. Low deployment friction and a growing AI visibility capability are the draw.",{"data":2277,"content":2278,"nodeType":870},{},[2279,2283,2290],{"data":2280,"marks":2281,"value":2282,"nodeType":874},{},[],"Akamai announced the intent to acquire LayerX in mid-2026 to complement its Zero Trust portfolio. For buyers evaluating LayerX as a long-term platform bet, the ",{"data":2284,"content":2285,"nodeType":966},{"uri":2060},[2286],{"data":2287,"marks":2288,"value":2289,"nodeType":874},{},[],"question is what the roadmap looks like 18 months post-close",{"data":2291,"marks":2292,"value":2293,"nodeType":874},{},[],", given Akamai's track record of absorbing acquisitions (Guardicore, Neosec, Inverse) into its broader platform.",{"data":2295,"content":2296,"nodeType":896},{},[],{"data":2298,"content":2299,"nodeType":900},{},[2300],{"data":2301,"marks":2302,"value":2304,"nodeType":874},{},[2303],{"type":882},"6. SquareX (Zscaler) – Enterprise browser extension",{"data":2306,"content":2307,"nodeType":870},{},[2308],{"data":2309,"marks":2310,"value":2311,"nodeType":874},{},[],"SquareX takes a detection-minded posture, inspecting files and links while browsing, neutralizing malicious content before it reaches the endpoint, and offering disposable browser environments for high-risk activity. It was clearly built by people who think in attacker terms.",{"data":2313,"content":2314,"nodeType":870},{},[2315],{"data":2316,"marks":2317,"value":2318,"nodeType":874},{},[],"Zscaler acquired SquareX in early 2026, integrating it into the Zero Trust Exchange alongside its existing SSE capabilities.",{"data":2320,"content":2321,"nodeType":896},{},[],{"data":2323,"content":2324,"nodeType":900},{},[2325],{"data":2326,"marks":2327,"value":2329,"nodeType":874},{},[2328],{"type":882},"7. Keep Aware – Enterprise browser extension",{"data":2331,"content":2332,"nodeType":870},{},[2333],{"data":2334,"marks":2335,"value":2336,"nodeType":874},{},[],"Keep Aware is an agentless extension built with security operations in mind. It's quick to deploy through MDM or group policy, and focused on surfacing browser threats, extension risk, and AI usage into existing SOC workflows. Detection and response is the throughline, with SIEM integration as a core part of the offering.",{"data":2338,"content":2339,"nodeType":870},{},[2340],{"data":2341,"marks":2342,"value":2343,"nodeType":874},{},[],"Founded in 2022, Keep Aware has been iterating quickly with a focused product roadmap around browser detection and response.",{"data":2345,"content":2346,"nodeType":896},{},[],{"data":2348,"content":2349,"nodeType":900},{},[2350],{"data":2351,"marks":2352,"value":2354,"nodeType":874},{},[2353],{"type":882},"8. Menlo Security – Remote browser isolation",{"data":2356,"content":2357,"nodeType":870},{},[2358,2362,2370],{"data":2359,"marks":2360,"value":2361,"nodeType":874},{},[],"Menlo pioneered ",{"data":2363,"content":2365,"nodeType":966},{"uri":2364},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation",[2366],{"data":2367,"marks":2368,"value":2369,"nodeType":874},{},[],"remote browser isolation",{"data":2371,"marks":2372,"value":2373,"nodeType":874},{},[],": web content renders in a disposable cloud container and the user receives a clean visual stream, so nothing malicious ever touches the endpoint. For zero-tolerance environments and third-party or contractor access where you don't fully trust the device, the approach has a solid track record. Cloud rendering introduces latency and the occasional site-compatibility issue, though Menlo has invested in reducing both over the years.",{"data":2375,"content":2376,"nodeType":896},{},[],{"data":2378,"content":2379,"nodeType":900},{},[2380],{"data":2381,"marks":2382,"value":2384,"nodeType":874},{},[2383],{"type":882},"9. Chrome Enterprise \u002F Edge for Business – Enterprise browser",{"data":2386,"content":2387,"nodeType":870},{},[2388],{"data":2389,"marks":2390,"value":2391,"nodeType":874},{},[],"The security controls are already built into the browsers most of your people use. Chrome Enterprise offers centralized management, Safe Browsing, and identity tool integration across the fleet; Edge for Business adds work-and-personal separation, phishing protection, and tight integration with Microsoft 365 and Defender.",{"data":2393,"content":2394,"nodeType":870},{},[2395],{"data":2396,"marks":2397,"value":2398,"nodeType":874},{},[],"These are baseline controls, and for many organizations they're effectively free with what's already deployed. Most organizations treat them as the foundation that the rest of the tools on this list build on.",{"data":2400,"content":2404,"nodeType":1215},{"target":2401},{"sys":2402},{"id":2403,"type":1220,"linkType":1221},"7Gbd8bBWa19gP5DMfeeB7J",[],{"data":2406,"content":2407,"nodeType":896},{},[],{"data":2409,"content":2410,"nodeType":900},{},[2411],{"data":2412,"marks":2413,"value":2415,"nodeType":874},{},[2414],{"type":882},"10. SURF Security – Enterprise browser",{"data":2417,"content":2418,"nodeType":870},{},[2419],{"data":2420,"marks":2421,"value":2422,"nodeType":874},{},[],"SURF is a Chromium-based enterprise browser built zero-trust-first, with identity-based access controls, DLP, and session security inside a fully managed environment. Centralized, policy-driven control by default is the pitch, aimed at security-first organizations that want a locked-down browser from day one.",{"data":2424,"content":2425,"nodeType":870},{},[2426],{"data":2427,"marks":2428,"value":2429,"nodeType":874},{},[],"Like Island and Prisma, it's a browser replacement, so it follows the same deployment model — plan for a migration alongside the capabilities.",{"data":2431,"content":2432,"nodeType":896},{},[],{"data":2434,"content":2435,"nodeType":900},{},[2436],{"data":2437,"marks":2438,"value":2440,"nodeType":874},{},[2439],{"type":882},"Learn more about Push Security",{"data":2442,"content":2443,"nodeType":870},{},[2444],{"data":2445,"marks":2446,"value":1084,"nodeType":874},{},[],{"data":2448,"content":2449,"nodeType":870},{},[2450,2454,2461],{"data":2451,"marks":2452,"value":2453,"nodeType":874},{},[],"Push is the best choice for organizations looking to ",{"data":2455,"content":2456,"nodeType":966},{"uri":2111},[2457],{"data":2458,"marks":2459,"value":2460,"nodeType":874},{},[],"solve the most impactful security problems in the browse",{"data":2462,"marks":2463,"value":2464,"nodeType":874},{},[],"r, with use cases including detecting and stopping advanced attacks, data loss and insider investigations, identity and shadow IT security, and AI visibility and control. ",{"data":2466,"content":2470,"nodeType":1215},{"target":2467},{"sys":2468},{"id":2469,"type":1220,"linkType":1221},"4nGzT9cNG0Yid93uUCCuTt",[],{"data":2472,"content":2473,"nodeType":870},{},[2474],{"data":2475,"marks":2476,"value":1091,"nodeType":874},{},[],{"data":2478,"content":2479,"nodeType":870},{},[2480,2484,2491],{"data":2481,"marks":2482,"value":2483,"nodeType":874},{},[],"Book a ",{"data":2485,"content":2486,"nodeType":966},{"uri":1102},[2487],{"data":2488,"marks":2489,"value":2490,"nodeType":874},{},[],"live demo",{"data":2492,"marks":2493,"value":2494,"nodeType":874},{},[]," to learn more.","The top 10 browser security solutions: Push Security, Island, LayerX and more","Browser security means a lot of different things depending on who's talking. Here's your guide to the browser security market from a vendor perspective in 2026.","2026-07-27T00:00:00.000Z","the-top-10-browser-security-solutions-in-2026",{"items":2500},[2501,2504],{"sys":2502,"name":289},{"id":2503},"3pjES4THCIfSAwhGdNwBcy",{"sys":2505,"name":334},{"id":2010},{"items":2507},[2508],{"fullName":2509,"firstName":2510,"jobTitle":2511,"profilePicture":2512},"Alex Henshall","Alex","Product Team",{"url":2513},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2rz3Pre3b1MexPIQ4hzPUe\u002F0ef8a092b7e7df00fbce3f7d1ccb96d1\u002FAlex_Henshall.jpeg",{"__typename":1126,"sys":2515,"content":2517,"title":3810,"synopsis":3811,"hashTags":60,"publishedDate":3812,"slug":3813,"tagsCollection":3814,"authorsCollection":3820},{"id":2516},"vLb3RhwYt7Xc6mkX3pWyI",{"json":2518},{"data":2519,"content":2520,"nodeType":866},{},[2521,2528,2531,2539,2569,2577,2583,2614,2729,2770,2778,2833,2864,2870,2873,2881,2888,2896,2913,2968,2974,2981,3000,3006,3013,3019,3026,3032,3039,3045,3053,3096,3127,3146,3177,3185,3216,3247,3278,3286,3293,3312,3366,3397,3405,3423,3466,3469,3477,3484,3491,3509,3515,3522,3634,3676,3684,3703,3710,3713,3721,3728,3771,3778,3781,3787,3793],{"data":2522,"content":2523,"nodeType":870},{},[2524],{"data":2525,"marks":2526,"value":2527,"nodeType":874},{},[],"Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.",{"data":2529,"content":2530,"nodeType":896},{},[],{"data":2532,"content":2533,"nodeType":900},{},[2534],{"data":2535,"marks":2536,"value":2538,"nodeType":874},{},[2537],{"type":882},"The SLH playbook becomes the industry standard",{"data":2540,"content":2541,"nodeType":870},{},[2542,2546,2554,2558,2565],{"data":2543,"marks":2544,"value":2545,"nodeType":874},{},[],"Criminals associated with \"The Com,\" broadly known as the ",{"data":2547,"content":2549,"nodeType":966},{"uri":2548},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters",[2550],{"data":2551,"marks":2552,"value":2553,"nodeType":874},{},[],"Scattered Lapsus$ Hunters",{"data":2555,"marks":2556,"value":2557,"nodeType":874},{},[]," collective, have spent the past three years establishing a playbook ",{"data":2559,"content":2560,"nodeType":966},{"uri":1204},[2561],{"data":2562,"marks":2563,"value":2564,"nodeType":874},{},[],"focused on identity compromise and cloud data theft",{"data":2566,"marks":2567,"value":2568,"nodeType":874},{},[]," for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).",{"data":2570,"content":2571,"nodeType":870},{},[2572],{"data":2573,"marks":2574,"value":2576,"nodeType":874},{},[2575],{"type":882},"Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, groups linked to \"The Com\" such as Scattered Spider, ShinyHunters, and Lapsus$ are responsible for roughly 70% (not just in 2026, but since the start of 2024). ",{"data":2578,"content":2582,"nodeType":1215},{"target":2579},{"sys":2580},{"id":2581,"type":1220,"linkType":1221},"3hODobO3VJr3LvbXkzso8I",[],{"data":2584,"content":2585,"nodeType":870},{},[2586,2590,2598,2602,2610],{"data":2587,"marks":2588,"value":2589,"nodeType":874},{},[],"The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in ",{"data":2591,"content":2593,"nodeType":966},{"uri":2592},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-spider-defending-against-help-desk-scams",[2594],{"data":2595,"marks":2596,"value":2597,"nodeType":874},{},[],"tricking help desks into performing account resets",{"data":2599,"marks":2600,"value":2601,"nodeType":874},{},[],". This year, they've switched to using voice-based lures in tandem with ",{"data":2603,"content":2605,"nodeType":966},{"uri":2604},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign",[2606],{"data":2607,"marks":2608,"value":2609,"nodeType":874},{},[],"browser-based phishing payloads",{"data":2611,"marks":2612,"value":2613,"nodeType":874},{},[]," — usually impersonating IT staff under the guise of \"setting up passkeys.\"",{"data":2615,"content":2616,"nodeType":870},{},[2617,2621,2629,2633,2641,2645,2653,2657,2665,2669,2677,2681,2689,2693,2701,2705,2713,2717,2725],{"data":2618,"marks":2619,"value":2620,"nodeType":874},{},[],"The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: ",{"data":2622,"content":2624,"nodeType":966},{"uri":2623},"https:\u002F\u002Fwww.securityweek.com\u002Fpanera-bread-data-breach-linked-to-shinyhunters-sso-campaign\u002F",[2625],{"data":2626,"marks":2627,"value":2628,"nodeType":874},{},[],"Panera Bread",{"data":2630,"marks":2631,"value":2632,"nodeType":874},{},[]," (~14M records), ",{"data":2634,"content":2636,"nodeType":966},{"uri":2635},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmatch-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\u002F",[2637],{"data":2638,"marks":2639,"value":2640,"nodeType":874},{},[],"Match Group",{"data":2642,"marks":2643,"value":2644,"nodeType":874},{},[]," (Hinge, Tinder, OkCupid; 10M+ records), ",{"data":2646,"content":2648,"nodeType":966},{"uri":2647},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fexpansion-shinyhunters-saas-data-theft",[2649],{"data":2650,"marks":2651,"value":2652,"nodeType":874},{},[],"Betterment",{"data":2654,"marks":2655,"value":2656,"nodeType":874},{},[]," (~20M records), ",{"data":2658,"content":2660,"nodeType":966},{"uri":2659},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-extortion-gang-claims-odido-breach-affecting-millions\u002F",[2661],{"data":2662,"marks":2663,"value":2664,"nodeType":874},{},[],"Odido",{"data":2666,"marks":2667,"value":2668,"nodeType":874},{},[]," (6.2M Dutch telecom customers with BSNs and IBANs exposed), ",{"data":2670,"content":2672,"nodeType":966},{"uri":2671},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fadt-confirms-data-breach-after-shinyhunters-leak-threat\u002F",[2673],{"data":2674,"marks":2675,"value":2676,"nodeType":874},{},[],"ADT",{"data":2678,"marks":2679,"value":2680,"nodeType":874},{},[]," (5.5M records), ",{"data":2682,"content":2684,"nodeType":966},{"uri":2683},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcharter-communications-data-breach-affects-49-million-accounts\u002F",[2685],{"data":2686,"marks":2687,"value":2688,"nodeType":874},{},[],"Charter Communications",{"data":2690,"marks":2691,"value":2692,"nodeType":874},{},[]," (4.9M accounts), ",{"data":2694,"content":2696,"nodeType":966},{"uri":2695},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F24\u002Fshinyhunters_claim_cruise_giant_carnivals\u002F",[2697],{"data":2698,"marks":2699,"value":2700,"nodeType":874},{},[],"Carnival Corporation",{"data":2702,"marks":2703,"value":2704,"nodeType":874},{},[]," (6M records), and",{"data":2706,"content":2708,"nodeType":966},{"uri":2707},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F28\u002Fpitney_bowes_is_the_latest\u002F",[2709],{"data":2710,"marks":2711,"value":2712,"nodeType":874},{},[]," Pitney Bowes",{"data":2714,"marks":2715,"value":2716,"nodeType":874},{},[]," (8.2M emails per HIBP). ",{"data":2718,"content":2720,"nodeType":966},{"uri":2719},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack\u002F",[2721],{"data":2722,"marks":2723,"value":2724,"nodeType":874},{},[],"Optimizely",{"data":2726,"marks":2727,"value":2728,"nodeType":874},{},[]," is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.",{"data":2730,"content":2731,"nodeType":870},{},[2732,2736,2743,2747,2755,2759,2767],{"data":2733,"marks":2734,"value":2735,"nodeType":874},{},[],"Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal ",{"data":2737,"content":2738,"nodeType":966},{"uri":1529},[2739],{"data":2740,"marks":2741,"value":2742,"nodeType":874},{},[],"device code phishing",{"data":2744,"marks":2745,"value":2746,"nodeType":874},{},[]," campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like ",{"data":2748,"content":2750,"nodeType":966},{"uri":2749},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fdata-theft-salesforce-instances-via-salesloft-drift",[2751],{"data":2752,"marks":2753,"value":2754,"nodeType":874},{},[],"Salesloft, Drift, and GainSight",{"data":2756,"marks":2757,"value":2758,"nodeType":874},{},[]," and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since ",{"data":2760,"content":2762,"nodeType":966},{"uri":2761},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach",[2763],{"data":2764,"marks":2765,"value":2766,"nodeType":874},{},[],"repeated at scale",{"data":2768,"marks":2769,"value":1581,"nodeType":874},{},[],{"data":2771,"content":2772,"nodeType":944},{},[2773],{"data":2774,"marks":2775,"value":2777,"nodeType":874},{},[2776],{"type":882},"Copycats and nation-state adoption",{"data":2779,"content":2780,"nodeType":870},{},[2781,2785,2793,2797,2805,2809,2817,2821,2829],{"data":2782,"marks":2783,"value":2784,"nodeType":874},{},[],"Wider groups are now running the SLH playbook independently. ",{"data":2786,"content":2788,"nodeType":966},{"uri":2787},"https:\u002F\u002Fhackread.com\u002Fpink-extortion-microsoft-365-cloud-data-vishing-scams\u002F",[2789],{"data":2790,"marks":2791,"value":2792,"nodeType":874},{},[],"Pink",{"data":2794,"marks":2795,"value":2796,"nodeType":874},{},[]," (the latest rebrand in the",{"data":2798,"content":2800,"nodeType":966},{"uri":2799},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Func6671-targets-financial-services-and-enterprise-cloud-environments",[2801],{"data":2802,"marks":2803,"value":2804,"nodeType":874},{},[]," BlackFile",{"data":2806,"marks":2807,"value":2808,"nodeType":874},{},[],"-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. ",{"data":2810,"content":2812,"nodeType":966},{"uri":2811},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks\u002F",[2813],{"data":2814,"marks":2815,"value":2816,"nodeType":874},{},[],"Helix",{"data":2818,"marks":2819,"value":2820,"nodeType":874},{},[]," also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. ",{"data":2822,"content":2824,"nodeType":966},{"uri":2823},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fkongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches\u002F",[2825],{"data":2826,"marks":2827,"value":2828,"nodeType":874},{},[],"KongTuke",{"data":2830,"marks":2831,"value":2832,"nodeType":874},{},[],", an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.",{"data":2834,"content":2835,"nodeType":870},{},[2836,2840,2848,2852,2860],{"data":2837,"marks":2838,"value":2839,"nodeType":874},{},[],"It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used ",{"data":2841,"content":2843,"nodeType":966},{"uri":2842},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F07\u002F31\u002Fcaptivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\u002F",[2844],{"data":2845,"marks":2846,"value":2847,"nodeType":874},{},[],"compromised hotel and conference Wi-Fi gateways",{"data":2849,"marks":2850,"value":2851,"nodeType":874},{},[]," to direct victims to AiTM, ClickFix, and device code phishing pages. And ",{"data":2853,"content":2855,"nodeType":966},{"uri":2854},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fchinese-language-phishing-services\u002F",[2856],{"data":2857,"marks":2858,"value":2859,"nodeType":874},{},[],"Google Threat Intelligence mapped",{"data":2861,"marks":2862,"value":2863,"nodeType":874},{},[]," a dozen Chinese-language PhaaS platforms with real-time MFA interception.",{"data":2865,"content":2869,"nodeType":1215},{"target":2866},{"sys":2867},{"id":2868,"type":1220,"linkType":1221},"6q2NwH6Q4DJE7RNeYheIvJ",[],{"data":2871,"content":2872,"nodeType":896},{},[],{"data":2874,"content":2875,"nodeType":900},{},[2876],{"data":2877,"marks":2878,"value":2880,"nodeType":874},{},[2879],{"type":882},"Phishing infrastructure has reached an industrial scale",{"data":2882,"content":2883,"nodeType":870},{},[2884],{"data":2885,"marks":2886,"value":2887,"nodeType":874},{},[],"The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.",{"data":2889,"content":2890,"nodeType":944},{},[2891],{"data":2892,"marks":2893,"value":2895,"nodeType":874},{},[2894],{"type":882},"Device code phishing goes mainstream",{"data":2897,"content":2898,"nodeType":870},{},[2899,2903,2909],{"data":2900,"marks":2901,"value":2902,"nodeType":874},{},[],"We're tracking a huge spike in ",{"data":2904,"content":2905,"nodeType":966},{"uri":1529},[2906],{"data":2907,"marks":2908,"value":2742,"nodeType":874},{},[],{"data":2910,"marks":2911,"value":2912,"nodeType":874},{},[]," since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.",{"data":2914,"content":2915,"nodeType":870},{},[2916,2920,2928,2932,2940,2944,2952,2956,2964],{"data":2917,"marks":2918,"value":2919,"nodeType":874},{},[],"What began with ",{"data":2921,"content":2923,"nodeType":966},{"uri":2922},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2025\u002F02\u002F13\u002Fstorm-2372-conducts-device-code-phishing-campaign\u002F",[2924],{"data":2925,"marks":2926,"value":2927,"nodeType":874},{},[],"Storm-2372's nation-state campaigns",{"data":2929,"marks":2930,"value":2931,"nodeType":874},{},[]," in August 2024 has proliferated through criminal kits like ",{"data":2933,"content":2935,"nodeType":966},{"uri":2934},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fthe-new-phishing-click-how-oauth-consent.html",[2936],{"data":2937,"marks":2938,"value":2939,"nodeType":874},{},[],"EvilTokens",{"data":2941,"marks":2942,"value":2943,"nodeType":874},{},[]," (340+ organizations in its first five weeks), ",{"data":2945,"content":2947,"nodeType":966},{"uri":2946},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fkali365-device-code-phishing-kit",[2948],{"data":2949,"marks":2950,"value":2951,"nodeType":874},{},[],"Kali365",{"data":2953,"marks":2954,"value":2955,"nodeType":874},{},[]," (which earned an FBI public advisory), ",{"data":2957,"content":2959,"nodeType":966},{"uri":2958},"https:\u002F\u002Fblog.talosintelligence.com\u002Fartoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365\u002F",[2960],{"data":2961,"marks":2962,"value":2963,"nodeType":874},{},[],"ARToken",{"data":2965,"marks":2966,"value":2967,"nodeType":874},{},[],", DEBULL, Forg365, and many more.",{"data":2969,"content":2973,"nodeType":1215},{"target":2970},{"sys":2971},{"id":2972,"type":1220,"linkType":1221},"7G6ytXRQPWatOyYarqgMK2",[],{"data":2975,"content":2976,"nodeType":870},{},[2977],{"data":2978,"marks":2979,"value":2980,"nodeType":874},{},[],"The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.",{"data":2982,"content":2983,"nodeType":870},{},[2984,2988,2996],{"data":2985,"marks":2986,"value":2987,"nodeType":874},{},[],"Established AiTM vendors like Tycoon 2FA have ",{"data":2989,"content":2991,"nodeType":966},{"uri":2990},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing\u002F",[2992],{"data":2993,"marks":2994,"value":2995,"nodeType":874},{},[],"added device code phishing",{"data":2997,"marks":2998,"value":2999,"nodeType":874},{},[]," alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.",{"data":3001,"content":3005,"nodeType":1215},{"target":3002},{"sys":3003},{"id":3004,"type":1220,"linkType":1221},"3urXbEwK0OSjXQ7lOMDEoc",[],{"data":3007,"content":3008,"nodeType":870},{},[3009],{"data":3010,"marks":3011,"value":3012,"nodeType":874},{},[],"When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.",{"data":3014,"content":3018,"nodeType":1215},{"target":3015},{"sys":3016},{"id":3017,"type":1220,"linkType":1221},"4ipTS2U4HE1VLSLmA6DJgB",[],{"data":3020,"content":3021,"nodeType":870},{},[3022],{"data":3023,"marks":3024,"value":3025,"nodeType":874},{},[],"PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.",{"data":3027,"content":3031,"nodeType":1215},{"target":3028},{"sys":3029},{"id":3030,"type":1220,"linkType":1221},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":3033,"content":3034,"nodeType":870},{},[3035],{"data":3036,"marks":3037,"value":3038,"nodeType":874},{},[],"And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.",{"data":3040,"content":3044,"nodeType":1215},{"target":3041},{"sys":3042},{"id":3043,"type":1220,"linkType":1221},"3SPsKzwBNxl4d9QRukBtwt",[],{"data":3046,"content":3047,"nodeType":944},{},[3048],{"data":3049,"marks":3050,"value":3052,"nodeType":874},{},[3051],{"type":882},"PhaaS platform evolution and evasion",{"data":3054,"content":3055,"nodeType":870},{},[3056,3060,3068,3072,3080,3084,3092],{"data":3057,"marks":3058,"value":3059,"nodeType":874},{},[],"The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include ",{"data":3061,"content":3063,"nodeType":966},{"uri":3062},"https:\u002F\u002Fwww.cloudsek.com\u002Fblog\u002Fbluekit-phishing-as-a-service-phaas",[3064],{"data":3065,"marks":3066,"value":3067,"nodeType":874},{},[],"Bluekit",{"data":3069,"marks":3070,"value":3071,"nodeType":874},{},[],", ",{"data":3073,"content":3075,"nodeType":966},{"uri":3074},"https:\u002F\u002Fabnormal.ai\u002Fblog\u002Fblacksite-aitm-phishing-kit-cloaked-gg",[3076],{"data":3077,"marks":3078,"value":3079,"nodeType":874},{},[],"Blacksite and Cloaked.gg",{"data":3081,"marks":3082,"value":3083,"nodeType":874},{},[]," — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and ",{"data":3085,"content":3087,"nodeType":966},{"uri":3086},"https:\u002F\u002Fthreatactix.com\u002F2026\u002F07\u002F02\u002Fa-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations\u002F",[3088],{"data":3089,"marks":3090,"value":3091,"nodeType":874},{},[],"WackoGinx",{"data":3093,"marks":3094,"value":3095,"nodeType":874},{},[],", a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.",{"data":3097,"content":3098,"nodeType":870},{},[3099,3103,3111,3115,3123],{"data":3100,"marks":3101,"value":3102,"nodeType":874},{},[],"Sneaky 2FA changes have also been documented, with what ",{"data":3104,"content":3106,"nodeType":966},{"uri":3105},"https:\u002F\u002Fzerobec.com\u002Fblog\u002Fsneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay",[3107],{"data":3108,"marks":3109,"value":3110,"nodeType":874},{},[],"ZeroBEC calls \"route polymorphism\"",{"data":3112,"marks":3113,"value":3114,"nodeType":874},{},[]," (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting ",{"data":3116,"content":3118,"nodeType":966},{"uri":3117},"https:\u002F\u002Fblog.barracuda.com\u002F2026\u002F06\u002F29\u002Femail-threat-radar-june-2026",[3119],{"data":3120,"marks":3121,"value":3122,"nodeType":874},{},[],"split-click buttons and blob URLs",{"data":3124,"marks":3125,"value":3126,"nodeType":874},{},[]," designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page). ",{"data":3128,"content":3129,"nodeType":870},{},[3130,3134,3142],{"data":3131,"marks":3132,"value":3133,"nodeType":874},{},[],"The speed of technique adoption across these platforms is itself accelerating. ",{"data":3135,"content":3137,"nodeType":966},{"uri":3136},"https:\u002F\u002Fsublime.security\u002Fblog\u002Fflowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation\u002F",[3138],{"data":3139,"marks":3140,"value":3141,"nodeType":874},{},[],"FlowerStorm adopted",{"data":3143,"marks":3144,"value":3145,"nodeType":874},{},[]," KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.",{"data":3147,"content":3148,"nodeType":870},{},[3149,3153,3161,3165,3173],{"data":3150,"marks":3151,"value":3152,"nodeType":874},{},[],"At the same time, target surfaces are expanding: ",{"data":3154,"content":3156,"nodeType":966},{"uri":3155},"https:\u002F\u002Fsecuritylabs.datadoghq.com\u002Farticles\u002Fbehind-the-console-aws-aitm-phishing-kit-and-beyond\u002F",[3157],{"data":3158,"marks":3159,"value":3160,"nodeType":874},{},[],"Datadog documented",{"data":3162,"marks":3163,"value":3164,"nodeType":874},{},[]," an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of ",{"data":3166,"content":3168,"nodeType":966},{"uri":3167},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks",[3169],{"data":3170,"marks":3171,"value":3172,"nodeType":874},{},[],"MFA downgrade",{"data":3174,"marks":3175,"value":3176,"nodeType":874},{},[]," in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.",{"data":3178,"content":3179,"nodeType":944},{},[3180],{"data":3181,"marks":3182,"value":3184,"nodeType":874},{},[3183],{"type":882},"ClickFix as a service",{"data":3186,"content":3187,"nodeType":870},{},[3188,3192,3200,3204,3212],{"data":3189,"marks":3190,"value":3191,"nodeType":874},{},[],"ClickFix has also continued to industrialize. ",{"data":3193,"content":3195,"nodeType":966},{"uri":3194},"https:\u002F\u002Fblog.sekoia.io\u002Funveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework\u002F",[3196],{"data":3197,"marks":3198,"value":3199,"nodeType":874},{},[],"Sekoia documented",{"data":3201,"marks":3202,"value":3203,"nodeType":874},{},[]," the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers ",{"data":3205,"content":3207,"nodeType":966},{"uri":3206},"https:\u002F\u002Fkqlquery.com\u002Fposts\u002Fclickfix-gift-that-keeps-on-giving\u002F",[3208],{"data":3209,"marks":3210,"value":3211,"nodeType":874},{},[],"mapped approximately 3,000 live ClickFix payloads",{"data":3213,"marks":3214,"value":3215,"nodeType":874},{},[]," being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.",{"data":3217,"content":3218,"nodeType":870},{},[3219,3223,3231,3235,3243],{"data":3220,"marks":3221,"value":3222,"nodeType":874},{},[],"The technique has also expanded cross-platform, with Unit 42 documenting ",{"data":3224,"content":3226,"nodeType":966},{"uri":3225},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer\u002F",[3227],{"data":3228,"marks":3229,"value":3230,"nodeType":874},{},[],"macOS ClickFix variants",{"data":3232,"marks":3233,"value":3234,"nodeType":874},{},[]," that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over ",{"data":3236,"content":3238,"nodeType":966},{"uri":3237},"https:\u002F\u002Fblog.xlab.qianxin.com\u002Fghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks\u002F",[3239],{"data":3240,"marks":3241,"value":3242,"nodeType":874},{},[],"700 Ghost CMS sites were compromised",{"data":3244,"marks":3245,"value":3246,"nodeType":874},{},[]," to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.",{"data":3248,"content":3249,"nodeType":870},{},[3250,3254,3262,3266,3274],{"data":3251,"marks":3252,"value":3253,"nodeType":874},{},[],"Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: ",{"data":3255,"content":3257,"nodeType":966},{"uri":3256},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fbluenoroff-zoom-phishing-kit-profiles.html",[3258],{"data":3259,"marks":3260,"value":3261,"nodeType":874},{},[],"BlueNoroff",{"data":3263,"marks":3264,"value":3265,"nodeType":874},{},[]," targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and ",{"data":3267,"content":3269,"nodeType":966},{"uri":3268},"https:\u002F\u002Fsocradar.io\u002Fblog\u002Fdprk-clickfake-pylangghost-golangghost-rats\u002F",[3270],{"data":3271,"marks":3272,"value":3273,"nodeType":874},{},[],"Famous Chollima",{"data":3275,"marks":3276,"value":3277,"nodeType":874},{},[]," embedding ClickFix in multi-stage fake job interviews.",{"data":3279,"content":3280,"nodeType":944},{},[3281],{"data":3282,"marks":3283,"value":3285,"nodeType":874},{},[3284],{"type":882},"Vishing as a payload delivery mechanism",{"data":3287,"content":3288,"nodeType":870},{},[3289],{"data":3290,"marks":3291,"value":3292,"nodeType":874},{},[],"Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.",{"data":3294,"content":3295,"nodeType":870},{},[3296,3300,3308],{"data":3297,"marks":3298,"value":3299,"nodeType":874},{},[],"When Push researchers ",{"data":3301,"content":3303,"nodeType":966},{"uri":3302},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel\u002F",[3304],{"data":3305,"marks":3306,"value":3307,"nodeType":874},{},[],"infiltrated the phishing panels",{"data":3309,"marks":3310,"value":3311,"nodeType":874},{},[]," linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.",{"data":3313,"content":3314,"nodeType":870},{},[3315,3319,3327,3331,3339,3343,3351,3355,3363],{"data":3316,"marks":3317,"value":3318,"nodeType":874},{},[],"The financial scale is now quantifiable: ",{"data":3320,"content":3322,"nodeType":966},{"uri":3321},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fsilent-ransom-us-law-firms-extortion-attacks",[3323],{"data":3324,"marks":3325,"value":3326,"nodeType":874},{},[],"Luna Moth",{"data":3328,"marks":3329,"value":3330,"nodeType":874},{},[]," (Silent Ransom Group), a ",{"data":3332,"content":3334,"nodeType":966},{"uri":3333},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fadversaries\u002Fchatty-spider\u002F",[3335],{"data":3336,"marks":3337,"value":3338,"nodeType":874},{},[],"Russia-linked Conti spinoff",{"data":3340,"marks":3341,"value":3342,"nodeType":874},{},[]," operating independently of the Com, has extracted ",{"data":3344,"content":3346,"nodeType":966},{"uri":3345},"https:\u002F\u002Fwww.theinsurer.com\u002Fti\u002Fnews\u002Fexclusive-weil-gotshal-paid-double-digit-millions-in-suppression-payment-to-luna-2026-05-27\u002F",[3347],{"data":3348,"marks":3349,"value":3350,"nodeType":874},{},[],"up to $48 million",{"data":3352,"marks":3353,"value":3354,"nodeType":874},{},[]," from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the ",{"data":3356,"content":3358,"nodeType":966},{"uri":3357},"https:\u002F\u002Fwww.ic3.gov\u002FCSA\u002F2026\u002F260526.pdf",[3359],{"data":3360,"marks":3361,"value":3362,"nodeType":874},{},[],"FBI issuing a dedicated flash alert",{"data":3364,"marks":3365,"value":1581,"nodeType":874},{},[],{"data":3367,"content":3368,"nodeType":870},{},[3369,3373,3381,3385,3393],{"data":3370,"marks":3371,"value":3372,"nodeType":874},{},[],"The infrastructure behind these campaigns is industrializing independently. ",{"data":3374,"content":3376,"nodeType":966},{"uri":3375},"https:\u002F\u002Fwww.okta.com\u002Fblog\u002Fthreat-intelligence\u002Fbehind-the-scenes-of-a-vishing-operation\u002F",[3377],{"data":3378,"marks":3379,"value":3380,"nodeType":874},{},[],"Okta obtained access to Work Panel",{"data":3382,"marks":3383,"value":3384,"nodeType":874},{},[],", a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately ",{"data":3386,"content":3388,"nodeType":966},{"uri":3387},"https:\u002F\u002Fwww.zscaler.com\u002Fblogs\u002Fsecurity-research\u002Fhelpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor",[3389],{"data":3390,"marks":3391,"value":3392,"nodeType":874},{},[],"documented a dedicated Teams-vishing initial access broker",{"data":3394,"marks":3395,"value":3396,"nodeType":874},{},[]," operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.",{"data":3398,"content":3399,"nodeType":944},{},[3400],{"data":3401,"marks":3402,"value":3404,"nodeType":874},{},[3403],{"type":882},"OAuth supply chain attacks",{"data":3406,"content":3407,"nodeType":870},{},[3408,3412,3419],{"data":3409,"marks":3410,"value":3411,"nodeType":874},{},[],"The OAuth supply chain dimension has also continued to produce confirmed victims. The ",{"data":3413,"content":3414,"nodeType":966},{"uri":2749},[3415],{"data":3416,"marks":3417,"value":3418,"nodeType":874},{},[],"Salesloft\u002FDrift supply chain attack",{"data":3420,"marks":3421,"value":3422,"nodeType":874},{},[]," in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.",{"data":3424,"content":3425,"nodeType":870},{},[3426,3430,3438,3442,3450,3454,3462],{"data":3427,"marks":3428,"value":3429,"nodeType":874},{},[],"In 2026, the ",{"data":3431,"content":3433,"nodeType":966},{"uri":3432},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvimeo-data-breach-exposes-personal-information-of-119-000-people\u002F",[3434],{"data":3435,"marks":3436,"value":3437,"nodeType":874},{},[],"Anodot compromise",{"data":3439,"marks":3440,"value":3441,"nodeType":874},{},[]," cascaded through to Vimeo, Rockstar Games, and Zara. The ",{"data":3443,"content":3445,"nodeType":966},{"uri":3444},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach\u002F",[3446],{"data":3447,"marks":3448,"value":3449,"nodeType":874},{},[],"Context.ai → Vercel",{"data":3451,"marks":3452,"value":3453,"nodeType":874},{},[]," breach followed the same structural pattern. And the ",{"data":3455,"content":3457,"nodeType":966},{"uri":3456},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fklue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack\u002F",[3458],{"data":3459,"marks":3460,"value":3461,"nodeType":874},{},[],"Klue\u002FIcarus breach",{"data":3463,"marks":3464,"value":3465,"nodeType":874},{},[]," in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.",{"data":3467,"content":3468,"nodeType":896},{},[],{"data":3470,"content":3471,"nodeType":900},{},[3472],{"data":3473,"marks":3474,"value":3476,"nodeType":874},{},[3475],{"type":882},"AI is a force multiplier for attackers",{"data":3478,"content":3479,"nodeType":870},{},[3480],{"data":3481,"marks":3482,"value":3483,"nodeType":874},{},[],"Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.",{"data":3485,"content":3486,"nodeType":870},{},[3487],{"data":3488,"marks":3489,"value":3490,"nodeType":874},{},[],"The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits. ",{"data":3492,"content":3493,"nodeType":870},{},[3494,3498,3506],{"data":3495,"marks":3496,"value":3497,"nodeType":874},{},[],"You can see more examples of these kits under the hood in our blog post ",{"data":3499,"content":3501,"nodeType":966},{"uri":3500},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel",[3502],{"data":3503,"marks":3504,"value":3505,"nodeType":874},{},[],"infiltrating a criminal phishing panel. ",{"data":3507,"marks":3508,"value":21,"nodeType":874},{},[],{"data":3510,"content":3514,"nodeType":1215},{"target":3511},{"sys":3512},{"id":3513,"type":1220,"linkType":1221},"01mOiserRBXraawXwQyJNm",[],{"data":3516,"content":3517,"nodeType":870},{},[3518],{"data":3519,"marks":3520,"value":3521,"nodeType":874},{},[],"Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability. ",{"data":3523,"content":3524,"nodeType":1763},{},[3525,3547,3568,3590,3612],{"data":3526,"content":3527,"nodeType":1767},{},[3528],{"data":3529,"content":3530,"nodeType":870},{},[3531,3535,3543],{"data":3532,"marks":3533,"value":3534,"nodeType":874},{},[],"The first major device code phishing kit identified in the wild, EvilTokens, ",{"data":3536,"content":3538,"nodeType":966},{"uri":3537},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Frailway-paas-m365-token-replay-campaign",[3539],{"data":3540,"marks":3541,"value":3542,"nodeType":874},{},[],"heavily used Railway",{"data":3544,"marks":3545,"value":3546,"nodeType":874},{},[],", a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes. ",{"data":3548,"content":3549,"nodeType":1767},{},[3550],{"data":3551,"content":3552,"nodeType":870},{},[3553,3557,3564],{"data":3554,"marks":3555,"value":3556,"nodeType":874},{},[],"Kali365's E2 edition includes an AI-powered BEC module that ",{"data":3558,"content":3559,"nodeType":966},{"uri":2946},[3560],{"data":3561,"marks":3562,"value":3563,"nodeType":874},{},[],"uses Claude Sonnet",{"data":3565,"marks":3566,"value":3567,"nodeType":874},{},[]," to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.",{"data":3569,"content":3570,"nodeType":1767},{},[3571],{"data":3572,"content":3573,"nodeType":870},{},[3574,3577,3586],{"data":3575,"marks":3576,"value":21,"nodeType":874},{},[],{"data":3578,"content":3580,"nodeType":966},{"uri":3579},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fexposed-server-reveals-ai-assisted.html",[3581],{"data":3582,"marks":3583,"value":3585,"nodeType":874},{},[3584],{"type":974},"Rapid7's analysis of an exposed server",{"data":3587,"marks":3588,"value":3589,"nodeType":874},{},[]," containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.",{"data":3591,"content":3592,"nodeType":1767},{},[3593],{"data":3594,"content":3595,"nodeType":870},{},[3596,3600,3608],{"data":3597,"marks":3598,"value":3599,"nodeType":874},{},[],"Three independent operators were ",{"data":3601,"content":3603,"nodeType":966},{"uri":3602},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fmisconfigured-server-reveals-three.html",[3604],{"data":3605,"marks":3606,"value":3607,"nodeType":874},{},[],"found running kits from public GitHub forks",{"data":3609,"marks":3610,"value":3611,"nodeType":874},{},[]," with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain. ",{"data":3613,"content":3614,"nodeType":1767},{},[3615],{"data":3616,"content":3617,"nodeType":870},{},[3618,3622,3630],{"data":3619,"marks":3620,"value":3621,"nodeType":874},{},[],"The tooling itself is starting to embed AI as a product feature — ",{"data":3623,"content":3625,"nodeType":966},{"uri":3624},"https:\u002F\u002Fwww.varonis.com\u002Fblog\u002Fdolphin-x-stealer",[3626],{"data":3627,"marks":3628,"value":3629,"nodeType":874},{},[],"Dolphin X",{"data":3631,"marks":3632,"value":3633,"nodeType":874},{},[],", a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.",{"data":3635,"content":3636,"nodeType":870},{},[3637,3641,3649,3653,3660,3664,3672],{"data":3638,"marks":3639,"value":3640,"nodeType":874},{},[],"AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a ",{"data":3642,"content":3644,"nodeType":966},{"uri":3643},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Ffakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",[3645],{"data":3646,"marks":3647,"value":3648,"nodeType":874},{},[],"malicious Claude.ai Artifact impersonating a download portal",{"data":3650,"marks":3651,"value":3652,"nodeType":874},{},[]," drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the ",{"data":3654,"content":3655,"nodeType":966},{"uri":1433},[3656],{"data":3657,"marks":3658,"value":3659,"nodeType":874},{},[],"LLMShare attack pattern",{"data":3661,"marks":3662,"value":3663,"nodeType":874},{},[]," we documented in May. A second campaign, ",{"data":3665,"content":3667,"nodeType":966},{"uri":3666},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fmacsync-stealer-rat-reverse-engineering",[3668],{"data":3669,"marks":3670,"value":3671,"nodeType":874},{},[],"MacSync",{"data":3673,"marks":3674,"value":3675,"nodeType":874},{},[],", used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.",{"data":3677,"content":3678,"nodeType":944},{},[3679],{"data":3680,"marks":3681,"value":3683,"nodeType":874},{},[3682],{"type":882},"But the core techniques aren't changing",{"data":3685,"content":3686,"nodeType":870},{},[3687,3691,3699],{"data":3688,"marks":3689,"value":3690,"nodeType":874},{},[],"AI compresses the bottom layers of the ",{"data":3692,"content":3694,"nodeType":966},{"uri":3693},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-pyramid-of-pain-in-the-ai-era\u002F",[3695],{"data":3696,"marks":3697,"value":3698,"nodeType":874},{},[],"Pyramid of Pain",{"data":3700,"marks":3701,"value":3702,"nodeType":874},{},[]," (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.",{"data":3704,"content":3705,"nodeType":870},{},[3706],{"data":3707,"marks":3708,"value":3709,"nodeType":874},{},[],"A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.",{"data":3711,"content":3712,"nodeType":896},{},[],{"data":3714,"content":3715,"nodeType":900},{},[3716],{"data":3717,"marks":3718,"value":3720,"nodeType":874},{},[3719],{"type":882},"What this means for defenders",{"data":3722,"content":3723,"nodeType":870},{},[3724],{"data":3725,"marks":3726,"value":3727,"nodeType":874},{},[],"Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.",{"data":3729,"content":3730,"nodeType":1763},{},[3731,3741,3751,3761],{"data":3732,"content":3733,"nodeType":1767},{},[3734],{"data":3735,"content":3736,"nodeType":870},{},[3737],{"data":3738,"marks":3739,"value":3740,"nodeType":874},{},[],"For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.",{"data":3742,"content":3743,"nodeType":1767},{},[3744],{"data":3745,"content":3746,"nodeType":870},{},[3747],{"data":3748,"marks":3749,"value":3750,"nodeType":874},{},[],"For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.",{"data":3752,"content":3753,"nodeType":1767},{},[3754],{"data":3755,"content":3756,"nodeType":870},{},[3757],{"data":3758,"marks":3759,"value":3760,"nodeType":874},{},[],"For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.",{"data":3762,"content":3763,"nodeType":1767},{},[3764],{"data":3765,"content":3766,"nodeType":870},{},[3767],{"data":3768,"marks":3769,"value":3770,"nodeType":874},{},[],"For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.",{"data":3772,"content":3773,"nodeType":870},{},[3774],{"data":3775,"marks":3776,"value":3777,"nodeType":874},{},[],"As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.",{"data":3779,"content":3780,"nodeType":896},{},[],{"data":3782,"content":3783,"nodeType":870},{},[3784],{"data":3785,"marks":3786,"value":1084,"nodeType":874},{},[],{"data":3788,"content":3789,"nodeType":870},{},[3790],{"data":3791,"marks":3792,"value":1091,"nodeType":874},{},[],{"data":3794,"content":3795,"nodeType":870},{},[3796,3799,3807],{"data":3797,"marks":3798,"value":21,"nodeType":874},{},[],{"data":3800,"content":3802,"nodeType":966},{"uri":3801},"https:\u002F\u002Fpushsecurity.com\u002Fdemo\u002F",[3803],{"data":3804,"marks":3805,"value":1105,"nodeType":874},{},[3806],{"type":974},{"data":3808,"marks":3809,"value":21,"nodeType":874},{},[],"Browser threat landscape: mid-year update 2026","PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.","2026-08-10T00:00:00.000Z","browser-threat-landscape-mid-year-update-2026",{"items":3815},[3816,3818],{"sys":3817,"name":2007},{"id":2006},{"sys":3819,"name":334},{"id":2010},{"items":3821},[3822],{"fullName":2014,"firstName":2015,"jobTitle":2016,"profilePicture":3823},{"url":2018},"proofpoint-x-push-partnership-announcement","blog\u002Fproofpoint-x-push-partnership-announcement",{"json":3827},{"data":3828,"content":3829,"nodeType":866},{},[3830],{"data":3831,"content":3832,"nodeType":870},{},[3833],{"data":3834,"marks":3835,"value":3836,"nodeType":874},{},[],"Push Security is partnering with Proofpoint, bringing Push’s in-browser threat protection to Proofpoint customers to tackle browser-native threats as phishing moves beyond the inbox.","Push Security is partnering with Proofpoint, bringing Push’s in-browser threat protection to Proofpoint customers.",{"id":3839,"publishedAt":3840},"2W68nOLYgy1TpDqV5yWdRT","2026-09-29T07:17:47.925Z",{"items":3842},[3843],{"sys":3844,"name":3846},{"id":3845},"4EtskIWlj3SOH3UHbFR8uG","Company news",{"items":3848},[3849,3851,3853,3855,3857,3859,3861,3863],{"sys":3850,"name":510,"slug":511,"tier":31},{"id":507},{"sys":3852,"name":289,"slug":290,"tier":31},{"id":286},{"sys":3854,"name":262,"slug":263,"tier":45},{"id":259},{"sys":3856,"name":466,"slug":467,"tier":45},{"id":463},{"sys":3858,"name":378,"slug":379,"tier":45},{"id":375},{"sys":3860,"name":599,"slug":600,"tier":45},{"id":596},{"sys":3862,"name":271,"slug":272,"tier":31},{"id":268},{"sys":3864,"name":334,"slug":335,"tier":31},{"id":331},"JHpj6BtfH61p_Q8YYHAiMGE95UGIMSW6QZBSioI_ruY",{"id":3867,"title":3810,"authorsCollection":3868,"content":3874,"extension":219,"faqItemsCollection":5011,"faqTitle":60,"featured":6,"hashTags":60,"meta":5013,"metaTitle":5014,"ogImage":60,"postType":5015,"publishedDate":3812,"relatedBlogPostsCollection":5016,"slug":3813,"stem":6980,"subtitle":60,"summary":6981,"synopsis":3811,"sys":6991,"tagsCollection":6993,"topicsCollection":6999,"__hash__":7051},"blog\u002Fblog\u002Fbrowser-threat-landscape-mid-year-update-2026.json",{"items":3869},[3870],{"fullName":2014,"firstName":2015,"jobTitle":2016,"socialLinks":3871,"profilePicture":3873},[3872],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fdaniel-g-\u002F",{"url":2018},{"json":3875,"links":4922},{"data":3876,"content":3877,"nodeType":866},{},[3878,3884,3887,3894,3918,3925,3930,3954,4041,4074,4081,4123,4147,4152,4155,4162,4168,4175,4190,4232,4237,4243,4258,4263,4269,4274,4280,4285,4291,4296,4303,4336,4360,4375,4399,4406,4430,4454,4478,4485,4491,4506,4548,4572,4579,4594,4627,4630,4637,4643,4649,4664,4669,4675,4769,4802,4809,4824,4830,4833,4840,4846,4885,4891,4894,4900,4906],{"data":3879,"content":3880,"nodeType":870},{},[3881],{"data":3882,"marks":3883,"value":2527,"nodeType":874},{},[],{"data":3885,"content":3886,"nodeType":896},{},[],{"data":3888,"content":3889,"nodeType":900},{},[3890],{"data":3891,"marks":3892,"value":2538,"nodeType":874},{},[3893],{"type":882},{"data":3895,"content":3896,"nodeType":870},{},[3897,3900,3906,3909,3915],{"data":3898,"marks":3899,"value":2545,"nodeType":874},{},[],{"data":3901,"content":3902,"nodeType":966},{"uri":2548},[3903],{"data":3904,"marks":3905,"value":2553,"nodeType":874},{},[],{"data":3907,"marks":3908,"value":2557,"nodeType":874},{},[],{"data":3910,"content":3911,"nodeType":966},{"uri":1204},[3912],{"data":3913,"marks":3914,"value":2564,"nodeType":874},{},[],{"data":3916,"marks":3917,"value":2568,"nodeType":874},{},[],{"data":3919,"content":3920,"nodeType":870},{},[3921],{"data":3922,"marks":3923,"value":2576,"nodeType":874},{},[3924],{"type":882},{"data":3926,"content":3929,"nodeType":1215},{"target":3927},{"sys":3928},{"id":2581,"type":1220,"linkType":1221},[],{"data":3931,"content":3932,"nodeType":870},{},[3933,3936,3942,3945,3951],{"data":3934,"marks":3935,"value":2589,"nodeType":874},{},[],{"data":3937,"content":3938,"nodeType":966},{"uri":2592},[3939],{"data":3940,"marks":3941,"value":2597,"nodeType":874},{},[],{"data":3943,"marks":3944,"value":2601,"nodeType":874},{},[],{"data":3946,"content":3947,"nodeType":966},{"uri":2604},[3948],{"data":3949,"marks":3950,"value":2609,"nodeType":874},{},[],{"data":3952,"marks":3953,"value":2613,"nodeType":874},{},[],{"data":3955,"content":3956,"nodeType":870},{},[3957,3960,3966,3969,3975,3978,3984,3987,3993,3996,4002,4005,4011,4014,4020,4023,4029,4032,4038],{"data":3958,"marks":3959,"value":2620,"nodeType":874},{},[],{"data":3961,"content":3962,"nodeType":966},{"uri":2623},[3963],{"data":3964,"marks":3965,"value":2628,"nodeType":874},{},[],{"data":3967,"marks":3968,"value":2632,"nodeType":874},{},[],{"data":3970,"content":3971,"nodeType":966},{"uri":2635},[3972],{"data":3973,"marks":3974,"value":2640,"nodeType":874},{},[],{"data":3976,"marks":3977,"value":2644,"nodeType":874},{},[],{"data":3979,"content":3980,"nodeType":966},{"uri":2647},[3981],{"data":3982,"marks":3983,"value":2652,"nodeType":874},{},[],{"data":3985,"marks":3986,"value":2656,"nodeType":874},{},[],{"data":3988,"content":3989,"nodeType":966},{"uri":2659},[3990],{"data":3991,"marks":3992,"value":2664,"nodeType":874},{},[],{"data":3994,"marks":3995,"value":2668,"nodeType":874},{},[],{"data":3997,"content":3998,"nodeType":966},{"uri":2671},[3999],{"data":4000,"marks":4001,"value":2676,"nodeType":874},{},[],{"data":4003,"marks":4004,"value":2680,"nodeType":874},{},[],{"data":4006,"content":4007,"nodeType":966},{"uri":2683},[4008],{"data":4009,"marks":4010,"value":2688,"nodeType":874},{},[],{"data":4012,"marks":4013,"value":2692,"nodeType":874},{},[],{"data":4015,"content":4016,"nodeType":966},{"uri":2695},[4017],{"data":4018,"marks":4019,"value":2700,"nodeType":874},{},[],{"data":4021,"marks":4022,"value":2704,"nodeType":874},{},[],{"data":4024,"content":4025,"nodeType":966},{"uri":2707},[4026],{"data":4027,"marks":4028,"value":2712,"nodeType":874},{},[],{"data":4030,"marks":4031,"value":2716,"nodeType":874},{},[],{"data":4033,"content":4034,"nodeType":966},{"uri":2719},[4035],{"data":4036,"marks":4037,"value":2724,"nodeType":874},{},[],{"data":4039,"marks":4040,"value":2728,"nodeType":874},{},[],{"data":4042,"content":4043,"nodeType":870},{},[4044,4047,4053,4056,4062,4065,4071],{"data":4045,"marks":4046,"value":2735,"nodeType":874},{},[],{"data":4048,"content":4049,"nodeType":966},{"uri":1529},[4050],{"data":4051,"marks":4052,"value":2742,"nodeType":874},{},[],{"data":4054,"marks":4055,"value":2746,"nodeType":874},{},[],{"data":4057,"content":4058,"nodeType":966},{"uri":2749},[4059],{"data":4060,"marks":4061,"value":2754,"nodeType":874},{},[],{"data":4063,"marks":4064,"value":2758,"nodeType":874},{},[],{"data":4066,"content":4067,"nodeType":966},{"uri":2761},[4068],{"data":4069,"marks":4070,"value":2766,"nodeType":874},{},[],{"data":4072,"marks":4073,"value":1581,"nodeType":874},{},[],{"data":4075,"content":4076,"nodeType":944},{},[4077],{"data":4078,"marks":4079,"value":2777,"nodeType":874},{},[4080],{"type":882},{"data":4082,"content":4083,"nodeType":870},{},[4084,4087,4093,4096,4102,4105,4111,4114,4120],{"data":4085,"marks":4086,"value":2784,"nodeType":874},{},[],{"data":4088,"content":4089,"nodeType":966},{"uri":2787},[4090],{"data":4091,"marks":4092,"value":2792,"nodeType":874},{},[],{"data":4094,"marks":4095,"value":2796,"nodeType":874},{},[],{"data":4097,"content":4098,"nodeType":966},{"uri":2799},[4099],{"data":4100,"marks":4101,"value":2804,"nodeType":874},{},[],{"data":4103,"marks":4104,"value":2808,"nodeType":874},{},[],{"data":4106,"content":4107,"nodeType":966},{"uri":2811},[4108],{"data":4109,"marks":4110,"value":2816,"nodeType":874},{},[],{"data":4112,"marks":4113,"value":2820,"nodeType":874},{},[],{"data":4115,"content":4116,"nodeType":966},{"uri":2823},[4117],{"data":4118,"marks":4119,"value":2828,"nodeType":874},{},[],{"data":4121,"marks":4122,"value":2832,"nodeType":874},{},[],{"data":4124,"content":4125,"nodeType":870},{},[4126,4129,4135,4138,4144],{"data":4127,"marks":4128,"value":2839,"nodeType":874},{},[],{"data":4130,"content":4131,"nodeType":966},{"uri":2842},[4132],{"data":4133,"marks":4134,"value":2847,"nodeType":874},{},[],{"data":4136,"marks":4137,"value":2851,"nodeType":874},{},[],{"data":4139,"content":4140,"nodeType":966},{"uri":2854},[4141],{"data":4142,"marks":4143,"value":2859,"nodeType":874},{},[],{"data":4145,"marks":4146,"value":2863,"nodeType":874},{},[],{"data":4148,"content":4151,"nodeType":1215},{"target":4149},{"sys":4150},{"id":2868,"type":1220,"linkType":1221},[],{"data":4153,"content":4154,"nodeType":896},{},[],{"data":4156,"content":4157,"nodeType":900},{},[4158],{"data":4159,"marks":4160,"value":2880,"nodeType":874},{},[4161],{"type":882},{"data":4163,"content":4164,"nodeType":870},{},[4165],{"data":4166,"marks":4167,"value":2887,"nodeType":874},{},[],{"data":4169,"content":4170,"nodeType":944},{},[4171],{"data":4172,"marks":4173,"value":2895,"nodeType":874},{},[4174],{"type":882},{"data":4176,"content":4177,"nodeType":870},{},[4178,4181,4187],{"data":4179,"marks":4180,"value":2902,"nodeType":874},{},[],{"data":4182,"content":4183,"nodeType":966},{"uri":1529},[4184],{"data":4185,"marks":4186,"value":2742,"nodeType":874},{},[],{"data":4188,"marks":4189,"value":2912,"nodeType":874},{},[],{"data":4191,"content":4192,"nodeType":870},{},[4193,4196,4202,4205,4211,4214,4220,4223,4229],{"data":4194,"marks":4195,"value":2919,"nodeType":874},{},[],{"data":4197,"content":4198,"nodeType":966},{"uri":2922},[4199],{"data":4200,"marks":4201,"value":2927,"nodeType":874},{},[],{"data":4203,"marks":4204,"value":2931,"nodeType":874},{},[],{"data":4206,"content":4207,"nodeType":966},{"uri":2934},[4208],{"data":4209,"marks":4210,"value":2939,"nodeType":874},{},[],{"data":4212,"marks":4213,"value":2943,"nodeType":874},{},[],{"data":4215,"content":4216,"nodeType":966},{"uri":2946},[4217],{"data":4218,"marks":4219,"value":2951,"nodeType":874},{},[],{"data":4221,"marks":4222,"value":2955,"nodeType":874},{},[],{"data":4224,"content":4225,"nodeType":966},{"uri":2958},[4226],{"data":4227,"marks":4228,"value":2963,"nodeType":874},{},[],{"data":4230,"marks":4231,"value":2967,"nodeType":874},{},[],{"data":4233,"content":4236,"nodeType":1215},{"target":4234},{"sys":4235},{"id":2972,"type":1220,"linkType":1221},[],{"data":4238,"content":4239,"nodeType":870},{},[4240],{"data":4241,"marks":4242,"value":2980,"nodeType":874},{},[],{"data":4244,"content":4245,"nodeType":870},{},[4246,4249,4255],{"data":4247,"marks":4248,"value":2987,"nodeType":874},{},[],{"data":4250,"content":4251,"nodeType":966},{"uri":2990},[4252],{"data":4253,"marks":4254,"value":2995,"nodeType":874},{},[],{"data":4256,"marks":4257,"value":2999,"nodeType":874},{},[],{"data":4259,"content":4262,"nodeType":1215},{"target":4260},{"sys":4261},{"id":3004,"type":1220,"linkType":1221},[],{"data":4264,"content":4265,"nodeType":870},{},[4266],{"data":4267,"marks":4268,"value":3012,"nodeType":874},{},[],{"data":4270,"content":4273,"nodeType":1215},{"target":4271},{"sys":4272},{"id":3017,"type":1220,"linkType":1221},[],{"data":4275,"content":4276,"nodeType":870},{},[4277],{"data":4278,"marks":4279,"value":3025,"nodeType":874},{},[],{"data":4281,"content":4284,"nodeType":1215},{"target":4282},{"sys":4283},{"id":3030,"type":1220,"linkType":1221},[],{"data":4286,"content":4287,"nodeType":870},{},[4288],{"data":4289,"marks":4290,"value":3038,"nodeType":874},{},[],{"data":4292,"content":4295,"nodeType":1215},{"target":4293},{"sys":4294},{"id":3043,"type":1220,"linkType":1221},[],{"data":4297,"content":4298,"nodeType":944},{},[4299],{"data":4300,"marks":4301,"value":3052,"nodeType":874},{},[4302],{"type":882},{"data":4304,"content":4305,"nodeType":870},{},[4306,4309,4315,4318,4324,4327,4333],{"data":4307,"marks":4308,"value":3059,"nodeType":874},{},[],{"data":4310,"content":4311,"nodeType":966},{"uri":3062},[4312],{"data":4313,"marks":4314,"value":3067,"nodeType":874},{},[],{"data":4316,"marks":4317,"value":3071,"nodeType":874},{},[],{"data":4319,"content":4320,"nodeType":966},{"uri":3074},[4321],{"data":4322,"marks":4323,"value":3079,"nodeType":874},{},[],{"data":4325,"marks":4326,"value":3083,"nodeType":874},{},[],{"data":4328,"content":4329,"nodeType":966},{"uri":3086},[4330],{"data":4331,"marks":4332,"value":3091,"nodeType":874},{},[],{"data":4334,"marks":4335,"value":3095,"nodeType":874},{},[],{"data":4337,"content":4338,"nodeType":870},{},[4339,4342,4348,4351,4357],{"data":4340,"marks":4341,"value":3102,"nodeType":874},{},[],{"data":4343,"content":4344,"nodeType":966},{"uri":3105},[4345],{"data":4346,"marks":4347,"value":3110,"nodeType":874},{},[],{"data":4349,"marks":4350,"value":3114,"nodeType":874},{},[],{"data":4352,"content":4353,"nodeType":966},{"uri":3117},[4354],{"data":4355,"marks":4356,"value":3122,"nodeType":874},{},[],{"data":4358,"marks":4359,"value":3126,"nodeType":874},{},[],{"data":4361,"content":4362,"nodeType":870},{},[4363,4366,4372],{"data":4364,"marks":4365,"value":3133,"nodeType":874},{},[],{"data":4367,"content":4368,"nodeType":966},{"uri":3136},[4369],{"data":4370,"marks":4371,"value":3141,"nodeType":874},{},[],{"data":4373,"marks":4374,"value":3145,"nodeType":874},{},[],{"data":4376,"content":4377,"nodeType":870},{},[4378,4381,4387,4390,4396],{"data":4379,"marks":4380,"value":3152,"nodeType":874},{},[],{"data":4382,"content":4383,"nodeType":966},{"uri":3155},[4384],{"data":4385,"marks":4386,"value":3160,"nodeType":874},{},[],{"data":4388,"marks":4389,"value":3164,"nodeType":874},{},[],{"data":4391,"content":4392,"nodeType":966},{"uri":3167},[4393],{"data":4394,"marks":4395,"value":3172,"nodeType":874},{},[],{"data":4397,"marks":4398,"value":3176,"nodeType":874},{},[],{"data":4400,"content":4401,"nodeType":944},{},[4402],{"data":4403,"marks":4404,"value":3184,"nodeType":874},{},[4405],{"type":882},{"data":4407,"content":4408,"nodeType":870},{},[4409,4412,4418,4421,4427],{"data":4410,"marks":4411,"value":3191,"nodeType":874},{},[],{"data":4413,"content":4414,"nodeType":966},{"uri":3194},[4415],{"data":4416,"marks":4417,"value":3199,"nodeType":874},{},[],{"data":4419,"marks":4420,"value":3203,"nodeType":874},{},[],{"data":4422,"content":4423,"nodeType":966},{"uri":3206},[4424],{"data":4425,"marks":4426,"value":3211,"nodeType":874},{},[],{"data":4428,"marks":4429,"value":3215,"nodeType":874},{},[],{"data":4431,"content":4432,"nodeType":870},{},[4433,4436,4442,4445,4451],{"data":4434,"marks":4435,"value":3222,"nodeType":874},{},[],{"data":4437,"content":4438,"nodeType":966},{"uri":3225},[4439],{"data":4440,"marks":4441,"value":3230,"nodeType":874},{},[],{"data":4443,"marks":4444,"value":3234,"nodeType":874},{},[],{"data":4446,"content":4447,"nodeType":966},{"uri":3237},[4448],{"data":4449,"marks":4450,"value":3242,"nodeType":874},{},[],{"data":4452,"marks":4453,"value":3246,"nodeType":874},{},[],{"data":4455,"content":4456,"nodeType":870},{},[4457,4460,4466,4469,4475],{"data":4458,"marks":4459,"value":3253,"nodeType":874},{},[],{"data":4461,"content":4462,"nodeType":966},{"uri":3256},[4463],{"data":4464,"marks":4465,"value":3261,"nodeType":874},{},[],{"data":4467,"marks":4468,"value":3265,"nodeType":874},{},[],{"data":4470,"content":4471,"nodeType":966},{"uri":3268},[4472],{"data":4473,"marks":4474,"value":3273,"nodeType":874},{},[],{"data":4476,"marks":4477,"value":3277,"nodeType":874},{},[],{"data":4479,"content":4480,"nodeType":944},{},[4481],{"data":4482,"marks":4483,"value":3285,"nodeType":874},{},[4484],{"type":882},{"data":4486,"content":4487,"nodeType":870},{},[4488],{"data":4489,"marks":4490,"value":3292,"nodeType":874},{},[],{"data":4492,"content":4493,"nodeType":870},{},[4494,4497,4503],{"data":4495,"marks":4496,"value":3299,"nodeType":874},{},[],{"data":4498,"content":4499,"nodeType":966},{"uri":3302},[4500],{"data":4501,"marks":4502,"value":3307,"nodeType":874},{},[],{"data":4504,"marks":4505,"value":3311,"nodeType":874},{},[],{"data":4507,"content":4508,"nodeType":870},{},[4509,4512,4518,4521,4527,4530,4536,4539,4545],{"data":4510,"marks":4511,"value":3318,"nodeType":874},{},[],{"data":4513,"content":4514,"nodeType":966},{"uri":3321},[4515],{"data":4516,"marks":4517,"value":3326,"nodeType":874},{},[],{"data":4519,"marks":4520,"value":3330,"nodeType":874},{},[],{"data":4522,"content":4523,"nodeType":966},{"uri":3333},[4524],{"data":4525,"marks":4526,"value":3338,"nodeType":874},{},[],{"data":4528,"marks":4529,"value":3342,"nodeType":874},{},[],{"data":4531,"content":4532,"nodeType":966},{"uri":3345},[4533],{"data":4534,"marks":4535,"value":3350,"nodeType":874},{},[],{"data":4537,"marks":4538,"value":3354,"nodeType":874},{},[],{"data":4540,"content":4541,"nodeType":966},{"uri":3357},[4542],{"data":4543,"marks":4544,"value":3362,"nodeType":874},{},[],{"data":4546,"marks":4547,"value":1581,"nodeType":874},{},[],{"data":4549,"content":4550,"nodeType":870},{},[4551,4554,4560,4563,4569],{"data":4552,"marks":4553,"value":3372,"nodeType":874},{},[],{"data":4555,"content":4556,"nodeType":966},{"uri":3375},[4557],{"data":4558,"marks":4559,"value":3380,"nodeType":874},{},[],{"data":4561,"marks":4562,"value":3384,"nodeType":874},{},[],{"data":4564,"content":4565,"nodeType":966},{"uri":3387},[4566],{"data":4567,"marks":4568,"value":3392,"nodeType":874},{},[],{"data":4570,"marks":4571,"value":3396,"nodeType":874},{},[],{"data":4573,"content":4574,"nodeType":944},{},[4575],{"data":4576,"marks":4577,"value":3404,"nodeType":874},{},[4578],{"type":882},{"data":4580,"content":4581,"nodeType":870},{},[4582,4585,4591],{"data":4583,"marks":4584,"value":3411,"nodeType":874},{},[],{"data":4586,"content":4587,"nodeType":966},{"uri":2749},[4588],{"data":4589,"marks":4590,"value":3418,"nodeType":874},{},[],{"data":4592,"marks":4593,"value":3422,"nodeType":874},{},[],{"data":4595,"content":4596,"nodeType":870},{},[4597,4600,4606,4609,4615,4618,4624],{"data":4598,"marks":4599,"value":3429,"nodeType":874},{},[],{"data":4601,"content":4602,"nodeType":966},{"uri":3432},[4603],{"data":4604,"marks":4605,"value":3437,"nodeType":874},{},[],{"data":4607,"marks":4608,"value":3441,"nodeType":874},{},[],{"data":4610,"content":4611,"nodeType":966},{"uri":3444},[4612],{"data":4613,"marks":4614,"value":3449,"nodeType":874},{},[],{"data":4616,"marks":4617,"value":3453,"nodeType":874},{},[],{"data":4619,"content":4620,"nodeType":966},{"uri":3456},[4621],{"data":4622,"marks":4623,"value":3461,"nodeType":874},{},[],{"data":4625,"marks":4626,"value":3465,"nodeType":874},{},[],{"data":4628,"content":4629,"nodeType":896},{},[],{"data":4631,"content":4632,"nodeType":900},{},[4633],{"data":4634,"marks":4635,"value":3476,"nodeType":874},{},[4636],{"type":882},{"data":4638,"content":4639,"nodeType":870},{},[4640],{"data":4641,"marks":4642,"value":3483,"nodeType":874},{},[],{"data":4644,"content":4645,"nodeType":870},{},[4646],{"data":4647,"marks":4648,"value":3490,"nodeType":874},{},[],{"data":4650,"content":4651,"nodeType":870},{},[4652,4655,4661],{"data":4653,"marks":4654,"value":3497,"nodeType":874},{},[],{"data":4656,"content":4657,"nodeType":966},{"uri":3500},[4658],{"data":4659,"marks":4660,"value":3505,"nodeType":874},{},[],{"data":4662,"marks":4663,"value":21,"nodeType":874},{},[],{"data":4665,"content":4668,"nodeType":1215},{"target":4666},{"sys":4667},{"id":3513,"type":1220,"linkType":1221},[],{"data":4670,"content":4671,"nodeType":870},{},[4672],{"data":4673,"marks":4674,"value":3521,"nodeType":874},{},[],{"data":4676,"content":4677,"nodeType":1763},{},[4678,4696,4714,4733,4751],{"data":4679,"content":4680,"nodeType":1767},{},[4681],{"data":4682,"content":4683,"nodeType":870},{},[4684,4687,4693],{"data":4685,"marks":4686,"value":3534,"nodeType":874},{},[],{"data":4688,"content":4689,"nodeType":966},{"uri":3537},[4690],{"data":4691,"marks":4692,"value":3542,"nodeType":874},{},[],{"data":4694,"marks":4695,"value":3546,"nodeType":874},{},[],{"data":4697,"content":4698,"nodeType":1767},{},[4699],{"data":4700,"content":4701,"nodeType":870},{},[4702,4705,4711],{"data":4703,"marks":4704,"value":3556,"nodeType":874},{},[],{"data":4706,"content":4707,"nodeType":966},{"uri":2946},[4708],{"data":4709,"marks":4710,"value":3563,"nodeType":874},{},[],{"data":4712,"marks":4713,"value":3567,"nodeType":874},{},[],{"data":4715,"content":4716,"nodeType":1767},{},[4717],{"data":4718,"content":4719,"nodeType":870},{},[4720,4723,4730],{"data":4721,"marks":4722,"value":21,"nodeType":874},{},[],{"data":4724,"content":4725,"nodeType":966},{"uri":3579},[4726],{"data":4727,"marks":4728,"value":3585,"nodeType":874},{},[4729],{"type":974},{"data":4731,"marks":4732,"value":3589,"nodeType":874},{},[],{"data":4734,"content":4735,"nodeType":1767},{},[4736],{"data":4737,"content":4738,"nodeType":870},{},[4739,4742,4748],{"data":4740,"marks":4741,"value":3599,"nodeType":874},{},[],{"data":4743,"content":4744,"nodeType":966},{"uri":3602},[4745],{"data":4746,"marks":4747,"value":3607,"nodeType":874},{},[],{"data":4749,"marks":4750,"value":3611,"nodeType":874},{},[],{"data":4752,"content":4753,"nodeType":1767},{},[4754],{"data":4755,"content":4756,"nodeType":870},{},[4757,4760,4766],{"data":4758,"marks":4759,"value":3621,"nodeType":874},{},[],{"data":4761,"content":4762,"nodeType":966},{"uri":3624},[4763],{"data":4764,"marks":4765,"value":3629,"nodeType":874},{},[],{"data":4767,"marks":4768,"value":3633,"nodeType":874},{},[],{"data":4770,"content":4771,"nodeType":870},{},[4772,4775,4781,4784,4790,4793,4799],{"data":4773,"marks":4774,"value":3640,"nodeType":874},{},[],{"data":4776,"content":4777,"nodeType":966},{"uri":3643},[4778],{"data":4779,"marks":4780,"value":3648,"nodeType":874},{},[],{"data":4782,"marks":4783,"value":3652,"nodeType":874},{},[],{"data":4785,"content":4786,"nodeType":966},{"uri":1433},[4787],{"data":4788,"marks":4789,"value":3659,"nodeType":874},{},[],{"data":4791,"marks":4792,"value":3663,"nodeType":874},{},[],{"data":4794,"content":4795,"nodeType":966},{"uri":3666},[4796],{"data":4797,"marks":4798,"value":3671,"nodeType":874},{},[],{"data":4800,"marks":4801,"value":3675,"nodeType":874},{},[],{"data":4803,"content":4804,"nodeType":944},{},[4805],{"data":4806,"marks":4807,"value":3683,"nodeType":874},{},[4808],{"type":882},{"data":4810,"content":4811,"nodeType":870},{},[4812,4815,4821],{"data":4813,"marks":4814,"value":3690,"nodeType":874},{},[],{"data":4816,"content":4817,"nodeType":966},{"uri":3693},[4818],{"data":4819,"marks":4820,"value":3698,"nodeType":874},{},[],{"data":4822,"marks":4823,"value":3702,"nodeType":874},{},[],{"data":4825,"content":4826,"nodeType":870},{},[4827],{"data":4828,"marks":4829,"value":3709,"nodeType":874},{},[],{"data":4831,"content":4832,"nodeType":896},{},[],{"data":4834,"content":4835,"nodeType":900},{},[4836],{"data":4837,"marks":4838,"value":3720,"nodeType":874},{},[4839],{"type":882},{"data":4841,"content":4842,"nodeType":870},{},[4843],{"data":4844,"marks":4845,"value":3727,"nodeType":874},{},[],{"data":4847,"content":4848,"nodeType":1763},{},[4849,4858,4867,4876],{"data":4850,"content":4851,"nodeType":1767},{},[4852],{"data":4853,"content":4854,"nodeType":870},{},[4855],{"data":4856,"marks":4857,"value":3740,"nodeType":874},{},[],{"data":4859,"content":4860,"nodeType":1767},{},[4861],{"data":4862,"content":4863,"nodeType":870},{},[4864],{"data":4865,"marks":4866,"value":3750,"nodeType":874},{},[],{"data":4868,"content":4869,"nodeType":1767},{},[4870],{"data":4871,"content":4872,"nodeType":870},{},[4873],{"data":4874,"marks":4875,"value":3760,"nodeType":874},{},[],{"data":4877,"content":4878,"nodeType":1767},{},[4879],{"data":4880,"content":4881,"nodeType":870},{},[4882],{"data":4883,"marks":4884,"value":3770,"nodeType":874},{},[],{"data":4886,"content":4887,"nodeType":870},{},[4888],{"data":4889,"marks":4890,"value":3777,"nodeType":874},{},[],{"data":4892,"content":4893,"nodeType":896},{},[],{"data":4895,"content":4896,"nodeType":870},{},[4897],{"data":4898,"marks":4899,"value":1084,"nodeType":874},{},[],{"data":4901,"content":4902,"nodeType":870},{},[4903],{"data":4904,"marks":4905,"value":1091,"nodeType":874},{},[],{"data":4907,"content":4908,"nodeType":870},{},[4909,4912,4919],{"data":4910,"marks":4911,"value":21,"nodeType":874},{},[],{"data":4913,"content":4914,"nodeType":966},{"uri":3801},[4915],{"data":4916,"marks":4917,"value":1105,"nodeType":874},{},[4918],{"type":974},{"data":4920,"marks":4921,"value":21,"nodeType":874},{},[],{"entries":4923},{"hyperlink":4924,"inline":4925,"block":4926},[],[],[4927,4935,4957,4962,4988,4994,5000,5004],{"sys":4928,"__typename":4929,"title":4930,"caption":4930,"layoutMode":60,"file":4931},{"id":2581},"Image"," Public breaches and campaigns with a browser and identity-related breach vector in 2026.",{"url":4932,"width":4933,"height":4934},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7DDf4WnfcZa3U9C6Leyu14\u002Ff6b7e43f663a387ed7238e4a47e4e215\u002Fimage2.png",1999,1125,{"sys":4936,"__typename":4937,"content":4938,"name":4956,"title":60},{"id":2868},"InsightTextBlockComponent",{"json":4939},{"nodeType":866,"data":4940,"content":4941},{},[4942,4949],{"nodeType":870,"data":4943,"content":4944},{},[4945],{"nodeType":874,"value":4946,"marks":4947,"data":4948},"\"The Com\" affiliates increasingly set the playbook for other criminal groups, and even nation-state operators. It might not always be super sophisticated, but they've proven the playbook works. And from the APT's perspective, why burn an exploit if you can achieve the same with a phish kit?",[],{},{"nodeType":870,"data":4950,"content":4951},{},[4952],{"nodeType":874,"value":4953,"marks":4954,"data":4955},"\n",[],{},"Browser attacks update IB1",{"sys":4958,"__typename":4929,"title":4959,"caption":4959,"layoutMode":60,"file":4960},{"id":2972},"Detections by device code phishing kit. Kits are multiplying and fragmenting each month, with a long tail of kits not named here.",{"url":4961,"width":4933,"height":4934},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3VgSTD544VehTl3THm4zpa\u002Fdd7e8610c29b283f38a3fa17a0614c90\u002Fimage1.png",{"sys":4963,"__typename":4937,"content":4964,"name":4987,"title":60},{"id":3004},{"json":4965},{"nodeType":866,"data":4966,"content":4967},{},[4968],{"nodeType":870,"data":4969,"content":4970},{},[4971,4975,4983],{"nodeType":874,"value":4972,"marks":4973,"data":4974},"Tycoon is a particularly notable example because following a public takedown of its AiTM infrastructure, some recent reports have ",[],{},{"nodeType":966,"data":4976,"content":4978},{"uri":4977},"https:\u002F\u002Fcybersecuritynews.com\u002Ftop-10-phishing-kits-used-by-hackers\u002F",[4979],{"nodeType":874,"value":4980,"marks":4981,"data":4982},"Tycoon detections dropping",[],{},{"nodeType":874,"value":4984,"marks":4985,"data":4986},", but we're finding that actually Tycoon device code attacks in particular have bounced back in our detections. ",[],{},"Browser attacks update IB2",{"sys":4989,"__typename":4929,"title":4990,"caption":4990,"layoutMode":60,"file":4991},{"id":3017},"Push Security detections by phishing kit, April-June 2026",{"url":4992,"width":4933,"height":4993},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F71NeNdtXc5hbJrhfypTFS1\u002Fb7159dc73169225ff36bbbdf75d7b059\u002Fimage3.png",1082,{"sys":4995,"__typename":4996,"title":4997,"arcadeDemoUrl":4998,"playText":4999},{"id":3030},"ArcadeDemo","Tycoon2FA Device Code Phishing","https:\u002F\u002Fdemo.arcade.software\u002FSPNMxNkoyY5vTMPPlqWS?embed","30 secs",{"sys":5001,"__typename":4996,"title":5002,"arcadeDemoUrl":5003,"playText":4999},{"id":3043},"Device code phishing to AITM fallback","https:\u002F\u002Fdemo.arcade.software\u002F6qbvBCrv9ncUnwSv7kQJ?embed",{"sys":5005,"__typename":4929,"title":5006,"caption":5006,"layoutMode":60,"file":5007},{"id":3513},"Verbose phishing kit comments (a clear sign of AI involvement).",{"url":5008,"width":5009,"height":5010},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2XOX0xzOxsmBKUuQbup47x\u002Fa624c2141879f9238704167a35fdeb39\u002FScreenshot_2026-05-07_at_12.53.27.png",1100,1332,{"items":5012},[],{},"How browser attacks are evolving in 2026 so far","thought-leadership",{"items":5017},[5018,5696,6127],{"__typename":1126,"sys":5019,"content":5021,"title":5680,"synopsis":5681,"hashTags":60,"publishedDate":5682,"slug":5683,"tagsCollection":5684,"authorsCollection":5692},{"id":5020},"4NY2NbkAPucFOJY45yrrrE",{"json":5022},{"data":5023,"content":5024,"nodeType":866},{},[5025,5032,5039,5046,5052,5055,5063,5070,5103,5110,5140,5146,5149,5157,5164,5172,5215,5221,5228,5234,5237,5245,5252,5260,5267,5274,5290,5298,5323,5330,5336,5343,5351,5366,5393,5399,5417,5423,5431,5438,5463,5470,5477,5484,5490,5493,5501,5508,5515,5534,5542,5549,5557,5580,5592,5598,5601,5609,5616,5623,5630,5649,5652,5658,5664],{"data":5026,"content":5027,"nodeType":870},{},[5028],{"data":5029,"marks":5030,"value":5031,"nodeType":874},{},[],"Employees have been self-adopting apps, creating unmanaged accounts, and introducing third-party software dependencies into their organizations for years, and the core problem hasn't changed: unmanaged software expanding your attack surface without your knowledge.",{"data":5033,"content":5034,"nodeType":870},{},[5035],{"data":5036,"marks":5037,"value":5038,"nodeType":874},{},[],"But the rate at which employees are signing up for AI tools is unprecedented, and the depth of interconnectivity those tools demand is fundamentally different from traditional shadow SaaS. ",{"data":5040,"content":5041,"nodeType":870},{},[5042],{"data":5043,"marks":5044,"value":5045,"nodeType":874},{},[],"AI tools aren't just standalone apps that employees sign into — they're increasingly used as agents that drive other applications, pulling data from one platform, acting on another — they are becoming a core that other apps are integrating to, and that users are integrating with their wider SaaS stack. It’s becoming a focal integration point for app access and functionality in a way that's more comparable to an enterprise cloud platform than a typical SaaS tool. ",{"data":5047,"content":5051,"nodeType":1215},{"target":5048},{"sys":5049},{"id":5050,"type":1220,"linkType":1221},"2Vxb48M5JN9Jdy8BG6nbUJ",[],{"data":5053,"content":5054,"nodeType":896},{},[],{"data":5056,"content":5057,"nodeType":900},{},[5058],{"data":5059,"marks":5060,"value":5062,"nodeType":874},{},[5061],{"type":882},"What is shadow AI? A quick 101",{"data":5064,"content":5065,"nodeType":870},{},[5066],{"data":5067,"marks":5068,"value":5069,"nodeType":874},{},[],"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Shadow AI risks cut in two directions:",{"data":5071,"content":5072,"nodeType":1763},{},[5073,5088],{"data":5074,"content":5075,"nodeType":1767},{},[5076],{"data":5077,"content":5078,"nodeType":870},{},[5079,5084],{"data":5080,"marks":5081,"value":5083,"nodeType":874},{},[5082],{"type":882},"Data exposure:",{"data":5085,"marks":5086,"value":5087,"nodeType":874},{},[]," source code, credentials, internal documents, and customer data routinely get pasted into AI prompts or uploaded as context, and once shared, that data is outside the organization's control. ",{"data":5089,"content":5090,"nodeType":1767},{},[5091],{"data":5092,"content":5093,"nodeType":870},{},[5094,5099],{"data":5095,"marks":5096,"value":5098,"nodeType":874},{},[5097],{"type":882},"Attack surface:",{"data":5100,"marks":5101,"value":5102,"nodeType":874},{},[]," Every shadow AI app is an unmanaged identity with credentials that can be phished or stuffed, OAuth grants that give persistent API access to corporate systems, and browser extensions that can be compromised in supply chain attacks. ",{"data":5104,"content":5105,"nodeType":870},{},[5106],{"data":5107,"marks":5108,"value":5109,"nodeType":874},{},[],"AI tools increasingly function as hubs, connected via OAuth and MCP to email, cloud storage, code repositories, and other high-value systems. Every app connection an employee grants turns that AI tool into a node in a web of interconnected services, which means the more you hook in, the larger the attack surface across all the connected apps — and the greater the blast radius if the account used to access the AI tool is compromised.",{"data":5111,"content":5112,"nodeType":870},{},[5113,5117,5125,5129,5136],{"data":5114,"marks":5115,"value":5116,"nodeType":874},{},[],"Each integration creates a persistent trust relationship that survives password resets and MFA changes. Compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate. Attackers are already exploiting this interconnectivity — from ",{"data":5118,"content":5120,"nodeType":966},{"uri":5119},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign",[5121],{"data":5122,"marks":5123,"value":5124,"nodeType":874},{},[],"malvertising campaigns that impersonate AI tools",{"data":5126,"marks":5127,"value":5128,"nodeType":874},{},[]," to steal credentials, to ",{"data":5130,"content":5131,"nodeType":966},{"uri":1204},[5132],{"data":5133,"marks":5134,"value":5135,"nodeType":874},{},[],"leveraging OAuth consent grants in supply chain attacks",{"data":5137,"marks":5138,"value":5139,"nodeType":874},{},[],". ",{"data":5141,"content":5145,"nodeType":1215},{"target":5142},{"sys":5143},{"id":5144,"type":1220,"linkType":1221},"1BWCa7AHCMlYw7XgPLx3h7",[],{"data":5147,"content":5148,"nodeType":896},{},[],{"data":5150,"content":5151,"nodeType":900},{},[5152],{"data":5153,"marks":5154,"value":5156,"nodeType":874},{},[5155],{"type":882},"The state of shadow AI, using Push data",{"data":5158,"content":5159,"nodeType":870},{},[5160],{"data":5161,"marks":5162,"value":5163,"nodeType":874},{},[],"We analyzed a snapshot of AI activity across Push customers during an average week in April 2026. We wanted to make sure it captured actual activity, not just historical data on apps that were added once and no longer used.",{"data":5165,"content":5166,"nodeType":870},{},[5167],{"data":5168,"marks":5169,"value":5171,"nodeType":874},{},[5170],{"type":882},"The numbers paint a picture that most security teams will find uncomfortable.",{"data":5173,"content":5174,"nodeType":870},{},[5175,5179,5184,5188,5193,5197,5202,5206,5211],{"data":5176,"marks":5177,"value":5178,"nodeType":874},{},[],"The average organization has ",{"data":5180,"marks":5181,"value":5183,"nodeType":874},{},[5182],{"type":882},"16 unique AI apps",{"data":5185,"marks":5186,"value":5187,"nodeType":874},{},[]," in active use, ",{"data":5189,"marks":5190,"value":5192,"nodeType":874},{},[5191],{"type":882},"17 unique AI browser extensions",{"data":5194,"marks":5195,"value":5196,"nodeType":874},{},[],", and ",{"data":5198,"marks":5199,"value":5201,"nodeType":874},{},[5200],{"type":882},"17 unique AI OAuth integrations",{"data":5203,"marks":5204,"value":5205,"nodeType":874},{},[]," connected into just Google Workspace and Microsoft 365 — with some organizations reaching as high as 40 unique AI apps, 163 AI extensions, and 55 OAuth connections to AI apps respectively. At the other end, the smallest organization with the ",{"data":5207,"marks":5208,"value":5210,"nodeType":874},{},[5209],{"type":1144},"lowest",{"data":5212,"marks":5213,"value":5214,"nodeType":874},{},[]," adoption level is actively using two. ",{"data":5216,"content":5220,"nodeType":1215},{"target":5217},{"sys":5218},{"id":5219,"type":1220,"linkType":1221},"2AfeiHub5kyZN8wuf6CJch",[],{"data":5222,"content":5223,"nodeType":870},{},[5224],{"data":5225,"marks":5226,"value":5227,"nodeType":874},{},[],"If most organizations have sanctioned one or two core AI assistants\u002Fplatforms for business use, the gap between what's approved and what's actually happening is significant.",{"data":5229,"content":5233,"nodeType":1215},{"target":5230},{"sys":5231},{"id":5232,"type":1220,"linkType":1221},"2hsKQ9DEspflhmtR0bE7QY",[],{"data":5235,"content":5236,"nodeType":896},{},[],{"data":5238,"content":5239,"nodeType":900},{},[5240],{"data":5241,"marks":5242,"value":5244,"nodeType":874},{},[5243],{"type":882},"Understanding the four categories of shadow AI",{"data":5246,"content":5247,"nodeType":870},{},[5248],{"data":5249,"marks":5250,"value":5251,"nodeType":874},{},[],"Shadow SaaS has always been a problem, but in the context of AI apps there are four categories of shadow IT that security teams need to understand, because each one introduces a different kind of risk and requires a different approach to tackling it.",{"data":5253,"content":5254,"nodeType":944},{},[5255],{"data":5256,"marks":5257,"value":5259,"nodeType":874},{},[5258],{"type":882},"Shadow AI apps",{"data":5261,"content":5262,"nodeType":870},{},[5263],{"data":5264,"marks":5265,"value":5266,"nodeType":874},{},[],"Shadow apps are AI tools that employees have signed up to and are using for business purposes without approval. This is the most visible dimension of the problem, and the one most people think of when they hear \"shadow AI\" — an employee pastes sensitive internal documents into ChatGPT, uploads confidential files to an AI assistant, or uses an unapproved coding tool to generate production code.",{"data":5268,"content":5269,"nodeType":870},{},[5270],{"data":5271,"marks":5272,"value":5273,"nodeType":874},{},[],"All of that is sensitive data leaving the organization through channels the security team can't see - and often accessible using personal accounts that can be compromised on personal devices or workstations. ",{"data":5275,"content":5276,"nodeType":870},{},[5277,5281,5286],{"data":5278,"marks":5279,"value":5280,"nodeType":874},{},[],"The 2026 DBIR's data loss prevention analysis underscores the scale — shadow AI is now the ",{"data":5282,"marks":5283,"value":5285,"nodeType":874},{},[5284],{"type":882},"third most common non-malicious insider action",{"data":5287,"marks":5288,"value":5289,"nodeType":874},{},[]," in DLP data, a 4x increase year-over-year. Across 858,000+ DLP events targeting GenAI tools, the most common data types being submitted were source code (28%), images (16%), structured data (14%), documents (13%), and PDFs (10%). That's not employees asking ChatGPT to fix their grammar — it's core intellectual property, production code, and internal documentation flowing into platforms the security team has no visibility into. But shadow apps themselves are only the most obvious part of the problem.",{"data":5291,"content":5292,"nodeType":944},{},[5293],{"data":5294,"marks":5295,"value":5297,"nodeType":874},{},[5296],{"type":882},"Shadow tenants",{"data":5299,"content":5300,"nodeType":870},{},[5301,5305,5310,5314,5319],{"data":5302,"marks":5303,"value":5304,"nodeType":874},{},[],"Even when an organization has approved an AI tool — say, an enterprise ChatGPT deployment — employees frequently access the same app with personal accounts, creating shadow tenants that sit entirely outside organizational control. The DBIR found that ",{"data":5306,"marks":5307,"value":5309,"nodeType":874},{},[5308],{"type":882},"67% of GenAI users on corporate devices are using non-corporate accounts",{"data":5311,"marks":5312,"value":5313,"nodeType":874},{},[],", and our own data shows that ",{"data":5315,"marks":5316,"value":5318,"nodeType":874},{},[5317],{"type":882},"38% of file uploads to AI tools are made from shadow accounts",{"data":5320,"marks":5321,"value":5322,"nodeType":874},{},[]," rather than approved organizational ones.",{"data":5324,"content":5325,"nodeType":870},{},[5326],{"data":5327,"marks":5328,"value":5329,"nodeType":874},{},[],"When an organization approves Claude, ChatGPT, or another core AI platform, you typically also approve the OAuth integration and browser extension for core apps (e.g. M365, Google Workspace, and so on). When that integration is approved, it is approved for all tenants — not just your corporate tenant. ",{"data":5331,"content":5335,"nodeType":1215},{"target":5332},{"sys":5333},{"id":5334,"type":1220,"linkType":1221},"3Rvw0n28AYIM3FQXtHyafD",[],{"data":5337,"content":5338,"nodeType":870},{},[5339],{"data":5340,"marks":5341,"value":5342,"nodeType":874},{},[],"This means that even if you've deployed enterprise controls around your sanctioned AI tools — DLP policies, retention settings, admin oversight — more than a third of the file uploads hitting AI tools are bypassing those controls entirely because they're happening through personal accounts on corporate devices.",{"data":5344,"content":5345,"nodeType":944},{},[5346],{"data":5347,"marks":5348,"value":5350,"nodeType":874},{},[5349],{"type":882},"Shadow extensions",{"data":5352,"content":5353,"nodeType":870},{},[5354,5358,5362],{"data":5355,"marks":5356,"value":5357,"nodeType":874},{},[],"Many AI tools come with a browser extension counterpart, and there's a large ecosystem of third-party AI extensions that offer everything from writing assistance to automated data extraction. The average organization in our dataset has ",{"data":5359,"marks":5360,"value":5192,"nodeType":874},{},[5361],{"type":882},{"data":5363,"marks":5364,"value":5365,"nodeType":874},{},[]," deployed across its workforce, with the highest we observed reaching 163 — and since each of those average 17 different extensions may be installed by multiple employees, the actual number of individual extension installs across the organization is much higher still.",{"data":5367,"content":5368,"nodeType":870},{},[5369,5373,5380,5384,5389],{"data":5370,"marks":5371,"value":5372,"nodeType":874},{},[],"The extension dimension is particularly concerning because most extensions operate with significant privilege inside the browser — they can read and modify page content, access cookies and session tokens, and interact with virtually every web application an employee uses. As we detailed in our recent analysis of ",{"data":5374,"content":5375,"nodeType":966},{"uri":1684},[5376],{"data":5377,"marks":5378,"value":5379,"nodeType":874},{},[],"browser extension risk scoring",{"data":5381,"marks":5382,"value":5383,"nodeType":874},{},[],", at least ",{"data":5385,"marks":5386,"value":5388,"nodeType":874},{},[5387],{"type":882},"46.76% of all extensions across Push customers have the permission combinations needed to perform account takeover with no user interaction",{"data":5390,"marks":5391,"value":5392,"nodeType":874},{},[],", and the extensions involved in every major supply chain breach of the past 18 months scored as normal or low-risk beforehand.",{"data":5394,"content":5398,"nodeType":1215},{"target":5395},{"sys":5396},{"id":5397,"type":1220,"linkType":1221},"3z4JOMALI52xoOXZkzPHLD",[],{"data":5400,"content":5401,"nodeType":870},{},[5402,5406,5413],{"data":5403,"marks":5404,"value":5405,"nodeType":874},{},[],"AI extensions add a specific wrinkle to this problem: many are branded to look like official companions to well-known AI tools but are actually third-party creations with no affiliation to the original vendor. They're not necessarily malicious at the point of installation, but they're exactly the kind of extension that's likely to be ",{"data":5407,"content":5408,"nodeType":966},{"uri":1684},[5409],{"data":5410,"marks":5411,"value":5412,"nodeType":874},{},[],"acquired and weaponized",{"data":5414,"marks":5415,"value":5416,"nodeType":874},{},[]," down the line — and in the meantime, they're collecting data that their permissions entitle them to (which, in most cases, means everything the user can see in their browser).",{"data":5418,"content":5422,"nodeType":1215},{"target":5419},{"sys":5420},{"id":5421,"type":1220,"linkType":1221},"6K3z67rohss6H3lCsSn12B",[],{"data":5424,"content":5425,"nodeType":944},{},[5426],{"data":5427,"marks":5428,"value":5430,"nodeType":874},{},[5429],{"type":882},"Shadow integrations",{"data":5432,"content":5433,"nodeType":870},{},[5434],{"data":5435,"marks":5436,"value":5437,"nodeType":874},{},[],"The fourth dimension — and arguably the most dangerous — is shadow integrations: OAuth connections between AI tools and core enterprise apps that aren't known or approved by the security team. Even if an organization has approved an AI tool for standalone use, plugging that tool directly into Google Workspace, Microsoft 365, Salesforce, or any other one of the dozen or so SaaS apps in a typical user’s work stack is a fundamentally different risk decision, because it creates a persistent, programmatic bridge between your environment and a third party.",{"data":5439,"content":5440,"nodeType":870},{},[5441,5445,5450,5454,5459],{"data":5442,"marks":5443,"value":5444,"nodeType":874},{},[],"On average, we see ",{"data":5446,"marks":5447,"value":5449,"nodeType":874},{},[5448],{"type":882},"17 unique AI app OAuth integrations per organization",{"data":5451,"marks":5452,"value":5453,"nodeType":874},{},[]," in ",{"data":5455,"marks":5456,"value":5458,"nodeType":874},{},[5457],{"type":1144},"just",{"data":5460,"marks":5461,"value":5462,"nodeType":874},{},[]," Google Workspace and Microsoft 365 (to be clear: this number excludes the dozens of downstream apps the AI assistants are integrated with as well), with the highest reaching 55. Each of those represents a unique AI product that has been granted OAuth access — the total number of individual consent grants across users is larger, because popular integrations get authorized by multiple employees independently.",{"data":5464,"content":5465,"nodeType":870},{},[5466],{"data":5467,"marks":5468,"value":5469,"nodeType":874},{},[],"The actual number of AI-related OAuth connections across the full SaaS estate is considerably higher again, because AI tools that automate workflows need to be connected to be useful — pulling data from one app, analyzing it in another, presenting results in a third.",{"data":5471,"content":5472,"nodeType":870},{},[5473],{"data":5474,"marks":5475,"value":5476,"nodeType":874},{},[],"MCP connections use OAuth to achieve this interconnectivity in the same way, and AI coding agents create a particularly concentrated version of the risk: a single agent configuration can hold OAuth tokens for Jira, Confluence, Salesforce, GitHub, and more, meaning that compromising one agent — whether through prompt injection, a malicious repository config, or a supply chain attack on an MCP server — yields persistent, broadly scoped tokens for every service it was connected to, tokens that survive session restarts and generate audit log entries indistinguishable from legitimate user activity.",{"data":5478,"content":5479,"nodeType":870},{},[5480],{"data":5481,"marks":5482,"value":5483,"nodeType":874},{},[],"It's also worth noting that OAuth blast radius is almost always larger than organizations expect. A single well-permissioned user can expose secrets, dashboards, and internal tooling without tenant-wide admin access. And every new AI tool an employee connects makes the web of abusable permissions a little wider.",{"data":5485,"content":5489,"nodeType":1215},{"target":5486},{"sys":5487},{"id":5488,"type":1220,"linkType":1221},"4SnzJ9T93gHzFIUASx7Yb3",[],{"data":5491,"content":5492,"nodeType":896},{},[],{"data":5494,"content":5495,"nodeType":900},{},[5496],{"data":5497,"marks":5498,"value":5500,"nodeType":874},{},[5499],{"type":882},"Why shadow AI needs a different solution to shadow SaaS",{"data":5502,"content":5503,"nodeType":870},{},[5504],{"data":5505,"marks":5506,"value":5507,"nodeType":874},{},[],"The reason it's worth distinguishing between these four dimensions isn't academic. Each one requires a different control, and addressing one doesn't solve the others.",{"data":5509,"content":5510,"nodeType":870},{},[5511],{"data":5512,"marks":5513,"value":5514,"nodeType":874},{},[],"Blocking unsanctioned AI apps does nothing for the personal accounts accessing approved ones, and neither addresses the average 17 different AI extensions running with broad browser permissions, let alone the dozens of OAuth integrations that have already been granted persistent access to core enterprise apps — and even auditing OAuth in Google Workspace and Microsoft 365, where the controls are relatively mature, leaves the broader SaaS estate unaddressed, where admin tooling is inconsistent and visibility is limited.",{"data":5516,"content":5517,"nodeType":870},{},[5518,5522,5530],{"data":5519,"marks":5520,"value":5521,"nodeType":874},{},[],"The tooling gap compounds the policy gap. ",{"data":5523,"content":5525,"nodeType":966},{"uri":5524},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market\u002F",[5526],{"data":5527,"marks":5528,"value":5529,"nodeType":874},{},[],"Omdia found",{"data":5531,"marks":5532,"value":5533,"nodeType":874},{},[]," that 58% of organizations rely on secure web gateways to secure GenAI usage — but an SWG can tell you that a user visited ChatGPT, not whether they pasted your source code into the prompt. That link between knowing where data went and knowing what the user actually did is the fundamental visibility gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":5535,"content":5536,"nodeType":944},{},[5537],{"data":5538,"marks":5539,"value":5541,"nodeType":874},{},[5540],{"type":882},"Advice for security teams",{"data":5543,"content":5544,"nodeType":870},{},[5545],{"data":5546,"marks":5547,"value":5548,"nodeType":874},{},[],"The principles behind managing shadow AI are the same ones that have governed shadow SaaS and software supply chain management for years: default-deny where feasible, comprehensive inventory where it isn't, and continuous monitoring for changes that signal increased risk. But it's vital that teams act fast to stop the snowball.",{"data":5550,"content":5551,"nodeType":870},{},[5552],{"data":5553,"marks":5554,"value":5556,"nodeType":874},{},[5555],{"type":882},"That starts with visibility into which AI tools employees are actually using and which accounts they're using to access them — without that baseline, every other control is built on assumptions.",{"data":5558,"content":5559,"nodeType":870},{},[5560,5565,5569,5576],{"data":5561,"marks":5562,"value":5564,"nodeType":874},{},[5563],{"type":882},"Extensions",{"data":5566,"marks":5567,"value":5568,"nodeType":874},{},[]," need the same ",{"data":5570,"content":5571,"nodeType":966},{"uri":1684},[5572],{"data":5573,"marks":5574,"value":5575,"nodeType":874},{},[],"default-deny allowlisting approach",{"data":5577,"marks":5578,"value":5579,"nodeType":874},{},[]," that has been best practice for software management elsewhere: build a complete inventory, allowlist what's vetted, block everything else, and monitor the approved set for changes that precede weaponization.",{"data":5581,"content":5582,"nodeType":870},{},[5583,5588],{"data":5584,"marks":5585,"value":5587,"nodeType":874},{},[5586],{"type":882},"OAuth",{"data":5589,"marks":5590,"value":5591,"nodeType":874},{},[]," demands the most urgency, because each unmanaged integration is a persistent trust relationship that survives password resets and MFA changes — adopt default-deny for consent grants in your primary enterprise apps, routinely audit what's already connected, and critically extend that visibility beyond Google and Microsoft to the broader SaaS estate where the controls are weaker and the sprawl is harder to track.",{"data":5593,"content":5597,"nodeType":1215},{"target":5594},{"sys":5595},{"id":5596,"type":1220,"linkType":1221},"3RFLFtJtDXvhTz1mVztfV9",[],{"data":5599,"content":5600,"nodeType":896},{},[],{"data":5602,"content":5603,"nodeType":900},{},[5604],{"data":5605,"marks":5606,"value":5608,"nodeType":874},{},[5607],{"type":882},"Browser visibility and control is key to de-risking AI adoption",{"data":5610,"content":5611,"nodeType":870},{},[5612],{"data":5613,"marks":5614,"value":5615,"nodeType":874},{},[],"AI usage is fundamentally browser-based activity — every LLM interaction, every prompt containing sensitive data, every AI agent authorization, every OAuth consent grant happens inside a browser session — which makes the browser the natural control point for AI governance across the workforce. ",{"data":5617,"content":5618,"nodeType":870},{},[5619],{"data":5620,"marks":5621,"value":5622,"nodeType":874},{},[],"Push tracks AI app usage and login security across the workforce, inventories and controls AI browser extensions, monitors and blocks OAuth consent flows across any app (not just the primary enterprise platforms), and gives security teams a single view of the full shadow AI picture across all four dimensions.",{"data":5624,"content":5625,"nodeType":870},{},[5626],{"data":5627,"marks":5628,"value":5629,"nodeType":874},{},[],"Shadow AI isn't a problem that will age well if ignored. Every week that passes without visibility adds more apps, more extensions, more integrations, and more potential breach paths into the environment — and as the Vercel breach demonstrated, it only takes one forgotten OAuth grant to turn an employee's idle curiosity into an organization-wide incident.",{"data":5631,"content":5632,"nodeType":870},{},[5633,5637,5645],{"data":5634,"marks":5635,"value":5636,"nodeType":874},{},[],"Learn more about how you can tackle ",{"data":5638,"content":5640,"nodeType":966},{"uri":5639},"https:\u002F\u002Fpushsecurity.com\u002Fuc\u002Fshadow-ai",[5641],{"data":5642,"marks":5643,"value":573,"nodeType":874},{},[5644],{"type":974},{"data":5646,"marks":5647,"value":5648,"nodeType":874},{},[]," with Push. ",{"data":5650,"content":5651,"nodeType":896},{},[],{"data":5653,"content":5654,"nodeType":870},{},[5655],{"data":5656,"marks":5657,"value":1084,"nodeType":874},{},[],{"data":5659,"content":5660,"nodeType":870},{},[5661],{"data":5662,"marks":5663,"value":1091,"nodeType":874},{},[],{"data":5665,"content":5666,"nodeType":870},{},[5667,5670,5677],{"data":5668,"marks":5669,"value":2483,"nodeType":874},{},[],{"data":5671,"content":5672,"nodeType":966},{"uri":1102},[5673],{"data":5674,"marks":5675,"value":2490,"nodeType":874},{},[5676],{"type":974},{"data":5678,"marks":5679,"value":2494,"nodeType":874},{},[],"Shadow AI: what Push data reveals about the scale of the problem","Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.","2026-05-28T00:00:00.000Z","what-push-data-reveals-about-the-state-of-shadow-ai",{"items":5685},[5686,5690],{"sys":5687,"name":5689},{"id":5688},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"sys":5691,"name":289},{"id":2503},{"items":5693},[5694],{"fullName":2014,"firstName":2015,"jobTitle":2016,"profilePicture":5695},{"url":2018},{"__typename":1126,"sys":5697,"content":5699,"title":6110,"synopsis":6111,"hashTags":60,"publishedDate":6112,"slug":6113,"tagsCollection":6114,"authorsCollection":6120},{"id":5698},"4fUZAVpkaksHImeoT8jp0f",{"json":5700},{"data":5701,"content":5702,"nodeType":866},{},[5703,5710,5717,5724,5731,5738,5758,5765,5772,5779,5785,5788,5795,5814,5820,5836,5852,5868,5884,5891,5898,5905,5911,5918,5925,5932,5939,5945,5965,5980,5987,5994,6001,6008,6015,6022,6028,6035,6042,6049,6056,6063,6070,6077,6084,6091],{"data":5704,"content":5705,"nodeType":870},{},[5706],{"data":5707,"marks":5708,"value":5709,"nodeType":874},{},[],"Every security engineer has a version of this ritual. ",{"data":5711,"content":5712,"nodeType":870},{},[5713],{"data":5714,"marks":5715,"value":5716,"nodeType":874},{},[],"A new campaign hits the news, and you already hear the question coming, “Are we covered?”",{"data":5718,"content":5719,"nodeType":870},{},[5720],{"data":5721,"marks":5722,"value":5723,"nodeType":874},{},[],"So you read the writeup and quickly do the calculus on whether you can extract meaningful data, something to base a behavioral detection around — or not.",{"data":5725,"content":5726,"nodeType":870},{},[5727],{"data":5728,"marks":5729,"value":5730,"nodeType":874},{},[],"Then the choice is: Send the IOCs you can identify to your blocklists and move on for now, or try to dig deeper. The limitations of the first choice are clear; so are the challenges of the second.",{"data":5732,"content":5733,"nodeType":870},{},[5734],{"data":5735,"marks":5736,"value":5737,"nodeType":874},{},[],"That’s the uncomfortable gap between “We’re aware of this threat” and “We have strong detections around it.”",{"data":5739,"content":5740,"nodeType":870},{},[5741,5745,5754],{"data":5742,"marks":5743,"value":5744,"nodeType":874},{},[],"Because you already know that the IOCs for a novel browser-based attack are likely outdated the moment you block them. And in the case of a ",{"data":5746,"content":5748,"nodeType":966},{"uri":5747},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F03\u002F02\u002Foauth-redirection-abuse-enables-phishing-malware-delivery\u002F",[5749],{"data":5750,"marks":5751,"value":5753,"nodeType":874},{},[5752],{"type":974},"new technique observed by Microsoft",{"data":5755,"marks":5756,"value":5757,"nodeType":874},{},[]," earlier this year, you’d be right.",{"data":5759,"content":5760,"nodeType":870},{},[5761],{"data":5762,"marks":5763,"value":5764,"nodeType":874},{},[],"In March, Push’s AI agents took a close look at that Microsoft intel, which details a discovered campaign built around a novel OAuth redirect abuse technique used to deliver users to phishing pages under the cover of trusted services’ OAuth flows. ",{"data":5766,"content":5767,"nodeType":870},{},[5768],{"data":5769,"marks":5770,"value":5771,"nodeType":874},{},[],"What we found was indicative of how these attacks rapidly evolve: No matches for the published IOCs across our install base. But a few months later, we got a true positive. Except it was for new lures, new variants, and different IOCs. What hadn’t changed was the underlying attack delivery technique, and that’s what we used to detect a new campaign on Push customer estates.",{"data":5773,"content":5774,"nodeType":870},{},[5775],{"data":5776,"marks":5777,"value":5778,"nodeType":874},{},[],"In this article, we’ll walk through this example as a case study of how agentic threat hunting helps us go beyond IOCs to extract durable behavioral indicators that close the gap between “We’re aware of this threat” and “We’re covered.”",{"data":5780,"content":5784,"nodeType":1215},{"target":5781},{"sys":5782},{"id":5783,"type":1220,"linkType":1221},"6X7yXNdchH1Qp2tNKRAyVP",[],{"data":5786,"content":5787,"nodeType":896},{},[],{"data":5789,"content":5790,"nodeType":900},{},[5791],{"data":5792,"marks":5793,"value":5794,"nodeType":874},{},[],"The intel: Novel abuse of OAuth redirects as a phishing delivery mechanism",{"data":5796,"content":5797,"nodeType":870},{},[5798,5802,5810],{"data":5799,"marks":5800,"value":5801,"nodeType":874},{},[],"The technique ",{"data":5803,"content":5804,"nodeType":966},{"uri":5747},[5805],{"data":5806,"marks":5807,"value":5809,"nodeType":874},{},[5808],{"type":974},"Microsoft documented",{"data":5811,"marks":5812,"value":5813,"nodeType":874},{},[]," back in March is an interesting one. It doesn't steal tokens or abuse consent flows. Instead, it weaponizes the OAuth error-handling path itself — turning trusted identity provider domains into a delivery mechanism for phishing and malware.",{"data":5815,"content":5819,"nodeType":1215},{"target":5816},{"sys":5817},{"id":5818,"type":1220,"linkType":1221},"486pfUpMxx15vJupxuiePn",[],{"data":5821,"content":5822,"nodeType":870},{},[5823,5827,5832],{"data":5824,"marks":5825,"value":5826,"nodeType":874},{},[],"Here's how it works. The attacker registers a malicious application in an actor-controlled tenant, pointing its redirect URI at attacker infrastructure. They craft an authorization URL using ",{"data":5828,"marks":5829,"value":5831,"nodeType":874},{},[5830],{"type":882},"prompt=none",{"data":5833,"marks":5834,"value":5835,"nodeType":874},{},[]," (forcing silent authentication) and an intentionally invalid scope, which guarantees an OAuth error. ",{"data":5837,"content":5838,"nodeType":870},{},[5839,5843,5848],{"data":5840,"marks":5841,"value":5842,"nodeType":874},{},[],"The identity provider — Microsoft Entra ID, Google Workspace, or any OAuth-compliant service — handles that error the way the spec says it should: By redirecting the browser to the application's registered redirect URI. The user clicks a link that begins at ",{"data":5844,"marks":5845,"value":5847,"nodeType":874},{},[5846],{"type":882},"login.microsoftonline.com",{"data":5849,"marks":5850,"value":5851,"nodeType":874},{},[],", passes through a legitimate authentication endpoint, and lands on an attacker-controlled page.",{"data":5853,"content":5854,"nodeType":870},{},[5855,5859,5864],{"data":5856,"marks":5857,"value":5858,"nodeType":874},{},[],"Importantly, no token is stolen during the redirect. The OAuth flow is the delivery vehicle, not the compromise mechanism. What happens ",{"data":5860,"marks":5861,"value":5863,"nodeType":874},{},[5862],{"type":1144},"after",{"data":5865,"marks":5866,"value":5867,"nodeType":874},{},[]," the redirect — phishing, malware download, credential harvesting — is where the actual attack occurs.",{"data":5869,"content":5870,"nodeType":870},{},[5871,5875,5880],{"data":5872,"marks":5873,"value":5874,"nodeType":874},{},[],"This technique is also successful because conventional URL filtering sees a legitimate authentication domain, not a phishing destination. The redirect is standards-compliant behavior, and the initial URL carries the domain reputation of a trusted identity provider — which means the usual defenses at the network layer don't fire. (No TI or domain-based detection service in the world would raise a ",{"data":5876,"marks":5877,"value":5879,"nodeType":874},{},[5878],{"type":882},"microsoft.com",{"data":5881,"marks":5882,"value":5883,"nodeType":874},{},[]," domain as suspicious!)",{"data":5885,"content":5886,"nodeType":870},{},[5887],{"data":5888,"marks":5889,"value":5890,"nodeType":874},{},[],"With this intel, Push’s agents now had some useful fodder to hunt for.",{"data":5892,"content":5893,"nodeType":900},{},[5894],{"data":5895,"marks":5896,"value":5897,"nodeType":874},{},[],"Hunting from intel: How we developed a behavioral detection",{"data":5899,"content":5900,"nodeType":870},{},[5901],{"data":5902,"marks":5903,"value":5904,"nodeType":874},{},[],"It started with ingestion. When the Microsoft blog was published, Push's TI aggregation agent flagged it as relevant to our detection surface — the technique abuses OAuth redirect behavior observable in the browser, which maps directly to the metadata that Push's browser agent captures.",{"data":5906,"content":5910,"nodeType":1215},{"target":5907},{"sys":5908},{"id":5909,"type":1220,"linkType":1221},"26saWWXsyFAZrsrfspGwaF",[],{"data":5912,"content":5913,"nodeType":870},{},[5914],{"data":5915,"marks":5916,"value":5917,"nodeType":874},{},[],"The Push intel agent understands not to hunt for IOCs, but rather to think in terms of durable behaviors. It understands the telemetry available to the Push browser extension, and then compares that to the telemetry it would expect to be able to extract for a given technique, before deciding what to hunt for.",{"data":5919,"content":5920,"nodeType":870},{},[5921],{"data":5922,"marks":5923,"value":5924,"nodeType":874},{},[],"In this case, the intel agent extracted two distinct behavioral elements from the research to look for: the OAuth redirect technique and the page users land on after the error.",{"data":5926,"content":5927,"nodeType":870},{},[5928],{"data":5929,"marks":5930,"value":5931,"nodeType":874},{},[],"That extraction step is where surface-level details can become technique-driven hunts. Microsoft's article listed specific client IDs, redirect URLs, and PowerShell command patterns — indicators that are useful for retrospective hunting but will rotate as the campaign evolves. ",{"data":5933,"content":5934,"nodeType":870},{},[5935],{"data":5936,"marks":5937,"value":5938,"nodeType":874},{},[],"The pipeline's job was to identify what wouldn't change: The behavioral mechanics of abusing the OAuth error redirect path as a delivery mechanism, independent of which domains, client IDs, or post-redirect payloads the attacker chose to use. This is the Pyramid of Pain principle in practice: Hunt for the technique, not the indicator, because techniques are genuinely hard for attackers to change.",{"data":5940,"content":5944,"nodeType":1215},{"target":5941},{"sys":5942},{"id":5943,"type":1220,"linkType":1221},"7qUVlKVjHMkabu0MJ1S7gC",[],{"data":5946,"content":5947,"nodeType":870},{},[5948,5952,5961],{"data":5949,"marks":5950,"value":5951,"nodeType":874},{},[],"Next, the agents verified what they already knew from Push’s internal TTP knowledge base. In this case, the agents understood the well-known technique of ",{"data":5953,"content":5955,"nodeType":966},{"uri":5954},"https:\u002F\u002Fowasp.org\u002Fwww-community\u002Fattacks\u002Fopen_redirect",[5956],{"data":5957,"marks":5958,"value":5960,"nodeType":874},{},[5959],{"type":974},"open redirects",{"data":5962,"marks":5963,"value":5964,"nodeType":874},{},[],", where attackers leverage redirects to deliver users to a malicious page. The example originally published by Microsoft was a novel variation of that — abusing a trusted service and the open redirect technique via a legitimate OAuth error workflow to deliver a multi-stage phishing attack.",{"data":5966,"content":5967,"nodeType":870},{},[5968,5972,5976],{"data":5969,"marks":5970,"value":5971,"nodeType":874},{},[],"AI models’ deep knowledge of web programming and frameworks is a particular strength here, because they understand which OAuth redirect behavior is normal and common across diverse scenarios, and can pinpoint which elements will be the strongest signal to hunt for malicious behavior. The agents immediately recognized that hunting for ",{"data":5973,"marks":5974,"value":5831,"nodeType":874},{},[5975],{"type":882},{"data":5977,"marks":5978,"value":5979,"nodeType":874},{},[]," would be too noisy, as legitimate apps regularly use silent token refresh.",{"data":5981,"content":5982,"nodeType":870},{},[5983],{"data":5984,"marks":5985,"value":5986,"nodeType":874},{},[],"In this case, the approach was simply to find all the instances where a user hit an OAuth error page, and then landed on a login page afterward. Normal behavior for error states would be to return an error response — not send the user on to a page with a password form field or a CAPTCHA. That’s highly suspicious.",{"data":5988,"content":5989,"nodeType":870},{},[5990],{"data":5991,"marks":5992,"value":5993,"nodeType":874},{},[],"The agents then built behavioral queries targeting both behavioral attributes of the attack, and validated them across Push's install base. ",{"data":5995,"content":5996,"nodeType":870},{},[5997],{"data":5998,"marks":5999,"value":6000,"nodeType":874},{},[],"When agents first looked in March, the hunts returned no true positives — the specific campaign Microsoft documented wasn’t active against Push customers at that time.",{"data":6002,"content":6003,"nodeType":870},{},[6004],{"data":6005,"marks":6006,"value":6007,"nodeType":874},{},[],"But the query logic was sound — precise enough to avoid false positives, broad enough to catch technique variants without relying on the specific IOCs that Microsoft documented. So the pipeline promoted it to a live query — a continuing detection that would surface any future instances of the technique across the customer base.",{"data":6009,"content":6010,"nodeType":900},{},[6011],{"data":6012,"marks":6013,"value":6014,"nodeType":874},{},[],"The hunt pays off: A new variant, completely different IOCs",{"data":6016,"content":6017,"nodeType":870},{},[6018],{"data":6019,"marks":6020,"value":6021,"nodeType":874},{},[],"In June, the query fired. A single user at a single customer had been targeted, but with a completely different scenario. ",{"data":6023,"content":6027,"nodeType":1215},{"target":6024},{"sys":6025},{"id":6026,"type":1220,"linkType":1221},"7uXgOzxemy1PaJLhUa1txV",[],{"data":6029,"content":6030,"nodeType":870},{},[6031],{"data":6032,"marks":6033,"value":6034,"nodeType":874},{},[],"Where the Microsoft-documented example used lures presented as document-sharing links, Teams meeting recordings, or password resets, and the abused trusted service was a Microsoft login link used to trigger the OAuth error, the Push-observed attack chain used different elements. However, the behavioral technique at the core was the same.",{"data":6036,"content":6037,"nodeType":870},{},[6038],{"data":6039,"marks":6040,"value":6041,"nodeType":874},{},[],"In this case, the user clicked a link in a service desk ticket, triggering an OAuth flow that used a redirect URL with parameters designed to make it look like a Grammarly link. After hitting the OAuth error, the user was redirected to a page with a CAPTCHA, and then redirected again to a second page behind a Cloudflare Turnstile that was running a phish kit. While examining the phishing page, Push’s agents found a net-new phish kit that they later added additional detections for. ",{"data":6043,"content":6044,"nodeType":870},{},[6045],{"data":6046,"marks":6047,"value":6048,"nodeType":874},{},[],"Roughly a day after the Push detection fired, Google Safe Browsing flagged both domains as phishing domains. But when the user was first targeted, neither domain had been flagged. In this case, the user exited the redirect flow before entering any credentials.",{"data":6050,"content":6051,"nodeType":870},{},[6052],{"data":6053,"marks":6054,"value":6055,"nodeType":874},{},[],"It’s important to note that this phishing technique also bypasses other controls based on network content pattern analysis or domain-based detections. For example, a network proxy is designed to look for malicious webpages based on known-bad IOCs like domains or page content that contains known-bad script files. This technique uses a dynamic obfuscated Javascript blob that unpacks and loads the webpage on the client side after checking to see if it’s running in a live browser environment, evading proxy-based analysis.",{"data":6057,"content":6058,"nodeType":870},{},[6059],{"data":6060,"marks":6061,"value":6062,"nodeType":874},{},[],"The query now serves as another early-warning flag designed to be broad enough to catch other interesting new variants of this TTP.",{"data":6064,"content":6065,"nodeType":900},{},[6066],{"data":6067,"marks":6068,"value":6069,"nodeType":874},{},[],"Why technique-level detection pays dividends",{"data":6071,"content":6072,"nodeType":870},{},[6073],{"data":6074,"marks":6075,"value":6076,"nodeType":874},{},[],"This example demonstrates the value of behavioral detection. By focusing on technique extraction, we can stay a step ahead of attack evolution, identifying other contexts and campaigns that use the same behavioral technique, without relying on stale IOCs.",{"data":6078,"content":6079,"nodeType":870},{},[6080],{"data":6081,"marks":6082,"value":6083,"nodeType":874},{},[],"For customers, this means no one has to distil the threat intel report into behavioral elements, spend time crafting detections, or work to eliminate false positives. The Push agents do all that automatically, delivering a compounding benefit the more they learn. ",{"data":6085,"content":6086,"nodeType":870},{},[6087],{"data":6088,"marks":6089,"value":6090,"nodeType":874},{},[],"Customers get a fully operationalized threat-hunting and detection engineering capability; and the Push knowledge base itself expands with each new hunt, getting better at identifying emerging threats.",{"data":6092,"content":6093,"nodeType":870},{},[6094,6098,6106],{"data":6095,"marks":6096,"value":6097,"nodeType":874},{},[],"If you'd like to see how Push's detection pipeline would work in your environment, ",{"data":6099,"content":6100,"nodeType":966},{"uri":1102},[6101],{"data":6102,"marks":6103,"value":6105,"nodeType":874},{},[6104],{"type":974},"book a demo",{"data":6107,"marks":6108,"value":6109,"nodeType":874},{},[]," with our team.","From IOCs to TTPs: An agentic threat hunting case study","How Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources.","2026-07-31T00:00:00.000Z","from-iocs-to-ttps-an-agentic-threat-hunting-case-study",{"items":6115},[6116,6118],{"sys":6117,"name":2007},{"id":2006},{"sys":6119,"name":334},{"id":2010},{"items":6121},[6122],{"fullName":6123,"firstName":6124,"jobTitle":2511,"profilePicture":6125},"Kelly Davenport","Kelly",{"url":6126},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1hi8bEuVfn5sF57LivAq6d\u002F9a3b82426c697d765e2e450e33a18424\u002Fkelly_profile_pic.jpeg",{"__typename":1126,"sys":6128,"content":6130,"title":6966,"synopsis":6967,"hashTags":60,"publishedDate":6968,"slug":6969,"tagsCollection":6970,"authorsCollection":6976},{"id":6129},"211Dd0EIrXPOFpvRgs0fEE",{"json":6131},{"data":6132,"content":6133,"nodeType":866},{},[6134,6153,6172,6191,6197,6200,6208,6215,6222,6229,6236,6244,6247,6255,6262,6269,6276,6282,6290,6309,6316,6323,6339,6347,6376,6392,6399,6428,6436,6466,6473,6481,6499,6506,6513,6519,6526,6534,6552,6559,6578,6585,6588,6596,6603,6691,6698,6714,6717,6747,6766,6773,6780,6783,6791,6810,6817,6824,6841,6844,6852,6859,6892,6899,6916,6935,6941,6944,6951],{"data":6135,"content":6136,"nodeType":870},{},[6137,6141,6149],{"data":6138,"marks":6139,"value":6140,"nodeType":874},{},[],"When we released the ",{"data":6142,"content":6144,"nodeType":966},{"uri":6143},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsaas-attack-techniques\u002F",[6145],{"data":6146,"marks":6147,"value":6148,"nodeType":874},{},[],"SaaS attack matrix",{"data":6150,"marks":6151,"value":6152,"nodeType":874},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":6154,"content":6155,"nodeType":870},{},[6156,6160,6168],{"data":6157,"marks":6158,"value":6159,"nodeType":874},{},[],"A year later, we ",{"data":6161,"content":6163,"nodeType":966},{"uri":6162},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-saas-attack-matrix-one-year-on\u002F",[6164],{"data":6165,"marks":6166,"value":6167,"nodeType":874},{},[],"reviewed what had changed",{"data":6169,"marks":6170,"value":6171,"nodeType":874},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":6173,"content":6174,"nodeType":870},{},[6175,6179,6187],{"data":6176,"marks":6177,"value":6178,"nodeType":874},{},[],"Today, we're re-releasing the matrix as the ",{"data":6180,"content":6182,"nodeType":966},{"uri":6181},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002F",[6183],{"data":6184,"marks":6185,"value":6186,"nodeType":874},{},[],"Browser & Identity Attacks Matrix",{"data":6188,"marks":6189,"value":6190,"nodeType":874},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":6192,"content":6196,"nodeType":1215},{"target":6193},{"sys":6194},{"id":6195,"type":1220,"linkType":1221},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":6198,"content":6199,"nodeType":896},{},[],{"data":6201,"content":6202,"nodeType":900},{},[6203],{"data":6204,"marks":6205,"value":6207,"nodeType":874},{},[6206],{"type":882},"Why the scope needed to change",{"data":6209,"content":6210,"nodeType":870},{},[6211],{"data":6212,"marks":6213,"value":6214,"nodeType":874},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":6216,"content":6217,"nodeType":870},{},[6218],{"data":6219,"marks":6220,"value":6221,"nodeType":874},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":6223,"content":6224,"nodeType":870},{},[6225],{"data":6226,"marks":6227,"value":6228,"nodeType":874},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":6230,"content":6231,"nodeType":870},{},[6232],{"data":6233,"marks":6234,"value":6235,"nodeType":874},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":6237,"content":6238,"nodeType":870},{},[6239],{"data":6240,"marks":6241,"value":6243,"nodeType":874},{},[6242],{"type":882},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":6245,"content":6246,"nodeType":896},{},[],{"data":6248,"content":6249,"nodeType":900},{},[6250],{"data":6251,"marks":6252,"value":6254,"nodeType":874},{},[6253],{"type":882},"The technique landscape has transformed",{"data":6256,"content":6257,"nodeType":870},{},[6258],{"data":6259,"marks":6260,"value":6261,"nodeType":874},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":6263,"content":6264,"nodeType":870},{},[6265],{"data":6266,"marks":6267,"value":6268,"nodeType":874},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":6270,"content":6271,"nodeType":870},{},[6272],{"data":6273,"marks":6274,"value":6275,"nodeType":874},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":6277,"content":6281,"nodeType":1215},{"target":6278},{"sys":6279},{"id":6280,"type":1220,"linkType":1221},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":6283,"content":6284,"nodeType":944},{},[6285],{"data":6286,"marks":6287,"value":6289,"nodeType":874},{},[6288],{"type":882},"AiTM phishing has become the default phishing method",{"data":6291,"content":6292,"nodeType":870},{},[6293,6297,6305],{"data":6294,"marks":6295,"value":6296,"nodeType":874},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":6298,"content":6300,"nodeType":966},{"uri":6299},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F2025-top-phishing-trends\u002F",[6301],{"data":6302,"marks":6303,"value":6304,"nodeType":874},{},[],"62% of phishing detected by Microsoft",{"data":6306,"marks":6307,"value":6308,"nodeType":874},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":6310,"content":6311,"nodeType":870},{},[6312],{"data":6313,"marks":6314,"value":6315,"nodeType":874},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":6317,"content":6318,"nodeType":870},{},[6319],{"data":6320,"marks":6321,"value":6322,"nodeType":874},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":6324,"content":6325,"nodeType":870},{},[6326,6330,6335],{"data":6327,"marks":6328,"value":6329,"nodeType":874},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":6331,"marks":6332,"value":6334,"nodeType":874},{},[6333],{"type":882},"442% year-over-year increase",{"data":6336,"marks":6337,"value":6338,"nodeType":874},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":6340,"content":6341,"nodeType":944},{},[6342],{"data":6343,"marks":6344,"value":6346,"nodeType":874},{},[6345],{"type":882},"ClickFix is the top reported initial access vector",{"data":6348,"content":6349,"nodeType":870},{},[6350,6354,6361,6365,6372],{"data":6351,"marks":6352,"value":6353,"nodeType":874},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":6355,"content":6356,"nodeType":966},{"uri":1379},[6357],{"data":6358,"marks":6359,"value":6360,"nodeType":874},{},[],"most common initial access vector in 2025",{"data":6362,"marks":6363,"value":6364,"nodeType":874},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":6366,"content":6367,"nodeType":966},{"uri":1391},[6368],{"data":6369,"marks":6370,"value":6371,"nodeType":874},{},[],"563% increase",{"data":6373,"marks":6374,"value":6375,"nodeType":874},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":6377,"content":6378,"nodeType":870},{},[6379,6383,6388],{"data":6380,"marks":6381,"value":6382,"nodeType":874},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":6384,"marks":6385,"value":6387,"nodeType":874},{},[6386],{"type":882},"4 in 5 ClickFix payloads",{"data":6389,"marks":6390,"value":6391,"nodeType":874},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":6393,"content":6394,"nodeType":870},{},[6395],{"data":6396,"marks":6397,"value":6398,"nodeType":874},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":6400,"content":6401,"nodeType":870},{},[6402,6406,6414,6418,6424],{"data":6403,"marks":6404,"value":6405,"nodeType":874},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":6407,"content":6409,"nodeType":966},{"uri":6408},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix\u002F",[6410],{"data":6411,"marks":6412,"value":6413,"nodeType":874},{},[],"InstallFix",{"data":6415,"marks":6416,"value":6417,"nodeType":874},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":6419,"content":6420,"nodeType":966},{"uri":1562},[6421],{"data":6422,"marks":6423,"value":1552,"nodeType":874},{},[],{"data":6425,"marks":6426,"value":6427,"nodeType":874},{},[]," was a genuinely novel development.",{"data":6429,"content":6430,"nodeType":944},{},[6431],{"data":6432,"marks":6433,"value":6435,"nodeType":874},{},[6434],{"type":882},"Browser-native ClickFix: ConsentFix",{"data":6437,"content":6438,"nodeType":870},{},[6439,6443,6451,6455,6462],{"data":6440,"marks":6441,"value":6442,"nodeType":874},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":6444,"content":6446,"nodeType":966},{"uri":6445},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-debrief\u002F",[6447],{"data":6448,"marks":6449,"value":6450,"nodeType":874},{},[],"traced to APT29",{"data":6452,"marks":6453,"value":6454,"nodeType":874},{},[]," and has since been ",{"data":6456,"content":6457,"nodeType":966},{"uri":1574},[6458],{"data":6459,"marks":6460,"value":6461,"nodeType":874},{},[],"commercialized on criminal forums",{"data":6463,"marks":6464,"value":6465,"nodeType":874},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":6467,"content":6468,"nodeType":870},{},[6469],{"data":6470,"marks":6471,"value":6472,"nodeType":874},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":6474,"content":6475,"nodeType":944},{},[6476],{"data":6477,"marks":6478,"value":6480,"nodeType":874},{},[6479],{"type":882},"Attackers have pivoted to authorization attacks to get around login controls",{"data":6482,"content":6483,"nodeType":870},{},[6484,6488,6495],{"data":6485,"marks":6486,"value":6487,"nodeType":874},{},[],"Authorization attacks like device code phishing have seen a ",{"data":6489,"content":6490,"nodeType":966},{"uri":2990},[6491],{"data":6492,"marks":6493,"value":6494,"nodeType":874},{},[],"37.5x increase",{"data":6496,"marks":6497,"value":6498,"nodeType":874},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":6500,"content":6501,"nodeType":870},{},[6502],{"data":6503,"marks":6504,"value":6505,"nodeType":874},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":6507,"content":6508,"nodeType":870},{},[6509],{"data":6510,"marks":6511,"value":6512,"nodeType":874},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":6514,"content":6518,"nodeType":1215},{"target":6515},{"sys":6516},{"id":6517,"type":1220,"linkType":1221},"2WPb41lNRajdpt5pogQg8M",[],{"data":6520,"content":6521,"nodeType":870},{},[6522],{"data":6523,"marks":6524,"value":6525,"nodeType":874},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":6527,"content":6528,"nodeType":944},{},[6529],{"data":6530,"marks":6531,"value":6533,"nodeType":874},{},[6532],{"type":882},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":6535,"content":6536,"nodeType":870},{},[6537,6541,6548],{"data":6538,"marks":6539,"value":6540,"nodeType":874},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":6542,"content":6543,"nodeType":966},{"uri":1684},[6544],{"data":6545,"marks":6546,"value":6547,"nodeType":874},{},[],"Cyberhaven compromise",{"data":6549,"marks":6550,"value":6551,"nodeType":874},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":6553,"content":6554,"nodeType":870},{},[6555],{"data":6556,"marks":6557,"value":6558,"nodeType":874},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":6560,"content":6561,"nodeType":870},{},[6562,6566,6574],{"data":6563,"marks":6564,"value":6565,"nodeType":874},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":6567,"content":6568,"nodeType":966},{"uri":1684},[6569],{"data":6570,"marks":6571,"value":6573,"nodeType":874},{},[6572],{"type":974},"most malicious extensions didn't start out malicious",{"data":6575,"marks":6576,"value":6577,"nodeType":874},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":6579,"content":6580,"nodeType":870},{},[6581],{"data":6582,"marks":6583,"value":6584,"nodeType":874},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":6586,"content":6587,"nodeType":896},{},[],{"data":6589,"content":6590,"nodeType":900},{},[6591],{"data":6592,"marks":6593,"value":6595,"nodeType":874},{},[6594],{"type":882},"The evolution is playing out in public breaches",{"data":6597,"content":6598,"nodeType":870},{},[6599],{"data":6600,"marks":6601,"value":6602,"nodeType":874},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":6604,"content":6605,"nodeType":1763},{},[6606,6627,6649,6669],{"data":6607,"content":6608,"nodeType":1767},{},[6609],{"data":6610,"content":6611,"nodeType":870},{},[6612,6616,6623],{"data":6613,"marks":6614,"value":6615,"nodeType":874},{},[],"When ",{"data":6617,"content":6619,"nodeType":966},{"uri":6618},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters\u002F",[6620],{"data":6621,"marks":6622,"value":2553,"nodeType":874},{},[],{"data":6624,"marks":6625,"value":6626,"nodeType":874},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.",{"data":6628,"content":6629,"nodeType":1767},{},[6630],{"data":6631,"content":6632,"nodeType":870},{},[6633,6637,6645],{"data":6634,"marks":6635,"value":6636,"nodeType":874},{},[],"When the same collective launched ",{"data":6638,"content":6640,"nodeType":966},{"uri":6639},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign\u002F",[6641],{"data":6642,"marks":6643,"value":6644,"nodeType":874},{},[],"AiTM phishing campaigns",{"data":6646,"marks":6647,"value":6648,"nodeType":874},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":6650,"content":6651,"nodeType":1767},{},[6652],{"data":6653,"content":6654,"nodeType":870},{},[6655,6658,6665],{"data":6656,"marks":6657,"value":6615,"nodeType":874},{},[],{"data":6659,"content":6660,"nodeType":966},{"uri":1562},[6661],{"data":6662,"marks":6663,"value":6664,"nodeType":874},{},[],"APT29 deployed ConsentFix",{"data":6666,"marks":6667,"value":6668,"nodeType":874},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":6670,"content":6671,"nodeType":1767},{},[6672],{"data":6673,"content":6674,"nodeType":870},{},[6675,6679,6687],{"data":6676,"marks":6677,"value":6678,"nodeType":874},{},[],"The ",{"data":6680,"content":6682,"nodeType":966},{"uri":6681},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fidentity-attacks-in-the-wild\u002F#id-snowflake-june-2024",[6683],{"data":6684,"marks":6685,"value":6686,"nodeType":874},{},[],"Snowflake breach",{"data":6688,"marks":6689,"value":6690,"nodeType":874},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.",{"data":6692,"content":6693,"nodeType":870},{},[6694],{"data":6695,"marks":6696,"value":6697,"nodeType":874},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":6699,"content":6700,"nodeType":870},{},[6701,6705,6710],{"data":6702,"marks":6703,"value":6704,"nodeType":874},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":6706,"marks":6707,"value":6709,"nodeType":874},{},[6708],{"type":882},"29 minutes",{"data":6711,"marks":6712,"value":6713,"nodeType":874},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":6715,"content":6716,"nodeType":896},{},[],{"data":6718,"content":6719,"nodeType":900},{},[6720,6725,6731,6736,6742],{"data":6721,"marks":6722,"value":6724,"nodeType":874},{},[6723],{"type":882},"Sidenote: why we're looking at attacks ",{"data":6726,"marks":6727,"value":6730,"nodeType":874},{},[6728,6729],{"type":1144},{"type":882},"in",{"data":6732,"marks":6733,"value":6735,"nodeType":874},{},[6734],{"type":882}," the browser, not ",{"data":6737,"marks":6738,"value":6741,"nodeType":874},{},[6739,6740],{"type":1144},{"type":882},"on",{"data":6743,"marks":6744,"value":6746,"nodeType":874},{},[6745],{"type":882}," the browser",{"data":6748,"content":6749,"nodeType":870},{},[6750,6754,6762],{"data":6751,"marks":6752,"value":6753,"nodeType":874},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":6755,"content":6757,"nodeType":966},{"uri":6756},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002F2025-zero-day-review",[6758],{"data":6759,"marks":6760,"value":6761,"nodeType":874},{},[],"historic low of 9%",{"data":6763,"marks":6764,"value":6765,"nodeType":874},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":6767,"content":6768,"nodeType":870},{},[6769],{"data":6770,"marks":6771,"value":6772,"nodeType":874},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":6774,"content":6775,"nodeType":870},{},[6776],{"data":6777,"marks":6778,"value":6779,"nodeType":874},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":6781,"content":6782,"nodeType":896},{},[],{"data":6784,"content":6785,"nodeType":900},{},[6786],{"data":6787,"marks":6788,"value":6790,"nodeType":874},{},[6789],{"type":882},"What hasn't changed",{"data":6792,"content":6793,"nodeType":870},{},[6794,6798,6806],{"data":6795,"marks":6796,"value":6797,"nodeType":874},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":6799,"content":6801,"nodeType":966},{"uri":6800},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks",[6802],{"data":6803,"marks":6804,"value":6805,"nodeType":874},{},[],"GitHub",{"data":6807,"marks":6808,"value":6809,"nodeType":874},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":6811,"content":6812,"nodeType":870},{},[6813],{"data":6814,"marks":6815,"value":6816,"nodeType":874},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":6818,"content":6819,"nodeType":870},{},[6820],{"data":6821,"marks":6822,"value":6823,"nodeType":874},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":6825,"content":6826,"nodeType":870},{},[6827,6831,6838],{"data":6828,"marks":6829,"value":6830,"nodeType":874},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":6832,"content":6834,"nodeType":966},{"uri":6833},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fbrowser-identity-attacks-matrix",[6835],{"data":6836,"marks":6837,"value":6805,"nodeType":874},{},[],{"data":6839,"marks":6840,"value":1581,"nodeType":874},{},[],{"data":6842,"content":6843,"nodeType":896},{},[],{"data":6845,"content":6846,"nodeType":900},{},[6847],{"data":6848,"marks":6849,"value":6851,"nodeType":874},{},[6850],{"type":882},"Looking ahead",{"data":6853,"content":6854,"nodeType":870},{},[6855],{"data":6856,"marks":6857,"value":6858,"nodeType":874},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":6860,"content":6861,"nodeType":1763},{},[6862,6872,6882],{"data":6863,"content":6864,"nodeType":1767},{},[6865],{"data":6866,"content":6867,"nodeType":870},{},[6868],{"data":6869,"marks":6870,"value":6871,"nodeType":874},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":6873,"content":6874,"nodeType":1767},{},[6875],{"data":6876,"content":6877,"nodeType":870},{},[6878],{"data":6879,"marks":6880,"value":6881,"nodeType":874},{},[],"ClickFix has spawned fully browser-native variants.",{"data":6883,"content":6884,"nodeType":1767},{},[6885],{"data":6886,"content":6887,"nodeType":870},{},[6888],{"data":6889,"marks":6890,"value":6891,"nodeType":874},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":6893,"content":6894,"nodeType":870},{},[6895],{"data":6896,"marks":6897,"value":6898,"nodeType":874},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":6900,"content":6901,"nodeType":870},{},[6902,6906,6913],{"data":6903,"marks":6904,"value":6905,"nodeType":874},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":6907,"content":6908,"nodeType":966},{"uri":6181},[6909],{"data":6910,"marks":6911,"value":6912,"nodeType":874},{},[],"explore the matrix here",{"data":6914,"marks":6915,"value":1581,"nodeType":874},{},[],{"data":6917,"content":6918,"nodeType":870},{},[6919,6923,6931],{"data":6920,"marks":6921,"value":6922,"nodeType":874},{},[],"You can also read our recent ",{"data":6924,"content":6926,"nodeType":966},{"uri":6925},"https:\u002F\u002Fpushsecurity.com\u002Fthank-you\u002Fbrowser-attacks-report",[6927],{"data":6928,"marks":6929,"value":6930,"nodeType":874},{},[],"browser attack techniques report",{"data":6932,"marks":6933,"value":6934,"nodeType":874},{},[]," for more information.",{"data":6936,"content":6940,"nodeType":1215},{"target":6937},{"sys":6938},{"id":6939,"type":1220,"linkType":1221},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":6942,"content":6943,"nodeType":896},{},[],{"data":6945,"content":6946,"nodeType":870},{},[6947],{"data":6948,"marks":6949,"value":6950,"nodeType":874},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":6952,"content":6953,"nodeType":870},{},[6954,6957,6963],{"data":6955,"marks":6956,"value":2483,"nodeType":874},{},[],{"data":6958,"content":6959,"nodeType":966},{"uri":1102},[6960],{"data":6961,"marks":6962,"value":2490,"nodeType":874},{},[],{"data":6964,"marks":6965,"value":2494,"nodeType":874},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":6971},[6972,6974],{"sys":6973,"name":2007},{"id":2006},{"sys":6975,"name":334},{"id":2010},{"items":6977},[6978],{"fullName":2014,"firstName":2015,"jobTitle":2016,"profilePicture":6979},{"url":2018},"blog\u002Fbrowser-threat-landscape-mid-year-update-2026",{"json":6982},{"data":6983,"content":6984,"nodeType":866},{},[6985],{"data":6986,"content":6987,"nodeType":870},{},[6988],{"data":6989,"marks":6990,"value":3811,"nodeType":874},{},[],{"id":2516,"publishedAt":6992},"2026-08-26T11:56:53.261Z",{"items":6994},[6995,6997],{"sys":6996,"name":2007},{"id":2006},{"sys":6998,"name":334},{"id":2010},{"items":7000},[7001,7003,7005,7007,7009,7011,7013,7015,7017,7019,7021,7023,7025,7027,7029,7031,7033,7035,7037,7039,7041,7043,7045,7047,7049],{"sys":7002,"name":235,"slug":236,"tier":45},{"id":232},{"sys":7004,"name":519,"slug":520,"tier":45},{"id":516},{"sys":7006,"name":422,"slug":423,"tier":45},{"id":419},{"sys":7008,"name":262,"slug":263,"tier":45},{"id":259},{"sys":7010,"name":528,"slug":529,"tier":45},{"id":525},{"sys":7012,"name":643,"slug":644,"tier":45},{"id":640},{"sys":7014,"name":599,"slug":600,"tier":45},{"id":596},{"sys":7016,"name":440,"slug":441,"tier":45},{"id":437},{"sys":7018,"name":413,"slug":414,"tier":45},{"id":410},{"sys":7020,"name":395,"slug":396,"tier":45},{"id":392},{"sys":7022,"name":564,"slug":565,"tier":45},{"id":561},{"sys":7024,"name":484,"slug":485,"tier":45},{"id":481},{"sys":7026,"name":457,"slug":458,"tier":45},{"id":454},{"sys":7028,"name":431,"slug":432,"tier":45},{"id":428},{"sys":7030,"name":555,"slug":556,"tier":45},{"id":552},{"sys":7032,"name":352,"slug":353,"tier":45},{"id":349},{"sys":7034,"name":466,"slug":467,"tier":45},{"id":463},{"sys":7036,"name":502,"slug":503,"tier":45},{"id":499},{"sys":7038,"name":316,"slug":317,"tier":45},{"id":313},{"sys":7040,"name":307,"slug":308,"tier":45},{"id":304},{"sys":7042,"name":253,"slug":254,"tier":45},{"id":250},{"sys":7044,"name":634,"slug":635,"tier":31},{"id":631},{"sys":7046,"name":510,"slug":511,"tier":31},{"id":507},{"sys":7048,"name":537,"slug":538,"tier":31},{"id":534},{"sys":7050,"name":271,"slug":272,"tier":31},{"id":268},"s-m4f3m6SWAIErhOTXNAHECtIUwlHBoZ_uFaPQsee20",{"id":7053,"title":7054,"authorsCollection":7055,"content":7063,"extension":219,"faqItemsCollection":7202,"faqTitle":60,"featured":6,"hashTags":7204,"meta":7209,"metaTitle":7210,"ogImage":60,"postType":7211,"publishedDate":7212,"relatedBlogPostsCollection":7213,"slug":7924,"stem":7925,"subtitle":60,"summary":7926,"synopsis":7937,"sys":7938,"tagsCollection":7941,"topicsCollection":7947,"__hash__":7961},"blog\u002Fblog\u002Fcase-study-business-email-compromise-bec-attack-nearly-cost-us-millions.json","Case study: Business Email Compromise (BEC) attack nearly cost us millions",{"items":7056},[7057],{"fullName":7058,"firstName":7059,"jobTitle":7060,"socialLinks":60,"profilePicture":7061},"Tyrone Erasmus","Tyrone","Co-founder \u002F CTO",{"url":7062},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F5rkMblymL7lG4pZBiYzWo6\u002F26f0da21be8fc252b13b62aacc22d19d\u002FPush_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-22.jpg",{"json":7064,"links":7165},{"data":7065,"content":7066,"nodeType":866},{},[7067,7074,7077,7084,7091,7097,7104,7111,7118,7125,7132,7138,7145,7151,7158],{"data":7068,"content":7069,"nodeType":870},{},[7070],{"data":7071,"marks":7072,"value":7073,"nodeType":874},{},[],"The following is a personal account from the owner of an engineering consulting and projects company of how a Business Email Compromise (BEC) attack played out against his company, almost costing them millions.",{"data":7075,"content":7076,"nodeType":896},{},[],{"data":7078,"content":7079,"nodeType":870},{},[7080],{"data":7081,"marks":7082,"value":7083,"nodeType":874},{},[],"It started with a phone call from one of our customers. They wanted to make a payment to us and asked to confirm that our banking details had changed. They had not. Our customer explained they had received another email from us after our original invoice, stating that our banking details had changed.",{"data":7085,"content":7086,"nodeType":870},{},[7087],{"data":7088,"marks":7089,"value":7090,"nodeType":874},{},[],"So many questions ran through my mind. I assured them our details had not changed and asked them to send me the email that they had received.",{"data":7092,"content":7096,"nodeType":1215},{"target":7093},{"sys":7094},{"id":7095,"type":1220,"linkType":1221},"7oS3I99lcdKeHo0a4SM7f2",[],{"data":7098,"content":7099,"nodeType":870},{},[7100],{"data":7101,"marks":7102,"value":7103,"nodeType":874},{},[],"There it was. It even had our company logo and signature at the bottom.",{"data":7105,"content":7106,"nodeType":870},{},[7107],{"data":7108,"marks":7109,"value":7110,"nodeType":874},{},[],"We didn't know how the attacker got access to that email account and we assumed they were logging in and reading emails. So we changed the password on the affected email account and moved on.",{"data":7112,"content":7113,"nodeType":870},{},[7114],{"data":7115,"marks":7116,"value":7117,"nodeType":874},{},[],"A day later, the attacker followed up again with the customer and we got another phone call. After having a really difficult conversation, we had to dig deeper and find out what was going on. So we contacted our IT provider and launched an investigation.",{"data":7119,"content":7120,"nodeType":870},{},[7121],{"data":7122,"marks":7123,"value":7124,"nodeType":874},{},[],"We found that the email we sent containing the invoice was also forwarded to an external Gmail address. The attacker had also registered a visually similar domain name and cloned the look and feel of our emails to reply to our customers and trick them into believing it was from us. This 1-letter difference in the domain is highlighted in the image above.",{"data":7126,"content":7127,"nodeType":870},{},[7128],{"data":7129,"marks":7130,"value":7131,"nodeType":874},{},[],"The primary culprit behind the forwarding of the message was then discovered. A mail rule had been created that forwarded emails with the word \"payment\" (among others) in the subject.",{"data":7133,"content":7137,"nodeType":1215},{"target":7134},{"sys":7135},{"id":7136,"type":1220,"linkType":1221},"2aafjsTsqy7ljL5hh8c3MO",[],{"data":7139,"content":7140,"nodeType":870},{},[7141],{"data":7142,"marks":7143,"value":7144,"nodeType":874},{},[],"Some senior employees had received phishing emails a few days prior to this incident taking place. The email took them to a fake Microsoft login page and unfortunately one of them entered their password.",{"data":7146,"content":7150,"nodeType":1215},{"target":7147},{"sys":7148},{"id":7149,"type":1220,"linkType":1221},"3LqNjM8OlZLI6XQVtLaOe1",[],{"data":7152,"content":7153,"nodeType":870},{},[7154],{"data":7155,"marks":7156,"value":7157,"nodeType":874},{},[],"This stolen password was used to log in and set up the forwarding rule. This closed the loop and we understood what happened fully.",{"data":7159,"content":7160,"nodeType":870},{},[7161],{"data":7162,"marks":7163,"value":7164,"nodeType":874},{},[],"We learned a lot from the incident (and aged a few years!) and the main recommendations from our IT provider were to delete the mail rule, change the password again and enable MFA on all our email accounts. Had this customer paid this invoice without questioning the change of details, we would have lost millions.",{"entries":7166},{"hyperlink":7167,"inline":7168,"block":7169},[],[],[7170,7178,7195],{"sys":7171,"__typename":4929,"title":7172,"caption":7173,"layoutMode":60,"file":7174},{"id":7095},"BEC example","An email sent from the attacker, executing the final stages of the Business Email Compromise (BEC) attack.",{"url":7175,"width":7176,"height":7177},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F50pvGtctkN6sOtexSqU0pX\u002Fc212ca33b51ab9804bb944df8a45068f\u002F2021-06-18_11-24-48.png",670,585,{"sys":7179,"__typename":7180,"content":7181,"title":7192,"buttonText":7193,"buttonUrl":60,"signupRedirectUrl":7194},{"id":7136},"ActionBlockComponent",{"json":7182},{"data":7183,"content":7184,"nodeType":866},{},[7185],{"data":7186,"content":7187,"nodeType":870},{},[7188],{"data":7189,"marks":7190,"value":7191,"nodeType":874},{},[],"It takes less than two minutes to check all your Office 365 or Google Workspace mailboxes.","Use our free tool to check your user's mailboxes for malicious mail rules","Check now","\u002Fapp\u002Ffeature\u002Fdetect-malicious-mail-rules\u002F",{"sys":7196,"__typename":4929,"title":7197,"caption":7197,"layoutMode":60,"file":7198},{"id":7149},"Microsoft phishing page",{"url":7199,"width":7200,"height":7201},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FRaFBDuo2BmCqZvnNRlX5E\u002F51599d6d23ee89408b4a07a794f199fa\u002F2021-06-18_15-47-24.png",731,683,{"items":7203},[],[7205,263,7206,7207,7208],"businessemailcompromise","mailrules","office365","warstory",{},"Business Email Compromise (BEC) attack nearly cost millions","breach-analysis","2021-06-14T00:00:00.000+01:00",{"items":7214},[7215,7587],{"__typename":1126,"sys":7216,"content":7218,"title":7566,"synopsis":7567,"hashTags":7568,"publishedDate":7571,"slug":7572,"tagsCollection":7573,"authorsCollection":7579},{"id":7217},"2zZ8kxP0t8Smi9b6hpT34k",{"json":7219},{"data":7220,"content":7221,"nodeType":866},{},[7222,7229,7235,7242,7262,7291,7298,7382,7401,7404,7411,7429,7436,7443,7446,7453,7500,7507,7524,7531,7534,7542,7549],{"data":7223,"content":7224,"nodeType":870},{},[7225],{"data":7226,"marks":7227,"value":7228,"nodeType":874},{},[],"Mail rules are a handy feature found in most email clients. You might have used them to forward emails to your teammates while you’re off sipping Piña coladas, or to move incoming email from that spammy colleague to the ‘don’t read’ folder.",{"data":7230,"content":7234,"nodeType":1215},{"target":7231},{"sys":7232},{"id":7233,"type":1220,"linkType":1221},"7xLVXoCCjansV1u50e2pbM",[],{"data":7236,"content":7237,"nodeType":870},{},[7238],{"data":7239,"marks":7240,"value":7241,"nodeType":874},{},[],"Sadly for us defenders, they’re just as useful for attackers. After gaining access to a victim's account, attackers will often create a mail rule inside their mailbox as a way to maintain stealthy access. This mail rule can do anything a normal mail rule could but is usually used to forward emails matching sensitive keywords, like ‘invoice’ or ‘payment’, to an external email address controlled by the attacker.",{"data":7243,"content":7244,"nodeType":7261},{},[7245],{"data":7246,"content":7247,"nodeType":870},{},[7248,7252,7257],{"data":7249,"marks":7250,"value":7251,"nodeType":874},{},[],"This gives the ",{"data":7253,"marks":7254,"value":7256,"nodeType":874},{},[7255],{"type":882},"attacker persistent access to the mailbox",{"data":7258,"marks":7259,"value":7260,"nodeType":874},{},[],". Even if the victim's password is changed, they turn on MFA, or their workstation is completely rebuilt - as long as the rule stays in place, it remains effective.","blockquote",{"data":7263,"content":7264,"nodeType":870},{},[7265,7269,7278,7282,7287],{"data":7266,"marks":7267,"value":7268,"nodeType":874},{},[],"As another example, in ",{"data":7270,"content":7272,"nodeType":966},{"uri":7271},"https:\u002F\u002Fwww.reddit.com\u002Fr\u002Fsysadmin\u002Fcomments\u002F6l63x6\u002Fmalicious_outlook_rules\u002F",[7273],{"data":7274,"marks":7275,"value":7277,"nodeType":874},{},[7276],{"type":974},"this Reddit thread",{"data":7279,"marks":7280,"value":7281,"nodeType":874},{},[]," the author describes how mail rules were used to ",{"data":7283,"marks":7284,"value":7286,"nodeType":874},{},[7285],{"type":1144},"delete ",{"data":7288,"marks":7289,"value":7290,"nodeType":874},{},[],"any emails the affected user received from the company’s Chief Finance Officer (CFO) so that the attacker could pretend to be the CFO, sending them fake emails to convince them to transfer out company funds.",{"data":7292,"content":7293,"nodeType":870},{},[7294],{"data":7295,"marks":7296,"value":7297,"nodeType":874},{},[],"Business Email Compromise (BEC) like this is the most popular type of attack at the moment, causing damages well into the billions according to the FBI. Here are just a few publicly documented breaches involving mail rules:",{"data":7299,"content":7300,"nodeType":1763},{},[7301,7321,7341,7362],{"data":7302,"content":7303,"nodeType":1767},{},[7304],{"data":7305,"content":7306,"nodeType":870},{},[7307,7310,7318],{"data":7308,"marks":7309,"value":21,"nodeType":874},{},[],{"data":7311,"content":7313,"nodeType":966},{"uri":7312},"https:\u002F\u002Fwww.sans.org\u002Fdataincident2020",[7314],{"data":7315,"marks":7316,"value":7317,"nodeType":874},{},[],"SANS: 28,000 PII records lost",{"data":7319,"marks":7320,"value":21,"nodeType":874},{},[],{"data":7322,"content":7323,"nodeType":1767},{},[7324],{"data":7325,"content":7326,"nodeType":870},{},[7327,7330,7338],{"data":7328,"marks":7329,"value":21,"nodeType":874},{},[],{"data":7331,"content":7333,"nodeType":966},{"uri":7332},"https:\u002F\u002Fwww.ic3.gov\u002FMedia\u002FNews\u002F2020\u002F201204.pdf",[7334],{"data":7335,"marks":7336,"value":7337,"nodeType":874},{},[],"FBI report: BEC involving malicious mail rules costs company $175k",{"data":7339,"marks":7340,"value":21,"nodeType":874},{},[],{"data":7342,"content":7343,"nodeType":1767},{},[7344],{"data":7345,"content":7346,"nodeType":870},{},[7347,7350,7358],{"data":7348,"marks":7349,"value":21,"nodeType":874},{},[],{"data":7351,"content":7353,"nodeType":966},{"uri":7352},"https:\u002F\u002Fwww.reddit.com\u002Fr\u002FOffice365\u002Fcomments\u002Fej0wkx\u002Fhacker_created_forwarding_rules_for_users_account\u002F",[7354],{"data":7355,"marks":7356,"value":7357,"nodeType":874},{},[],"Reddit thread: Hacker created forwarding rule for user's account",{"data":7359,"marks":7360,"value":7361,"nodeType":874},{},[]," ",{"data":7363,"content":7364,"nodeType":1767},{},[7365],{"data":7366,"content":7367,"nodeType":870},{},[7368,7371,7379],{"data":7369,"marks":7370,"value":21,"nodeType":874},{},[],{"data":7372,"content":7374,"nodeType":966},{"uri":7373},"https:\u002F\u002Fwww.microsoft.com\u002Fsecurity\u002Fblog\u002F2021\u002F06\u002F14\u002Fbehind-the-scenes-of-business-email-compromise-using-cross-domain-threat-data-to-disrupt-a-large-bec-infrastructure\u002F",[7375],{"data":7376,"marks":7377,"value":7378,"nodeType":874},{},[],"Microsoft case study of BEC operation using mail rules",{"data":7380,"marks":7381,"value":21,"nodeType":874},{},[],{"data":7383,"content":7384,"nodeType":870},{},[7385,7389,7397],{"data":7386,"marks":7387,"value":7388,"nodeType":874},{},[],"You can read ",{"data":7390,"content":7392,"nodeType":966},{"uri":7391},"\u002Fblog\u002Fcase-study-business-email-compromise-bec-attack-nearly-cost-us-millions\u002F",[7393],{"data":7394,"marks":7395,"value":7396,"nodeType":874},{},[],"this case study",{"data":7398,"marks":7399,"value":7400,"nodeType":874},{},[]," of a how a real Business Email Compromise (BEC) attack played out at an engineering firm that we interviewed.",{"data":7402,"content":7403,"nodeType":896},{},[],{"data":7405,"content":7406,"nodeType":900},{},[7407],{"data":7408,"marks":7409,"value":7410,"nodeType":874},{},[],"How likely is this to actually happen?",{"data":7412,"content":7413,"nodeType":870},{},[7414,7417,7425],{"data":7415,"marks":7416,"value":21,"nodeType":874},{},[],{"data":7418,"content":7420,"nodeType":966},{"uri":7419},"https:\u002F\u002Fattack.mitre.org\u002Ftechniques\u002FT1114\u002F003\u002F",[7421],{"data":7422,"marks":7423,"value":7424,"nodeType":874},{},[],"MITRE lists threat groups",{"data":7426,"marks":7427,"value":7428,"nodeType":874},{},[]," that have been known to use mail rules in this way as part of targeted attacks. However, most often, this technique is used opportunistically.",{"data":7430,"content":7431,"nodeType":870},{},[7432],{"data":7433,"marks":7434,"value":7435,"nodeType":874},{},[],"Attackers run phishing campaigns containing thousands of harvested emails from multiple companies. A classic scenario is to trick a user into logging in to a fake Office 365 or Google Workspace login screen, stealing their credentials. Those credentials are then used to create a malicious mail rule inside the compromised user's mailbox. For scale and speed, this process is completely automated.",{"data":7437,"content":7438,"nodeType":870},{},[7439],{"data":7440,"marks":7441,"value":7442,"nodeType":874},{},[],"Similarly a mail rule could be created automatically as the result of a user’s workstation becoming infected with malware.",{"data":7444,"content":7445,"nodeType":896},{},[],{"data":7447,"content":7448,"nodeType":900},{},[7449],{"data":7450,"marks":7451,"value":7452,"nodeType":874},{},[],"How to defend against this type of attack?",{"data":7454,"content":7455,"nodeType":870},{},[7456,7460,7468,7472,7483,7487,7497],{"data":7457,"marks":7458,"value":7459,"nodeType":874},{},[],"The first step is to check your mailboxes to make sure no malicious mail rules have already been created. On Office 365, this will require rolling some PowerShell; on Google Workspace, you'll need to query the APIs (we discuss some detail of these options ",{"data":7461,"content":7463,"nodeType":966},{"uri":7462},"\u002Fblog\u002Fshould-you-disable-external-email-auto-forwarding\u002F",[7464],{"data":7465,"marks":7466,"value":7467,"nodeType":874},{},[],"in this post",{"data":7469,"marks":7470,"value":7471,"nodeType":874},{},[],"). Or you can save yourself some pain and use the free tool linked above, which we built for this very purpose. If you find rules that don't look right, follow these guides for what to do next on ",{"data":7473,"content":7477,"nodeType":7482},{"target":7474},{"sys":7475},{"id":7476,"type":1220,"linkType":1221},"e4805bba-2531-4250-bdcc-ab996dd33519",[7478],{"data":7479,"marks":7480,"value":7481,"nodeType":874},{},[],"Office 365","entry-hyperlink",{"data":7484,"marks":7485,"value":7486,"nodeType":874},{},[]," or ",{"data":7488,"content":7492,"nodeType":7482},{"target":7489},{"sys":7490},{"id":7491,"type":1220,"linkType":1221},"50dab356-e78b-479d-ad45-a07b898b5ec4",[7493],{"data":7494,"marks":7495,"value":7496,"nodeType":874},{},[],"Google Workspace",{"data":7498,"marks":7499,"value":1581,"nodeType":874},{},[],{"data":7501,"content":7502,"nodeType":870},{},[7503],{"data":7504,"marks":7505,"value":7506,"nodeType":874},{},[],"It's also possible to stop users from creating auto-forwarding rules altogether. If no one is using the feature, this is probably a good idea - you might as well reduce risk. However, there are plenty of situations where teams benefit from the automation and efficiency mail rules bring. Security works best when it enables the business to work securely, rather than constraining it - leaving the feature available whilst managing the risk through detection is a good option as well.",{"data":7508,"content":7509,"nodeType":870},{},[7510,7514,7521],{"data":7511,"marks":7512,"value":7513,"nodeType":874},{},[],"We discuss more about the pros and cons of disabling mail rules and some options for some security controls you can implement so that you can keep them enabled ",{"data":7515,"content":7516,"nodeType":966},{"uri":7462},[7517],{"data":7518,"marks":7519,"value":7520,"nodeType":874},{},[],"in this blog post",{"data":7522,"marks":7523,"value":1581,"nodeType":874},{},[],{"data":7525,"content":7526,"nodeType":870},{},[7527],{"data":7528,"marks":7529,"value":7530,"nodeType":874},{},[],"If you'd like, try Push for free and we'll spot any suspicious mail rules, then work with employees to make sure the mail rule wasn't something they created for a legitimate use. If they haven't, we'll notify you to take action and investigate a potential incident. Find out more here.",{"data":7532,"content":7533,"nodeType":896},{},[],{"data":7535,"content":7536,"nodeType":900},{},[7537],{"data":7538,"marks":7539,"value":7541,"nodeType":874},{},[7540],{"type":882},"Learn more",{"data":7543,"content":7544,"nodeType":870},{},[7545],{"data":7546,"marks":7547,"value":7548,"nodeType":874},{},[],"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":7550,"content":7551,"nodeType":870},{},[7552,7556,7563],{"data":7553,"marks":7554,"value":7555,"nodeType":874},{},[],"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":7557,"content":7559,"nodeType":966},{"uri":7558},"https:\u002F\u002Fpushsecurity.com\u002Fdemo?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[7560],{"data":7561,"marks":7562,"value":1991,"nodeType":874},{},[],{"data":7564,"marks":7565,"value":1581,"nodeType":874},{},[],"Email security: How hackers use mail rules to access your inbox","After phishing campaigns target Office 365 and Google Workspace users, malicious mail rules are automatically added to the user’s mailbox. Take steps to defend.",[7205,263,7206,7207,7569,7570],"googleworkspace","emailsecurity","2021-06-10T00:00:00.000+01:00","email-security-how-hackers-use-mail-rules-to-access-your-inbox",{"items":7574},[7575,7577],{"sys":7576,"name":2007},{"id":2006},{"sys":7578,"name":334},{"id":2010},{"items":7580},[7581],{"fullName":7582,"firstName":7583,"jobTitle":7584,"profilePicture":7585},"Andy Waugh","Andy","VP Product",{"url":7586},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3Rf76rJn6S9inMb4dUnAIJ\u002F0a787f8141d05b95300e2fe77c4493fa\u002FDSC_6868.jpg",{"__typename":1126,"sys":7588,"content":7590,"title":7909,"synopsis":7910,"hashTags":7911,"publishedDate":7912,"slug":7913,"tagsCollection":7914,"authorsCollection":7920},{"id":7589},"roVnr9Z2sHDPGtemZUE7u",{"json":7591},{"data":7592,"content":7593,"nodeType":866},{},[7594,7613,7620,7649,7665,7672,7679,7686,7694,7701,7721,7728,7748,7753,7761,7768,7788,7796,7815,7823,7830,7883,7890,7897,7903],{"data":7595,"content":7596,"nodeType":870},{},[7597,7601,7609],{"data":7598,"marks":7599,"value":7600,"nodeType":874},{},[],"Mail rules can be abused by attackers to get stealthy, persistent access to a mailbox, leak data and facilitate high-impact Business Email Compromise (",{"data":7602,"content":7604,"nodeType":966},{"uri":7603},"\u002Fblog\u002Femail-security-how-hackers-use-mail-rules-to-access-your-inbox\u002F",[7605],{"data":7606,"marks":7607,"value":7608,"nodeType":874},{},[],"read more here",{"data":7610,"marks":7611,"value":7612,"nodeType":874},{},[],"). So, lots of organisations decide to ban external auto-forwarding of email altogether. The question is, is this a good move?",{"data":7614,"content":7615,"nodeType":944},{},[7616],{"data":7617,"marks":7618,"value":7619,"nodeType":874},{},[],"This is damage limitation, not prevention",{"data":7621,"content":7622,"nodeType":870},{},[7623,7627,7632,7636,7645],{"data":7624,"marks":7625,"value":7626,"nodeType":874},{},[],"It’s important to recognise that adding a malicious mail rule to a user’s mailbox is a ",{"data":7628,"marks":7629,"value":7631,"nodeType":874},{},[7630],{"type":882},"post-compromise activity",{"data":7633,"marks":7634,"value":7635,"nodeType":874},{},[],". That is, an attacker has already compromised the victim somehow - compromised their password, deployed malware on their machine, performed consent phishing etc. - they already have access to their mailbox. At this point, you should assume all data in the mailbox is compromised anyway. (See here for “",{"data":7637,"content":7640,"nodeType":7482},{"target":7638},{"sys":7639},{"id":7476,"type":1220,"linkType":1221},[7641],{"data":7642,"marks":7643,"value":7644,"nodeType":874},{},[],"what to do if I find a malicious mail rule?",{"data":7646,"marks":7647,"value":7648,"nodeType":874},{},[],"”)",{"data":7650,"content":7651,"nodeType":870},{},[7652,7656,7661],{"data":7653,"marks":7654,"value":7655,"nodeType":874},{},[],"Preventing external auto-forwarding rules therefore reduces",{"data":7657,"marks":7658,"value":7660,"nodeType":874},{},[7659],{"type":882}," further potential impact",{"data":7662,"marks":7663,"value":7664,"nodeType":874},{},[]," to a compromised account - worth doing if no one is using the feature, but what if your users are?",{"data":7666,"content":7667,"nodeType":944},{},[7668],{"data":7669,"marks":7670,"value":7671,"nodeType":874},{},[],"Security vs. user experience",{"data":7673,"content":7674,"nodeType":870},{},[7675],{"data":7676,"marks":7677,"value":7678,"nodeType":874},{},[],"Good security should enable a business and its users to work securely rather than constrain it. Controls that restrict users’ productivity or are seen as a nuisance will be bypassed and although you might prevent a potential attack type, you’ll ultimately cause less secure behaviour from your users.",{"data":7680,"content":7681,"nodeType":870},{},[7682],{"data":7683,"marks":7684,"value":7685,"nodeType":874},{},[],"With that in mind, if external auto-forwarding of email is something your users need - and there are plenty of legitimate scenarios where this may be the case - you should be considering how to manage the risk, rather than eliminate it. The good news is this is totally doable. Equally, if none, or most of your users don’t need this feature, you should of course disable it to reduce your overall risk.",{"data":7687,"content":7688,"nodeType":870},{},[7689],{"data":7690,"marks":7691,"value":7693,"nodeType":874},{},[7692],{"type":882},"Managing the risk on Exchange Online for Microsoft 365 through detection alone",{"data":7695,"content":7696,"nodeType":870},{},[7697],{"data":7698,"marks":7699,"value":7700,"nodeType":874},{},[],"Managing the risk of external auto-forwarding email rules means making sure you’re alerted when one is created. ",{"data":7702,"content":7703,"nodeType":870},{},[7704,7708,7717],{"data":7705,"marks":7706,"value":7707,"nodeType":874},{},[],"If you’re using Exchange Online for Microsoft 365, ",{"data":7709,"content":7711,"nodeType":966},{"uri":7710},"https:\u002F\u002Fprotection.office.com\u002Falertpolicies",[7712],{"data":7713,"marks":7714,"value":7716,"nodeType":874},{},[7715],{"type":974},"an informational alert policy",{"data":7718,"marks":7719,"value":7720,"nodeType":874},{},[]," - “Creation of forwarding\u002Fredirect rule” - can be enabled so alerts of this type of suspicious rules will be sent to tenant admins when they are created in future. ",{"data":7722,"content":7723,"nodeType":870},{},[7724],{"data":7725,"marks":7726,"value":7727,"nodeType":874},{},[],"\u002Fprod",{"data":7729,"content":7730,"nodeType":870},{},[7731,7735,7744],{"data":7732,"marks":7733,"value":7734,"nodeType":874},{},[],"The downside of this approach is it isn’t possible to look retrospectively (",{"data":7736,"content":7738,"nodeType":966},{"uri":7737},"https:\u002F\u002Fgcits.com\u002Fknowledge-base\u002Ffind-inbox-rules-forward-mail-externally-office-365-powershell\u002F",[7739],{"data":7740,"marks":7741,"value":7743,"nodeType":874},{},[7742],{"type":974},"without using PowerShell",{"data":7745,"marks":7746,"value":7747,"nodeType":874},{},[],") so alerts will only fire on future creation of forwarding rules. Additionally, alerts also fire for internal forwarding rules which can generate a lot of noise when looking specifically for malicious rules. ",{"data":7749,"content":7752,"nodeType":1215},{"target":7750},{"sys":7751},{"id":7136,"type":1220,"linkType":1221},[],{"data":7754,"content":7755,"nodeType":870},{},[7756],{"data":7757,"marks":7758,"value":7760,"nodeType":874},{},[7759],{"type":882},"Managing the risk on Exchange Online for Microsoft 365  through detection & prevention",{"data":7762,"content":7763,"nodeType":870},{},[7764],{"data":7765,"marks":7766,"value":7767,"nodeType":874},{},[],"In addition to being alerted when rules are created, you can take steps to either disallow external auto-forwarding rules altogether, or prevent them taking effect. You might think disallowing their creation is better but if you can permit creation but stop them from taking effect, you keep a high-fidelity detection of account compromise, without adding any additional risk.",{"data":7769,"content":7770,"nodeType":870},{},[7771,7775,7784],{"data":7772,"marks":7773,"value":7774,"nodeType":874},{},[],"In Exchange Online for Microsoft 365, you can achieve this with ",{"data":7776,"content":7778,"nodeType":966},{"uri":7777},"https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fmicrosoft-365\u002Fsecurity\u002Foffice-365-security\u002Fexternal-email-forwarding?view=o365-worldwide",[7779],{"data":7780,"marks":7781,"value":7783,"nodeType":874},{},[7782],{"type":974},"outbound spam filter policies",{"data":7785,"marks":7786,"value":7787,"nodeType":874},{},[]," to automatically stop any emails auto-forwarded out of your organisation. If an attacker creates a malicious auto-forwarding rule, any forwarded mail will be blocked by the spam filter; if you have your alerts set up correctly, you’ll still receive an alert about the new malicious rule.",{"data":7789,"content":7790,"nodeType":870},{},[7791],{"data":7792,"marks":7793,"value":7795,"nodeType":874},{},[7794],{"type":882},"Managing the risk on Gmail for Google Workspace",{"data":7797,"content":7798,"nodeType":870},{},[7799,7803,7812],{"data":7800,"marks":7801,"value":7802,"nodeType":874},{},[],"Google Workspace only allows complete prevention, such that your users (and attackers) are not able to create forwarding settings. If you decide that is right for you, you can disable automatic forwarding entirely by ",{"data":7804,"content":7806,"nodeType":966},{"uri":7805},"https:\u002F\u002Fsupport.google.com\u002Fa\u002Fanswer\u002F2491924?hl=en",[7807],{"data":7808,"marks":7809,"value":7811,"nodeType":874},{},[7810],{"type":974},"following these instructions",{"data":7813,"marks":7814,"value":1581,"nodeType":874},{},[],{"data":7816,"content":7817,"nodeType":870},{},[7818],{"data":7819,"marks":7820,"value":7822,"nodeType":874},{},[7821],{"type":882},"Managing the risk using the Push platform",{"data":7824,"content":7825,"nodeType":870},{},[7826],{"data":7827,"marks":7828,"value":7829,"nodeType":874},{},[],"Using the Push platform makes managing this risk a lot easier with less of your time:",{"data":7831,"content":7832,"nodeType":1763},{},[7833,7843,7853,7863,7873],{"data":7834,"content":7835,"nodeType":1767},{},[7836],{"data":7837,"content":7838,"nodeType":870},{},[7839],{"data":7840,"marks":7841,"value":7842,"nodeType":874},{},[],"Connect your platform with a few clicks and we’ll sweep your estate for any suspicious rules currently in place.",{"data":7844,"content":7845,"nodeType":1767},{},[7846],{"data":7847,"content":7848,"nodeType":870},{},[7849],{"data":7850,"marks":7851,"value":7852,"nodeType":874},{},[],"Get alerts via email or ChatOps (Slack or Teams) when new rules are created. Triage and deal with them directly from the email or chat platform.",{"data":7854,"content":7855,"nodeType":1767},{},[7856],{"data":7857,"content":7858,"nodeType":870},{},[7859],{"data":7860,"marks":7861,"value":7862,"nodeType":874},{},[],"Use our ChatOps features to ask users directly if they recognise a rule when you’re unsure. You can even automate this so user feedback is already collected by the time you come to triage.",{"data":7864,"content":7865,"nodeType":1767},{},[7866],{"data":7867,"content":7868,"nodeType":870},{},[7869],{"data":7870,"marks":7871,"value":7872,"nodeType":874},{},[],"Disable rules directly from the platform for quick response.",{"data":7874,"content":7875,"nodeType":1767},{},[7876],{"data":7877,"content":7878,"nodeType":870},{},[7879],{"data":7880,"marks":7881,"value":7882,"nodeType":874},{},[],"Follow our detailed and clear guides for how to respond comprehensively.",{"data":7884,"content":7885,"nodeType":870},{},[7886],{"data":7887,"marks":7888,"value":1946,"nodeType":874},{},[7889],{"type":882},{"data":7891,"content":7892,"nodeType":870},{},[7893],{"data":7894,"marks":7895,"value":7896,"nodeType":874},{},[],"If your users don’t use external email auto-forwarding, it makes sense to prevent the feature to limit the impact of a malicious mail rule. However, if there are legitimate business reasons for keeping the feature active, this risk can be sufficiently managed through detection.",{"data":7898,"content":7902,"nodeType":1215},{"target":7899},{"sys":7900},{"id":7901,"type":1220,"linkType":1221},"2y0INxqAi594O7rCAVKhTI",[],{"data":7904,"content":7905,"nodeType":870},{},[7906],{"data":7907,"marks":7908,"value":21,"nodeType":874},{},[],"Should you disable external email auto-forwarding?","External email auto-forwarding is a feature but also a risk; learn whether you should disable it, and, if you can't, how to manage the risk through detection.",[7205,263,7206,7207,7569],"2021-06-03T00:00:00.000+01:00","should-you-disable-external-email-auto-forwarding",{"items":7915},[7916,7918],{"sys":7917,"name":2007},{"id":2006},{"sys":7919,"name":334},{"id":2010},{"items":7921},[7922],{"fullName":7582,"firstName":7583,"jobTitle":7584,"profilePicture":7923},{"url":7586},"case-study-business-email-compromise-bec-attack-nearly-cost-us-millions","blog\u002Fcase-study-business-email-compromise-bec-attack-nearly-cost-us-millions",{"json":7927},{"data":7928,"content":7929,"nodeType":866},{},[7930],{"data":7931,"content":7932,"nodeType":870},{},[7933],{"data":7934,"marks":7935,"value":7936,"nodeType":874},{},[],"An interesting BEC example. After attackers gained access to a senior employee's email account they began their Business Email Compromise (BEC) attack. They created a mail rule that forwarded all payment emails to another address and then followed up with an email changing the banking details. This nearly resulted in millions lost.","A story by the owner of an Engineering company on how they almost lost millions from a Business Email Compromise (BEC) style attack. An interesting BEC example.",{"id":7939,"publishedAt":7940},"pj2eLZXa4PyrY1DD4NCHt","2026-08-12T11:56:59.726Z",{"items":7942},[7943,7945],{"sys":7944,"name":2007},{"id":2006},{"sys":7946,"name":5689},{"id":5688},{"items":7948},[7949,7951,7953,7955,7957,7959],{"sys":7950,"name":510,"slug":511,"tier":31},{"id":507},{"sys":7952,"name":404,"slug":405,"tier":31},{"id":401},{"sys":7954,"name":599,"slug":600,"tier":45},{"id":596},{"sys":7956,"name":316,"slug":317,"tier":45},{"id":313},{"sys":7958,"name":519,"slug":520,"tier":45},{"id":516},{"sys":7960,"name":262,"slug":263,"tier":45},{"id":259},"GPW5i2q4kIJIUzZrHVyit-PrYWEE8lojkWBldlT8KyY",{"id":7963,"title":7566,"authorsCollection":7964,"content":7968,"extension":219,"faqItemsCollection":8287,"faqTitle":60,"featured":6,"hashTags":8289,"meta":8290,"metaTitle":8291,"ogImage":60,"postType":8292,"publishedDate":7571,"relatedBlogPostsCollection":8293,"slug":7572,"stem":10346,"subtitle":60,"summary":10347,"synopsis":7567,"sys":10358,"tagsCollection":10360,"topicsCollection":10366,"__hash__":10378},"blog\u002Fblog\u002Femail-security-how-hackers-use-mail-rules-to-access-your-inbox.json",{"items":7965},[7966],{"fullName":7582,"firstName":7583,"jobTitle":7584,"socialLinks":60,"profilePicture":7967},{"url":7586},{"json":7969,"links":8264},{"data":7970,"content":7971,"nodeType":866},{},[7972,7978,7983,7989,8005,8028,8034,8109,8124,8127,8133,8148,8154,8160,8163,8169,8206,8212,8227,8233,8236,8243,8249],{"data":7973,"content":7974,"nodeType":870},{},[7975],{"data":7976,"marks":7977,"value":7228,"nodeType":874},{},[],{"data":7979,"content":7982,"nodeType":1215},{"target":7980},{"sys":7981},{"id":7233,"type":1220,"linkType":1221},[],{"data":7984,"content":7985,"nodeType":870},{},[7986],{"data":7987,"marks":7988,"value":7241,"nodeType":874},{},[],{"data":7990,"content":7991,"nodeType":7261},{},[7992],{"data":7993,"content":7994,"nodeType":870},{},[7995,7998,8002],{"data":7996,"marks":7997,"value":7251,"nodeType":874},{},[],{"data":7999,"marks":8000,"value":7256,"nodeType":874},{},[8001],{"type":882},{"data":8003,"marks":8004,"value":7260,"nodeType":874},{},[],{"data":8006,"content":8007,"nodeType":870},{},[8008,8011,8018,8021,8025],{"data":8009,"marks":8010,"value":7268,"nodeType":874},{},[],{"data":8012,"content":8013,"nodeType":966},{"uri":7271},[8014],{"data":8015,"marks":8016,"value":7277,"nodeType":874},{},[8017],{"type":974},{"data":8019,"marks":8020,"value":7281,"nodeType":874},{},[],{"data":8022,"marks":8023,"value":7286,"nodeType":874},{},[8024],{"type":1144},{"data":8026,"marks":8027,"value":7290,"nodeType":874},{},[],{"data":8029,"content":8030,"nodeType":870},{},[8031],{"data":8032,"marks":8033,"value":7297,"nodeType":874},{},[],{"data":8035,"content":8036,"nodeType":1763},{},[8037,8055,8073,8091],{"data":8038,"content":8039,"nodeType":1767},{},[8040],{"data":8041,"content":8042,"nodeType":870},{},[8043,8046,8052],{"data":8044,"marks":8045,"value":21,"nodeType":874},{},[],{"data":8047,"content":8048,"nodeType":966},{"uri":7312},[8049],{"data":8050,"marks":8051,"value":7317,"nodeType":874},{},[],{"data":8053,"marks":8054,"value":21,"nodeType":874},{},[],{"data":8056,"content":8057,"nodeType":1767},{},[8058],{"data":8059,"content":8060,"nodeType":870},{},[8061,8064,8070],{"data":8062,"marks":8063,"value":21,"nodeType":874},{},[],{"data":8065,"content":8066,"nodeType":966},{"uri":7332},[8067],{"data":8068,"marks":8069,"value":7337,"nodeType":874},{},[],{"data":8071,"marks":8072,"value":21,"nodeType":874},{},[],{"data":8074,"content":8075,"nodeType":1767},{},[8076],{"data":8077,"content":8078,"nodeType":870},{},[8079,8082,8088],{"data":8080,"marks":8081,"value":21,"nodeType":874},{},[],{"data":8083,"content":8084,"nodeType":966},{"uri":7352},[8085],{"data":8086,"marks":8087,"value":7357,"nodeType":874},{},[],{"data":8089,"marks":8090,"value":7361,"nodeType":874},{},[],{"data":8092,"content":8093,"nodeType":1767},{},[8094],{"data":8095,"content":8096,"nodeType":870},{},[8097,8100,8106],{"data":8098,"marks":8099,"value":21,"nodeType":874},{},[],{"data":8101,"content":8102,"nodeType":966},{"uri":7373},[8103],{"data":8104,"marks":8105,"value":7378,"nodeType":874},{},[],{"data":8107,"marks":8108,"value":21,"nodeType":874},{},[],{"data":8110,"content":8111,"nodeType":870},{},[8112,8115,8121],{"data":8113,"marks":8114,"value":7388,"nodeType":874},{},[],{"data":8116,"content":8117,"nodeType":966},{"uri":7391},[8118],{"data":8119,"marks":8120,"value":7396,"nodeType":874},{},[],{"data":8122,"marks":8123,"value":7400,"nodeType":874},{},[],{"data":8125,"content":8126,"nodeType":896},{},[],{"data":8128,"content":8129,"nodeType":900},{},[8130],{"data":8131,"marks":8132,"value":7410,"nodeType":874},{},[],{"data":8134,"content":8135,"nodeType":870},{},[8136,8139,8145],{"data":8137,"marks":8138,"value":21,"nodeType":874},{},[],{"data":8140,"content":8141,"nodeType":966},{"uri":7419},[8142],{"data":8143,"marks":8144,"value":7424,"nodeType":874},{},[],{"data":8146,"marks":8147,"value":7428,"nodeType":874},{},[],{"data":8149,"content":8150,"nodeType":870},{},[8151],{"data":8152,"marks":8153,"value":7435,"nodeType":874},{},[],{"data":8155,"content":8156,"nodeType":870},{},[8157],{"data":8158,"marks":8159,"value":7442,"nodeType":874},{},[],{"data":8161,"content":8162,"nodeType":896},{},[],{"data":8164,"content":8165,"nodeType":900},{},[8166],{"data":8167,"marks":8168,"value":7452,"nodeType":874},{},[],{"data":8170,"content":8171,"nodeType":870},{},[8172,8175,8181,8184,8192,8195,8203],{"data":8173,"marks":8174,"value":7459,"nodeType":874},{},[],{"data":8176,"content":8177,"nodeType":966},{"uri":7462},[8178],{"data":8179,"marks":8180,"value":7467,"nodeType":874},{},[],{"data":8182,"marks":8183,"value":7471,"nodeType":874},{},[],{"data":8185,"content":8188,"nodeType":7482},{"target":8186},{"sys":8187},{"id":7476,"type":1220,"linkType":1221},[8189],{"data":8190,"marks":8191,"value":7481,"nodeType":874},{},[],{"data":8193,"marks":8194,"value":7486,"nodeType":874},{},[],{"data":8196,"content":8199,"nodeType":7482},{"target":8197},{"sys":8198},{"id":7491,"type":1220,"linkType":1221},[8200],{"data":8201,"marks":8202,"value":7496,"nodeType":874},{},[],{"data":8204,"marks":8205,"value":1581,"nodeType":874},{},[],{"data":8207,"content":8208,"nodeType":870},{},[8209],{"data":8210,"marks":8211,"value":7506,"nodeType":874},{},[],{"data":8213,"content":8214,"nodeType":870},{},[8215,8218,8224],{"data":8216,"marks":8217,"value":7513,"nodeType":874},{},[],{"data":8219,"content":8220,"nodeType":966},{"uri":7462},[8221],{"data":8222,"marks":8223,"value":7520,"nodeType":874},{},[],{"data":8225,"marks":8226,"value":1581,"nodeType":874},{},[],{"data":8228,"content":8229,"nodeType":870},{},[8230],{"data":8231,"marks":8232,"value":7530,"nodeType":874},{},[],{"data":8234,"content":8235,"nodeType":896},{},[],{"data":8237,"content":8238,"nodeType":900},{},[8239],{"data":8240,"marks":8241,"value":7541,"nodeType":874},{},[8242],{"type":882},{"data":8244,"content":8245,"nodeType":870},{},[8246],{"data":8247,"marks":8248,"value":7548,"nodeType":874},{},[],{"data":8250,"content":8251,"nodeType":870},{},[8252,8255,8261],{"data":8253,"marks":8254,"value":7555,"nodeType":874},{},[],{"data":8256,"content":8257,"nodeType":966},{"uri":7558},[8258],{"data":8259,"marks":8260,"value":1991,"nodeType":874},{},[],{"data":8262,"marks":8263,"value":1581,"nodeType":874},{},[],{"entries":8265},{"inline":8266,"hyperlink":8267,"block":8279},[],[8268,8274],{"sys":8269,"__typename":8270,"title":8271,"slug":8272,"articleId":8273},{"id":7476},"HelpArticle","What to do if you find a malicious mail rule in Microsoft 365","what-to-do-if-you-find-a-malicious-mail-rule-microsoft-office-365",10021,{"sys":8275,"__typename":8270,"title":8276,"slug":8277,"articleId":8278},{"id":7491},"What to do when you find a malicious mail filter in Google Workspace","what-to-do-when-you-find-a-malicious-mail-filter-in-google-workspace",10022,[8280],{"sys":8281,"__typename":4929,"title":8282,"caption":8282,"layoutMode":60,"file":8283},{"id":7233},"Microsoft Outlook ‘forward email’ rule in Office 365",{"url":8284,"width":8285,"height":8286},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7d9KtwtX1HE0imQzE6tvwm\u002Fd1316f98a9bfc1245d93377236c94282\u002Flegit-rules.jpg",930,408,{"items":8288},[],[7205,263,7206,7207,7569,7570],{},"How hackers use mail rules to access your inbox","threat-research",{"items":8294},[8295,8961,9823],{"__typename":1126,"sys":8296,"content":8298,"title":8947,"synopsis":8948,"hashTags":60,"publishedDate":8949,"slug":8950,"tagsCollection":8951,"authorsCollection":8957},{"id":8297},"3dtvtDQdcQ6fAW7CB8VOFP",{"json":8299},{"data":8300,"content":8301,"nodeType":866},{},[8302,8309,8316,8323,8326,8334,8341,8361,8394,8400,8420,8426,8451,8454,8462,8469,8485,8501,8507,8514,8521,8527,8543,8546,8554,8561,8568,8575,8582,8585,8593,8600,8607,8627,8634,8642,8685,8692,8698,8705,8711,8718,8721,8729,8744,8751,8793,8805,8808,8816,8823,8830,8863,8870,8890,8896,8902,8905,8912,8919,8935,8941],{"data":8303,"content":8304,"nodeType":870},{},[8305],{"data":8306,"marks":8307,"value":8308,"nodeType":874},{},[],"Phishing attacks remain a huge challenge for organizations in 2025. In fact, with attackers increasingly leveraging identity-based techniques over software exploits, phishing arguably poses a bigger threat than ever before. ",{"data":8310,"content":8311,"nodeType":870},{},[8312],{"data":8313,"marks":8314,"value":8315,"nodeType":874},{},[],"Attackers are turning to identity attacks like phishing because they can achieve all of the same objectives as they would in a traditional endpoint or network attack, simply by logging into a victim’s account. And with organizations now using hundreds of internet apps across their workforce, the scope of accounts that can be phished or targeted with stolen credentials has grown exponentially. ",{"data":8317,"content":8318,"nodeType":870},{},[8319],{"data":8320,"marks":8321,"value":8322,"nodeType":874},{},[],"With MFA-bypassing phishing kits the new normal, capable of phishing accounts protected by SMS, OTP, and push-based methods, detection controls are being put under constant pressure as prevention controls fall short. ",{"data":8324,"content":8325,"nodeType":896},{},[],{"data":8327,"content":8328,"nodeType":900},{},[8329],{"data":8330,"marks":8331,"value":8333,"nodeType":874},{},[8332],{"type":882},"Attackers are bypassing detection controls",{"data":8335,"content":8336,"nodeType":870},{},[8337],{"data":8338,"marks":8339,"value":8340,"nodeType":874},{},[],"The majority of phishing detection and control enforcement is focused at the email and network layer — typically at the Secure Email Gateway (SEG), Secure Web Gateway (SWG)\u002Fproxy, or both. ",{"data":8342,"content":8343,"nodeType":870},{},[8344,8348,8357],{"data":8345,"marks":8346,"value":8347,"nodeType":874},{},[],"But attackers know this, ",{"data":8349,"content":8351,"nodeType":966},{"uri":8350},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-aitm-phishing-kits-evade-detection-p2\u002F",[8352],{"data":8353,"marks":8354,"value":8356,"nodeType":874},{},[8355],{"type":974},"and are taking steps to avoid these controls",{"data":8358,"marks":8359,"value":8360,"nodeType":874},{},[],", by:",{"data":8362,"content":8363,"nodeType":1763},{},[8364,8374,8384],{"data":8365,"content":8366,"nodeType":1767},{},[8367],{"data":8368,"content":8369,"nodeType":870},{},[8370],{"data":8371,"marks":8372,"value":8373,"nodeType":874},{},[],"Routinely evading IoC driven blocklists by dynamically rotating and updating commonly signatured elements like IPs, domains, and URLs.",{"data":8375,"content":8376,"nodeType":1767},{},[8377],{"data":8378,"content":8379,"nodeType":870},{},[8380],{"data":8381,"marks":8382,"value":8383,"nodeType":874},{},[],"Preventing analysis of their phishing pages by implementing bot protection like CAPTCHA or Cloudflare Turnstile alongside other detection evasion methods. ",{"data":8385,"content":8386,"nodeType":1767},{},[8387],{"data":8388,"content":8389,"nodeType":870},{},[8390],{"data":8391,"marks":8392,"value":8393,"nodeType":874},{},[],"Changing visual and DOM elements on the page so that even when the page is loaded, detection signatures may fail to trigger.  ",{"data":8395,"content":8399,"nodeType":1215},{"target":8396},{"sys":8397},{"id":8398,"type":1220,"linkType":1221},"5w44LsamEfcwSACx3MA997",[],{"data":8401,"content":8402,"nodeType":870},{},[8403,8407,8416],{"data":8404,"marks":8405,"value":8406,"nodeType":874},{},[],"And in fact, by launching multi- and cross-channel attacks, attackers are evading email-based controls entirely. Just see ",{"data":8408,"content":8410,"nodeType":966},{"uri":8409},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finvestigating-a-recent-malvertising-campaign-targeting-onfido-customers\u002F?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[8411],{"data":8412,"marks":8413,"value":8415,"nodeType":874},{},[8414],{"type":974},"this recent example",{"data":8417,"marks":8418,"value":8419,"nodeType":874},{},[],", where attackers impersonating Onfido delivered their phishing attack via malicious Google ads (aka malvertising) — bypassing email altogether. ",{"data":8421,"content":8425,"nodeType":1215},{"target":8422},{"sys":8423},{"id":8424,"type":1220,"linkType":1221},"3sGmVHl1Rwjyw3TMZSYuy4",[],{"data":8427,"content":8428,"nodeType":870},{},[8429,8433,8438,8442,8447],{"data":8430,"marks":8431,"value":8432,"nodeType":874},{},[],"It’s worth pointing out the limitations of email-based solutions here too. Email has some additional checks around the sender’s reputation and things like DMARC\u002FDKIM, but these don’t actually identify malicious ",{"data":8434,"marks":8435,"value":8437,"nodeType":874},{},[8436],{"type":882},"pages",{"data":8439,"marks":8440,"value":8441,"nodeType":874},{},[],". Similarly, some modern email solutions are doing much deeper analysis of the ",{"data":8443,"marks":8444,"value":8446,"nodeType":874},{},[8445],{"type":882},"content",{"data":8448,"marks":8449,"value":8450,"nodeType":874},{},[]," of an email. But… that doesn’t really help with identifying the phishing sites themselves (just indicates that one might be linked in the email). This is much more appropriate for BEC-style attacks where the goal is to social engineer the victim, as opposed to linking them to a malicious page. And this still doesn’t help with attacks launched over different mediums as we’ve highlighted above.",{"data":8452,"content":8453,"nodeType":896},{},[],{"data":8455,"content":8456,"nodeType":900},{},[8457],{"data":8458,"marks":8459,"value":8461,"nodeType":874},{},[8460],{"type":882},"How browser-based detection and response can level the playing field",{"data":8463,"content":8464,"nodeType":870},{},[8465],{"data":8466,"marks":8467,"value":8468,"nodeType":874},{},[],"Most phishing attacks involve the delivery of a malicious link to a user. The user clicks the link and loads a malicious page. In the vast majority of cases, the malicious page is a login portal for a specific website, where the goal for the attacker is to steal the victim’s account.",{"data":8470,"content":8471,"nodeType":870},{},[8472,8476,8481],{"data":8473,"marks":8474,"value":8475,"nodeType":874},{},[],"These attacks are happening pretty much exclusively in the victim’s browser. So rather than building more email or network based controls looking from the outside-in at phishing pages accessed in the browser, there’s a huge opportunity presented by building phishing detection and response capabilities ",{"data":8477,"marks":8478,"value":8480,"nodeType":874},{},[8479],{"type":1144},"inside",{"data":8482,"marks":8483,"value":8484,"nodeType":874},{},[]," the browser. ",{"data":8486,"content":8487,"nodeType":870},{},[8488,8492,8497],{"data":8489,"marks":8490,"value":8491,"nodeType":874},{},[],"When we look at the history of detection and response, this makes a lot of sense. When endpoint attacks skyrocketed in the late 2000s \u002F early 2010s, they took advantage of the fact that defenders were trying to detect malware with primarily network-based detections, signature-based analysis of files, and running files in sandboxes (which was reliably defeated with sandbox-aware malware and using things as simple as putting an execution delay in the code). But this gave way to EDR, which presented a better way of observing and intercepting malicious software in ",{"data":8493,"marks":8494,"value":8496,"nodeType":874},{},[8495],{"type":882},"real-time",{"data":8498,"marks":8499,"value":8500,"nodeType":874},{},[],". ",{"data":8502,"content":8506,"nodeType":1215},{"target":8503},{"sys":8504},{"id":8505,"type":1220,"linkType":1221},"1KFwJvbIMiWHb1erWlljZf",[],{"data":8508,"content":8509,"nodeType":870},{},[8510],{"data":8511,"marks":8512,"value":8513,"nodeType":874},{},[],"The key here was getting inside the data stream to be able to observe activity in real-time on the endpoint. ",{"data":8515,"content":8516,"nodeType":870},{},[8517],{"data":8518,"marks":8519,"value":8520,"nodeType":874},{},[],"We’re in a similar position today. Modern phishing attacks are happening on web pages accessed via the browser, and the tools we’re relying on — email, network, even endpoint — don’t have the required visibility. They’re looking from the outside-in. ",{"data":8522,"content":8526,"nodeType":1215},{"target":8523},{"sys":8524},{"id":8525,"type":1220,"linkType":1221},"59t6AcjpRjs3VQQXQO3PWu",[],{"data":8528,"content":8529,"nodeType":870},{},[8530,8534,8539],{"data":8531,"marks":8532,"value":8533,"nodeType":874},{},[],"But what if we could do detection and response from ",{"data":8535,"marks":8536,"value":8538,"nodeType":874},{},[8537],{"type":882},"inside the browser?",{"data":8540,"marks":8541,"value":8542,"nodeType":874},{},[]," Here’s three reasons why the browser is best for stopping phishing attacks:",{"data":8544,"content":8545,"nodeType":896},{},[],{"data":8547,"content":8548,"nodeType":900},{},[8549],{"data":8550,"marks":8551,"value":8553,"nodeType":874},{},[8552],{"type":882},"#1: Analyze pages, not links",{"data":8555,"content":8556,"nodeType":870},{},[8557],{"data":8558,"marks":8559,"value":8560,"nodeType":874},{},[],"Common phishing detections rely on the analysis of links or static HTML as opposed to malicious pages. Modern phishing pages are no longer static HTML — like most other modern web pages, these are dynamic web apps rendered in the browser, with JavaScript dynamically rewriting the page and launching the malicious content. This means that most basic, static checks fail to identify the malicious content running on the page. ",{"data":8562,"content":8563,"nodeType":870},{},[8564],{"data":8565,"marks":8566,"value":8567,"nodeType":874},{},[],"Without deeper analysis, you’re reliant on analyzing things like domains, URLs and IP addresses against known-bad blocklists. But these are all highly disposable. Attackers are buying them in bulk, constantly taking over legitimate domains, and generally planning for the fact that they’ll get through a lot of them. Modern phishing architecture is also able to dynamically rotate and update the links served to visitors from a continually refreshed pool (so every person that clicks the link gets served a different URL) and even going as far as using things like one-time magic links (which also means that any security team members trying to investigate the page later won’t be able to do so). ",{"data":8569,"content":8570,"nodeType":870},{},[8571],{"data":8572,"marks":8573,"value":8574,"nodeType":874},{},[],"Ultimately, this means that blocklists just aren’t that effective — because it’s trivial for attackers to change the indicators being used to create detections. If you think about the Pyramid of Pain, these indicators sit right at the bottom — the kind of thing we’ve been moving away from for years in the endpoint security world.  ",{"data":8576,"content":8577,"nodeType":870},{},[8578],{"data":8579,"marks":8580,"value":8581,"nodeType":874},{},[],"But in the browser, you can observe the rendered web page in all its glory. With much deeper visibility of the page (and its malicious elements) you can…",{"data":8583,"content":8584,"nodeType":896},{},[],{"data":8586,"content":8587,"nodeType":900},{},[8588],{"data":8589,"marks":8590,"value":8592,"nodeType":874},{},[8591],{"type":882},"#2: Detect TTPs, not IoCs",{"data":8594,"content":8595,"nodeType":870},{},[8596],{"data":8597,"marks":8598,"value":8599,"nodeType":874},{},[],"Even where TTP-based detections are in play, they’re typically reliant on either piecing together network requests, or loading the page in a sandbox. ",{"data":8601,"content":8602,"nodeType":870},{},[8603],{"data":8604,"marks":8605,"value":8606,"nodeType":874},{},[],"However, attackers are getting pretty good at evading sandbox analysis — simply by implementing bot protection by requiring user interaction with a CAPTCHA or Cloudflare Turnstile. Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":8608,"content":8609,"nodeType":870},{},[8610,8614,8623],{"data":8611,"marks":8612,"value":8613,"nodeType":874},{},[],"And if all this wasn’t enough, ",{"data":8615,"content":8617,"nodeType":966},{"uri":8616},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-aitm-phishing-kits-evade-detection-p2\u002F?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[8618],{"data":8619,"marks":8620,"value":8622,"nodeType":874},{},[8621],{"type":974},"they’re also obfuscating both visual and DOM elements to prevent signature-based detections from picking them up",{"data":8624,"marks":8625,"value":8626,"nodeType":874},{},[]," — so even if you can land on the page, there’s a high chance that your detections won’t trigger.",{"data":8628,"content":8629,"nodeType":870},{},[8630],{"data":8631,"marks":8632,"value":8633,"nodeType":874},{},[],"When using a proxy, you’ll have some visibility of the network traffic generated by a user accessing and interacting with a page. However, you’ll struggle to correlate key actions like whether the user entered their password with the specific tab when dealing with the sheer volume of disorganized network traffic data. ",{"data":8635,"content":8636,"nodeType":870},{},[8637],{"data":8638,"marks":8639,"value":8641,"nodeType":874},{},[8640],{"type":882},"But you get much better visibility of all this in the browser, with access to:",{"data":8643,"content":8644,"nodeType":1763},{},[8645,8655,8665,8675],{"data":8646,"content":8647,"nodeType":1767},{},[8648],{"data":8649,"content":8650,"nodeType":870},{},[8651],{"data":8652,"marks":8653,"value":8654,"nodeType":874},{},[],"Full decrypted HTTP traffic — not just DNS and TCP\u002FIP metadata",{"data":8656,"content":8657,"nodeType":1767},{},[8658],{"data":8659,"content":8660,"nodeType":870},{},[8661],{"data":8662,"marks":8663,"value":8664,"nodeType":874},{},[],"Full user interaction tracing — every click, keystroke, or DOM change can be traced",{"data":8666,"content":8667,"nodeType":1767},{},[8668],{"data":8669,"content":8670,"nodeType":870},{},[8671],{"data":8672,"marks":8673,"value":8674,"nodeType":874},{},[],"Full inspection at every layer of execution, not just initial HTML served",{"data":8676,"content":8677,"nodeType":1767},{},[8678],{"data":8679,"content":8680,"nodeType":870},{},[8681],{"data":8682,"marks":8683,"value":8684,"nodeType":874},{},[],"Full access to browser APIs, to correlate with browser history, local storage, attached cookies, etc.",{"data":8686,"content":8687,"nodeType":870},{},[8688],{"data":8689,"marks":8690,"value":8691,"nodeType":874},{},[],"This gives you everything you need to build high-fidelity detections focused on page behavior and user interaction – that are much harder for attackers to get around when compared to IoC-based detections. ",{"data":8693,"content":8697,"nodeType":1215},{"target":8694},{"sys":8695},{"id":8696,"type":1220,"linkType":1221},"1YggWcADAWgt3sUkXMsVIw",[],{"data":8699,"content":8700,"nodeType":870},{},[8701],{"data":8702,"marks":8703,"value":8704,"nodeType":874},{},[],"In the browser, you get much better visibility of the user and page behavior to enable phishing page detection.",{"data":8706,"content":8710,"nodeType":1215},{"target":8707},{"sys":8708},{"id":8709,"type":1220,"linkType":1221},"1BKgjnYkLJIRW0LJZYpfga",[],{"data":8712,"content":8713,"nodeType":870},{},[8714],{"data":8715,"marks":8716,"value":8717,"nodeType":874},{},[],"And with this new visibility, because you’re in the browser and seeing the page at the same time as the user is interacting with it, you can…",{"data":8719,"content":8720,"nodeType":896},{},[],{"data":8722,"content":8723,"nodeType":900},{},[8724],{"data":8725,"marks":8726,"value":8728,"nodeType":874},{},[8727],{"type":882},"#3: Intercept in real time, not post mortem",{"data":8730,"content":8731,"nodeType":870},{},[8732,8736,8741],{"data":8733,"marks":8734,"value":8735,"nodeType":874},{},[],"For non-browser solutions, ",{"data":8737,"marks":8738,"value":8740,"nodeType":874},{},[8739],{"type":882},"real-time phishing detection is basically nonexistent",{"data":8742,"marks":8743,"value":8500,"nodeType":874},{},[],{"data":8745,"content":8746,"nodeType":870},{},[8747],{"data":8748,"marks":8749,"value":8750,"nodeType":874},{},[],"At best, your proxy-based solution might be able to detect malicious behavior via the network traffic generated by your user interacting with the page. But because of the complexity of reconstructing network requests post-TLS-encryption, this typically happens on a time delay and is not entirely reliable. ",{"data":8752,"content":8753,"nodeType":870},{},[8754,8758,8763,8767,8772,8776,8780,8784,8789],{"data":8755,"marks":8756,"value":8757,"nodeType":874},{},[],"If a page is flagged, it usually requires further investigation by a security team to rule out any false positives and kick off an investigation. This can take ",{"data":8759,"marks":8760,"value":8762,"nodeType":874},{},[8761],{"type":882},"hours",{"data":8764,"marks":8765,"value":8766,"nodeType":874},{},[]," at best, probably ",{"data":8768,"marks":8769,"value":8771,"nodeType":874},{},[8770],{"type":882},"days",{"data":8773,"marks":8774,"value":8775,"nodeType":874},{},[],". Then, once a page is identified as malicious and IoCs are created, it can take ",{"data":8777,"marks":8778,"value":8771,"nodeType":874},{},[8779],{"type":882},{"data":8781,"marks":8782,"value":8783,"nodeType":874},{},[]," or even ",{"data":8785,"marks":8786,"value":8788,"nodeType":874},{},[8787],{"type":882},"weeks",{"data":8790,"marks":8791,"value":8792,"nodeType":874},{},[]," before the information is distributed, TI feeds are updated, and ingested into blocklists. ",{"data":8794,"content":8795,"nodeType":870},{},[8796,8800],{"data":8797,"marks":8798,"value":8799,"nodeType":874},{},[],"But in the browser, you’re observing the page in real-time, as the user sees it, from inside the browser. This is a game changer when it comes to not just detecting, but intercepting and shutting down attacks before a user is phished and the damage is done. ",{"data":8801,"marks":8802,"value":8804,"nodeType":874},{},[8803],{"type":882},"This changes the focus from post mortem containment and cleanup, to pre-compromise interception in real time. ",{"data":8806,"content":8807,"nodeType":896},{},[],{"data":8809,"content":8810,"nodeType":900},{},[8811],{"data":8812,"marks":8813,"value":8815,"nodeType":874},{},[8814],{"type":882},"The future of phishing detection and response is browser based",{"data":8817,"content":8818,"nodeType":870},{},[8819],{"data":8820,"marks":8821,"value":8822,"nodeType":874},{},[],"Push provides a browser-based identity security solution that intercepts phishing attacks as they happen — in employee browsers. Being in the browser delivers a lot of advantages when it comes to detecting and intercepting phishing attacks. You see the live webpage that the user sees, as they see it, meaning you have much better visibility of malicious elements running on the page. It also means that you can implement real-time controls that kick in when a malicious element is detected. ",{"data":8824,"content":8825,"nodeType":870},{},[8826],{"data":8827,"marks":8828,"value":8829,"nodeType":874},{},[],"When a phishing attack hits a user with Push, regardless of the delivery channel, our browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page, detecting that:",{"data":8831,"content":8832,"nodeType":1763},{},[8833,8843,8853],{"data":8834,"content":8835,"nodeType":1767},{},[8836],{"data":8837,"content":8838,"nodeType":870},{},[8839],{"data":8840,"marks":8841,"value":8842,"nodeType":874},{},[],"The password the user is entering into the phishing site has been used to log into another site previously. This means that the password is being reused (bad) or the user is being phished (even worse).  ",{"data":8844,"content":8845,"nodeType":1767},{},[8846],{"data":8847,"content":8848,"nodeType":870},{},[8849],{"data":8850,"marks":8851,"value":8852,"nodeType":874},{},[],"The web page is cloned from a legitimate login page that has been fingerprinted by Push. ",{"data":8854,"content":8855,"nodeType":1767},{},[8856],{"data":8857,"content":8858,"nodeType":870},{},[8859],{"data":8860,"marks":8861,"value":8862,"nodeType":874},{},[],"A phishing toolkit is running on the web page. ",{"data":8864,"content":8865,"nodeType":870},{},[8866],{"data":8867,"marks":8868,"value":8869,"nodeType":874},{},[],"As a result, the user is blocked from interacting with the phishing site and prevented from continuing. ",{"data":8871,"content":8872,"nodeType":870},{},[8873,8878,8887],{"data":8874,"marks":8875,"value":8877,"nodeType":874},{},[8876],{"type":882},"These are good examples of detections that are difficult (or impossible) for an attacker to evade — you can’t phish a victim if they can’t enter their credentials into your phishing site! ",{"data":8879,"content":8881,"nodeType":966},{"uri":8880},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdetecting-and-blocking-phishing-attacks-in-the-browser\u002F?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[8882],{"data":8883,"marks":8884,"value":8886,"nodeType":874},{},[8885],{"type":974},"Find out more about how Push detects and blocks phishing attacks here.",{"data":8888,"marks":8889,"value":21,"nodeType":874},{},[],{"data":8891,"content":8895,"nodeType":1215},{"target":8892},{"sys":8893},{"id":8894,"type":1220,"linkType":1221},"4ixcEsEW4EyqckOTmP5Pbb",[],{"data":8897,"content":8901,"nodeType":1215},{"target":8898},{"sys":8899},{"id":8900,"type":1220,"linkType":1221},"4PJKxWTroEPohYm4mklfl6",[],{"data":8903,"content":8904,"nodeType":896},{},[],{"data":8906,"content":8907,"nodeType":900},{},[8908],{"data":8909,"marks":8910,"value":7541,"nodeType":874},{},[8911],{"type":882},{"data":8913,"content":8914,"nodeType":870},{},[8915],{"data":8916,"marks":8917,"value":8918,"nodeType":874},{},[],"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":8920,"content":8921,"nodeType":870},{},[8922,8925,8932],{"data":8923,"marks":8924,"value":7555,"nodeType":874},{},[],{"data":8926,"content":8927,"nodeType":966},{"uri":7558},[8928],{"data":8929,"marks":8930,"value":1991,"nodeType":874},{},[8931],{"type":974},{"data":8933,"marks":8934,"value":1581,"nodeType":874},{},[],{"data":8936,"content":8940,"nodeType":1215},{"target":8937},{"sys":8938},{"id":8939,"type":1220,"linkType":1221},"2DviJNOMbKgbcqwkNl0LDP",[],{"data":8942,"content":8943,"nodeType":870},{},[8944],{"data":8945,"marks":8946,"value":21,"nodeType":874},{},[],"Three reasons why browser is best for stopping phishing attacks","Why being in the browser gives defenders a key advantage over network and email phishing prevention, detection, and response tools. ","2025-04-28T00:00:00.000Z","three-reasons-why-browser-is-best-for-stopping-phishing-attacks",{"items":8952},[8953,8955],{"sys":8954,"name":334},{"id":2010},{"sys":8956,"name":2007},{"id":2006},{"items":8958},[8959],{"fullName":2014,"firstName":2015,"jobTitle":2016,"profilePicture":8960},{"url":2018},{"__typename":1126,"sys":8962,"content":8964,"title":9805,"synopsis":9806,"hashTags":60,"publishedDate":9807,"slug":9808,"tagsCollection":9809,"authorsCollection":9815},{"id":8963},"7DJnckJxP4CXyXhPJJpby5",{"json":8965},{"data":8966,"content":8967,"nodeType":866},{},[8968,8975,8982,8989,8996,9003,9010,9017,9024,9031,9037,9044,9051,9058,9115,9122,9129,9149,9156,9163,9170,9203,9219,9226,9233,9240,9247,9254,9261,9281,9300,9408,9415,9435,9442,9449,9456,9462,9469,9476,9483,9516,9523,9530,9563,9570,9577,9674,9692,9698,9705,9712,9719,9777,9784,9787,9794,9799],{"data":8969,"content":8970,"nodeType":870},{},[8971],{"data":8972,"marks":8973,"value":8974,"nodeType":874},{},[],"Phishing attacks have always been a go-to technique for both red teamers and real-world threat actors alike. Whether focused on harvesting creds or running malicious payloads, phishing has continued to be adapted to circumvent defenses and has remained highly effective due to this.",{"data":8976,"content":8977,"nodeType":870},{},[8978],{"data":8979,"marks":8980,"value":8981,"nodeType":874},{},[],"As MFA has become more common, classic password harvesting focused phishing attacks have become less effective. Typically, for a full account compromise, an MFA push notification or a one-time passcode (OTP) needs to be entered at the time of login. This means harvesting passwords and using them later is no longer effective alone, because an MFA factor is still required each time a valid login is performed.",{"data":8983,"content":8984,"nodeType":870},{},[8985],{"data":8986,"marks":8987,"value":8988,"nodeType":874},{},[],"Adversary-in-the-Middle (AitM) phishing is a newer variant of phishing that allows attackers to circumvent MFA protection. In this article, we’re going to look at what AitM phishing is, how it works, and what you can do about it.",{"data":8990,"content":8991,"nodeType":900},{},[8992],{"data":8993,"marks":8994,"value":8995,"nodeType":874},{},[],"What is AitM phishing?",{"data":8997,"content":8998,"nodeType":870},{},[8999],{"data":9000,"marks":9001,"value":9002,"nodeType":874},{},[],"AitM phishing is a technique that uses dedicated tooling to act as a proxy between the target and a legitimate login portal for an application, principally to make it easier to defeat MFA protection. ",{"data":9004,"content":9005,"nodeType":870},{},[9006],{"data":9007,"marks":9008,"value":9009,"nodeType":874},{},[],"While any login portal can be a target, attackers typically look for SSO login portals such as Microsoft Entra, Okta, or Google Workspace. This allows the target to log in successfully with a legitimate service they use and even continue to interact with it, while providing additional access to connected SSO apps if the attack is successful. ",{"data":9011,"content":9012,"nodeType":870},{},[9013],{"data":9014,"marks":9015,"value":9016,"nodeType":874},{},[],"As it’s a proxy to the real application, the page will appear exactly as the user expects, because they are logging into the legitimate site – just taking a detour via the attacker’s device. For example, if accessing their webmail, the user will see all their real emails; if accessing their cloud file store then all their real files will be present, etc. This gives the method an increased sense of authenticity and makes the compromise less obvious to the user. However, because the attacker is sitting in the middle of this connection, they are able to observe all interactions and also take control of the authenticated session to gain control of the user account. ",{"data":9018,"content":9019,"nodeType":870},{},[9020],{"data":9021,"marks":9022,"value":9023,"nodeType":874},{},[],"While this access is technically temporary, since the attacker is unable to re-authenticate in future without additional MFA prompts, in practice authenticated sessions can often last as long as 30 days or more if kept active. Additionally, there are a wide range of persistence techniques that allow an attacker to maintain some level of access to the user account and\u002For targeted application indefinitely. ",{"data":9025,"content":9026,"nodeType":870},{},[9027],{"data":9028,"marks":9029,"value":9030,"nodeType":874},{},[],"We’ll revisit this point later, but for now let’s consider the two main techniques that are used to implement AitM phishing: Reverse web proxies and Browser-in-the-Middle techniques.",{"data":9032,"content":9036,"nodeType":1215},{"target":9033},{"sys":9034},{"id":9035,"type":1220,"linkType":1221},"6WEolDcviadCgAW4dCgTPW",[],{"data":9038,"content":9039,"nodeType":944},{},[9040],{"data":9041,"marks":9042,"value":9043,"nodeType":874},{},[],"Reverse web proxy techniques",{"data":9045,"content":9046,"nodeType":870},{},[9047],{"data":9048,"marks":9049,"value":9050,"nodeType":874},{},[],"One common AitM phishing approach is to use tooling that acts as a reverse web proxy. For example, let’s say a victim is tricked into visiting a malicious domain. Under the hood, HTTP requests are passed between the victim’s browser and the real site via the malicious site. When the malicious site receives an HTTP request, it forwards this request on to the legitimate site it is impersonating, receives the response, and then forwards that on to the victim. ",{"data":9052,"content":9053,"nodeType":870},{},[9054],{"data":9055,"marks":9056,"value":9057,"nodeType":874},{},[],"In practice, there are many technical challenges, such as rewriting all links and references to the impersonated site to ensure everything continues to be sent to the attacker. However, at a high level, it really is just acting as a reverse web proxy.",{"data":9059,"content":9060,"nodeType":870},{},[9061,9065,9074,9077,9086,9090,9099,9103,9112],{"data":9062,"marks":9063,"value":9064,"nodeType":874},{},[],"This is arguably the most scalable and reliable approach from an attacker’s point of view. Open-source tools that demonstrate this method include ",{"data":9066,"content":9068,"nodeType":966},{"uri":9067},"https:\u002F\u002Fgithub.com\u002Fdrk1wi\u002FModlishka",[9069],{"data":9070,"marks":9071,"value":9073,"nodeType":874},{},[9072],{"type":974},"Modlishka",{"data":9075,"marks":9076,"value":3071,"nodeType":874},{},[],{"data":9078,"content":9080,"nodeType":966},{"uri":9079},"https:\u002F\u002Fgithub.com\u002Fmuraenateam\u002Fmuraena",[9081],{"data":9082,"marks":9083,"value":9085,"nodeType":874},{},[9084],{"type":974},"Muraena",{"data":9087,"marks":9088,"value":9089,"nodeType":874},{},[],", and the ever popular ",{"data":9091,"content":9093,"nodeType":966},{"uri":9092},"https:\u002F\u002Fgithub.com\u002Fkgretzky\u002Fevilginx2",[9094],{"data":9095,"marks":9096,"value":9098,"nodeType":874},{},[9097],{"type":974},"Evilginx",{"data":9100,"marks":9101,"value":9102,"nodeType":874},{},[],". In the criminal world, there are also similar private toolsets available that have been used in many breaches in the past. A good example of this would be ",{"data":9104,"content":9106,"nodeType":966},{"uri":9105},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fevilproxy-uses-indeedcom-open-redirect-for-microsoft-365-phishing\u002F",[9107],{"data":9108,"marks":9109,"value":9111,"nodeType":874},{},[9110],{"type":974},"Evilproxy",{"data":9113,"marks":9114,"value":1581,"nodeType":874},{},[],{"data":9116,"content":9117,"nodeType":870},{},[9118],{"data":9119,"marks":9120,"value":9121,"nodeType":874},{},[],"One downside to this approach is that there are controls that can be put in place to block it. For example, application developers can hide obfuscated JavaScript code that will fail if the correct value is not produced, checking that the origin matches the expected (legitimate) domains or contains encrypted tokens including this material sent as part of the login process. ",{"data":9123,"content":9124,"nodeType":870},{},[9125],{"data":9126,"marks":9127,"value":9128,"nodeType":874},{},[],"While your average small website is not going to be implementing such checks, major identity providers have a strong vested interest in evolving their defenses to block these techniques. At this point, it’s a cat-and-mouse game. ",{"data":9130,"content":9131,"nodeType":870},{},[9132,9136,9145],{"data":9133,"marks":9134,"value":9135,"nodeType":874},{},[],"If you want to know more about this space, then definitely check out ",{"data":9137,"content":9139,"nodeType":966},{"uri":9138},"https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=C-Fh4sIdY8c",[9140],{"data":9141,"marks":9142,"value":9144,"nodeType":874},{},[9143],{"type":974},"Kuba Gretzky’s talk on this at x33fcon",{"data":9146,"marks":9147,"value":9148,"nodeType":874},{},[],".  ",{"data":9150,"content":9151,"nodeType":944},{},[9152],{"data":9153,"marks":9154,"value":9155,"nodeType":874},{},[],"Browser-in-the-Middle (BitM) techniques ",{"data":9157,"content":9158,"nodeType":870},{},[9159],{"data":9160,"marks":9161,"value":9162,"nodeType":874},{},[],"Another common approach is known as Browser-in-the-Middle (BitM). Rather than act as a reverse web proxy, this technique tricks a target into directly controlling the attacker’s own browser remotely using desktop screen sharing and control approaches, much like VNC and RDP. This enables the attacker to harvest not just the username and password, but all other associated secrets and tokens that go along with the login. ",{"data":9164,"content":9165,"nodeType":870},{},[9166],{"data":9167,"marks":9168,"value":9169,"nodeType":874},{},[],"In this case, the victim isn’t interacting with a fake website clone or proxy. They are literally remotely controlling the attacker’s browser to log in to the legitimate application without realizing. This is the virtual equivalent of an attacker handing their laptop to their victim, asking them to login to Okta for them, and then taking their laptop back afterwards. Thanks very much!",{"data":9171,"content":9172,"nodeType":870},{},[9173,9177,9186,9190,9199],{"data":9174,"marks":9175,"value":9176,"nodeType":874},{},[],"Practically speaking, the most common approach for implementing this technique is using the open-source project noVNC, which is a JavaScript-based VNC client that allows VNC to be used in the browser. Probably the most well-known example of an offensive tool implementing this is ",{"data":9178,"content":9180,"nodeType":966},{"uri":9179},"https:\u002F\u002Fgithub.com\u002FJoelGMSec\u002FEvilnoVNC",[9181],{"data":9182,"marks":9183,"value":9185,"nodeType":874},{},[9184],{"type":974},"EvilnoVNC",{"data":9187,"marks":9188,"value":9189,"nodeType":874},{},[],", which spins up Docker instances of VNC and proxies access to them, while also logging keystrokes and cookies to facilitate account compromise. Tools like ",{"data":9191,"content":9193,"nodeType":966},{"uri":9192},"https:\u002F\u002Fposts.specterops.io\u002Fphishing-with-dynamite-7d33d8fac038",[9194],{"data":9195,"marks":9196,"value":9198,"nodeType":874},{},[9197],{"type":974},"Cuddlephish",{"data":9200,"marks":9201,"value":9202,"nodeType":874},{},[]," offer similar functionality using WebRTC. ",{"data":9204,"content":9205,"nodeType":870},{},[9206,9210,9215],{"data":9207,"marks":9208,"value":9209,"nodeType":874},{},[],"The advantage of this approach is that ",{"data":9211,"marks":9212,"value":9214,"nodeType":874},{},[9213],{"type":882},"it is incredibly difficult for the target websites to do anything to stop it",{"data":9216,"marks":9217,"value":9218,"nodeType":874},{},[],". From their perspective, all they see is a legitimate browser accessing their website and logging in. None of the JavaScript tricks for checking the origin will work. They aren’t in a position to be able to see that the browser is secretly being controlled remotely by the victim user without their knowledge. ",{"data":9220,"content":9221,"nodeType":870},{},[9222],{"data":9223,"marks":9224,"value":9225,"nodeType":874},{},[],"On the downside, while noVNC can be extremely convincing, the illusion can sometimes be broken due to it not behaving exactly like a real website would due it being a graphical rendering. For example, something as simple as resizing the browser window can introduce render resolution issues. It’s also more difficult to scale for attacking large numbers of users than a reverse proxy technique.",{"data":9227,"content":9228,"nodeType":870},{},[9229],{"data":9230,"marks":9231,"value":9232,"nodeType":874},{},[],"Footnote: BitM is not to be confused with Browser-in-the-Browser (BitB), which is more of a malicious pop-up (think when a login button spawns a new browser window). ",{"data":9234,"content":9235,"nodeType":900},{},[9236],{"data":9237,"marks":9238,"value":9239,"nodeType":874},{},[],"Beyond initial access",{"data":9241,"content":9242,"nodeType":870},{},[9243],{"data":9244,"marks":9245,"value":9246,"nodeType":874},{},[],"So maybe you’re thinking now “OK, sounds kinda bad, but I’m not that worried. Maybe some user accounts get compromised by this method despite all my MFA protections, but at least the attacker only has temporary access, right?” ",{"data":9248,"content":9249,"nodeType":870},{},[9250],{"data":9251,"marks":9252,"value":9253,"nodeType":874},{},[],"In theory, access is temporary as sessions time out. And if spotted, the security team can respond by killing the authenticated sessions and forcing password changes for the compromised users. Then the attacker is back to square one, right? Their session is lost, they still don’t have MFA, and even the password they keylogged has now been changed.",{"data":9255,"content":9256,"nodeType":870},{},[9257],{"data":9258,"marks":9259,"value":9260,"nodeType":874},{},[],"In practice, it’s not this simple. We mentioned earlier how SSO portals are often the most common targets for these attacks. For most modern organizations, this means their core identity provider, which just so happens to be the gateway to accessing many other web applications, whether internal applications or a multitude of SaaS applications. ",{"data":9262,"content":9263,"nodeType":870},{},[9264,9268,9277],{"data":9265,"marks":9266,"value":9267,"nodeType":874},{},[],"Let’s consider the example of an organization using Okta where their Okta login portal has been used as the target for AitM phishing. A smart attacker is going to immediately leverage this access to establish authenticated sessions on every single application that Okta provides the user access to. They are also going to ",{"data":9269,"content":9271,"nodeType":966},{"uri":9270},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fokta-swa\u002F",[9272],{"data":9273,"marks":9274,"value":9276,"nodeType":874},{},[9275],{"type":974},"abuse Okta SWA",{"data":9278,"marks":9279,"value":9280,"nodeType":874},{},[]," to steal valid credentials for whichever applications support this method. And if that’s not enough, there are a variety of simple methods to achieve persistence on most downstream SaaS applications and sometimes even identity providers themselves.",{"data":9282,"content":9283,"nodeType":870},{},[9284,9288,9296],{"data":9285,"marks":9286,"value":9287,"nodeType":874},{},[],"While the full details of these persistence attacks are outside the scope of this article, more details on some key attacks can be found in a resource we created called the ",{"data":9289,"content":9290,"nodeType":966},{"uri":6800},[9291],{"data":9292,"marks":9293,"value":9295,"nodeType":874},{},[9294],{"type":974},"SaaS attacks matrix",{"data":9297,"marks":9298,"value":9299,"nodeType":874},{},[],". Some of the most common techniques that apply here are: ",{"data":9301,"content":9302,"nodeType":1763},{},[9303,9324,9345,9366,9387],{"data":9304,"content":9305,"nodeType":1767},{},[9306],{"data":9307,"content":9308,"nodeType":870},{},[9309,9312,9321],{"data":9310,"marks":9311,"value":21,"nodeType":874},{},[],{"data":9313,"content":9315,"nodeType":966},{"uri":9314},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fapi_keys\u002Fdescription.md",[9316],{"data":9317,"marks":9318,"value":9320,"nodeType":874},{},[9319],{"type":974},"SAT1004 - API keys",{"data":9322,"marks":9323,"value":21,"nodeType":874},{},[],{"data":9325,"content":9326,"nodeType":1767},{},[9327],{"data":9328,"content":9329,"nodeType":870},{},[9330,9333,9342],{"data":9331,"marks":9332,"value":21,"nodeType":874},{},[],{"data":9334,"content":9336,"nodeType":966},{"uri":9335},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Flink_sharing\u002Fdescription.md",[9337],{"data":9338,"marks":9339,"value":9341,"nodeType":874},{},[9340],{"type":974},"SAT1022 - Link sharing",{"data":9343,"marks":9344,"value":21,"nodeType":874},{},[],{"data":9346,"content":9347,"nodeType":1767},{},[9348],{"data":9349,"content":9350,"nodeType":870},{},[9351,9354,9363],{"data":9352,"marks":9353,"value":21,"nodeType":874},{},[],{"data":9355,"content":9357,"nodeType":966},{"uri":9356},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fghost_logins\u002Fdescription.md",[9358],{"data":9359,"marks":9360,"value":9362,"nodeType":874},{},[9361],{"type":974},"SAT1017 - Ghost logins",{"data":9364,"marks":9365,"value":21,"nodeType":874},{},[],{"data":9367,"content":9368,"nodeType":1767},{},[9369],{"data":9370,"content":9371,"nodeType":870},{},[9372,9375,9384],{"data":9373,"marks":9374,"value":21,"nodeType":874},{},[],{"data":9376,"content":9378,"nodeType":966},{"uri":9377},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Foauth_tokens\u002Fdescription.md",[9379],{"data":9380,"marks":9381,"value":9383,"nodeType":874},{},[9382],{"type":974},"SAT1027 - OAuth tokens",{"data":9385,"marks":9386,"value":21,"nodeType":874},{},[],{"data":9388,"content":9389,"nodeType":1767},{},[9390],{"data":9391,"content":9392,"nodeType":870},{},[9393,9396,9405],{"data":9394,"marks":9395,"value":21,"nodeType":874},{},[],{"data":9397,"content":9399,"nodeType":966},{"uri":9398},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fshadow_workflows\u002Fdescription.md",[9400],{"data":9401,"marks":9402,"value":9404,"nodeType":874},{},[9403],{"type":974},"SAT1033 - Shadow workflows",{"data":9406,"marks":9407,"value":21,"nodeType":874},{},[],{"data":9409,"content":9410,"nodeType":870},{},[9411],{"data":9412,"marks":9413,"value":9414,"nodeType":874},{},[],"Suddenly, containing the breach just got a LOT more complicated.",{"data":9416,"content":9417,"nodeType":870},{},[9418,9422,9431],{"data":9419,"marks":9420,"value":9421,"nodeType":874},{},[],"It’s not just application-level lateral movement and persistence to worry about, though. It’s possible the attacker can start moving laterally across other user accounts. If they have selected their targets well, they might even find they have admin access to some downstream SaaS application that has been configured for SAML logins using Okta. For example, maybe they compromise a finance employee who has admin access to their business expenses SaaS application. Then the attacker might be able to use a new technique like ",{"data":9423,"content":9425,"nodeType":966},{"uri":9424},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fsamljacking\u002Fdescription.md",[9426],{"data":9427,"marks":9428,"value":9430,"nodeType":874},{},[9429],{"type":974},"SAMLjacking",{"data":9432,"marks":9433,"value":9434,"nodeType":874},{},[]," to start attacking other users in a watering hole attack to achieve lateral movement.",{"data":9436,"content":9437,"nodeType":900},{},[9438],{"data":9439,"marks":9440,"value":9441,"nodeType":874},{},[],"Video demo – chaining it all together",{"data":9443,"content":9444,"nodeType":870},{},[9445],{"data":9446,"marks":9447,"value":9448,"nodeType":874},{},[],"OK, so we’ve just jumped from an account compromise for initial access using an AitM phishing attack to bringing up a huge number of other connected techniques. Let’s look at a quick video demonstration of an AitM phishing attack chained together with post-exploitation steps for persistence and lateral movement so we can see how it all fits together.",{"data":9450,"content":9451,"nodeType":870},{},[9452],{"data":9453,"marks":9454,"value":9455,"nodeType":874},{},[],"In this case, we’ll use EvilnoVNC targeting Okta as the core example for the AitM phishing attack:",{"data":9457,"content":9461,"nodeType":1215},{"target":9458},{"sys":9459},{"id":9460,"type":1220,"linkType":1221},"QGTEWzmOL1vrgjXPuV4Gg",[],{"data":9463,"content":9464,"nodeType":870},{},[9465],{"data":9466,"marks":9467,"value":9468,"nodeType":874},{},[],"We can see here that AitM phishing attacks are not only highly effective even in the presence of MFA, but that post-exploitation steps have become so numerous that effective response and containment for even a low-privileged user account are now a significant challenge.",{"data":9470,"content":9471,"nodeType":900},{},[9472],{"data":9473,"marks":9474,"value":9475,"nodeType":874},{},[],"Post-exploitation automation is coming",{"data":9477,"content":9478,"nodeType":870},{},[9479],{"data":9480,"marks":9481,"value":9482,"nodeType":874},{},[],"There is a saying that attacks only become more effective over time. In the past, toolsets like Metasploit and Cobalt Strike became increasingly focused on post-exploitation and automation to enable much more sophisticated compromises.",{"data":9484,"content":9485,"nodeType":870},{},[9486,9490,9503,9507,9512],{"data":9487,"marks":9488,"value":9489,"nodeType":874},{},[],"As AitM becomes increasingly popular (for example, researchers at Lab539 have reported ",{"data":9491,"content":9493,"nodeType":966},{"uri":9492},"https:\u002F\u002Fwww.lab539.com\u002Fblog\u002F6-months-tracking-aitm-campaigns",[9494,9499],{"data":9495,"marks":9496,"value":9498,"nodeType":874},{},[9497],{"type":974},"a significant ramp up in attacker infrastructure linked to AitM campaigns",{"data":9500,"marks":9501,"value":9502,"nodeType":874},{},[],")",{"data":9504,"marks":9505,"value":9506,"nodeType":874},{},[]," it’s only a matter of time now before we see AitM phishing frameworks moving in the same direction and performing many of the lateral movement and persistence steps we saw above – automatically on every successful account compromise. The threat will increase ",{"data":9508,"marks":9509,"value":9511,"nodeType":874},{},[9510],{"type":882},"significantly",{"data":9513,"marks":9514,"value":9515,"nodeType":874},{},[]," when this becomes the case.",{"data":9517,"content":9518,"nodeType":900},{},[9519],{"data":9520,"marks":9521,"value":9522,"nodeType":874},{},[],"Impact summary",{"data":9524,"content":9525,"nodeType":870},{},[9526],{"data":9527,"marks":9528,"value":9529,"nodeType":874},{},[],"We’ve covered a lot of ground here, so let’s take a step back and consider the key points of impact:",{"data":9531,"content":9532,"nodeType":1763},{},[9533,9543,9553],{"data":9534,"content":9535,"nodeType":1767},{},[9536],{"data":9537,"content":9538,"nodeType":870},{},[9539],{"data":9540,"marks":9541,"value":9542,"nodeType":874},{},[],"AitM phishing techniques are highly effective and increasingly common, and can bypass most common forms of MFA.",{"data":9544,"content":9545,"nodeType":1767},{},[9546],{"data":9547,"content":9548,"nodeType":870},{},[9549],{"data":9550,"marks":9551,"value":9552,"nodeType":874},{},[],"These techniques are being used by real threat actors and red teamers alike, with both criminal and open-source tools available for performing these attacks.",{"data":9554,"content":9555,"nodeType":1767},{},[9556],{"data":9557,"content":9558,"nodeType":870},{},[9559],{"data":9560,"marks":9561,"value":9562,"nodeType":874},{},[],"There are many options for lateral movement and persistence after an account compromise, so simple containment actions like password resets for SSO credentials are not nearly enough to contain a knowledgeable attacker.",{"data":9564,"content":9565,"nodeType":900},{},[9566],{"data":9567,"marks":9568,"value":9569,"nodeType":874},{},[],"What can blue teams do about it?",{"data":9571,"content":9572,"nodeType":870},{},[9573],{"data":9574,"marks":9575,"value":9576,"nodeType":874},{},[],"It’s important that organizations develop their capability to detect and respond to AitM attacks. Possible approaches include:",{"data":9578,"content":9579,"nodeType":1763},{},[9580,9595,9631,9659],{"data":9581,"content":9582,"nodeType":1767},{},[9583],{"data":9584,"content":9585,"nodeType":870},{},[9586,9591],{"data":9587,"marks":9588,"value":9590,"nodeType":874},{},[9589],{"type":882},"Move to FIDO MFA where possible",{"data":9592,"marks":9593,"value":9594,"nodeType":874},{},[]," (though, if no more susceptible backup methods are enabled, this does introduce operational challenges if passkeys are lost).",{"data":9596,"content":9597,"nodeType":1767},{},[9598],{"data":9599,"content":9600,"nodeType":870},{},[9601,9606,9610,9615,9619,9628],{"data":9602,"marks":9603,"value":9605,"nodeType":874},{},[9604],{"type":882},"Detect and block known-bad malicious",{"data":9607,"marks":9608,"value":9609,"nodeType":874},{},[]," ",{"data":9611,"marks":9612,"value":9614,"nodeType":874},{},[9613],{"type":882},"sites",{"data":9616,"marks":9617,"value":9618,"nodeType":874},{},[]," used in phishing campaigns. There are many threat intelligence feeds that can be ingested to achieve this. Usually, a domain has to be used in a malicious campaign before it can be catalogued – meaning there's typically a window of opportunity before the infrastructure is burned. That said, security researchers at Lab539 (yes, another shout out) have developed a way of identifying sites running AitM tooling – even before they are used for the first time. ",{"data":9620,"content":9622,"nodeType":966},{"uri":9621},"https:\u002F\u002Fwww.lab539.com\u002Faitm",[9623],{"data":9624,"marks":9625,"value":9627,"nodeType":874},{},[9626],{"type":974},"You can sign up to get access to their feed here.",{"data":9629,"marks":9630,"value":21,"nodeType":874},{},[],{"data":9632,"content":9633,"nodeType":1767},{},[9634],{"data":9635,"content":9636,"nodeType":870},{},[9637,9642,9646,9655],{"data":9638,"marks":9639,"value":9641,"nodeType":874},{},[9640],{"type":882},"Introduce controls to detect phishing toolkits and cloned websites",{"data":9643,"marks":9644,"value":9645,"nodeType":874},{},[],". You can never rely on blocking malicious sites via TI feeds alone, so additional layers of defence are required. Push customers benefit from detection of AitM toolkits like Evilginx and EvilNoVNC in the browser (more to come on this soon!), while Thinkst Canary has developed ",{"data":9647,"content":9649,"nodeType":966},{"uri":9648},"https:\u002F\u002Fblog.thinkst.com\u002F2024\u002F01\u002Fdefending-against-the-attack-of-the-cloned-websites.html",[9650],{"data":9651,"marks":9652,"value":9654,"nodeType":874},{},[9653],{"type":974},"methods of detecting whenever your website or login portal is cloned",{"data":9656,"marks":9657,"value":9658,"nodeType":874},{},[]," – very cool.  ",{"data":9660,"content":9661,"nodeType":1767},{},[9662],{"data":9663,"content":9664,"nodeType":870},{},[9665,9670],{"data":9666,"marks":9667,"value":9669,"nodeType":874},{},[9668],{"type":882},"Update IR playbooks to to deal with SSO account compromise,",{"data":9671,"marks":9672,"value":9673,"nodeType":874},{},[]," factoring in lateral movement and persistence across cloud apps. This really necessitates that you understand what business apps your organization is using, how they are accessed (e.g. SSO or username and password) and what functionality exists that could be abused by an attacker. ",{"data":9675,"content":9676,"nodeType":870},{},[9677,9681,9689],{"data":9678,"marks":9679,"value":9680,"nodeType":874},{},[],"If you want to know more about how Push detects and blocks phishing tools in the browser, you can ",{"data":9682,"content":9684,"nodeType":966},{"uri":9683},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser\u002F",[9685],{"data":9686,"marks":9687,"value":9688,"nodeType":874},{},[],"check out our article here",{"data":9690,"marks":9691,"value":5139,"nodeType":874},{},[],{"data":9693,"content":9694,"nodeType":900},{},[9695],{"data":9696,"marks":9697,"value":1946,"nodeType":874},{},[],{"data":9699,"content":9700,"nodeType":870},{},[9701],{"data":9702,"marks":9703,"value":9704,"nodeType":874},{},[],"We’ve seen in this article how there are multiple ways to perform AitM phishing attacks and how they can be extremely effective at targeting users even when their accounts are protected by MFA.  ",{"data":9706,"content":9707,"nodeType":870},{},[9708],{"data":9709,"marks":9710,"value":9711,"nodeType":874},{},[],"Very few organizations are universally using phishing-resistant MFA, such as FIDO-based methods, and even those that do often have fallback options to handle situations where they cannot be used and\u002For tokens malfunction or are lost. Therefore, the vast majority of organizations are at risk of AitM phishing attacks.",{"data":9713,"content":9714,"nodeType":870},{},[9715],{"data":9716,"marks":9717,"value":9718,"nodeType":874},{},[],"To make things worse, there are lateral movement and persistence techniques that can be exploited to greatly extend the depth of compromise even for a single low-privilege user account. This makes response and containment a significant challenge.",{"data":9720,"content":9721,"nodeType":870},{},[9722,9726,9735,9738,9747,9751,9760,9764,9773],{"data":9723,"marks":9724,"value":9725,"nodeType":874},{},[],"Phishing attacks are clearly evolving. Phishing attacks are no longer limited to email-based delivery mechanisms or being hosted on custom domains. There are many options now for delivering phishing attacks using ",{"data":9727,"content":9729,"nodeType":966},{"uri":9728},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fslack-phishing-for-initial-access\u002F",[9730],{"data":9731,"marks":9732,"value":9734,"nodeType":874},{},[9733],{"type":974},"Slack",{"data":9736,"marks":9737,"value":7486,"nodeType":874},{},[],{"data":9739,"content":9741,"nodeType":966},{"uri":9740},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fphishing-microsoft-teams-for-initial-access\u002F",[9742],{"data":9743,"marks":9744,"value":9746,"nodeType":874},{},[9745],{"type":974},"Microsoft Teams",{"data":9748,"marks":9749,"value":9750,"nodeType":874},{},[],", using ",{"data":9752,"content":9754,"nodeType":966},{"uri":9753},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsamljacking-a-poisoned-tenant\u002F",[9755],{"data":9756,"marks":9757,"value":9759,"nodeType":874},{},[9758],{"type":974},"SAMLjacking attacks",{"data":9761,"marks":9762,"value":9763,"nodeType":874},{},[]," to host the initial landing page on legitimate SaaS web domains or even using ",{"data":9765,"content":9767,"nodeType":966},{"uri":9766},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Foktajacking\u002F",[9768],{"data":9769,"marks":9770,"value":9772,"nodeType":874},{},[9771],{"type":974},"Okta to keylog credentials",{"data":9774,"marks":9775,"value":9776,"nodeType":874},{},[]," on behalf of the attacker. ",{"data":9778,"content":9779,"nodeType":870},{},[9780],{"data":9781,"marks":9782,"value":9783,"nodeType":874},{},[],"Increasingly, we should expect to see AitM toolkits being used as a standard part of phishing campaigns, and featured in Initial Access Broker tooling – AitM will effectively supersede legacy phishing methods in line with MFA adoption. Rather, it already is. ",{"data":9785,"content":9786,"nodeType":896},{},[],{"data":9788,"content":9789,"nodeType":870},{},[9790],{"data":9791,"marks":9792,"value":9793,"nodeType":874},{},[],"If you're interested in seeing some more AitM tools in action, you can watch our recent webinar on-demand via the link below. ",{"data":9795,"content":9798,"nodeType":1215},{"target":9796},{"sys":9797},{"id":9035,"type":1220,"linkType":1221},[],{"data":9800,"content":9801,"nodeType":870},{},[9802],{"data":9803,"marks":9804,"value":21,"nodeType":874},{},[],"Phishing 2.0 – how phishing toolkits are evolving with AitM","Attackers are using Adversary in the Middle (AitM) phishing toolkits to bypass MFA. We look at what AitM is, how it works, and what you can do about it.","2024-05-23T00:00:00.000Z","phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm",{"items":9810},[9811,9813],{"sys":9812,"name":2007},{"id":2006},{"sys":9814,"name":334},{"id":2010},{"items":9816},[9817],{"fullName":9818,"firstName":9819,"jobTitle":9820,"profilePicture":9821},"Luke Jennings","Luke","Vice President, R&D",{"url":9822},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4Hosb4zKi1dA0PUyDLMe1h\u002F27e09d894861f2196ba794037986fb08\u002FT016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":1126,"sys":9824,"content":9826,"title":10333,"synopsis":10334,"hashTags":60,"publishedDate":8949,"slug":10335,"tagsCollection":10336,"authorsCollection":10342},{"id":9825},"7JngmuGwqKvYLzU8bGMTQD",{"json":9827},{"data":9828,"content":9829,"nodeType":866},{},[9830,9836,9842,9854,9866,9869,9877,9883,9890,9897,9904,9911,9917,9924,9929,9932,9940,9947,9980,9987,9995,10002,10009,10016,10022,10030,10037,10042,10049,10070,10077,10085,10092,10099,10106,10111,10118,10135,10138,10146,10160,10166,10200,10208,10211,10219,10226,10240,10245,10251,10257,10264,10269,10276,10281,10284,10291,10297,10302,10307,10327],{"data":9831,"content":9832,"nodeType":870},{},[9833],{"data":9834,"marks":9835,"value":8308,"nodeType":874},{},[],{"data":9837,"content":9838,"nodeType":870},{},[9839],{"data":9840,"marks":9841,"value":8322,"nodeType":874},{},[],{"data":9843,"content":9844,"nodeType":870},{},[9845,9849],{"data":9846,"marks":9847,"value":9848,"nodeType":874},{},[],"A key challenge with phishing detection is that based on the known-bad indicators that we as an industry use to commonly detect phishing pages, pretty much every phishing attack looks different and uses a unique combination of domain, URL, IPs, page composition, target app, etc. ",{"data":9850,"marks":9851,"value":9853,"nodeType":874},{},[9852],{"type":882},"Effectively, every phishing attack is completely novel. You might even describe them as “zero-days” (cue the collective sharp intake of breath)...",{"data":9855,"content":9856,"nodeType":870},{},[9857,9861],{"data":9858,"marks":9859,"value":9860,"nodeType":874},{},[],"The goal here isn’t to sensationalize phishing attacks — quite the opposite. Rather, this shines a light on the state of phishing detection controls. ",{"data":9862,"marks":9863,"value":9865,"nodeType":874},{},[9864],{"type":882},"Frankly, if every phishing attack is a zero-day, something has gone very wrong with how we detect these attacks…",{"data":9867,"content":9868,"nodeType":896},{},[],{"data":9870,"content":9871,"nodeType":900},{},[9872],{"data":9873,"marks":9874,"value":9876,"nodeType":874},{},[9875],{"type":882},"Phishing detection 101",{"data":9878,"content":9879,"nodeType":870},{},[9880],{"data":9881,"marks":9882,"value":8468,"nodeType":874},{},[],{"data":9884,"content":9885,"nodeType":870},{},[9886],{"data":9887,"marks":9888,"value":9889,"nodeType":874},{},[],"Phishing detection, at its core, relies on blocklists made up of indicators of compromise (IoCs) relating to phishing pages that have been successfully identified as malicious. These IoCs consist of malicious domains, URLs, and IPs that have appeared in an attack. ",{"data":9891,"content":9892,"nodeType":870},{},[9893],{"data":9894,"marks":9895,"value":9896,"nodeType":874},{},[],"IoCs are collected by security vendors and service providers across a range of sources. Mostly though, the malicious page needs to be used in a phishing campaign before it has a chance of being detected. This means that a would-be victim needs to interact with it in some way — either by falling for a phishing attack, or reporting it as suspicious. ",{"data":9898,"content":9899,"nodeType":870},{},[9900],{"data":9901,"marks":9902,"value":9903,"nodeType":874},{},[],"Once a page is flagged, it can be investigated — either manually (by a security person) or automatically (by a product\u002Ftool). If the page can be accessed and analyzed, and malicious content is found (more on this later) then the page’s IoCs can be collected and added to a blocklist. ",{"data":9905,"content":9906,"nodeType":870},{},[9907],{"data":9908,"marks":9909,"value":9910,"nodeType":874},{},[],"This information will then begin to circulate across the various threat intelligence feeds and security products leveraging this information. The majority of phishing detection and control enforcement is focused at the email and network layer — typically at the Secure Email Gateway (SEG), Secure Web Gateway (SWG)\u002Fproxy, or both. ",{"data":9912,"content":9916,"nodeType":1215},{"target":9913},{"sys":9914},{"id":9915,"type":1220,"linkType":1221},"7xPrHlTjDI1Lc620fAnxvX",[],{"data":9918,"content":9919,"nodeType":870},{},[9920],{"data":9921,"marks":9922,"value":9923,"nodeType":874},{},[],"If you’re following the thought pattern here, you can probably already see the root of the problem. To detect and block a phishing page, it needs to be used in an attack first…",{"data":9925,"content":9928,"nodeType":1215},{"target":9926},{"sys":9927},{"id":8939,"type":1220,"linkType":1221},[],{"data":9930,"content":9931,"nodeType":896},{},[],{"data":9933,"content":9934,"nodeType":900},{},[9935],{"data":9936,"marks":9937,"value":9939,"nodeType":874},{},[9938],{"type":882},"Why most phishing attacks are zero-day",{"data":9941,"content":9942,"nodeType":870},{},[9943],{"data":9944,"marks":9945,"value":9946,"nodeType":874},{},[],"Attackers know that phishing detection and blocking:",{"data":9948,"content":9949,"nodeType":1763},{},[9950,9960,9970],{"data":9951,"content":9952,"nodeType":1767},{},[9953],{"data":9954,"content":9955,"nodeType":870},{},[9956],{"data":9957,"marks":9958,"value":9959,"nodeType":874},{},[],"Relies on blocklisting IoCs like domains, URLs and IPs",{"data":9961,"content":9962,"nodeType":1767},{},[9963],{"data":9964,"content":9965,"nodeType":870},{},[9966],{"data":9967,"marks":9968,"value":9969,"nodeType":874},{},[],"Is situated at the email and network layer",{"data":9971,"content":9972,"nodeType":1767},{},[9973],{"data":9974,"content":9975,"nodeType":870},{},[9976],{"data":9977,"marks":9978,"value":9979,"nodeType":874},{},[],"Requires that a page is accessed and analyzed before it can be blocked",{"data":9981,"content":9982,"nodeType":870},{},[9983],{"data":9984,"marks":9985,"value":9986,"nodeType":874},{},[],"These methods have remained practically unchanged for more than a decade. So it stands to reason that attackers are getting pretty good at avoiding them. ",{"data":9988,"content":9989,"nodeType":944},{},[9990],{"data":9991,"marks":9992,"value":9994,"nodeType":874},{},[9993],{"type":882},"It’s easy for attackers to evade IoC-based detections",{"data":9996,"content":9997,"nodeType":870},{},[9998],{"data":9999,"marks":10000,"value":10001,"nodeType":874},{},[],"Phishing domains are highly disposable by nature. Attackers are buying them in bulk, constantly taking over legitimate domains, and generally planning for the fact that they’ll get through a lot of them.",{"data":10003,"content":10004,"nodeType":870},{},[10005],{"data":10006,"marks":10007,"value":10008,"nodeType":874},{},[],"Modern phishing architecture is also able to dynamically rotate and update commonly signatured elements — for example, by dynamically rotating the links served to visitors from a continually refreshed pool (so every person that clicks the link gets served a different URL) and even going as far as using things like one-time magic links (which also means that any security team members trying to investigate the page later won’t be able to do so). ",{"data":10010,"content":10011,"nodeType":870},{},[10012],{"data":10013,"marks":10014,"value":10015,"nodeType":874},{},[],"You could look at which IP address the user connects to, but these days it’s very simple for attackers to add a new IP to their cloud-hosted server. If a domain is flagged as known-bad, the attacker only has to register a new domain, or compromise a WordPress server on an already trusted domain. Both of these things are happening on a massive scale as attackers pre-plan for the fact that their domains will be burned at some point. ",{"data":10017,"content":10018,"nodeType":870},{},[10019],{"data":10020,"marks":10021,"value":8574,"nodeType":874},{},[],{"data":10023,"content":10024,"nodeType":944},{},[10025],{"data":10026,"marks":10027,"value":10029,"nodeType":874},{},[10028],{"type":882},"Phishing doesn’t just happen over email",{"data":10031,"content":10032,"nodeType":870},{},[10033],{"data":10034,"marks":10035,"value":10036,"nodeType":874},{},[],"To evade email-based detections, attackers are going multi- and cross-channel with their attacks. ",{"data":10038,"content":10041,"nodeType":1215},{"target":10039},{"sys":10040},{"id":8424,"type":1220,"linkType":1221},[],{"data":10043,"content":10044,"nodeType":870},{},[10045],{"data":10046,"marks":10047,"value":10048,"nodeType":874},{},[],"Not only are attackers using different phishing vectors, they’re chaining them together to prevent security tools from intercepting the link. So for example, a social media message that sends you a non-malicious PDF with a link embedded in it, that finally directs you to a malicious webpage.",{"data":10050,"content":10051,"nodeType":870},{},[10052,10056,10060,10063,10067],{"data":10053,"marks":10054,"value":10055,"nodeType":874},{},[],"It’s worth also pointing out the limitations of email-based solutions here too. Email has some additional checks around the sender’s reputation and things like DMARC\u002FDKIM, but these don’t actually identify malicious ",{"data":10057,"marks":10058,"value":8437,"nodeType":874},{},[10059],{"type":882},{"data":10061,"marks":10062,"value":8441,"nodeType":874},{},[],{"data":10064,"marks":10065,"value":8446,"nodeType":874},{},[10066],{"type":882},{"data":10068,"marks":10069,"value":8450,"nodeType":874},{},[],{"data":10071,"content":10072,"nodeType":870},{},[10073],{"data":10074,"marks":10075,"value":10076,"nodeType":874},{},[],"In any case, while modern email solutions can bring a lot more to the table, neither email or network (proxy) based tools can’t definitively know that a page is malicious unless they can access the page and analyze it… ",{"data":10078,"content":10079,"nodeType":944},{},[10080],{"data":10081,"marks":10082,"value":10084,"nodeType":874},{},[10083],{"type":882},"Attackers are preventing their pages from being analyzed",{"data":10086,"content":10087,"nodeType":870},{},[10088],{"data":10089,"marks":10090,"value":10091,"nodeType":874},{},[],"Both email and network (proxy) based solutions rely on being able to inspect and analyze a page to identify whether it is malicious or not, after which IoCs are generated that can be enforced when a link is clicked (or received in your email inbox).",{"data":10093,"content":10094,"nodeType":870},{},[10095],{"data":10096,"marks":10097,"value":10098,"nodeType":874},{},[],"Modern phishing pages aren’t static HTML — like most other modern web pages, these are dynamic web apps rendered in the browser, with JavaScript dynamically rewriting the page and launching the malicious content. This means that most basic, static checks fail to identify the malicious content running on the page. ",{"data":10100,"content":10101,"nodeType":870},{},[10102],{"data":10103,"marks":10104,"value":10105,"nodeType":874},{},[],"To address this, both email and network security tools will try to explode links in a sandbox to observe the page’s behavior. But attackers are getting around this simply by implementing bot protection by requiring user interaction with a CAPTCHA or Cloudflare Turnstile. ",{"data":10107,"content":10110,"nodeType":1215},{"target":10108},{"sys":10109},{"id":8398,"type":1220,"linkType":1221},[],{"data":10112,"content":10113,"nodeType":870},{},[10114],{"data":10115,"marks":10116,"value":10117,"nodeType":874},{},[],"Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":10119,"content":10120,"nodeType":870},{},[10121,10124,10132],{"data":10122,"marks":10123,"value":8613,"nodeType":874},{},[],{"data":10125,"content":10127,"nodeType":966},{"uri":10126},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-aitm-phishing-kits-evade-detection-p2\u002F?utm_campaign=12100141-FY25Q2_Bleeping-Computer-Article&utm_source=bleepingcomputer&utm_medium=sponsored&utm_content=external-article",[10128],{"data":10129,"marks":10130,"value":8622,"nodeType":874},{},[10131],{"type":974},{"data":10133,"marks":10134,"value":8626,"nodeType":874},{},[],{"data":10136,"content":10137,"nodeType":896},{},[],{"data":10139,"content":10140,"nodeType":900},{},[10141],{"data":10142,"marks":10143,"value":10145,"nodeType":874},{},[10144],{"type":882},"Phishing attacks are zero-day because phishing detection is post mortem",{"data":10147,"content":10148,"nodeType":870},{},[10149,10153,10157],{"data":10150,"marks":10151,"value":10152,"nodeType":874},{},[],"The result of these detection evasion and obfuscation techniques is that ",{"data":10154,"marks":10155,"value":8740,"nodeType":874},{},[10156],{"type":882},{"data":10158,"marks":10159,"value":8500,"nodeType":874},{},[],{"data":10161,"content":10162,"nodeType":870},{},[10163],{"data":10164,"marks":10165,"value":8750,"nodeType":874},{},[],{"data":10167,"content":10168,"nodeType":870},{},[10169,10172,10176,10179,10183,10186,10190,10193,10197],{"data":10170,"marks":10171,"value":8757,"nodeType":874},{},[],{"data":10173,"marks":10174,"value":8762,"nodeType":874},{},[10175],{"type":882},{"data":10177,"marks":10178,"value":8766,"nodeType":874},{},[],{"data":10180,"marks":10181,"value":8771,"nodeType":874},{},[10182],{"type":882},{"data":10184,"marks":10185,"value":8775,"nodeType":874},{},[],{"data":10187,"marks":10188,"value":8771,"nodeType":874},{},[10189],{"type":882},{"data":10191,"marks":10192,"value":8783,"nodeType":874},{},[],{"data":10194,"marks":10195,"value":8788,"nodeType":874},{},[10196],{"type":882},{"data":10198,"marks":10199,"value":8792,"nodeType":874},{},[],{"data":10201,"content":10202,"nodeType":870},{},[10203],{"data":10204,"marks":10205,"value":10207,"nodeType":874},{},[10206],{"type":882},"The result? Most phishing attacks are entirely novel because phishing detection is inherently post mortem — it relies on known-bads. How does something become known-bad? When a user is phished…",{"data":10209,"content":10210,"nodeType":896},{},[],{"data":10212,"content":10213,"nodeType":900},{},[10214],{"data":10215,"marks":10216,"value":10218,"nodeType":874},{},[10217],{"type":882},"To fix phishing detection, we need real-time analysis",{"data":10220,"content":10221,"nodeType":870},{},[10222],{"data":10223,"marks":10224,"value":10225,"nodeType":874},{},[],"It’s clear that how we detect and block phishing attacks is fundamentally flawed. The good news is, we’ve been here before. ",{"data":10227,"content":10228,"nodeType":870},{},[10229,10233,10237],{"data":10230,"marks":10231,"value":10232,"nodeType":874},{},[],"When endpoint attacks skyrocketed in the late 2000s \u002F early 2010s, they took advantage of the fact that defenders were trying to detect malware with primarily network-based detections, signature-based analysis of files, and running files in sandboxes (which was reliably defeated with sandbox-aware malware and using things as simple as putting an execution delay in the code). But this gave way to EDR, which presented a better way of observing and intercepting malicious software in ",{"data":10234,"marks":10235,"value":8496,"nodeType":874},{},[10236],{"type":882},{"data":10238,"marks":10239,"value":8500,"nodeType":874},{},[],{"data":10241,"content":10244,"nodeType":1215},{"target":10242},{"sys":10243},{"id":8505,"type":1220,"linkType":1221},[],{"data":10246,"content":10247,"nodeType":870},{},[10248],{"data":10249,"marks":10250,"value":8513,"nodeType":874},{},[],{"data":10252,"content":10253,"nodeType":870},{},[10254],{"data":10255,"marks":10256,"value":8520,"nodeType":874},{},[],{"data":10258,"content":10259,"nodeType":870},{},[10260],{"data":10261,"marks":10262,"value":10263,"nodeType":874},{},[],"In many ways, the browser is the new Operating System. It’s where modern work predominantly takes place — and where attacks are happening too.  ",{"data":10265,"content":10268,"nodeType":1215},{"target":10266},{"sys":10267},{"id":8525,"type":1220,"linkType":1221},[],{"data":10270,"content":10271,"nodeType":870},{},[10272],{"data":10273,"marks":10274,"value":10275,"nodeType":874},{},[],"To stop phishing attacks as they happen, we need to be able to observe the page in real-time, as the user sees it from inside the browser. Not in a sandbox — seeing the real page, at the same time as the user. Only then can we build the detection and containment controls required to move phishing beyond the current cat-and-mouse game, where attackers are always two steps ahead. ",{"data":10277,"content":10280,"nodeType":1215},{"target":10278},{"sys":10279},{"id":8696,"type":1220,"linkType":1221},[],{"data":10282,"content":10283,"nodeType":896},{},[],{"data":10285,"content":10286,"nodeType":900},{},[10287],{"data":10288,"marks":10289,"value":8815,"nodeType":874},{},[10290],{"type":882},{"data":10292,"content":10293,"nodeType":870},{},[10294],{"data":10295,"marks":10296,"value":8822,"nodeType":874},{},[],{"data":10298,"content":10301,"nodeType":1215},{"target":10299},{"sys":10300},{"id":8709,"type":1220,"linkType":1221},[],{"data":10303,"content":10306,"nodeType":1215},{"target":10304},{"sys":10305},{"id":8939,"type":1220,"linkType":1221},[],{"data":10308,"content":10309,"nodeType":7261},{},[10310],{"data":10311,"content":10312,"nodeType":870},{},[10313,10316,10324],{"data":10314,"marks":10315,"value":7555,"nodeType":874},{},[],{"data":10317,"content":10319,"nodeType":966},{"uri":10318},"https:\u002F\u002Fpushsecurity.com\u002Fdemo?utm_campaign=12100141-FY25Q2_Bleeping-Computer-Article&utm_source=bleepingcomputer&utm_medium=sponsored&utm_content=external-article",[10320],{"data":10321,"marks":10322,"value":1991,"nodeType":874},{},[10323],{"type":974},{"data":10325,"marks":10326,"value":1581,"nodeType":874},{},[],{"data":10328,"content":10329,"nodeType":870},{},[10330],{"data":10331,"marks":10332,"value":21,"nodeType":874},{},[],"Why most phishing attacks feel like a zero-day","Most phishing attacks involve a phishing page that has never been seen before. When detection relies on known-bad, this makes every attack feel like a zero-day.","why-most-phishing-attacks-feel-like-a-zero-day",{"items":10337},[10338,10340],{"sys":10339,"name":334},{"id":2010},{"sys":10341,"name":2007},{"id":2006},{"items":10343},[10344],{"fullName":2014,"firstName":2015,"jobTitle":2016,"profilePicture":10345},{"url":2018},"blog\u002Femail-security-how-hackers-use-mail-rules-to-access-your-inbox",{"json":10348},{"data":10349,"content":10350,"nodeType":866},{},[10351],{"data":10352,"content":10353,"nodeType":870},{},[10354],{"data":10355,"marks":10356,"value":10357,"nodeType":874},{},[],"After a successful phishing campaign against Office 365 and Google Workspace users, a malicious mail rule can be automatically created in the user’s mailbox that forwards sensitive emails to an external address. Learn the best way to protect your company.",{"id":7217,"publishedAt":10359},"2026-08-13T09:35:35.165Z",{"items":10361},[10362,10364],{"sys":10363,"name":2007},{"id":2006},{"sys":10365,"name":334},{"id":2010},{"items":10367},[10368,10370,10372,10374,10376],{"sys":10369,"name":404,"slug":405,"tier":31},{"id":401},{"sys":10371,"name":510,"slug":511,"tier":31},{"id":507},{"sys":10373,"name":334,"slug":335,"tier":31},{"id":331},{"sys":10375,"name":316,"slug":317,"tier":45},{"id":313},{"sys":10377,"name":262,"slug":263,"tier":45},{"id":259},"sEfRQ2v3Pofnqnyx_DZd0ngcEk-VVASvWZrQKcO4_TQ",{"id":10380,"title":7909,"authorsCollection":10381,"content":10385,"extension":219,"faqItemsCollection":10684,"faqTitle":60,"featured":6,"hashTags":10686,"meta":10687,"metaTitle":10688,"ogImage":60,"postType":5015,"publishedDate":7912,"relatedBlogPostsCollection":10689,"slug":7913,"stem":11101,"subtitle":60,"summary":11102,"synopsis":7910,"sys":11113,"tagsCollection":11115,"topicsCollection":11121,"__hash__":11131},"blog\u002Fblog\u002Fshould-you-disable-external-email-auto-forwarding.json",{"items":10382},[10383],{"fullName":7582,"firstName":7583,"jobTitle":7584,"socialLinks":60,"profilePicture":10384},{"url":7586},{"json":10386,"links":10658},{"data":10387,"content":10388,"nodeType":866},{},[10389,10404,10410,10434,10447,10453,10459,10465,10472,10478,10494,10500,10516,10521,10528,10534,10550,10557,10573,10580,10586,10634,10641,10647,10652],{"data":10390,"content":10391,"nodeType":870},{},[10392,10395,10401],{"data":10393,"marks":10394,"value":7600,"nodeType":874},{},[],{"data":10396,"content":10397,"nodeType":966},{"uri":7603},[10398],{"data":10399,"marks":10400,"value":7608,"nodeType":874},{},[],{"data":10402,"marks":10403,"value":7612,"nodeType":874},{},[],{"data":10405,"content":10406,"nodeType":944},{},[10407],{"data":10408,"marks":10409,"value":7619,"nodeType":874},{},[],{"data":10411,"content":10412,"nodeType":870},{},[10413,10416,10420,10423,10431],{"data":10414,"marks":10415,"value":7626,"nodeType":874},{},[],{"data":10417,"marks":10418,"value":7631,"nodeType":874},{},[10419],{"type":882},{"data":10421,"marks":10422,"value":7635,"nodeType":874},{},[],{"data":10424,"content":10427,"nodeType":7482},{"target":10425},{"sys":10426},{"id":7476,"type":1220,"linkType":1221},[10428],{"data":10429,"marks":10430,"value":7644,"nodeType":874},{},[],{"data":10432,"marks":10433,"value":7648,"nodeType":874},{},[],{"data":10435,"content":10436,"nodeType":870},{},[10437,10440,10444],{"data":10438,"marks":10439,"value":7655,"nodeType":874},{},[],{"data":10441,"marks":10442,"value":7660,"nodeType":874},{},[10443],{"type":882},{"data":10445,"marks":10446,"value":7664,"nodeType":874},{},[],{"data":10448,"content":10449,"nodeType":944},{},[10450],{"data":10451,"marks":10452,"value":7671,"nodeType":874},{},[],{"data":10454,"content":10455,"nodeType":870},{},[10456],{"data":10457,"marks":10458,"value":7678,"nodeType":874},{},[],{"data":10460,"content":10461,"nodeType":870},{},[10462],{"data":10463,"marks":10464,"value":7685,"nodeType":874},{},[],{"data":10466,"content":10467,"nodeType":870},{},[10468],{"data":10469,"marks":10470,"value":7693,"nodeType":874},{},[10471],{"type":882},{"data":10473,"content":10474,"nodeType":870},{},[10475],{"data":10476,"marks":10477,"value":7700,"nodeType":874},{},[],{"data":10479,"content":10480,"nodeType":870},{},[10481,10484,10491],{"data":10482,"marks":10483,"value":7707,"nodeType":874},{},[],{"data":10485,"content":10486,"nodeType":966},{"uri":7710},[10487],{"data":10488,"marks":10489,"value":7716,"nodeType":874},{},[10490],{"type":974},{"data":10492,"marks":10493,"value":7720,"nodeType":874},{},[],{"data":10495,"content":10496,"nodeType":870},{},[10497],{"data":10498,"marks":10499,"value":7727,"nodeType":874},{},[],{"data":10501,"content":10502,"nodeType":870},{},[10503,10506,10513],{"data":10504,"marks":10505,"value":7734,"nodeType":874},{},[],{"data":10507,"content":10508,"nodeType":966},{"uri":7737},[10509],{"data":10510,"marks":10511,"value":7743,"nodeType":874},{},[10512],{"type":974},{"data":10514,"marks":10515,"value":7747,"nodeType":874},{},[],{"data":10517,"content":10520,"nodeType":1215},{"target":10518},{"sys":10519},{"id":7136,"type":1220,"linkType":1221},[],{"data":10522,"content":10523,"nodeType":870},{},[10524],{"data":10525,"marks":10526,"value":7760,"nodeType":874},{},[10527],{"type":882},{"data":10529,"content":10530,"nodeType":870},{},[10531],{"data":10532,"marks":10533,"value":7767,"nodeType":874},{},[],{"data":10535,"content":10536,"nodeType":870},{},[10537,10540,10547],{"data":10538,"marks":10539,"value":7774,"nodeType":874},{},[],{"data":10541,"content":10542,"nodeType":966},{"uri":7777},[10543],{"data":10544,"marks":10545,"value":7783,"nodeType":874},{},[10546],{"type":974},{"data":10548,"marks":10549,"value":7787,"nodeType":874},{},[],{"data":10551,"content":10552,"nodeType":870},{},[10553],{"data":10554,"marks":10555,"value":7795,"nodeType":874},{},[10556],{"type":882},{"data":10558,"content":10559,"nodeType":870},{},[10560,10563,10570],{"data":10561,"marks":10562,"value":7802,"nodeType":874},{},[],{"data":10564,"content":10565,"nodeType":966},{"uri":7805},[10566],{"data":10567,"marks":10568,"value":7811,"nodeType":874},{},[10569],{"type":974},{"data":10571,"marks":10572,"value":1581,"nodeType":874},{},[],{"data":10574,"content":10575,"nodeType":870},{},[10576],{"data":10577,"marks":10578,"value":7822,"nodeType":874},{},[10579],{"type":882},{"data":10581,"content":10582,"nodeType":870},{},[10583],{"data":10584,"marks":10585,"value":7829,"nodeType":874},{},[],{"data":10587,"content":10588,"nodeType":1763},{},[10589,10598,10607,10616,10625],{"data":10590,"content":10591,"nodeType":1767},{},[10592],{"data":10593,"content":10594,"nodeType":870},{},[10595],{"data":10596,"marks":10597,"value":7842,"nodeType":874},{},[],{"data":10599,"content":10600,"nodeType":1767},{},[10601],{"data":10602,"content":10603,"nodeType":870},{},[10604],{"data":10605,"marks":10606,"value":7852,"nodeType":874},{},[],{"data":10608,"content":10609,"nodeType":1767},{},[10610],{"data":10611,"content":10612,"nodeType":870},{},[10613],{"data":10614,"marks":10615,"value":7862,"nodeType":874},{},[],{"data":10617,"content":10618,"nodeType":1767},{},[10619],{"data":10620,"content":10621,"nodeType":870},{},[10622],{"data":10623,"marks":10624,"value":7872,"nodeType":874},{},[],{"data":10626,"content":10627,"nodeType":1767},{},[10628],{"data":10629,"content":10630,"nodeType":870},{},[10631],{"data":10632,"marks":10633,"value":7882,"nodeType":874},{},[],{"data":10635,"content":10636,"nodeType":870},{},[10637],{"data":10638,"marks":10639,"value":1946,"nodeType":874},{},[10640],{"type":882},{"data":10642,"content":10643,"nodeType":870},{},[10644],{"data":10645,"marks":10646,"value":7896,"nodeType":874},{},[],{"data":10648,"content":10651,"nodeType":1215},{"target":10649},{"sys":10650},{"id":7901,"type":1220,"linkType":1221},[],{"data":10653,"content":10654,"nodeType":870},{},[10655],{"data":10656,"marks":10657,"value":21,"nodeType":874},{},[],{"entries":10659},{"inline":10660,"hyperlink":10661,"block":10664},[],[10662],{"sys":10663,"__typename":8270,"title":8271,"slug":8272,"articleId":8273},{"id":7476},[10665,10677],{"sys":10666,"__typename":7180,"content":10667,"title":7192,"buttonText":7193,"buttonUrl":60,"signupRedirectUrl":7194},{"id":7136},{"json":10668},{"data":10669,"content":10670,"nodeType":866},{},[10671],{"data":10672,"content":10673,"nodeType":870},{},[10674],{"data":10675,"marks":10676,"value":7191,"nodeType":874},{},[],{"sys":10678,"__typename":10679,"type":10680,"ctaText":10681,"buttonLabel":10682,"buttonColour":10683,"buttonUrl":60},{"id":7901},"CtaWidget","LinkedIn","See more original research and technical content from Push","Follow us on LinkedIn","orange",{"items":10685},[],[7205,263,7206,7207,7569],{},"Understanding the risks of external email auto-forwarding",{"items":10690},[10691,11000],{"__typename":1126,"sys":10692,"content":10693,"title":7566,"synopsis":7567,"hashTags":10989,"publishedDate":7571,"slug":7572,"tagsCollection":10990,"authorsCollection":10996},{"id":7217},{"json":10694},{"data":10695,"content":10696,"nodeType":866},{},[10697,10703,10708,10714,10730,10753,10759,10834,10849,10852,10858,10873,10879,10885,10888,10894,10931,10937,10952,10958,10961,10968,10974],{"data":10698,"content":10699,"nodeType":870},{},[10700],{"data":10701,"marks":10702,"value":7228,"nodeType":874},{},[],{"data":10704,"content":10707,"nodeType":1215},{"target":10705},{"sys":10706},{"id":7233,"type":1220,"linkType":1221},[],{"data":10709,"content":10710,"nodeType":870},{},[10711],{"data":10712,"marks":10713,"value":7241,"nodeType":874},{},[],{"data":10715,"content":10716,"nodeType":7261},{},[10717],{"data":10718,"content":10719,"nodeType":870},{},[10720,10723,10727],{"data":10721,"marks":10722,"value":7251,"nodeType":874},{},[],{"data":10724,"marks":10725,"value":7256,"nodeType":874},{},[10726],{"type":882},{"data":10728,"marks":10729,"value":7260,"nodeType":874},{},[],{"data":10731,"content":10732,"nodeType":870},{},[10733,10736,10743,10746,10750],{"data":10734,"marks":10735,"value":7268,"nodeType":874},{},[],{"data":10737,"content":10738,"nodeType":966},{"uri":7271},[10739],{"data":10740,"marks":10741,"value":7277,"nodeType":874},{},[10742],{"type":974},{"data":10744,"marks":10745,"value":7281,"nodeType":874},{},[],{"data":10747,"marks":10748,"value":7286,"nodeType":874},{},[10749],{"type":1144},{"data":10751,"marks":10752,"value":7290,"nodeType":874},{},[],{"data":10754,"content":10755,"nodeType":870},{},[10756],{"data":10757,"marks":10758,"value":7297,"nodeType":874},{},[],{"data":10760,"content":10761,"nodeType":1763},{},[10762,10780,10798,10816],{"data":10763,"content":10764,"nodeType":1767},{},[10765],{"data":10766,"content":10767,"nodeType":870},{},[10768,10771,10777],{"data":10769,"marks":10770,"value":21,"nodeType":874},{},[],{"data":10772,"content":10773,"nodeType":966},{"uri":7312},[10774],{"data":10775,"marks":10776,"value":7317,"nodeType":874},{},[],{"data":10778,"marks":10779,"value":21,"nodeType":874},{},[],{"data":10781,"content":10782,"nodeType":1767},{},[10783],{"data":10784,"content":10785,"nodeType":870},{},[10786,10789,10795],{"data":10787,"marks":10788,"value":21,"nodeType":874},{},[],{"data":10790,"content":10791,"nodeType":966},{"uri":7332},[10792],{"data":10793,"marks":10794,"value":7337,"nodeType":874},{},[],{"data":10796,"marks":10797,"value":21,"nodeType":874},{},[],{"data":10799,"content":10800,"nodeType":1767},{},[10801],{"data":10802,"content":10803,"nodeType":870},{},[10804,10807,10813],{"data":10805,"marks":10806,"value":21,"nodeType":874},{},[],{"data":10808,"content":10809,"nodeType":966},{"uri":7352},[10810],{"data":10811,"marks":10812,"value":7357,"nodeType":874},{},[],{"data":10814,"marks":10815,"value":7361,"nodeType":874},{},[],{"data":10817,"content":10818,"nodeType":1767},{},[10819],{"data":10820,"content":10821,"nodeType":870},{},[10822,10825,10831],{"data":10823,"marks":10824,"value":21,"nodeType":874},{},[],{"data":10826,"content":10827,"nodeType":966},{"uri":7373},[10828],{"data":10829,"marks":10830,"value":7378,"nodeType":874},{},[],{"data":10832,"marks":10833,"value":21,"nodeType":874},{},[],{"data":10835,"content":10836,"nodeType":870},{},[10837,10840,10846],{"data":10838,"marks":10839,"value":7388,"nodeType":874},{},[],{"data":10841,"content":10842,"nodeType":966},{"uri":7391},[10843],{"data":10844,"marks":10845,"value":7396,"nodeType":874},{},[],{"data":10847,"marks":10848,"value":7400,"nodeType":874},{},[],{"data":10850,"content":10851,"nodeType":896},{},[],{"data":10853,"content":10854,"nodeType":900},{},[10855],{"data":10856,"marks":10857,"value":7410,"nodeType":874},{},[],{"data":10859,"content":10860,"nodeType":870},{},[10861,10864,10870],{"data":10862,"marks":10863,"value":21,"nodeType":874},{},[],{"data":10865,"content":10866,"nodeType":966},{"uri":7419},[10867],{"data":10868,"marks":10869,"value":7424,"nodeType":874},{},[],{"data":10871,"marks":10872,"value":7428,"nodeType":874},{},[],{"data":10874,"content":10875,"nodeType":870},{},[10876],{"data":10877,"marks":10878,"value":7435,"nodeType":874},{},[],{"data":10880,"content":10881,"nodeType":870},{},[10882],{"data":10883,"marks":10884,"value":7442,"nodeType":874},{},[],{"data":10886,"content":10887,"nodeType":896},{},[],{"data":10889,"content":10890,"nodeType":900},{},[10891],{"data":10892,"marks":10893,"value":7452,"nodeType":874},{},[],{"data":10895,"content":10896,"nodeType":870},{},[10897,10900,10906,10909,10917,10920,10928],{"data":10898,"marks":10899,"value":7459,"nodeType":874},{},[],{"data":10901,"content":10902,"nodeType":966},{"uri":7462},[10903],{"data":10904,"marks":10905,"value":7467,"nodeType":874},{},[],{"data":10907,"marks":10908,"value":7471,"nodeType":874},{},[],{"data":10910,"content":10913,"nodeType":7482},{"target":10911},{"sys":10912},{"id":7476,"type":1220,"linkType":1221},[10914],{"data":10915,"marks":10916,"value":7481,"nodeType":874},{},[],{"data":10918,"marks":10919,"value":7486,"nodeType":874},{},[],{"data":10921,"content":10924,"nodeType":7482},{"target":10922},{"sys":10923},{"id":7491,"type":1220,"linkType":1221},[10925],{"data":10926,"marks":10927,"value":7496,"nodeType":874},{},[],{"data":10929,"marks":10930,"value":1581,"nodeType":874},{},[],{"data":10932,"content":10933,"nodeType":870},{},[10934],{"data":10935,"marks":10936,"value":7506,"nodeType":874},{},[],{"data":10938,"content":10939,"nodeType":870},{},[10940,10943,10949],{"data":10941,"marks":10942,"value":7513,"nodeType":874},{},[],{"data":10944,"content":10945,"nodeType":966},{"uri":7462},[10946],{"data":10947,"marks":10948,"value":7520,"nodeType":874},{},[],{"data":10950,"marks":10951,"value":1581,"nodeType":874},{},[],{"data":10953,"content":10954,"nodeType":870},{},[10955],{"data":10956,"marks":10957,"value":7530,"nodeType":874},{},[],{"data":10959,"content":10960,"nodeType":896},{},[],{"data":10962,"content":10963,"nodeType":900},{},[10964],{"data":10965,"marks":10966,"value":7541,"nodeType":874},{},[10967],{"type":882},{"data":10969,"content":10970,"nodeType":870},{},[10971],{"data":10972,"marks":10973,"value":7548,"nodeType":874},{},[],{"data":10975,"content":10976,"nodeType":870},{},[10977,10980,10986],{"data":10978,"marks":10979,"value":7555,"nodeType":874},{},[],{"data":10981,"content":10982,"nodeType":966},{"uri":7558},[10983],{"data":10984,"marks":10985,"value":1991,"nodeType":874},{},[],{"data":10987,"marks":10988,"value":1581,"nodeType":874},{},[],[7205,263,7206,7207,7569,7570],{"items":10991},[10992,10994],{"sys":10993,"name":2007},{"id":2006},{"sys":10995,"name":334},{"id":2010},{"items":10997},[10998],{"fullName":7582,"firstName":7583,"jobTitle":7584,"profilePicture":10999},{"url":7586},{"__typename":1126,"sys":11001,"content":11002,"title":7054,"synopsis":7937,"hashTags":11090,"publishedDate":7212,"slug":7924,"tagsCollection":11091,"authorsCollection":11097},{"id":7939},{"json":11003},{"data":11004,"content":11005,"nodeType":866},{},[11006,11012,11015,11021,11027,11032,11038,11044,11050,11056,11062,11067,11073,11078,11084],{"data":11007,"content":11008,"nodeType":870},{},[11009],{"data":11010,"marks":11011,"value":7073,"nodeType":874},{},[],{"data":11013,"content":11014,"nodeType":896},{},[],{"data":11016,"content":11017,"nodeType":870},{},[11018],{"data":11019,"marks":11020,"value":7083,"nodeType":874},{},[],{"data":11022,"content":11023,"nodeType":870},{},[11024],{"data":11025,"marks":11026,"value":7090,"nodeType":874},{},[],{"data":11028,"content":11031,"nodeType":1215},{"target":11029},{"sys":11030},{"id":7095,"type":1220,"linkType":1221},[],{"data":11033,"content":11034,"nodeType":870},{},[11035],{"data":11036,"marks":11037,"value":7103,"nodeType":874},{},[],{"data":11039,"content":11040,"nodeType":870},{},[11041],{"data":11042,"marks":11043,"value":7110,"nodeType":874},{},[],{"data":11045,"content":11046,"nodeType":870},{},[11047],{"data":11048,"marks":11049,"value":7117,"nodeType":874},{},[],{"data":11051,"content":11052,"nodeType":870},{},[11053],{"data":11054,"marks":11055,"value":7124,"nodeType":874},{},[],{"data":11057,"content":11058,"nodeType":870},{},[11059],{"data":11060,"marks":11061,"value":7131,"nodeType":874},{},[],{"data":11063,"content":11066,"nodeType":1215},{"target":11064},{"sys":11065},{"id":7136,"type":1220,"linkType":1221},[],{"data":11068,"content":11069,"nodeType":870},{},[11070],{"data":11071,"marks":11072,"value":7144,"nodeType":874},{},[],{"data":11074,"content":11077,"nodeType":1215},{"target":11075},{"sys":11076},{"id":7149,"type":1220,"linkType":1221},[],{"data":11079,"content":11080,"nodeType":870},{},[11081],{"data":11082,"marks":11083,"value":7157,"nodeType":874},{},[],{"data":11085,"content":11086,"nodeType":870},{},[11087],{"data":11088,"marks":11089,"value":7164,"nodeType":874},{},[],[7205,263,7206,7207,7208],{"items":11092},[11093,11095],{"sys":11094,"name":2007},{"id":2006},{"sys":11096,"name":5689},{"id":5688},{"items":11098},[11099],{"fullName":7058,"firstName":7059,"jobTitle":7060,"profilePicture":11100},{"url":7062},"blog\u002Fshould-you-disable-external-email-auto-forwarding",{"json":11103},{"data":11104,"content":11105,"nodeType":866},{},[11106],{"data":11107,"content":11108,"nodeType":870},{},[11109],{"data":11110,"marks":11111,"value":11112,"nodeType":874},{},[],"If your users have a business case for external email auto-forwarding, this risk can absolutely be managed - it's not something you must disable. However, if no one’s using the feature, it is a good idea to disable it since it limits the potential impact of an account compromise.",{"id":7589,"publishedAt":11114},"2026-08-13T09:35:37.268Z",{"items":11116},[11117,11119],{"sys":11118,"name":2007},{"id":2006},{"sys":11120,"name":334},{"id":2010},{"items":11122},[11123,11125,11127,11129],{"sys":11124,"name":404,"slug":405,"tier":31},{"id":401},{"sys":11126,"name":334,"slug":335,"tier":31},{"id":331},{"sys":11128,"name":360,"slug":361,"tier":45},{"id":357},{"sys":11130,"name":262,"slug":263,"tier":45},{"id":259},"UXjk5K1jZ7rS9D7aFOMIXdnZFjSoSgkDV-poBKH-Pes",1790667129500]