[{"data":1,"prerenderedAt":94544},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"blog-topics":226,"trust-badges":656,"solution-nav":677,"fa-icon-solid-faUserSecret":800,"fa-icon-sharp-regular-faLaptopCode":804,"fa-icon-solid-faPlugCircleXmark":806,"fa-icon-sharp-regular-faPuzzlePiece":808,"fa-icon-solid-faFileCircleXmark":810,"fa-icon-solid-faGhost":813,"fa-icon-solid-faQrcode":816,"fa-icon-solid-faCookieBite":818,"fa-icon-sharp-regular-faFishingRod":820,"fa-icon-sharp-regular-faUserSecret":822,"fa-icon-sharp-regular-faRadar":824,"fa-icon-sharp-regular-faSatelliteDish":826,"fa-icon-sharp-regular-faShieldCheck":828,"fa-icon-sharp-regular-faBrainCircuit":830,"fa-icon-solid-faMobileScreenButton":832,"fa-icon-brands-faChrome":834,"fa-icon-solid-faDisplay":836,"fa-icon-solid-faFilter":838,"fa-icon-solid-faCloudArrowUp":840,"blog-topic-browser-extensions":842},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https://pushsecurity.com/resources/browser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"j7ew2tin4q",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Do you know how much AI is in your workforce? Find out August 20th.\u003C/p>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Save your seat →\u003C/p>","https://pushsecurity.com/webinar/shadow-ai",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-k74nkzlquog","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1786155414606,"kYgMv6WsbvfmlOUYqR2SFwGzw6e2",{"breakpoints":99,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"1lcyl36j3gz",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"xal7chkxmdh","/customer-stories/inductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"5mqgwlt47hs",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","/resources/browser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"kg131t0jkvo","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"470xio0yv7r",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,{"id":227,"extension":228,"items":229,"meta":653,"stem":654,"__hash__":655},"blogTopics/blogtopics.json","json",[230,239,247,256,265,274,283,292,301,310,319,328,337,346,355,363,372,381,390,399,408,417,426,435,443,452,461,470,479,488,497,506,514,523,532,540,549,558,566,575,584,593,602,611,619,628,637,645],{"sys":231,"faqItemsCollection":233,"name":235,"slug":236,"tier":31,"intro":237,"faqTitle":59,"postCount":238,"hasPage":19},{"id":232},"topic-ai",{"items":234},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":240,"faqItemsCollection":242,"name":244,"slug":245,"tier":45,"intro":246,"faqTitle":59,"postCount":238,"hasPage":19},{"id":241},"topic-ai-attacks",{"items":243},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",{"sys":248,"faqItemsCollection":250,"name":252,"slug":253,"tier":45,"intro":254,"faqTitle":59,"postCount":255,"hasPage":19},{"id":249},"topic-ai-governance",{"items":251},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":257,"faqItemsCollection":259,"name":261,"slug":262,"tier":45,"intro":263,"faqTitle":59,"postCount":264,"hasPage":19},{"id":258},"topic-aitm",{"items":260},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",77,{"sys":266,"faqItemsCollection":268,"name":270,"slug":271,"tier":45,"intro":272,"faqTitle":59,"postCount":273,"hasPage":6},{"id":267},"topic-bec",{"items":269},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",3,{"sys":275,"faqItemsCollection":277,"name":279,"slug":280,"tier":31,"intro":281,"faqTitle":59,"postCount":282,"hasPage":19},{"id":276},"topic-browser-attacks",{"items":278},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",118,{"sys":284,"faqItemsCollection":286,"name":288,"slug":289,"tier":45,"intro":290,"faqTitle":59,"postCount":291,"hasPage":19},{"id":285},"topic-browser-extensions",{"items":287},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",30,{"sys":293,"faqItemsCollection":295,"name":297,"slug":298,"tier":31,"intro":299,"faqTitle":59,"postCount":300,"hasPage":19},{"id":294},"topic-browser-security",{"items":296},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",127,{"sys":302,"faqItemsCollection":304,"name":306,"slug":307,"tier":45,"intro":308,"faqTitle":59,"postCount":309,"hasPage":19},{"id":303},"topic-casb",{"items":305},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":311,"faqItemsCollection":313,"name":315,"slug":316,"tier":45,"intro":317,"faqTitle":59,"postCount":318,"hasPage":19},{"id":312},"topic-clickfix",{"items":314},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",39,{"sys":320,"faqItemsCollection":322,"name":324,"slug":325,"tier":45,"intro":326,"faqTitle":59,"postCount":327,"hasPage":19},{"id":321},"topic-credential-phishing",{"items":323},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",89,{"sys":329,"faqItemsCollection":331,"name":333,"slug":334,"tier":45,"intro":335,"faqTitle":59,"postCount":336,"hasPage":19},{"id":330},"topic-credential-stuffing",{"items":332},[],"Credential stuffing","credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":338,"faqItemsCollection":340,"name":342,"slug":343,"tier":31,"intro":344,"faqTitle":59,"postCount":345,"hasPage":19},{"id":339},"topic-detection-and-response",{"items":341},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",101,{"sys":347,"faqItemsCollection":349,"name":351,"slug":352,"tier":45,"intro":353,"faqTitle":59,"postCount":354,"hasPage":19},{"id":348},"topic-detection-engineering",{"items":350},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",42,{"sys":356,"faqItemsCollection":358,"name":360,"slug":361,"tier":45,"intro":362,"faqTitle":59,"postCount":238,"hasPage":19},{"id":357},"topic-device-code-phishing",{"items":359},[],"Device code phishing","device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",{"sys":364,"faqItemsCollection":366,"name":368,"slug":369,"tier":45,"intro":370,"faqTitle":59,"postCount":371,"hasPage":19},{"id":365},"topic-dlp",{"items":367},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":373,"faqItemsCollection":375,"name":377,"slug":378,"tier":45,"intro":379,"faqTitle":59,"postCount":380,"hasPage":19},{"id":374},"topic-edr",{"items":376},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",24,{"sys":382,"faqItemsCollection":384,"name":386,"slug":387,"tier":45,"intro":388,"faqTitle":59,"postCount":389,"hasPage":19},{"id":383},"topic-enterprise-browser",{"items":385},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",6,{"sys":391,"faqItemsCollection":393,"name":395,"slug":396,"tier":45,"intro":397,"faqTitle":59,"postCount":398,"hasPage":19},{"id":392},"topic-ghost-logins",{"items":394},[],"Ghost logins","ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":400,"faqItemsCollection":402,"name":404,"slug":405,"tier":45,"intro":406,"faqTitle":59,"postCount":407,"hasPage":19},{"id":401},"topic-identity-attacks",{"items":403},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",56,{"sys":409,"faqItemsCollection":411,"name":413,"slug":414,"tier":31,"intro":415,"faqTitle":59,"postCount":416,"hasPage":19},{"id":410},"topic-identity-security",{"items":412},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":418,"faqItemsCollection":420,"name":422,"slug":423,"tier":45,"intro":424,"faqTitle":59,"postCount":425,"hasPage":19},{"id":419},"topic-infostealer",{"items":421},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",52,{"sys":427,"faqItemsCollection":429,"name":431,"slug":432,"tier":45,"intro":433,"faqTitle":59,"postCount":434,"hasPage":19},{"id":428},"topic-legitimate-service-abuse",{"items":430},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",28,{"sys":436,"faqItemsCollection":438,"name":440,"slug":441,"tier":45,"intro":442,"faqTitle":59,"postCount":291,"hasPage":19},{"id":437},"topic-malvertising",{"items":439},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":444,"faqItemsCollection":446,"name":448,"slug":449,"tier":45,"intro":450,"faqTitle":59,"postCount":451,"hasPage":19},{"id":445},"topic-malware-delivery",{"items":447},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",13,{"sys":453,"faqItemsCollection":455,"name":457,"slug":458,"tier":45,"intro":459,"faqTitle":59,"postCount":460,"hasPage":19},{"id":454},"topic-mfa",{"items":456},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":462,"faqItemsCollection":464,"name":466,"slug":467,"tier":45,"intro":468,"faqTitle":59,"postCount":469,"hasPage":19},{"id":463},"topic-mfa-bypass",{"items":465},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",58,{"sys":471,"faqItemsCollection":473,"name":475,"slug":476,"tier":45,"intro":477,"faqTitle":59,"postCount":478,"hasPage":19},{"id":472},"topic-non-email-phishing",{"items":474},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",51,{"sys":480,"faqItemsCollection":482,"name":484,"slug":485,"tier":45,"intro":486,"faqTitle":59,"postCount":487,"hasPage":19},{"id":481},"topic-oauth-abuse",{"items":483},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":489,"faqItemsCollection":491,"name":493,"slug":494,"tier":45,"intro":495,"faqTitle":59,"postCount":496,"hasPage":19},{"id":490},"topic-passkeys",{"items":492},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",21,{"sys":498,"faqItemsCollection":500,"name":502,"slug":503,"tier":45,"intro":504,"faqTitle":59,"postCount":505,"hasPage":19},{"id":499},"topic-password-security",{"items":501},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",79,{"sys":507,"faqItemsCollection":509,"name":511,"slug":512,"tier":45,"intro":513,"faqTitle":59,"postCount":318,"hasPage":19},{"id":508},"topic-phaas",{"items":510},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",{"sys":515,"faqItemsCollection":517,"name":519,"slug":520,"tier":31,"intro":521,"faqTitle":59,"postCount":522,"hasPage":19},{"id":516},"topic-phishing",{"items":518},[],"Phishing","phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",91,{"sys":524,"faqItemsCollection":526,"name":528,"slug":529,"tier":45,"intro":530,"faqTitle":59,"postCount":531,"hasPage":19},{"id":525},"topic-public-breach",{"items":527},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",29,{"sys":533,"faqItemsCollection":535,"name":537,"slug":538,"tier":45,"intro":539,"faqTitle":59,"postCount":451,"hasPage":19},{"id":534},"topic-ransomware",{"items":536},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":541,"faqItemsCollection":543,"name":545,"slug":546,"tier":31,"intro":547,"faqTitle":59,"postCount":548,"hasPage":19},{"id":542},"topic-saas-security",{"items":544},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",96,{"sys":550,"faqItemsCollection":552,"name":554,"slug":555,"tier":45,"intro":556,"faqTitle":59,"postCount":557,"hasPage":6},{"id":551},"topic-security-training",{"items":553},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":559,"faqItemsCollection":561,"name":563,"slug":564,"tier":45,"intro":565,"faqTitle":59,"postCount":389,"hasPage":19},{"id":560},"topic-seo-poisoning",{"items":562},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",{"sys":567,"faqItemsCollection":569,"name":571,"slug":572,"tier":45,"intro":573,"faqTitle":59,"postCount":574,"hasPage":19},{"id":568},"topic-session-hijacking",{"items":570},[],"Session hijacking","session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",74,{"sys":576,"faqItemsCollection":578,"name":580,"slug":581,"tier":45,"intro":582,"faqTitle":59,"postCount":583,"hasPage":19},{"id":577},"topic-shadow-ai",{"items":579},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":585,"faqItemsCollection":587,"name":589,"slug":590,"tier":45,"intro":591,"faqTitle":59,"postCount":592,"hasPage":19},{"id":586},"topic-shadow-saas",{"items":588},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",75,{"sys":594,"faqItemsCollection":596,"name":598,"slug":599,"tier":45,"intro":600,"faqTitle":59,"postCount":601,"hasPage":19},{"id":595},"topic-siem",{"items":597},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",19,{"sys":603,"faqItemsCollection":605,"name":607,"slug":608,"tier":45,"intro":609,"faqTitle":59,"postCount":610,"hasPage":19},{"id":604},"topic-social-engineering",{"items":606},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",59,{"sys":612,"faqItemsCollection":614,"name":616,"slug":617,"tier":31,"intro":618,"faqTitle":59,"postCount":557,"hasPage":6},{"id":613},"topic-supply-chain-security",{"items":615},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":620,"faqItemsCollection":622,"name":624,"slug":625,"tier":45,"intro":626,"faqTitle":59,"postCount":627,"hasPage":19},{"id":621},"topic-swg",{"items":623},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",17,{"sys":629,"faqItemsCollection":631,"name":633,"slug":634,"tier":45,"intro":635,"faqTitle":59,"postCount":636,"hasPage":19},{"id":630},"topic-third-party-risk",{"items":632},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":638,"faqItemsCollection":640,"name":642,"slug":643,"tier":31,"intro":644,"faqTitle":59,"postCount":398,"hasPage":19},{"id":639},"topic-threat-landscape",{"items":641},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",{"sys":646,"faqItemsCollection":648,"name":650,"slug":651,"tier":45,"intro":652,"faqTitle":59,"postCount":371,"hasPage":19},{"id":647},"topic-vishing",{"items":649},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",{},"blogtopics","w0ITersBlkytyrxHNkTEFmGsSW5X9NfdbmeXV1u8bAo",[657,661,665,669,673],{"title":658,"logo":659,"createdDate":660},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":662,"logo":663,"createdDate":664},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":666,"logo":667,"createdDate":668},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":670,"logo":671,"createdDate":672},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":674,"logo":675,"createdDate":676},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[678,730,775],{"id":679,"label":680,"text":21,"navIcon":681,"items":682},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[683,688,693,698,703,708,712,717,721,725],{"title":684,"text":685,"url":686,"navIcon":687},"Adversary-in-the-Middle","Detect and block AiTM proxies stealing session tokens.","/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks","solid:faUserSecret",{"title":689,"text":690,"url":691,"navIcon":692},"ClickFix (+Fix variants)","Block attacks that trick users into running malicious code.","/solution/stop-browser-based-attacks/clickfix-fix-variants","sharp-regular:faLaptopCode",{"title":694,"text":695,"url":696,"navIcon":697},"Malicious OAuth integrations","Detect suspicious OAuth consent flows and stop persistent access.","/solution/stop-browser-based-attacks/malicious-oauth-integrations","solid:faPlugCircleXmark",{"title":699,"text":700,"url":701,"navIcon":702},"Malicious browser extensions","Shine a light on risky browser extensions.","/solution/stop-browser-based-attacks/malicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":704,"text":705,"url":706,"navIcon":707},"Malicious file downloads","Gain visibility into browser downloads and block malicious files.","/solution/stop-browser-based-attacks/malicious-file-downloads","solid:faFileCircleXmark",{"title":395,"text":709,"url":710,"navIcon":711},"Surface hidden login paths that bypass SSO and expose accounts.","/solution/stop-browser-based-attacks/ghost-logins","solid:faGhost",{"title":713,"text":714,"url":715,"navIcon":716},"Mobile phishing (QR & SMS)","Detect phishing links delivered via SMS and QR codes.","/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms","solid:faQrcode",{"title":333,"text":718,"url":719,"navIcon":720},"Identify reused and compromised credentials across SaaS logins.","/solution/stop-browser-based-attacks/credential-stuffing","custom:credentialStuffing",{"title":571,"text":722,"url":723,"navIcon":724},"Detect and block stolen session tokens before attackers get access.","/solution/stop-browser-based-attacks/session-hijacking","solid:faCookieBite",{"title":726,"text":727,"url":728,"navIcon":729},"Zero-day phishing","Detect phishing TTPs directly in the browser and stop credential theft.","/solution/stop-browser-based-attacks/zero-day-phishing","sharp-regular:faFishingRod",{"id":731,"label":732,"text":21,"navIcon":733,"items":734},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[735,740,745,750,755,760,765,770],{"title":736,"text":737,"url":738,"navIcon":739},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","/solution/achieve-security-outcomes/stop-account-takeover","sharp-regular:faUserSecret",{"title":741,"text":742,"url":743,"navIcon":744},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","/solution/achieve-security-outcomes/harden-unmanaged-identities","sharp-regular:faRadar",{"title":746,"text":747,"url":748,"navIcon":749},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","/solution/achieve-security-outcomes/investigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":751,"text":752,"url":753,"navIcon":754},"Secure shadow SaaS","See and control shadow SaaS in the browser.","/solution/achieve-security-outcomes/secure-shadow-saas","sharp-regular:faShieldCheck",{"title":756,"text":757,"url":758,"navIcon":759},"Secure AI","See and control AI apps in the browser.","/solution/achieve-security-outcomes/secure-ai","sharp-regular:faBrainCircuit",{"title":761,"text":762,"url":763,"navIcon":764},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","/solution/achieve-security-outcomes/secure-bring-your-own-device","solid:faMobileScreenButton",{"title":766,"text":767,"url":768,"navIcon":769},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","/solution/achieve-security-outcomes/secure-chromebooks","brands:faChrome",{"title":771,"text":772,"url":773,"navIcon":774},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","/solution/achieve-security-outcomes/investigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":776,"label":777,"text":21,"navIcon":778,"items":779},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[780,785,790,795],{"title":781,"text":782,"url":783,"navIcon":784},"Remote browser isolation","Detect attacks that look like normal browsing.","/solution/tool-replacements/remote-browser-isolation","solid:faDisplay",{"title":786,"text":787,"url":788,"navIcon":789},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","/solution/tool-replacements/secure-web-gateways","solid:faFilter",{"title":791,"text":792,"url":793,"navIcon":794},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","/solution/tool-replacements/cloud-access-security-broker","solid:faCloudArrowUp",{"title":796,"text":797,"url":798,"navIcon":799},"Security awareness training","Block real phishing instead of training users on simulations.","/solution/tool-replacements/security-awareness-training","custom:securityAwareness",{"w":801,"h":802,"d":803},448,512,"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":802,"d":805},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":17,"h":802,"d":807},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":802,"h":802,"d":809},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":811,"h":802,"d":812},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":814,"h":802,"d":815},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":801,"h":802,"d":817},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":802,"h":802,"d":819},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":801,"h":802,"d":821},"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":801,"h":802,"d":823},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":802,"h":802,"d":825},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":802,"h":802,"d":827},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":802,"h":802,"d":829},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":802,"h":802,"d":831},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":814,"h":802,"d":833},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":802,"h":802,"d":835},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":802,"h":802,"d":837},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":802,"h":802,"d":839},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":811,"h":802,"d":841},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",[843,4943,8834,12035,15225,18760,24310,27433,30205,33299,36282,38920,42001,45022,49218,53477,59216,62953,64434,65745,69027,70260,73970,76892,79734,81492,84578,87160,90411,93169],{"id":844,"title":845,"authorsCollection":846,"content":854,"extension":228,"faqItemsCollection":1864,"faqTitle":2052,"featured":6,"hashTags":59,"meta":2053,"metaTitle":2054,"ogImage":59,"postType":59,"publishedDate":2055,"relatedBlogPostsCollection":2056,"slug":4882,"stem":4883,"subtitle":4884,"summary":4885,"synopsis":4895,"sys":4896,"tagsCollection":4899,"topicsCollection":4908,"__hash__":4942},"blog/blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps.json","Shadow AI: how to discover, govern, and secure AI apps",{"items":847},[848],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":59,"profilePicture":852},"Kelly Davenport","Kelly","Product Team",{"url":853},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"json":855,"links":1710},{"nodeType":856,"data":857,"content":858},"document",{},[859,868,875,926,933,940,995,1004,1008,1017,1024,1036,1042,1054,1060,1072,1078,1081,1089,1096,1115,1126,1133,1140,1143,1151,1158,1183,1189,1196,1212,1228,1234,1250,1266,1273,1280,1287,1293,1296,1304,1311,1319,1326,1342,1349,1374,1380,1387,1393,1405,1412,1418,1424,1427,1435,1442,1461,1468,1476,1483,1495,1511,1517,1529,1563,1570,1586,1592,1608,1615,1622,1625,1633,1640,1647,1654,1661,1668,1675,1678,1685,1692],{"nodeType":860,"data":861,"content":862},"paragraph",{},[863],{"nodeType":864,"value":865,"marks":866,"data":867},"text","Every security team that's blocked an AI tool at the network level has had the same experience three months later: The tool they blocked isn't in use, but a dozen they've never heard of are.",[],{},{"nodeType":860,"data":869,"content":870},{},[871],{"nodeType":864,"value":872,"marks":873,"data":874},"The block didn't stop employees from using AI. It just prevented the security team from seeing what’s actually happening.",[],{},{"nodeType":860,"data":876,"content":877},{},[878,882,891,895,901,905,910,914,922],{"nodeType":864,"value":879,"marks":880,"data":881},"The data backs up this pattern. ",[],{},{"nodeType":883,"data":884,"content":886},"hyperlink",{"uri":885},"https://pushsecurity.com/blog/what-push-data-reveals-about-the-state-of-shadow-ai/",[887],{"nodeType":864,"value":888,"marks":889,"data":890},"Push telemetry",[],{},{"nodeType":864,"value":892,"marks":893,"data":894}," shows that the average organization has ",[],{},{"nodeType":864,"value":896,"marks":897,"data":900},"16 AI apps, 17 AI browser extensions,",[898],{"type":899},"bold",{},{"nodeType":864,"value":902,"marks":903,"data":904}," and ",[],{},{"nodeType":864,"value":906,"marks":907,"data":909},"17 AI OAuth integrations",[908],{"type":899},{},{"nodeType":864,"value":911,"marks":912,"data":913}," in active use during a typical week — most unapproved. Meanwhile, ",[],{},{"nodeType":883,"data":915,"content":917},{"uri":916},"https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/",[918],{"nodeType":864,"value":919,"marks":920,"data":921},"Okta found",[],{},{"nodeType":864,"value":923,"marks":924,"data":925}," that 80% of employees who use unapproved AI tools do so because it's easier to use their own accounts, and 57% because the approval process is too slow.",[],{},{"nodeType":860,"data":927,"content":928},{},[929],{"nodeType":864,"value":930,"marks":931,"data":932},"The organizations getting this right have stopped treating AI governance as an access-control problem — which tools to allow, which to block — and started treating it as an invitation to build out an infrastructure to enable appropriate use. Employees are going to use the tools they need to get their work done. The question is whether they'll use them on a path you built and instrumented, or on one they carved themselves.",[],{},{"nodeType":860,"data":934,"content":935},{},[936],{"nodeType":864,"value":937,"marks":938,"data":939},"This guide walks through how to build that paved path. Using Push, you can:",[],{},{"nodeType":941,"data":942,"content":943},"unordered-list",{},[944,955,965,975,985],{"nodeType":945,"data":946,"content":947},"list-item",{},[948],{"nodeType":860,"data":949,"content":950},{},[951],{"nodeType":864,"value":952,"marks":953,"data":954},"Identify shadow AI, including personal accounts on approved corporate apps, AI browser extensions, OAuth integrations into sensitive systems, and AI browser usage.",[],{},{"nodeType":945,"data":956,"content":957},{},[958],{"nodeType":860,"data":959,"content":960},{},[961],{"nodeType":864,"value":962,"marks":963,"data":964},"Enforce policies on data flows into and out of AI apps, including blocking unapproved file uploads, downloads, and clipboard pastes; and monitoring AI chat transcripts.",[],{},{"nodeType":945,"data":966,"content":967},{},[968],{"nodeType":860,"data":969,"content":970},{},[971],{"nodeType":864,"value":972,"marks":973,"data":974},"Use just-in-time guardrails to intercept users accessing unapproved AI tools and point them at approved alternatives.",[],{},{"nodeType":945,"data":976,"content":977},{},[978],{"nodeType":860,"data":979,"content":980},{},[981],{"nodeType":864,"value":982,"marks":983,"data":984},"Prevent unwanted MCP connections with app-agnostic controls.",[],{},{"nodeType":945,"data":986,"content":987},{},[988],{"nodeType":860,"data":989,"content":990},{},[991],{"nodeType":864,"value":992,"marks":993,"data":994},"Automate a lot of the work so you don’t burn out your team as the AI landscape continues to shift.",[],{},{"nodeType":996,"data":997,"content":1003},"embedded-entry-block",{"target":998},{"sys":999},{"id":1000,"type":1001,"linkType":1002},"29N8YH9As3GHypOve3br80","Link","Entry",[],{"nodeType":1005,"data":1006,"content":1007},"hr",{},[],{"nodeType":1009,"data":1010,"content":1011},"heading-1",{},[1012],{"nodeType":864,"value":1013,"marks":1014,"data":1016},"What is shadow AI, and why can't you manage it like shadow IT?",[1015],{"type":899},{},{"nodeType":860,"data":1018,"content":1019},{},[1020],{"nodeType":864,"value":1021,"marks":1022,"data":1023},"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Security teams have been managing shadow SaaS for years, but shadow AI can't be addressed with the same playbook — for three reasons.",[],{},{"nodeType":860,"data":1025,"content":1026},{},[1027,1032],{"nodeType":864,"value":1028,"marks":1029,"data":1031},"First",[1030],{"type":899},{},{"nodeType":864,"value":1033,"marks":1034,"data":1035},", it spans multiple categories that each need different controls: unapproved AI apps, personal accounts on approved corporate AI tools, AI browser extensions, and OAuth integrations into corporate systems. Blocking unapproved apps doesn't address personal accounts on approved ones, and neither solves the extension or OAuth problem. ",[],{},{"nodeType":996,"data":1037,"content":1041},{"target":1038},{"sys":1039},{"id":1040,"type":1001,"linkType":1002},"2hsKQ9DEspflhmtR0bE7QY",[],{"nodeType":860,"data":1043,"content":1044},{},[1045,1050],{"nodeType":864,"value":1046,"marks":1047,"data":1049},"Second",[1048],{"type":899},{},{"nodeType":864,"value":1051,"marks":1052,"data":1053},", the tools most organizations rely on to manage shadow SaaS — SWGs, CASBs, EDR, IdP logs — are structurally blind to shadow AI. An SWG sees that someone visited an AI domain but can't tell you whether they logged in, pasted source code into a prompt, or granted OAuth access to your Google Workspace tenant. EDR doesn't see browser-layer activity at all. IdP logs capture OAuth grants routed through the identity provider but miss tools accessed via direct signup or personal accounts. Instead, the activity security teams need to see happens primarily inside the browser.",[],{},{"nodeType":996,"data":1055,"content":1059},{"target":1056},{"sys":1057},{"id":1058,"type":1001,"linkType":1002},"1vE0dyAKdnTSjyAJ4Xoadd",[],{"nodeType":860,"data":1061,"content":1062},{},[1063,1068],{"nodeType":864,"value":1064,"marks":1065,"data":1067},"Third",[1066],{"type":899},{},{"nodeType":864,"value":1069,"marks":1070,"data":1071},", the risk profile is different. Shadow AI tools increasingly function as hubs — connected via OAuth integrations and MCP to email, cloud storage, code repositories, and other high-value systems. They leak sensitive data outward (employees paste source code, credentials, and internal documents into prompts daily) while simultaneously expanding the attack surface inward (compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate). ",[],{},{"nodeType":996,"data":1073,"content":1077},{"target":1074},{"sys":1075},{"id":1076,"type":1001,"linkType":1002},"3ldZ23OORTu7INBfSnE7R7",[],{"nodeType":1005,"data":1079,"content":1080},{},[],{"nodeType":1009,"data":1082,"content":1083},{},[1084],{"nodeType":864,"value":1085,"marks":1086,"data":1088},"Why blocking AI usage fails",[1087],{"type":899},{},{"nodeType":860,"data":1090,"content":1091},{},[1092],{"nodeType":864,"value":1093,"marks":1094,"data":1095},"The instinct to block AI tools makes sense. Executives are asking about AI risk to the business, a new tool appears every week, and blocking unapproved apps feels like a quick way to stop the bleeding.",[],{},{"nodeType":860,"data":1097,"content":1098},{},[1099,1103,1111],{"nodeType":864,"value":1100,"marks":1101,"data":1102},"Unfortunately, blocking doesn't work for long. The latest security frameworks — including the ",[],{},{"nodeType":883,"data":1104,"content":1106},{"uri":1105},"https://www.sans.org/mlp/2026-ai-security-maturity-model-ebook",[1107],{"nodeType":864,"value":1108,"marks":1109,"data":1110},"SANS AI Security Maturity Model",[],{},{"nodeType":864,"value":1112,"marks":1113,"data":1114}," — all agree: Block-based AI policies drive usage underground rather than preventing it. ",[],{},{"nodeType":1116,"data":1117,"content":1118},"blockquote",{},[1119],{"nodeType":860,"data":1120,"content":1121},{},[1122],{"nodeType":864,"value":1123,"marks":1124,"data":1125},"A block-based AI policy may feel like risk management, but practitioner experience shows that it typically drives AI usage underground rather than preventing it. The goal is not to eliminate AI use; it is to bring it into visibility where it can be governed.",[],{},{"nodeType":860,"data":1127,"content":1128},{},[1129],{"nodeType":864,"value":1130,"marks":1131,"data":1132},"These kinds of barricades also fail for a structural reason: They're built on the network perimeter, and AI usage doesn't cross the perimeter in ways network tools can inspect.",[],{},{"nodeType":860,"data":1134,"content":1135},{},[1136],{"nodeType":864,"value":1137,"marks":1138,"data":1139},"The most damaging consequence of blocking isn't the workarounds themselves — it's the loss of visibility. To begin building a better path for employees, you have to start with seeing what's actually happening.",[],{},{"nodeType":1005,"data":1141,"content":1142},{},[],{"nodeType":1009,"data":1144,"content":1145},{},[1146],{"nodeType":864,"value":1147,"marks":1148,"data":1150},"Using Push to discover, govern, and control shadow AI",[1149],{"type":899},{},{"nodeType":860,"data":1152,"content":1153},{},[1154],{"nodeType":864,"value":1155,"marks":1156,"data":1157},"Push Security is a browser security platform that gets you the vantage point you need to start addressing shadow AI. Push deploys as a lightweight extension to employees' existing browsers rather than requiring a full browser migration, giving security teams visibility into browser-layer activity that network and endpoint tools structurally lack.",[],{},{"nodeType":860,"data":1159,"content":1160},{},[1161,1165,1170,1174,1179],{"nodeType":864,"value":1162,"marks":1163,"data":1164},"Push discovers AI tools through ",[],{},{"nodeType":864,"value":1166,"marks":1167,"data":1169},"automatic",[1168],{"type":899},{},{"nodeType":864,"value":1171,"marks":1172,"data":1173}," ",[],{},{"nodeType":864,"value":1175,"marks":1176,"data":1178},"app discovery",[1177],{"type":899},{},{"nodeType":864,"value":1180,"marks":1181,"data":1182},", allowing you to identify applications from actual browser login events rather than network traffic logs. ",[],{},{"nodeType":996,"data":1184,"content":1188},{"target":1185},{"sys":1186},{"id":1187,"type":1001,"linkType":1002},"4eTkgU2dxhMueHPiwuCWDl",[],{"nodeType":860,"data":1190,"content":1191},{},[1192],{"nodeType":864,"value":1193,"marks":1194,"data":1195},"When an employee signs into a new AI service, Push registers the authentication event, identifies the application, and logs how the employee authenticated — corporate SSO, OIDC, a standalone password, or a personal account. ",[],{},{"nodeType":860,"data":1197,"content":1198},{},[1199,1203,1208],{"nodeType":864,"value":1200,"marks":1201,"data":1202},"Push then applies ",[],{},{"nodeType":864,"value":1204,"marks":1205,"data":1207},"app categories ",[1206],{"type":899},{},{"nodeType":864,"value":1209,"marks":1210,"data":1211},"automatically, classifying the discovered application by type without requiring security teams to build or maintain manual lists.",[],{},{"nodeType":860,"data":1213,"content":1214},{},[1215,1219,1224],{"nodeType":864,"value":1216,"marks":1217,"data":1218},"Push extends the same discovery across the other three shadow AI dimensions. The platform’s ",[],{},{"nodeType":864,"value":1220,"marks":1221,"data":1223},"browser extension discovery ",[1222],{"type":899},{},{"nodeType":864,"value":1225,"marks":1226,"data":1227},"capability catalogs every AI-related extension installed across the workforce, including the specific permissions each extension has requested (access to page content, browsing history, clipboard data), allowing you to review whether those permission combinations could enable data exfiltration or account takeover. ",[],{},{"nodeType":996,"data":1229,"content":1233},{"target":1230},{"sys":1231},{"id":1232,"type":1001,"linkType":1002},"1z56sTWWN9E35dE3HhbRNY",[],{"nodeType":860,"data":1235,"content":1236},{},[1237,1241,1246],{"nodeType":864,"value":1238,"marks":1239,"data":1240},"Push’s ",[],{},{"nodeType":864,"value":1242,"marks":1243,"data":1245},"OAuth integration discovery",[1244],{"type":899},{},{"nodeType":864,"value":1247,"marks":1248,"data":1249}," identifies OAuth connections between AI tools and corporate systems — the grants that create persistent API-level access to platforms like Google Workspace.",[],{},{"nodeType":860,"data":1251,"content":1252},{},[1253,1257,1262],{"nodeType":864,"value":1254,"marks":1255,"data":1256},"For each discovered tool, Push also captures authentication context that points to ",[],{},{"nodeType":864,"value":1258,"marks":1259,"data":1261},"where hidden security risks lie",[1260],{"type":899},{},{"nodeType":864,"value":1263,"marks":1264,"data":1265},": SSO vs. password vs. personal account, MFA status, and password strength. An AI tool accessed via corporate SSO with MFA is a different risk than the same tool accessed through a personal Gmail account with a reused password. Similarly, employees using only a password to access AI tools that they’ve integrated with other sensitive corporate systems introduces another level of downstream risk. That context is what makes the inventory actionable.",[],{},{"nodeType":860,"data":1267,"content":1268},{},[1269],{"nodeType":864,"value":1270,"marks":1271,"data":1272},"Push also detects when employees are adopting agentic browsers — autonomous AI-powered browsers like Comet, Atlas, and Dia that browse the web and interact with applications on behalf of users or automated workflows. ",[],{},{"nodeType":860,"data":1274,"content":1275},{},[1276],{"nodeType":864,"value":1277,"marks":1278,"data":1279},"These represent an emerging category of non-human AI identity. They authenticate to SaaS applications, access corporate data, and make API calls, but they aren't managed through traditional identity infrastructure. Push helps you identify these agentic browsers as they appear in the environment, before they become a blind spot.",[],{},{"nodeType":860,"data":1281,"content":1282},{},[1283],{"nodeType":864,"value":1284,"marks":1285,"data":1286},"Returning to the paved path metaphor, this step is about surveying the site before you figure out where to put in the path. You need to understand who’s already doing what, where, so you can find the risks you need to address.",[],{},{"nodeType":996,"data":1288,"content":1292},{"target":1289},{"sys":1290},{"id":1291,"type":1001,"linkType":1002},"5iXyJbxwWiUt7WoP7FF0Y2",[],{"nodeType":1005,"data":1294,"content":1295},{},[],{"nodeType":1009,"data":1297,"content":1298},{},[1299],{"nodeType":864,"value":1300,"marks":1301,"data":1303},"Step-by-step guide to enforcing AI governance without blocking everything",[1302],{"type":899},{},{"nodeType":860,"data":1305,"content":1306},{},[1307],{"nodeType":864,"value":1308,"marks":1309,"data":1310},"The barricade approach favored by existing solutions like network proxies gives you two options: Allow or block. Enforcing AI policy effectively requires a third approach with a bit more nuance: Guide the user to do the right thing. ",[],{},{"nodeType":1312,"data":1313,"content":1314},"heading-2",{},[1315],{"nodeType":864,"value":1316,"marks":1317,"data":1318},"Building the \"paved path\" with Push",[],{},{"nodeType":860,"data":1320,"content":1321},{},[1322],{"nodeType":864,"value":1323,"marks":1324,"data":1325},"Push provides all three options as configurable enforcement modes for a variety of readymade controls. Progressing between them is how organizations can move from \"we don't know what people are doing with AI\" to evidence-based governance.",[],{},{"nodeType":860,"data":1327,"content":1328},{},[1329,1333,1338],{"nodeType":864,"value":1330,"marks":1331,"data":1332},"Push can be deployed silently and begin observing AI usage with no employee-facing intervention. This is effectively Push in ",[],{},{"nodeType":864,"value":1334,"marks":1335,"data":1337},"Monitor",[1336],{"type":899},{},{"nodeType":864,"value":1339,"marks":1340,"data":1341}," mode.",[],{},{"nodeType":860,"data":1343,"content":1344},{},[1345],{"nodeType":864,"value":1346,"marks":1347,"data":1348},"The platform records which tools are in use, how employees authenticated, and what usage patterns are emerging. Most organizations should start here to generate a baseline. Telemetry can be streamed to your SIEM or other downstream system to get alerted to newly adopted apps and extensions, and to surface security risks like insecure accounts.",[],{},{"nodeType":860,"data":1350,"content":1351},{},[1352,1356,1361,1365,1370],{"nodeType":864,"value":1353,"marks":1354,"data":1355},"Next, most organizations will transition to ",[],{},{"nodeType":864,"value":1357,"marks":1358,"data":1360},"Acknowledge",[1359],{"type":899},{},{"nodeType":864,"value":1362,"marks":1363,"data":1364}," mode for controls like in-browser ",[],{},{"nodeType":864,"value":1366,"marks":1367,"data":1369},"App banners",[1368],{"type":899},{},{"nodeType":864,"value":1371,"marks":1372,"data":1373},". With this control, you can warn employees when they attempt to use an unapproved AI tool and point them to approved alternatives.",[],{},{"nodeType":996,"data":1375,"content":1379},{"target":1376},{"sys":1377},{"id":1378,"type":1001,"linkType":1002},"17nT8JDTyHLExwhb2upb6T",[],{"nodeType":860,"data":1381,"content":1382},{},[1383],{"nodeType":864,"value":1384,"marks":1385,"data":1386},"The employee isn't blocked — they're guided toward the governed path at the moment they're about to step off it. This is more effective than a policy document because it arrives right when they need the reminder. ",[],{},{"nodeType":996,"data":1388,"content":1392},{"target":1389},{"sys":1390},{"id":1391,"type":1001,"linkType":1002},"2lDFCuc48jcGODcwD6nYhK",[],{"nodeType":860,"data":1394,"content":1395},{},[1396,1401],{"nodeType":864,"value":1397,"marks":1398,"data":1400},"Block",[1399],{"type":899},{},{"nodeType":864,"value":1402,"marks":1403,"data":1404}," mode prevents access entirely — Push presents a blocking banner to users who attempt to log in to unapproved apps. ",[],{},{"nodeType":860,"data":1406,"content":1407},{},[1408],{"nodeType":864,"value":1409,"marks":1410,"data":1411},"Push makes the Monitor → Acknowledge → Block progression practical through automatic app categorization. This means that new AI tools inherit whatever governance mode the team has set for that category, without manual blocklist updates. All controls are configurable per user group — the data science team can use AI coding assistants while uploads from finance are restricted — because different teams have different risk profiles.",[],{},{"nodeType":996,"data":1413,"content":1417},{"target":1414},{"sys":1415},{"id":1416,"type":1001,"linkType":1002},"5EBOHy6X6iJfmzJ65txGOv",[],{"nodeType":996,"data":1419,"content":1423},{"target":1420},{"sys":1421},{"id":1422,"type":1001,"linkType":1002},"31JnX2KNCAnlaVS9Qqqh8W",[],{"nodeType":1005,"data":1425,"content":1426},{},[],{"nodeType":1009,"data":1428,"content":1429},{},[1430],{"nodeType":864,"value":1431,"marks":1432,"data":1434},"Guardrails: how to prevent data loss to AI tools",[1433],{"type":899},{},{"nodeType":860,"data":1436,"content":1437},{},[1438],{"nodeType":864,"value":1439,"marks":1440,"data":1441},"Even on the paved path, you need guardrails because preventing data loss to AI tools is a separate problem from controlling which tools employees use. An employee on an approved AI tool can still paste an AWS access key into a prompt, upload a customer spreadsheet, or share confidential documents in a conversation.",[],{},{"nodeType":860,"data":1443,"content":1444},{},[1445,1448,1457],{"nodeType":864,"value":21,"marks":1446,"data":1447},[],{},{"nodeType":883,"data":1449,"content":1450},{"uri":916},[1451],{"nodeType":864,"value":1452,"marks":1453,"data":1456},"Okta's data",[1454],{"type":1455},"underline",{},{"nodeType":864,"value":1458,"marks":1459,"data":1460}," on what employees actually share shows what’s at stake: 54% share internal messages and emails with AI tools, 39% share confidential company documents, and 28% share banking and payment information.",[],{},{"nodeType":860,"data":1462,"content":1463},{},[1464],{"nodeType":864,"value":1465,"marks":1466,"data":1467},"Blocking is too much of a blunt instrument here, as obviously, you want employees to be able to use approved tools. The answer is controlling what data enters them.",[],{},{"nodeType":1312,"data":1469,"content":1470},{},[1471],{"nodeType":864,"value":1472,"marks":1473,"data":1475},"Browser-layer controls for AI data leakage",[1474],{"type":899},{},{"nodeType":860,"data":1477,"content":1478},{},[1479],{"nodeType":864,"value":1480,"marks":1481,"data":1482},"Push addresses this problem with four browser-layer data controls, each targeting a distinct exfiltration path and supporting the same Monitor → Warn → Block enforcement modes:",[],{},{"nodeType":860,"data":1484,"content":1485},{},[1486,1491],{"nodeType":864,"value":1487,"marks":1488,"data":1490},"Clipboard blocking",[1489],{"type":899},{},{"nodeType":864,"value":1492,"marks":1493,"data":1494}," addresses the most common path for sensitive data into AI tools: copy-paste. Push matches clipboard content against preconfigured patterns for AWS access keys, GitHub tokens, API keys, credit card numbers, and personal identifiers, plus custom content rules for organization-specific data like internal project codes. ",[],{},{"nodeType":860,"data":1496,"content":1497},{},[1498,1502,1507],{"nodeType":864,"value":1499,"marks":1500,"data":1501},"In ",[],{},{"nodeType":864,"value":1503,"marks":1504,"data":1506},"Warn",[1505],{"type":899},{},{"nodeType":864,"value":1508,"marks":1509,"data":1510}," mode, Push offers a redacted version of the sensitive data so the employee can continue their work — getting help with their code, for instance — without exposing the actual credential.",[],{},{"nodeType":996,"data":1512,"content":1516},{"target":1513},{"sys":1514},{"id":1515,"type":1001,"linkType":1002},"1JarUdbe8AkJlgB0LjchNR",[],{"nodeType":860,"data":1518,"content":1519},{},[1520,1525],{"nodeType":864,"value":1521,"marks":1522,"data":1524},"File upload blocking",[1523],{"type":899},{},{"nodeType":864,"value":1526,"marks":1527,"data":1528}," prevents files from being uploaded to specific AI apps, configurable by app, user group, and file type (Push provides a list for fast configuration).",[],{},{"nodeType":860,"data":1530,"content":1531},{},[1532,1537,1541,1550,1554,1559],{"nodeType":864,"value":1533,"marks":1534,"data":1536},"File download blocking",[1535],{"type":899},{},{"nodeType":864,"value":1538,"marks":1539,"data":1540}," addresses a different common risk: Employees downloading desktop versions of AI tools, which moves usage outside the browser where Push has visibility. Download blocking also covers files generated inside web applications, such as an AI tool that produces a downloadable asset. (Push’s detection and response capabilities also protect against scenarios in which attackers present users with ",[],{},{"nodeType":883,"data":1542,"content":1544},{"uri":1543},"https://pushsecurity.com/blog/llmshare-malvertising-campaign",[1545],{"nodeType":864,"value":1546,"marks":1547,"data":1549},"faked AI tool download pages",[1548],{"type":1455},{},{"nodeType":864,"value":1551,"marks":1552,"data":1553}," as part of phishing campaigns, a technique we dubbed ",[],{},{"nodeType":864,"value":1555,"marks":1556,"data":1558},"LLMShare",[1557],{"type":899},{},{"nodeType":864,"value":1560,"marks":1561,"data":1562},".)",[],{},{"nodeType":860,"data":1564,"content":1565},{},[1566],{"nodeType":864,"value":1567,"marks":1568,"data":1569},"Push also provides telemetry streams on all file upload and download events in your environment, so you can get a baseline pattern of life and identify anomalies that could indicate insider risk. ",[],{},{"nodeType":860,"data":1571,"content":1572},{},[1573,1577,1582],{"nodeType":864,"value":1574,"marks":1575,"data":1576},"The Push platform also provides the capability to write your own ",[],{},{"nodeType":864,"value":1578,"marks":1579,"data":1581},"custom detections",[1580],{"type":899},{},{"nodeType":864,"value":1583,"marks":1584,"data":1585},", which you can use for other organization-specific use cases, or even to extend your control over GenAI tool usage, such as by blocking unapproved MCP server connections.",[],{},{"nodeType":996,"data":1587,"content":1591},{"target":1588},{"sys":1589},{"id":1590,"type":1001,"linkType":1002},"5XYVgJjgUPUfY1W1Zcgrvm",[],{"nodeType":860,"data":1593,"content":1594},{},[1595,1599,1604],{"nodeType":864,"value":1596,"marks":1597,"data":1598},"Finally, ",[],{},{"nodeType":864,"value":1600,"marks":1601,"data":1603},"AI conversation visibility",[1602],{"type":899},{},{"nodeType":864,"value":1605,"marks":1606,"data":1607}," gives you a window into what is being shared in AI chats, consumable as a stream of events to your SIEM or SOAR. Over time, you can build up a picture of what’s normal or what violates company policy, and create a queryable history to identify potential data loss during an incident response process.",[],{},{"nodeType":860,"data":1609,"content":1610},{},[1611],{"nodeType":864,"value":1612,"marks":1613,"data":1614},"Traditional DLP at the endpoint or network layer misses these paths. Network DLP and SWGs can't inspect clipboard pastes into AI prompts — there's no network event to intercept. Endpoint DLP sees file-system operations but not in-browser activity. ",[],{},{"nodeType":860,"data":1616,"content":1617},{},[1618],{"nodeType":864,"value":1619,"marks":1620,"data":1621},"Push's controls operate where the data is flowing — inside the browser session.",[],{},{"nodeType":1005,"data":1623,"content":1624},{},[],{"nodeType":1312,"data":1626,"content":1627},{},[1628],{"nodeType":864,"value":1629,"marks":1630,"data":1632},"How to keep up with AI tool sprawl",[1631],{"type":899},{},{"nodeType":860,"data":1634,"content":1635},{},[1636],{"nodeType":864,"value":1637,"marks":1638,"data":1639},"Pragmatically, the hardest part of generative AI security isn't the initial steps you take — it's keeping up with the sprawl. Point-in-time audits quickly become outdated when the landscape changes so quickly.",[],{},{"nodeType":860,"data":1641,"content":1642},{},[1643],{"nodeType":864,"value":1644,"marks":1645,"data":1646},"Push addresses this with continuous discovery, telemetry streams for the most important points of user interaction with AI apps, and controls that allow you to adapt quickly with simple configuration changes.",[],{},{"nodeType":860,"data":1648,"content":1649},{},[1650],{"nodeType":864,"value":1651,"marks":1652,"data":1653},"With automatic app categorization, if an employee starts using a new AI code assistant that didn't exist last quarter, Push discovers it, classifies it, and applies your governance rules — no manual intervention required.",[],{},{"nodeType":860,"data":1655,"content":1656},{},[1657],{"nodeType":864,"value":1658,"marks":1659,"data":1660},"All AI-related telemetry — app logins, file uploads and downloads, clipboard events, browser extensions, AI chat transcripts — can be sent as structured data to your SIEM.",[],{},{"nodeType":860,"data":1662,"content":1663},{},[1664],{"nodeType":864,"value":1665,"marks":1666,"data":1667},"This gives you all the information you need to track your progress, check your compliance status, and identify trends in AI usage and risk across your business as you make progress toward your goal, armed with the right data you didn't have before.",[],{},{"nodeType":860,"data":1669,"content":1670},{},[1671],{"nodeType":864,"value":1672,"marks":1673,"data":1674},"The goal isn't perfect control over every AI interaction. It's having enough visibility to make informed decisions and enough control to enforce them, without intensifying the shadow AI usage problem you set out to solve. Push can help you get there.",[],{},{"nodeType":1005,"data":1676,"content":1677},{},[],{"nodeType":860,"data":1679,"content":1680},{},[1681],{"nodeType":864,"value":1682,"marks":1683,"data":1684},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":860,"data":1686,"content":1687},{},[1688],{"nodeType":864,"value":1689,"marks":1690,"data":1691},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":860,"data":1693,"content":1694},{},[1695,1698,1707],{"nodeType":864,"value":21,"marks":1696,"data":1697},[],{},{"nodeType":883,"data":1699,"content":1701},{"uri":1700},"https://pushsecurity.com/demo",[1702],{"nodeType":864,"value":1703,"marks":1704,"data":1706},"Book a live demo to learn more.",[1705],{"type":1455},{},{"nodeType":864,"value":21,"marks":1708,"data":1709},[],{},{"entries":1711},{"hyperlink":1712,"inline":1713,"block":1714},[],[],[1715,1722,1731,1738,1776,1783,1790,1796,1803,1830,1838,1852,1858],{"sys":1716,"__typename":1717,"type":1718,"ctaText":1719,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":58},{"id":1000},"CtaWidget","Custom","Don't miss our upcoming webinar on Shadow AI and how to manage it in your organization.","Register Now","sunny orange",{"sys":1723,"__typename":1724,"title":1725,"caption":1726,"layoutMode":59,"file":1727},{"id":1040},"Image","ai-sprawl-infographic","AI sprawl is worse than most organizations realize. ",{"url":1728,"width":1729,"height":1730},"https://images.ctfassets.net/y1cdw1ablpvd/7vCbQdyRkjLs5EmsjBBAQp/3bfb13e7ec19be76325cdc69297c48c3/ai-sprawl-infographic_2x__3_.png",1800,1192,{"sys":1732,"__typename":1724,"title":1733,"caption":1733,"layoutMode":59,"file":1734},{"id":1058},"Shadow AI visibility gaps using traditional tools",{"url":1735,"width":1736,"height":1737},"https://images.ctfassets.net/y1cdw1ablpvd/7HQl2qfsTiCwa2pRzCVqDE/d87180dd96358326097565d8a60e8591/image9.png",1999,1125,{"sys":1739,"__typename":1740,"content":1741,"name":1775,"title":59},{"id":1076},"InsightTextBlockComponent",{"json":1742},{"data":1743,"content":1744,"nodeType":856},{},[1745],{"data":1746,"content":1747,"nodeType":860},{},[1748,1752,1759,1763,1771],{"data":1749,"marks":1750,"value":1751,"nodeType":864},{},[],"Attackers are already exploiting this interconnectivity — from ",{"data":1753,"content":1754,"nodeType":883},{"uri":1543},[1755],{"data":1756,"marks":1757,"value":1758,"nodeType":864},{},[],"malvertising campaigns that impersonate AI tools",{"data":1760,"marks":1761,"value":1762,"nodeType":864},{},[]," to steal credentials, to ",{"data":1764,"content":1766,"nodeType":883},{"uri":1765},"https://pushsecurity.com/blog/analyzing-the-instructure-breach",[1767],{"data":1768,"marks":1769,"value":1770,"nodeType":864},{},[],"leveraging OAuth consent grants in supply chain attacks",{"data":1772,"marks":1773,"value":1774,"nodeType":864},{},[],". ","Shadow AI guide IB3",{"sys":1777,"__typename":1724,"title":1778,"caption":1778,"layoutMode":59,"file":1779},{"id":1187},"Push automatically discovers and inventories AI apps from browser login events.",{"url":1780,"width":1781,"height":1782},"https://images.ctfassets.net/y1cdw1ablpvd/5krEecjMxIJgVCa74A79xa/3bb94ca3b496e9486f94526d708e34d5/image8.png",1469,850,{"sys":1784,"__typename":1724,"title":1785,"caption":1785,"layoutMode":59,"file":1786},{"id":1232},"Push discovers AI browser extensions used by your users, across every browser.",{"url":1787,"width":1788,"height":1789},"https://images.ctfassets.net/y1cdw1ablpvd/14lMFifCBB9RwQpt101tNd/dabe2713e58e787175701ec0d35076ca/image2.png",1470,851,{"sys":1791,"__typename":1724,"title":1792,"caption":1792,"layoutMode":59,"file":1793},{"id":1291},"Push's four-step path to secure AI adoption",{"url":1794,"width":1736,"height":1795},"https://images.ctfassets.net/y1cdw1ablpvd/E1wuJW4EzmjeLTpnHHM9f/895569f4b215b1b7b82e697c40462cbc/image3.png",1013,{"sys":1797,"__typename":1724,"title":1798,"caption":1798,"layoutMode":59,"file":1799},{"id":1378},"Push in-browser warning screen guiding the user toward the preferred AI app",{"url":1800,"width":1801,"height":1802},"https://images.ctfassets.net/y1cdw1ablpvd/3ouLBkKhiEcBmY8V2XAaUz/71a3cb221adba7d2744ff8b02bab3891/image4.png",1435,738,{"sys":1804,"__typename":1740,"content":1805,"name":1829,"title":59},{"id":1391},{"json":1806},{"data":1807,"content":1808,"nodeType":856},{},[1809],{"data":1810,"content":1811,"nodeType":860},{},[1812,1816,1825],{"data":1813,"marks":1814,"value":1815,"nodeType":864},{},[],"“A published policy is not the same thing as people actually doing that,” explains Push customer Stephen Shkardoon, cybersecurity manager at Te Herenga Waka — Victoria University of Wellington in New Zealand, on one of the drivers for their ",{"data":1817,"content":1819,"nodeType":883},{"uri":1818},"https://pushsecurity.com/customer-stories/te-herenga-waka-victoria-university-of-wellington",[1820],{"data":1821,"marks":1822,"value":1824,"nodeType":864},{},[1823],{"type":1455},"selection of Push Security",{"data":1826,"marks":1827,"value":1828,"nodeType":864},{},[]," to get control of AI usage at their organization.","Shadow AI guide IB1",{"sys":1831,"__typename":1724,"title":1832,"caption":1833,"layoutMode":59,"file":1834},{"id":1416},"Rules for AI app controls can be configured on a variety of conditions, including user groups, app attributes, and what mode of enforcement you wish to use.","Rules for AI app controls can be configured on a variety of conditions, including user groups, app attributes, and the mode of enforcement.",{"url":1835,"width":1836,"height":1837},"https://images.ctfassets.net/y1cdw1ablpvd/7czh28QGwm0ZStUmeWXBaq/667ee2441911fa4006a2ec75ebf727ea/image6.png",692,830,{"sys":1839,"__typename":1740,"content":1840,"name":1851,"title":59},{"id":1422},{"json":1841},{"data":1842,"content":1843,"nodeType":856},{},[1844],{"data":1845,"content":1846,"nodeType":860},{},[1847],{"data":1848,"marks":1849,"value":1850,"nodeType":864},{},[],"Push customers love the flexibility of this control compared to an SWG or CASB, which often rely on binary enforcement at the domain level only. ","Shadow AI guide IB2",{"sys":1853,"__typename":1724,"title":1854,"caption":1854,"layoutMode":59,"file":1855},{"id":1515},"Push blocks clipboard copy events that violate your policy.",{"url":1856,"width":1736,"height":1857},"https://images.ctfassets.net/y1cdw1ablpvd/jjUt4bChHcCWQJXqNzyQ8/c16974d72ef2bbc65689bf46bcb59e6f/image5.png",1295,{"sys":1859,"__typename":1724,"title":1860,"caption":1860,"layoutMode":59,"file":1861},{"id":1590},"Push can block unapproved MCP connection requests in real time.",{"url":1862,"width":1736,"height":1863},"https://images.ctfassets.net/y1cdw1ablpvd/wTAwk90bIA1B3XSkRf4M4/e4d3630af83501e6b4b05217fdf2e600/image1.png",1203,{"items":1865},[1866,1879,1892,1912,1932,1952,1972,1992,2012,2032],{"answer":1867,"question":1878},{"json":1868},{"nodeType":856,"data":1869,"content":1870},{},[1871],{"nodeType":860,"data":1872,"content":1873},{},[1874],{"nodeType":864,"value":1875,"marks":1876,"data":1877},"Network monitoring tools see domain-level traffic but can't tell you what's actually happening inside an AI session — whether an employee is browsing a tool's marketing page or pasting source code into a prompt. IdP logs capture OAuth grants routed through the identity provider but miss AI tools accessed via direct signup or personal accounts. Browser-based security tools like Push Security monitor AI activity where it actually happens: inside the browser session. Push captures login events, clipboard pastes, file uploads, extension installations, and OAuth grants, providing structured telemetry on what data is moving into which AI tools, through which accounts, and whether those accounts are corporate or personal.",[],{},"How do you monitor what employees are doing with AI tools?",{"answer":1880,"question":1891},{"json":1881},{"nodeType":856,"data":1882,"content":1883},{},[1884],{"nodeType":860,"data":1885,"content":1886},{},[1887],{"nodeType":864,"value":1888,"marks":1889,"data":1890},"Binary allow/block decisions — whether enforced through a SWG, CASB, or enterprise browser — treat every AI interaction as equivalent, which pushes employees toward tools you can't see at all. Graduated enforcement offers a middle path. Push Security lets teams start with monitoring to build an accurate picture of AI usage, then introduce in-browser prompts that explain why a tool hasn't been approved and direct employees toward sanctioned alternatives, before applying hard blocks only where the data sensitivity or tool risk justifies it. Controls are configurable per user group, and new AI tools automatically inherit governance rules through automatic categorization — so enforcement keeps pace with the landscape without manual blocklist updates.",[],{},"How do you restrict AI usage without blocking everything?",{"answer":1893,"question":1911},{"json":1894},{"nodeType":856,"data":1895,"content":1896},{},[1897,1904],{"nodeType":860,"data":1898,"content":1899},{},[1900],{"nodeType":864,"value":1901,"marks":1902,"data":1903},"Network monitoring tools, IdP logs, and endpoint agents each catch a slice of shadow AI but miss entire categories. SWGs see domain traffic but can't confirm whether someone authenticated or what they did after login. IdPs capture OAuth grants routed through the identity provider but miss AI tools accessed via direct signup or personal accounts. EDR is blind to browser-layer activity entirely. ",[],{},{"nodeType":860,"data":1905,"content":1906},{},[1907],{"nodeType":864,"value":1908,"marks":1909,"data":1910},"Browser-based security tools like Push Security identify AI tools from actual login events, catching the four categories other tools miss: unapproved AI apps, personal accounts on approved tools, AI browser extensions with broad permissions, and OAuth integrations granting persistent API access to corporate systems. Each discovered app is automatically categorized and enriched with authentication context — SSO vs. password, MFA status, corporate vs. personal account — so security teams can assess actual risk rather than treating every AI tool as equivalent.",[],{},"How do you discover what AI tools employees are using?",{"answer":1913,"question":1931},{"json":1914},{"nodeType":856,"data":1915,"content":1916},{},[1917,1924],{"nodeType":860,"data":1918,"content":1919},{},[1920],{"nodeType":864,"value":1921,"marks":1922,"data":1923},"This is a gap that traditional DLP architectures weren't designed for. Network DLP and SWGs can't intercept clipboard pastes into AI prompts because there's no network event to inspect — the data moves from the clipboard to the browser DOM without crossing the wire. Endpoint DLP sees file-system operations but not in-browser activity. Browser-based controls operate where the paste actually happens. ",[],{},{"nodeType":860,"data":1925,"content":1926},{},[1927],{"nodeType":864,"value":1928,"marks":1929,"data":1930},"Push Security matches clipboard content against patterns for credentials, API keys, credit card numbers, and custom content rules, then offers the employee a redacted version so they can continue working without exposing the actual sensitive data. The same approach extends to file uploads and downloads, covering the exfiltration paths that network and endpoint DLP leave open.",[],{},"How do you prevent sensitive data from being pasted into AI tools?",{"answer":1933,"question":1951},{"json":1934},{"nodeType":856,"data":1935,"content":1936},{},[1937,1944],{"nodeType":860,"data":1938,"content":1939},{},[1940],{"nodeType":864,"value":1941,"marks":1942,"data":1943},"Policy documents distributed during onboarding don't change behavior at the moment someone reaches for an unapproved AI tool. SWGs can block a domain, but they can't explain why or point to an approved alternative — the employee sees an error page. ",[],{},{"nodeType":860,"data":1945,"content":1946},{},[1947],{"nodeType":864,"value":1948,"marks":1949,"data":1950},"Enterprise browsers like Push Security can deliver policy enforcement at the point of decision: when an employee navigates to an unsanctioned AI tool, an in-browser message explains why the tool hasn't been approved and directs them to approved alternatives. Controls are configurable per user group — and new AI tools automatically inherit governance rules through automatic categorization, without manual blocklist updates.",[],{},"How do you enforce an AI acceptable use policy in real time?",{"answer":1953,"question":1971},{"json":1954},{"nodeType":856,"data":1955,"content":1956},{},[1957,1964],{"nodeType":860,"data":1958,"content":1959},{},[1960],{"nodeType":864,"value":1961,"marks":1962,"data":1963},"No single traditional tool covers all aspects of shadow AI (apps, tenants, integrations, extensions) and the user interaction with those categories of tool. SWGs and CASBs see domain-level traffic but can't identify personal account usage, extension activity, or clipboard pastes into AI prompts. IdPs capture federated logins but miss direct signups and personal accounts entirely. EDR doesn't see browser-layer activity. DSPM monitors data at rest in cloud storage but not data in motion through browser sessions. ",[],{},{"nodeType":860,"data":1965,"content":1966},{},[1967],{"nodeType":864,"value":1968,"marks":1969,"data":1970},"Most organizations will need browser-layer visibility alongside their existing stack — not as a replacement, but to close the gaps those tools weren't designed to address. Tools like Push Security operate at the layer where AI activity actually happens, covering all shadow AI categories with graduated enforcement (monitor, warn, block), per-user-group policies, and telemetry on authentication methods, clipboard events, file uploads, and OAuth grants. ",[],{},"What tools do you need to manage shadow AI?",{"answer":1973,"question":1991},{"json":1974},{"nodeType":856,"data":1975,"content":1976},{},[1977,1984],{"nodeType":860,"data":1978,"content":1979},{},[1980],{"nodeType":864,"value":1981,"marks":1982,"data":1983},"AI browser extensions are a blind spot for most security stacks. Endpoint management tools may detect that an extension is installed but typically can't evaluate what permissions it has requested or whether those permissions create data exfiltration risk. SWGs and CASBs don't see extension activity at all — extensions operate within the browser, not over the network. ",[],{},{"nodeType":860,"data":1985,"content":1986},{},[1987],{"nodeType":864,"value":1988,"marks":1989,"data":1990},"Push Security inventories every AI-related extension installed across the workforce, surfaces the specific permissions each extension has requested (access to page content, browsing history, clipboard data), and identifies permission combinations that could enable account takeover or data exfiltration. Security teams can then apply monitor, warn, or block enforcement to extension categories — and new extensions automatically inherit governance rules without maintaining manual allowlists that go stale as new AI extensions appear daily.",[],{},"How do I stop employees installing AI browser extensions?",{"answer":1993,"question":2011},{"json":1994},{"nodeType":856,"data":1995,"content":1996},{},[1997,2004],{"nodeType":860,"data":1998,"content":1999},{},[2000],{"nodeType":864,"value":2001,"marks":2002,"data":2003},"Point-in-time audits — whether run through an IdP, a CASB, or manual surveys — tell you what was true when you ran them. AI tool adoption changes weekly; Gartner projects 150,000 AI agents per Fortune 500 enterprise by 2028. SWGs can log new domains but can't classify them or apply governance rules automatically. ",[],{},{"nodeType":860,"data":2005,"content":2006},{},[2007],{"nodeType":864,"value":2008,"marks":2009,"data":2010},"Push Security discovers new AI tools as employees start using them: when someone logs in to a new AI app, Push identifies it from the login event, automatically categorizes it, and applies the organization's existing governance rules without manual intervention. All AI-related telemetry — app access, file uploads, clipboard events, extension activity — streams as structured data to the customer's SIEM, providing the material for governance dashboards and compliance reporting that stays current as the landscape shifts.",[],{},"How do you get visibility into AI tool sprawl?",{"answer":2013,"question":2031},{"json":2014},{"nodeType":856,"data":2015,"content":2016},{},[2017,2024],{"nodeType":860,"data":2018,"content":2019},{},[2020],{"nodeType":864,"value":2021,"marks":2022,"data":2023},"AI visibility means knowing which AI tools employees are using, how they're accessing them, and what data flows into those tools. AI control is the ability to enforce rules on that usage — blocking unapproved tools, restricting data flows, requiring approved accounts. AI governance is the broader program that encompasses both: defining acceptable use policies, establishing risk frameworks for evaluating new tools, and building the organizational processes that turn visibility and control into sustained security outcomes. ",[],{},{"nodeType":860,"data":2025,"content":2026},{},[2027],{"nodeType":864,"value":2028,"marks":2029,"data":2030},"Most organizations that struggle with AI governance have a visibility problem first — they're trying to write policies for tools they don't know their employees are using. But visibility without control is just watching the problem happen. Push Security provides both: discovery and monitoring across all four categories of shadow AI, plus graduated enforcement controls that let you apply different responses based on the risk profile of each tool, account, and data flow, at the point of interaction in the browser for real-time enforcement.",[],{},"What is the difference between AI governance, AI visibility, and AI control?",{"answer":2033,"question":2051},{"json":2034},{"nodeType":856,"data":2035,"content":2036},{},[2037,2044],{"nodeType":860,"data":2038,"content":2039},{},[2040],{"nodeType":864,"value":2041,"marks":2042,"data":2043},"Data Security Posture Management (DSPM) tools monitor data at rest in cloud storage and SaaS applications, identifying misconfigurations, overly permissive access, and sensitive data exposure. They don't monitor data in motion through browser sessions — which is the primary path for shadow AI risk. ",[],{},{"nodeType":860,"data":2045,"content":2046},{},[2047],{"nodeType":864,"value":2048,"marks":2049,"data":2050},"When an employee pastes source code into an AI prompt or uploads a customer spreadsheet to an unapproved AI tool, that data movement happens entirely inside the browser and never touches the cloud storage layer that DSPM tools monitor. DSPM and browser security are complementary: DSPM secures data where it is stored, while browser-layer tools like Push Security secure data where it moves.",[],{},"Does Data Security Posture Management (DSPM) prevent shadow AI?","Shadow AI discovery and governance: Frequently asked questions",{},"How to discover AI, enforce policies, and prevent data loss","2026-08-13T00:00:00.000Z",{"items":2057},[2058,2741,3626],{"__typename":2059,"sys":2060,"content":2062,"title":2720,"synopsis":2721,"hashTags":59,"publishedDate":2722,"slug":2723,"tagsCollection":2724,"authorsCollection":2733},"BlogPosts",{"id":2061},"4NY2NbkAPucFOJY45yrrrE",{"json":2063},{"data":2064,"content":2065,"nodeType":856},{},[2066,2073,2080,2087,2093,2096,2104,2111,2144,2151,2176,2182,2185,2193,2200,2208,2252,2258,2265,2270,2273,2281,2288,2296,2303,2310,2326,2334,2359,2366,2372,2379,2387,2402,2430,2436,2454,2460,2468,2475,2500,2507,2514,2521,2527,2530,2538,2545,2552,2571,2579,2586,2594,2617,2629,2635,2638,2646,2653,2660,2667,2686,2689,2695,2701],{"data":2067,"content":2068,"nodeType":860},{},[2069],{"data":2070,"marks":2071,"value":2072,"nodeType":864},{},[],"Employees have been self-adopting apps, creating unmanaged accounts, and introducing third-party software dependencies into their organizations for years, and the core problem hasn't changed: unmanaged software expanding your attack surface without your knowledge.",{"data":2074,"content":2075,"nodeType":860},{},[2076],{"data":2077,"marks":2078,"value":2079,"nodeType":864},{},[],"But the rate at which employees are signing up for AI tools is unprecedented, and the depth of interconnectivity those tools demand is fundamentally different from traditional shadow SaaS. ",{"data":2081,"content":2082,"nodeType":860},{},[2083],{"data":2084,"marks":2085,"value":2086,"nodeType":864},{},[],"AI tools aren't just standalone apps that employees sign into — they're increasingly used as agents that drive other applications, pulling data from one platform, acting on another — they are becoming a core that other apps are integrating to, and that users are integrating with their wider SaaS stack. It’s becoming a focal integration point for app access and functionality in a way that's more comparable to an enterprise cloud platform than a typical SaaS tool. ",{"data":2088,"content":2092,"nodeType":996},{"target":2089},{"sys":2090},{"id":2091,"type":1001,"linkType":1002},"2Vxb48M5JN9Jdy8BG6nbUJ",[],{"data":2094,"content":2095,"nodeType":1005},{},[],{"data":2097,"content":2098,"nodeType":1009},{},[2099],{"data":2100,"marks":2101,"value":2103,"nodeType":864},{},[2102],{"type":899},"What is shadow AI? A quick 101",{"data":2105,"content":2106,"nodeType":860},{},[2107],{"data":2108,"marks":2109,"value":2110,"nodeType":864},{},[],"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Shadow AI risks cut in two directions:",{"data":2112,"content":2113,"nodeType":941},{},[2114,2129],{"data":2115,"content":2116,"nodeType":945},{},[2117],{"data":2118,"content":2119,"nodeType":860},{},[2120,2125],{"data":2121,"marks":2122,"value":2124,"nodeType":864},{},[2123],{"type":899},"Data exposure:",{"data":2126,"marks":2127,"value":2128,"nodeType":864},{},[]," source code, credentials, internal documents, and customer data routinely get pasted into AI prompts or uploaded as context, and once shared, that data is outside the organization's control. ",{"data":2130,"content":2131,"nodeType":945},{},[2132],{"data":2133,"content":2134,"nodeType":860},{},[2135,2140],{"data":2136,"marks":2137,"value":2139,"nodeType":864},{},[2138],{"type":899},"Attack surface:",{"data":2141,"marks":2142,"value":2143,"nodeType":864},{},[]," Every shadow AI app is an unmanaged identity with credentials that can be phished or stuffed, OAuth grants that give persistent API access to corporate systems, and browser extensions that can be compromised in supply chain attacks. ",{"data":2145,"content":2146,"nodeType":860},{},[2147],{"data":2148,"marks":2149,"value":2150,"nodeType":864},{},[],"AI tools increasingly function as hubs, connected via OAuth and MCP to email, cloud storage, code repositories, and other high-value systems. Every app connection an employee grants turns that AI tool into a node in a web of interconnected services, which means the more you hook in, the larger the attack surface across all the connected apps — and the greater the blast radius if the account used to access the AI tool is compromised.",{"data":2152,"content":2153,"nodeType":860},{},[2154,2158,2164,2167,2173],{"data":2155,"marks":2156,"value":2157,"nodeType":864},{},[],"Each integration creates a persistent trust relationship that survives password resets and MFA changes. Compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate. Attackers are already exploiting this interconnectivity — from ",{"data":2159,"content":2160,"nodeType":883},{"uri":1543},[2161],{"data":2162,"marks":2163,"value":1758,"nodeType":864},{},[],{"data":2165,"marks":2166,"value":1762,"nodeType":864},{},[],{"data":2168,"content":2169,"nodeType":883},{"uri":1765},[2170],{"data":2171,"marks":2172,"value":1770,"nodeType":864},{},[],{"data":2174,"marks":2175,"value":1774,"nodeType":864},{},[],{"data":2177,"content":2181,"nodeType":996},{"target":2178},{"sys":2179},{"id":2180,"type":1001,"linkType":1002},"1BWCa7AHCMlYw7XgPLx3h7",[],{"data":2183,"content":2184,"nodeType":1005},{},[],{"data":2186,"content":2187,"nodeType":1009},{},[2188],{"data":2189,"marks":2190,"value":2192,"nodeType":864},{},[2191],{"type":899},"The state of shadow AI, using Push data",{"data":2194,"content":2195,"nodeType":860},{},[2196],{"data":2197,"marks":2198,"value":2199,"nodeType":864},{},[],"We analyzed a snapshot of AI activity across Push customers during an average week in April 2026. We wanted to make sure it captured actual activity, not just historical data on apps that were added once and no longer used.",{"data":2201,"content":2202,"nodeType":860},{},[2203],{"data":2204,"marks":2205,"value":2207,"nodeType":864},{},[2206],{"type":899},"The numbers paint a picture that most security teams will find uncomfortable.",{"data":2209,"content":2210,"nodeType":860},{},[2211,2215,2220,2224,2229,2233,2238,2242,2248],{"data":2212,"marks":2213,"value":2214,"nodeType":864},{},[],"The average organization has ",{"data":2216,"marks":2217,"value":2219,"nodeType":864},{},[2218],{"type":899},"16 unique AI apps",{"data":2221,"marks":2222,"value":2223,"nodeType":864},{},[]," in active use, ",{"data":2225,"marks":2226,"value":2228,"nodeType":864},{},[2227],{"type":899},"17 unique AI browser extensions",{"data":2230,"marks":2231,"value":2232,"nodeType":864},{},[],", and ",{"data":2234,"marks":2235,"value":2237,"nodeType":864},{},[2236],{"type":899},"17 unique AI OAuth integrations",{"data":2239,"marks":2240,"value":2241,"nodeType":864},{},[]," connected into just Google Workspace and Microsoft 365 — with some organizations reaching as high as 40 unique AI apps, 163 AI extensions, and 55 OAuth connections to AI apps respectively. At the other end, the smallest organization with the ",{"data":2243,"marks":2244,"value":2247,"nodeType":864},{},[2245],{"type":2246},"italic","lowest",{"data":2249,"marks":2250,"value":2251,"nodeType":864},{},[]," adoption level is actively using two. ",{"data":2253,"content":2257,"nodeType":996},{"target":2254},{"sys":2255},{"id":2256,"type":1001,"linkType":1002},"2AfeiHub5kyZN8wuf6CJch",[],{"data":2259,"content":2260,"nodeType":860},{},[2261],{"data":2262,"marks":2263,"value":2264,"nodeType":864},{},[],"If most organizations have sanctioned one or two core AI assistants/platforms for business use, the gap between what's approved and what's actually happening is significant.",{"data":2266,"content":2269,"nodeType":996},{"target":2267},{"sys":2268},{"id":1040,"type":1001,"linkType":1002},[],{"data":2271,"content":2272,"nodeType":1005},{},[],{"data":2274,"content":2275,"nodeType":1009},{},[2276],{"data":2277,"marks":2278,"value":2280,"nodeType":864},{},[2279],{"type":899},"Understanding the four categories of shadow AI",{"data":2282,"content":2283,"nodeType":860},{},[2284],{"data":2285,"marks":2286,"value":2287,"nodeType":864},{},[],"Shadow SaaS has always been a problem, but in the context of AI apps there are four categories of shadow IT that security teams need to understand, because each one introduces a different kind of risk and requires a different approach to tackling it.",{"data":2289,"content":2290,"nodeType":1312},{},[2291],{"data":2292,"marks":2293,"value":2295,"nodeType":864},{},[2294],{"type":899},"Shadow AI apps",{"data":2297,"content":2298,"nodeType":860},{},[2299],{"data":2300,"marks":2301,"value":2302,"nodeType":864},{},[],"Shadow apps are AI tools that employees have signed up to and are using for business purposes without approval. This is the most visible dimension of the problem, and the one most people think of when they hear \"shadow AI\" — an employee pastes sensitive internal documents into ChatGPT, uploads confidential files to an AI assistant, or uses an unapproved coding tool to generate production code.",{"data":2304,"content":2305,"nodeType":860},{},[2306],{"data":2307,"marks":2308,"value":2309,"nodeType":864},{},[],"All of that is sensitive data leaving the organization through channels the security team can't see - and often accessible using personal accounts that can be compromised on personal devices or workstations. ",{"data":2311,"content":2312,"nodeType":860},{},[2313,2317,2322],{"data":2314,"marks":2315,"value":2316,"nodeType":864},{},[],"The 2026 DBIR's data loss prevention analysis underscores the scale — shadow AI is now the ",{"data":2318,"marks":2319,"value":2321,"nodeType":864},{},[2320],{"type":899},"third most common non-malicious insider action",{"data":2323,"marks":2324,"value":2325,"nodeType":864},{},[]," in DLP data, a 4x increase year-over-year. Across 858,000+ DLP events targeting GenAI tools, the most common data types being submitted were source code (28%), images (16%), structured data (14%), documents (13%), and PDFs (10%). That's not employees asking ChatGPT to fix their grammar — it's core intellectual property, production code, and internal documentation flowing into platforms the security team has no visibility into. But shadow apps themselves are only the most obvious part of the problem.",{"data":2327,"content":2328,"nodeType":1312},{},[2329],{"data":2330,"marks":2331,"value":2333,"nodeType":864},{},[2332],{"type":899},"Shadow tenants",{"data":2335,"content":2336,"nodeType":860},{},[2337,2341,2346,2350,2355],{"data":2338,"marks":2339,"value":2340,"nodeType":864},{},[],"Even when an organization has approved an AI tool — say, an enterprise ChatGPT deployment — employees frequently access the same app with personal accounts, creating shadow tenants that sit entirely outside organizational control. The DBIR found that ",{"data":2342,"marks":2343,"value":2345,"nodeType":864},{},[2344],{"type":899},"67% of GenAI users on corporate devices are using non-corporate accounts",{"data":2347,"marks":2348,"value":2349,"nodeType":864},{},[],", and our own data shows that ",{"data":2351,"marks":2352,"value":2354,"nodeType":864},{},[2353],{"type":899},"38% of file uploads to AI tools are made from shadow accounts",{"data":2356,"marks":2357,"value":2358,"nodeType":864},{},[]," rather than approved organizational ones.",{"data":2360,"content":2361,"nodeType":860},{},[2362],{"data":2363,"marks":2364,"value":2365,"nodeType":864},{},[],"When an organization approves Claude, ChatGPT, or another core AI platform, you typically also approve the OAuth integration and browser extension for core apps (e.g. M365, Google Workspace, and so on). When that integration is approved, it is approved for all tenants — not just your corporate tenant. ",{"data":2367,"content":2371,"nodeType":996},{"target":2368},{"sys":2369},{"id":2370,"type":1001,"linkType":1002},"3Rvw0n28AYIM3FQXtHyafD",[],{"data":2373,"content":2374,"nodeType":860},{},[2375],{"data":2376,"marks":2377,"value":2378,"nodeType":864},{},[],"This means that even if you've deployed enterprise controls around your sanctioned AI tools — DLP policies, retention settings, admin oversight — more than a third of the file uploads hitting AI tools are bypassing those controls entirely because they're happening through personal accounts on corporate devices.",{"data":2380,"content":2381,"nodeType":1312},{},[2382],{"data":2383,"marks":2384,"value":2386,"nodeType":864},{},[2385],{"type":899},"Shadow extensions",{"data":2388,"content":2389,"nodeType":860},{},[2390,2394,2398],{"data":2391,"marks":2392,"value":2393,"nodeType":864},{},[],"Many AI tools come with a browser extension counterpart, and there's a large ecosystem of third-party AI extensions that offer everything from writing assistance to automated data extraction. The average organization in our dataset has ",{"data":2395,"marks":2396,"value":2228,"nodeType":864},{},[2397],{"type":899},{"data":2399,"marks":2400,"value":2401,"nodeType":864},{},[]," deployed across its workforce, with the highest we observed reaching 163 — and since each of those average 17 different extensions may be installed by multiple employees, the actual number of individual extension installs across the organization is much higher still.",{"data":2403,"content":2404,"nodeType":860},{},[2405,2409,2417,2421,2426],{"data":2406,"marks":2407,"value":2408,"nodeType":864},{},[],"The extension dimension is particularly concerning because most extensions operate with significant privilege inside the browser — they can read and modify page content, access cookies and session tokens, and interact with virtually every web application an employee uses. As we detailed in our recent analysis of ",{"data":2410,"content":2412,"nodeType":883},{"uri":2411},"https://pushsecurity.com/blog/why-browser-extension-risk-scoring-wont-predict-your-next-breach/",[2413],{"data":2414,"marks":2415,"value":2416,"nodeType":864},{},[],"browser extension risk scoring",{"data":2418,"marks":2419,"value":2420,"nodeType":864},{},[],", at least ",{"data":2422,"marks":2423,"value":2425,"nodeType":864},{},[2424],{"type":899},"46.76% of all extensions across Push customers have the permission combinations needed to perform account takeover with no user interaction",{"data":2427,"marks":2428,"value":2429,"nodeType":864},{},[],", and the extensions involved in every major supply chain breach of the past 18 months scored as normal or low-risk beforehand.",{"data":2431,"content":2435,"nodeType":996},{"target":2432},{"sys":2433},{"id":2434,"type":1001,"linkType":1002},"3z4JOMALI52xoOXZkzPHLD",[],{"data":2437,"content":2438,"nodeType":860},{},[2439,2443,2450],{"data":2440,"marks":2441,"value":2442,"nodeType":864},{},[],"AI extensions add a specific wrinkle to this problem: many are branded to look like official companions to well-known AI tools but are actually third-party creations with no affiliation to the original vendor. They're not necessarily malicious at the point of installation, but they're exactly the kind of extension that's likely to be ",{"data":2444,"content":2445,"nodeType":883},{"uri":2411},[2446],{"data":2447,"marks":2448,"value":2449,"nodeType":864},{},[],"acquired and weaponized",{"data":2451,"marks":2452,"value":2453,"nodeType":864},{},[]," down the line — and in the meantime, they're collecting data that their permissions entitle them to (which, in most cases, means everything the user can see in their browser).",{"data":2455,"content":2459,"nodeType":996},{"target":2456},{"sys":2457},{"id":2458,"type":1001,"linkType":1002},"6K3z67rohss6H3lCsSn12B",[],{"data":2461,"content":2462,"nodeType":1312},{},[2463],{"data":2464,"marks":2465,"value":2467,"nodeType":864},{},[2466],{"type":899},"Shadow integrations",{"data":2469,"content":2470,"nodeType":860},{},[2471],{"data":2472,"marks":2473,"value":2474,"nodeType":864},{},[],"The fourth dimension — and arguably the most dangerous — is shadow integrations: OAuth connections between AI tools and core enterprise apps that aren't known or approved by the security team. Even if an organization has approved an AI tool for standalone use, plugging that tool directly into Google Workspace, Microsoft 365, Salesforce, or any other one of the dozen or so SaaS apps in a typical user’s work stack is a fundamentally different risk decision, because it creates a persistent, programmatic bridge between your environment and a third party.",{"data":2476,"content":2477,"nodeType":860},{},[2478,2482,2487,2491,2496],{"data":2479,"marks":2480,"value":2481,"nodeType":864},{},[],"On average, we see ",{"data":2483,"marks":2484,"value":2486,"nodeType":864},{},[2485],{"type":899},"17 unique AI app OAuth integrations per organization",{"data":2488,"marks":2489,"value":2490,"nodeType":864},{},[]," in ",{"data":2492,"marks":2493,"value":2495,"nodeType":864},{},[2494],{"type":2246},"just",{"data":2497,"marks":2498,"value":2499,"nodeType":864},{},[]," Google Workspace and Microsoft 365 (to be clear: this number excludes the dozens of downstream apps the AI assistants are integrated with as well), with the highest reaching 55. Each of those represents a unique AI product that has been granted OAuth access — the total number of individual consent grants across users is larger, because popular integrations get authorized by multiple employees independently.",{"data":2501,"content":2502,"nodeType":860},{},[2503],{"data":2504,"marks":2505,"value":2506,"nodeType":864},{},[],"The actual number of AI-related OAuth connections across the full SaaS estate is considerably higher again, because AI tools that automate workflows need to be connected to be useful — pulling data from one app, analyzing it in another, presenting results in a third.",{"data":2508,"content":2509,"nodeType":860},{},[2510],{"data":2511,"marks":2512,"value":2513,"nodeType":864},{},[],"MCP connections use OAuth to achieve this interconnectivity in the same way, and AI coding agents create a particularly concentrated version of the risk: a single agent configuration can hold OAuth tokens for Jira, Confluence, Salesforce, GitHub, and more, meaning that compromising one agent — whether through prompt injection, a malicious repository config, or a supply chain attack on an MCP server — yields persistent, broadly scoped tokens for every service it was connected to, tokens that survive session restarts and generate audit log entries indistinguishable from legitimate user activity.",{"data":2515,"content":2516,"nodeType":860},{},[2517],{"data":2518,"marks":2519,"value":2520,"nodeType":864},{},[],"It's also worth noting that OAuth blast radius is almost always larger than organizations expect. A single well-permissioned user can expose secrets, dashboards, and internal tooling without tenant-wide admin access. And every new AI tool an employee connects makes the web of abusable permissions a little wider.",{"data":2522,"content":2526,"nodeType":996},{"target":2523},{"sys":2524},{"id":2525,"type":1001,"linkType":1002},"4SnzJ9T93gHzFIUASx7Yb3",[],{"data":2528,"content":2529,"nodeType":1005},{},[],{"data":2531,"content":2532,"nodeType":1009},{},[2533],{"data":2534,"marks":2535,"value":2537,"nodeType":864},{},[2536],{"type":899},"Why shadow AI needs a different solution to shadow SaaS",{"data":2539,"content":2540,"nodeType":860},{},[2541],{"data":2542,"marks":2543,"value":2544,"nodeType":864},{},[],"The reason it's worth distinguishing between these four dimensions isn't academic. Each one requires a different control, and addressing one doesn't solve the others.",{"data":2546,"content":2547,"nodeType":860},{},[2548],{"data":2549,"marks":2550,"value":2551,"nodeType":864},{},[],"Blocking unsanctioned AI apps does nothing for the personal accounts accessing approved ones, and neither addresses the average 17 different AI extensions running with broad browser permissions, let alone the dozens of OAuth integrations that have already been granted persistent access to core enterprise apps — and even auditing OAuth in Google Workspace and Microsoft 365, where the controls are relatively mature, leaves the broader SaaS estate unaddressed, where admin tooling is inconsistent and visibility is limited.",{"data":2553,"content":2554,"nodeType":860},{},[2555,2559,2567],{"data":2556,"marks":2557,"value":2558,"nodeType":864},{},[],"The tooling gap compounds the policy gap. ",{"data":2560,"content":2562,"nodeType":883},{"uri":2561},"https://pushsecurity.com/blog/7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market/",[2563],{"data":2564,"marks":2565,"value":2566,"nodeType":864},{},[],"Omdia found",{"data":2568,"marks":2569,"value":2570,"nodeType":864},{},[]," that 58% of organizations rely on secure web gateways to secure GenAI usage — but an SWG can tell you that a user visited ChatGPT, not whether they pasted your source code into the prompt. That link between knowing where data went and knowing what the user actually did is the fundamental visibility gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":2572,"content":2573,"nodeType":1312},{},[2574],{"data":2575,"marks":2576,"value":2578,"nodeType":864},{},[2577],{"type":899},"Advice for security teams",{"data":2580,"content":2581,"nodeType":860},{},[2582],{"data":2583,"marks":2584,"value":2585,"nodeType":864},{},[],"The principles behind managing shadow AI are the same ones that have governed shadow SaaS and software supply chain management for years: default-deny where feasible, comprehensive inventory where it isn't, and continuous monitoring for changes that signal increased risk. But it's vital that teams act fast to stop the snowball.",{"data":2587,"content":2588,"nodeType":860},{},[2589],{"data":2590,"marks":2591,"value":2593,"nodeType":864},{},[2592],{"type":899},"That starts with visibility into which AI tools employees are actually using and which accounts they're using to access them — without that baseline, every other control is built on assumptions.",{"data":2595,"content":2596,"nodeType":860},{},[2597,2602,2606,2613],{"data":2598,"marks":2599,"value":2601,"nodeType":864},{},[2600],{"type":899},"Extensions",{"data":2603,"marks":2604,"value":2605,"nodeType":864},{},[]," need the same ",{"data":2607,"content":2608,"nodeType":883},{"uri":2411},[2609],{"data":2610,"marks":2611,"value":2612,"nodeType":864},{},[],"default-deny allowlisting approach",{"data":2614,"marks":2615,"value":2616,"nodeType":864},{},[]," that has been best practice for software management elsewhere: build a complete inventory, allowlist what's vetted, block everything else, and monitor the approved set for changes that precede weaponization.",{"data":2618,"content":2619,"nodeType":860},{},[2620,2625],{"data":2621,"marks":2622,"value":2624,"nodeType":864},{},[2623],{"type":899},"OAuth",{"data":2626,"marks":2627,"value":2628,"nodeType":864},{},[]," demands the most urgency, because each unmanaged integration is a persistent trust relationship that survives password resets and MFA changes — adopt default-deny for consent grants in your primary enterprise apps, routinely audit what's already connected, and critically extend that visibility beyond Google and Microsoft to the broader SaaS estate where the controls are weaker and the sprawl is harder to track.",{"data":2630,"content":2634,"nodeType":996},{"target":2631},{"sys":2632},{"id":2633,"type":1001,"linkType":1002},"3RFLFtJtDXvhTz1mVztfV9",[],{"data":2636,"content":2637,"nodeType":1005},{},[],{"data":2639,"content":2640,"nodeType":1009},{},[2641],{"data":2642,"marks":2643,"value":2645,"nodeType":864},{},[2644],{"type":899},"Browser visibility and control is key to de-risking AI adoption",{"data":2647,"content":2648,"nodeType":860},{},[2649],{"data":2650,"marks":2651,"value":2652,"nodeType":864},{},[],"AI usage is fundamentally browser-based activity — every LLM interaction, every prompt containing sensitive data, every AI agent authorization, every OAuth consent grant happens inside a browser session — which makes the browser the natural control point for AI governance across the workforce. ",{"data":2654,"content":2655,"nodeType":860},{},[2656],{"data":2657,"marks":2658,"value":2659,"nodeType":864},{},[],"Push tracks AI app usage and login security across the workforce, inventories and controls AI browser extensions, monitors and blocks OAuth consent flows across any app (not just the primary enterprise platforms), and gives security teams a single view of the full shadow AI picture across all four dimensions.",{"data":2661,"content":2662,"nodeType":860},{},[2663],{"data":2664,"marks":2665,"value":2666,"nodeType":864},{},[],"Shadow AI isn't a problem that will age well if ignored. Every week that passes without visibility adds more apps, more extensions, more integrations, and more potential breach paths into the environment — and as the Vercel breach demonstrated, it only takes one forgotten OAuth grant to turn an employee's idle curiosity into an organization-wide incident.",{"data":2668,"content":2669,"nodeType":860},{},[2670,2674,2682],{"data":2671,"marks":2672,"value":2673,"nodeType":864},{},[],"Learn more about how you can tackle ",{"data":2675,"content":2677,"nodeType":883},{"uri":2676},"https://pushsecurity.com/uc/shadow-ai",[2678],{"data":2679,"marks":2680,"value":580,"nodeType":864},{},[2681],{"type":1455},{"data":2683,"marks":2684,"value":2685,"nodeType":864},{},[]," with Push. ",{"data":2687,"content":2688,"nodeType":1005},{},[],{"data":2690,"content":2691,"nodeType":860},{},[2692],{"data":2693,"marks":2694,"value":1682,"nodeType":864},{},[],{"data":2696,"content":2697,"nodeType":860},{},[2698],{"data":2699,"marks":2700,"value":1689,"nodeType":864},{},[],{"data":2702,"content":2703,"nodeType":860},{},[2704,2708,2716],{"data":2705,"marks":2706,"value":2707,"nodeType":864},{},[],"Book a ",{"data":2709,"content":2710,"nodeType":883},{"uri":1700},[2711],{"data":2712,"marks":2713,"value":2715,"nodeType":864},{},[2714],{"type":1455},"live demo",{"data":2717,"marks":2718,"value":2719,"nodeType":864},{},[]," to learn more.","Shadow AI: what Push data reveals about the scale of the problem","Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.","2026-05-28T00:00:00.000Z","what-push-data-reveals-about-the-state-of-shadow-ai",{"items":2725},[2726,2730],{"sys":2727,"name":2729},{"id":2728},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"sys":2731,"name":297},{"id":2732},"3pjES4THCIfSAwhGdNwBcy",{"items":2734},[2735],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":2739},"Dan Green","Dan","Threat Research",{"url":2740},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":2059,"sys":2742,"content":2744,"title":3608,"synopsis":3609,"hashTags":59,"publishedDate":3610,"slug":3611,"tagsCollection":3612,"authorsCollection":3618},{"id":2743},"6Xn377JQfbDz49Np74cbGl",{"json":2745},{"data":2746,"content":2747,"nodeType":856},{},[2748,2755,2786,2804,2809,2816,2832,2835,2843,2861,2925,2932,2938,2945,3028,3035,3042,3058,3061,3069,3076,3083,3091,3098,3110,3116,3123,3130,3137,3140,3148,3164,3180,3187,3194,3201,3222,3308,3315,3322,3325,3333,3349,3356,3363,3371,3374,3382,3400,3407,3414,3447,3454,3461,3464,3472,3479,3491,3497,3509,3521,3527,3539,3561,3568,3571,3579,3586,3592],{"data":2749,"content":2750,"nodeType":860},{},[2751],{"data":2752,"marks":2753,"value":2754,"nodeType":864},{},[],"Most security leaders I talk to know they have an AI problem. They've seen the board questions, read the reports, maybe even drafted a policy. But when they start measuring where they stand — not plans or roadmaps, but actual current state — the gap between awareness and operational capability comes into focus.",{"data":2756,"content":2757,"nodeType":860},{},[2758,2762,2770,2774,2782],{"data":2759,"marks":2760,"value":2761,"nodeType":864},{},[],"The ",{"data":2763,"content":2765,"nodeType":883},{"uri":2764},"https://pushsecurity.com/blog/verizon-dbir-2026-review",[2766],{"data":2767,"marks":2768,"value":2769,"nodeType":864},{},[],"2026 Verizon DBIR",{"data":2771,"marks":2772,"value":2773,"nodeType":864},{},[]," quantifies the scale: 45% of employees are now regular AI users on corporate devices (up from 15% the prior year), with 67% using personal accounts. ",{"data":2775,"content":2777,"nodeType":883},{"uri":2776},"https://pushsecurity.com/blog/what-push-data-reveals-about-the-state-of-shadow-ai",[2778],{"data":2779,"marks":2780,"value":2781,"nodeType":864},{},[],"Push data",{"data":2783,"marks":2784,"value":2785,"nodeType":864},{},[]," further shows that 38% of file uploads to AI tools come from those shadow accounts rather than approved organizational ones — and the DBIR shows what's going into them: of 858,000+ DLP events targeting GenAI applications, the most common data types were source code (28%), structured data (14%), and documents and PDFs (23% combined).",{"data":2787,"content":2788,"nodeType":860},{},[2789,2793,2800],{"data":2790,"marks":2791,"value":2792,"nodeType":864},{},[],"The average organization now has ",{"data":2794,"content":2795,"nodeType":883},{"uri":2776},[2796],{"data":2797,"marks":2798,"value":2799,"nodeType":864},{},[],"16 unique AI apps, 17 AI browser extensions, and 17 AI OAuth integrations",{"data":2801,"marks":2802,"value":2803,"nodeType":864},{},[]," in active use, most unapproved. Shadow AI was the third most common non-malicious insider action in the DBIR, up 4x year over year.",{"data":2805,"content":2808,"nodeType":996},{"target":2806},{"sys":2807},{"id":1040,"type":1001,"linkType":1002},[],{"data":2810,"content":2811,"nodeType":860},{},[2812],{"data":2813,"marks":2814,"value":2815,"nodeType":864},{},[],"These statistics expose an attack surface and unmanaged risks at a high level. But the real problem is that most organizations can't produce a basic inventory of which AI tools are in use, let alone demonstrate controls around any of them. ",{"data":2817,"content":2818,"nodeType":860},{},[2819,2823,2828],{"data":2820,"marks":2821,"value":2822,"nodeType":864},{},[],"That gap between awareness and capability is where most organizations are stuck. And understanding ",{"data":2824,"marks":2825,"value":2827,"nodeType":864},{},[2826],{"type":2246},"why",{"data":2829,"marks":2830,"value":2831,"nodeType":864},{},[]," they're stuck requires a framework for what progress actually looks like.",{"data":2833,"content":2834,"nodeType":1005},{},[],{"data":2836,"content":2837,"nodeType":1009},{},[2838],{"data":2839,"marks":2840,"value":2842,"nodeType":864},{},[2841],{"type":899},"A model for measuring what most organizations already feel",{"data":2844,"content":2845,"nodeType":860},{},[2846,2850,2857],{"data":2847,"marks":2848,"value":2849,"nodeType":864},{},[],"Chris Cochran's ",{"data":2851,"content":2853,"nodeType":883},{"uri":2852},"https://sansorg.egnyte.com/dl/XtgqfjkjBjp8",[2854],{"data":2855,"marks":2856,"value":1108,"nodeType":864},{},[],{"data":2858,"marks":2859,"value":2860,"nodeType":864},{},[],", published earlier this year, provides a framework for addressing this gap. It defines five stages of AI security maturity across three pillars:",{"data":2862,"content":2863,"nodeType":941},{},[2864,2880,2896],{"data":2865,"content":2866,"nodeType":945},{},[2867],{"data":2868,"content":2869,"nodeType":860},{},[2870,2876],{"data":2871,"marks":2872,"value":2875,"nodeType":864},{},[2873,2874],{"type":899},{"type":1455},"Protect AI:",{"data":2877,"marks":2878,"value":2879,"nodeType":864},{},[]," Defending against AI-enabled threats like adversarial attacks, prompt injection, compromised browser extensions, and AI agents operating with unchecked permissions.",{"data":2881,"content":2882,"nodeType":945},{},[2883],{"data":2884,"content":2885,"nodeType":860},{},[2886,2892],{"data":2887,"marks":2888,"value":2891,"nodeType":864},{},[2889,2890],{"type":899},{"type":1455},"Utilize AI:",{"data":2893,"marks":2894,"value":2895,"nodeType":864},{},[]," Using AI to strengthen security operations by using AI-powered detection and triage, behavioral analytics, and automated response playbooks.",{"data":2897,"content":2898,"nodeType":945},{},[2899],{"data":2900,"content":2901,"nodeType":860},{},[2902,2908,2912,2921],{"data":2903,"marks":2904,"value":2907,"nodeType":864},{},[2905,2906],{"type":899},{"type":1455},"Govern AI:",{"data":2909,"marks":2910,"value":2911,"nodeType":864},{},[]," Managing how the organization adopts and uses AI tools. Things like acceptable use policies, shadow AI discovery, data classification, access controls, and risk assessment. This is the pillar that gets the most attention in boardroom conversations today, driven in part by ",{"data":2913,"content":2915,"nodeType":883},{"uri":2914},"https://pushsecurity.com/blog/browser-visibility-and-control-can-achieve-ai-compliance",[2916],{"data":2917,"marks":2918,"value":2920,"nodeType":864},{},[2919],{"type":1455},"regulatory pressure",{"data":2922,"marks":2923,"value":2924,"nodeType":864},{},[],".",{"data":2926,"content":2927,"nodeType":860},{},[2928],{"data":2929,"marks":2930,"value":2931,"nodeType":864},{},[],"How an organization invests across these three pillars, and whether it invests across all of them, determines whether it advances toward maturity in this area or stalls out at the early steps.",{"data":2933,"content":2937,"nodeType":996},{"target":2934},{"sys":2935},{"id":2936,"type":1001,"linkType":1002},"1JV3KG97JQNFKwODnMCMq2",[],{"data":2939,"content":2940,"nodeType":860},{},[2941],{"data":2942,"marks":2943,"value":2944,"nodeType":864},{},[],"The SANS AI maturity model outlines 5 stages that organizations must progress through in order to reach an optimal security posture:",{"data":2946,"content":2947,"nodeType":941},{},[2948,2964,2980,2996,3012],{"data":2949,"content":2950,"nodeType":945},{},[2951],{"data":2952,"content":2953,"nodeType":860},{},[2954,2960],{"data":2955,"marks":2956,"value":2959,"nodeType":864},{},[2957,2958],{"type":899},{"type":1455},"Stage 1 (Unaware / Ad Hoc)",{"data":2961,"marks":2962,"value":2963,"nodeType":864},{},[]," is where employees are freely using AI tools with no oversight, no inventory exists, and leadership may not even know how much AI is in use. There's no policy to violate, so technically it's not even shadow AI yet; it's just unmanaged adoption.",{"data":2965,"content":2966,"nodeType":945},{},[2967],{"data":2968,"content":2969,"nodeType":860},{},[2970,2976],{"data":2971,"marks":2972,"value":2975,"nodeType":864},{},[2973,2974],{"type":899},{"type":1455},"Stage 2 (Reactive / Policy-Emerging)",{"data":2977,"marks":2978,"value":2979,"nodeType":864},{},[]," means a policy exists, but it's course-grained: \"Don't use AI\" or \"use with caution.\" Known AI tools may be blocked at the network level. Security teams are learning about AI-specific threats but don't have dedicated expertise or tooling.",{"data":2981,"content":2982,"nodeType":945},{},[2983],{"data":2984,"content":2985,"nodeType":860},{},[2986,2992],{"data":2987,"marks":2988,"value":2991,"nodeType":864},{},[2989,2990],{"type":899},{"type":1455},"Stage 3 (Defined / Risk-Informed)",{"data":2993,"marks":2994,"value":2995,"nodeType":864},{},[]," is where things get intentional. AI usage is governed through enterprise tools rather than outright bans. AI systems are included in security assessments. The organization can demonstrate mature governance to regulators and partners. For many organizations, this is a strong and defensible operating position.",{"data":2997,"content":2998,"nodeType":945},{},[2999],{"data":3000,"content":3001,"nodeType":860},{},[3002,3008],{"data":3003,"marks":3004,"value":3007,"nodeType":864},{},[3005,3006],{"type":899},{"type":1455},"Stage 4 (Managed / Integrated)",{"data":3009,"marks":3010,"value":3011,"nodeType":864},{},[]," means AI is deeply embedded in security operations with measurable outcomes. AI systems are secured by design. Risk is quantified, not estimated. Decisions are data-driven. This is where organizations can handle AI-specific threats and operate at the tempo that AI-augmented adversaries demand.",{"data":3013,"content":3014,"nodeType":945},{},[3015],{"data":3016,"content":3017,"nodeType":860},{},[3018,3024],{"data":3019,"marks":3020,"value":3023,"nodeType":864},{},[3021,3022],{"type":899},{"type":1455},"Stage 5 (Optimizing / Adaptive)",{"data":3025,"marks":3026,"value":3027,"nodeType":864},{},[]," is the frontier of AI-native security with self-improving defenses. Elements of this stage exist primarily in large technology companies, defense contractors, and AI-native firms. For most organizations, this is a multi-year journey.",{"data":3029,"content":3030,"nodeType":860},{},[3031],{"data":3032,"marks":3033,"value":3034,"nodeType":864},{},[],"Most of the security leaders I talk to land between Stage 1 and Stage 2. They have awareness, maybe a policy, but not the tooling or telemetry to demonstrate much beyond that. ",{"data":3036,"content":3037,"nodeType":860},{},[3038],{"data":3039,"marks":3040,"value":3041,"nodeType":864},{},[],"The model is pragmatic about these challenges. It doesn't expect every organization to reach Stage 5, and it adjusts maturity targets by sector. ",{"data":3043,"content":3044,"nodeType":860},{},[3045,3049,3054],{"data":3046,"marks":3047,"value":3048,"nodeType":864},{},[],"But it ",{"data":3050,"marks":3051,"value":3053,"nodeType":864},{},[3052],{"type":2246},"does",{"data":3055,"marks":3056,"value":3057,"nodeType":864},{},[]," require evidence of progress, not just intent. And for the majority sitting at Stage 2, the hard part is identifying the right steps to move from being merely reactive to a posture of operational readiness. That’s the chasm to cross.",{"data":3059,"content":3060,"nodeType":1005},{},[],{"data":3062,"content":3063,"nodeType":1009},{},[3064],{"data":3065,"marks":3066,"value":3068,"nodeType":864},{},[3067],{"type":899},"The chasm",{"data":3070,"content":3071,"nodeType":860},{},[3072],{"data":3073,"marks":3074,"value":3075,"nodeType":864},{},[],"For the organizations sitting at Stage 2, current state often looks like this: They've written an AI acceptable use policy, and maybe they've blocked known AI apps at the network level. They've trained employees on what's allowed and what isn't. ",{"data":3077,"content":3078,"nodeType":860},{},[3079],{"data":3080,"marks":3081,"value":3082,"nodeType":864},{},[],"To be sure, blocking is the fastest lever a security team can pull, and it represents visible progress to the business. The problem is that it rarely stays effective. ",{"data":3084,"content":3085,"nodeType":860},{},[3086],{"data":3087,"marks":3088,"value":3090,"nodeType":864},{},[3089],{"type":899},"SANS calls the pattern that traps most organizations at Stage 2 the \"Framework of No.\" ",{"data":3092,"content":3093,"nodeType":860},{},[3094],{"data":3095,"marks":3096,"value":3097,"nodeType":864},{},[],"\"A block-based AI policy may feel like risk management, but practitioner experience shows it typically drives AI usage underground rather than preventing it,” the report notes. “This is the pattern SANS has documented as the 'Framework of No,' and it is why the Stage 2 to Stage 3 transition is so critical.\"",{"data":3099,"content":3100,"nodeType":860},{},[3101,3106],{"data":3102,"marks":3103,"value":3105,"nodeType":864},{},[3104],{"type":2246},"This",{"data":3107,"marks":3108,"value":3109,"nodeType":864},{},[]," is the chasm. On one side: awareness and policy. On the other: operational capability - the tooling, telemetry, and controls that let a security team see what's happening and respond to it. Most organizations are standing on the awareness side, looking across, not sure how to get over.",{"data":3111,"content":3115,"nodeType":996},{"target":3112},{"sys":3113},{"id":3114,"type":1001,"linkType":1002},"187mKPZV8tVbsw17L2cWIU",[],{"data":3117,"content":3118,"nodeType":860},{},[3119],{"data":3120,"marks":3121,"value":3122,"nodeType":864},{},[],"The model is specific about what crossing requires. The steps from Stage 2 to Stage 3 include technical BYOAI discovery (not a survey, but automated discovery), AI-specific data classification, AI-aware controls, and a cross-functional governance body. Data classification is a critical prerequisite: \"You cannot write an effective AI policy without knowing where sensitive data lives,\" the report emphasizes.",{"data":3124,"content":3125,"nodeType":860},{},[3126],{"data":3127,"marks":3128,"value":3129,"nodeType":864},{},[],"These are visibility and measurement problems before they're policy problems. You can't govern what you can't see. You can't classify risk you can't measure. And a blocklist that pushes usage underground doesn't give you either: it just makes the gap between your policy and your reality harder to detect.",{"data":3131,"content":3132,"nodeType":860},{},[3133],{"data":3134,"marks":3135,"value":3136,"nodeType":864},{},[],"Getting this visibility right is necessary for crossing the chasm. But it’s not the only step organizations must undertake if they want to address their AI risk.",{"data":3138,"content":3139,"nodeType":1005},{},[],{"data":3141,"content":3142,"nodeType":1009},{},[3143],{"data":3144,"marks":3145,"value":3147,"nodeType":864},{},[3146],{"type":899},"Governance is key, but don't forget about protection",{"data":3149,"content":3150,"nodeType":860},{},[3151,3155,3160],{"data":3152,"marks":3153,"value":3154,"nodeType":864},{},[],"Most AI security conversations today - the vendor pitches, board decks, and compliance checklists - are about the ",{"data":3156,"marks":3157,"value":3159,"nodeType":864},{},[3158],{"type":899},"Govern",{"data":3161,"marks":3162,"value":3163,"nodeType":864},{},[]," pillar. Shadow AI discovery. Usage policies. Data classification. Controls around what employees paste into AI prompts or upload to AI tools. It's important work.",{"data":3165,"content":3166,"nodeType":860},{},[3167,3171,3176],{"data":3168,"marks":3169,"value":3170,"nodeType":864},{},[],"But the SANS model gives roughly equal weight to a second pillar that gets almost no attention: ",{"data":3172,"marks":3173,"value":3175,"nodeType":864},{},[3174],{"type":899},"Protect",{"data":3177,"marks":3178,"value":3179,"nodeType":864},{},[]," - defending against AI-enabled attacks.",{"data":3181,"content":3182,"nodeType":860},{},[3183],{"data":3184,"marks":3185,"value":3186,"nodeType":864},{},[],"The Protect pillar starts from a stark baseline. At Stage 1, most organizations have no visibility into which AI agents or browser extensions have access to their corporate environment, let alone a framework for understanding how those could be attacked. ",{"data":3188,"content":3189,"nodeType":860},{},[3190],{"data":3191,"marks":3192,"value":3193,"nodeType":864},{},[],"By Stage 3, the model expects runtime validation of AI tools and plugins, detection capabilities mapped to AI-specific attack frameworks, and controls that cover the growing surface area of agentic AI. ",{"data":3195,"content":3196,"nodeType":860},{},[3197],{"data":3198,"marks":3199,"value":3200,"nodeType":864},{},[],"By Stage 4, organizations need real-time monitoring of AI agent behavior and defenses against attacks that exploit trust relationships between AI systems — capabilities most security teams haven't started scoping, much less building or procuring.",{"data":3202,"content":3203,"nodeType":860},{},[3204,3208,3218],{"data":3205,"marks":3206,"value":3207,"nodeType":864},{},[],"These are detection and response capabilities, not governance exercises — and the attacks they address are already well underway. ",{"data":3209,"content":3211,"nodeType":883},{"uri":3210},"https://pushsecurity.com/blog/the-cisos-data-problem-and-how-browser-telemetry-can-help/",[3212],{"data":3213,"marks":3214,"value":3217,"nodeType":864},{},[3215,3216],{"type":1455},{"type":899},"One in three phishing payloads",{"data":3219,"marks":3220,"value":3221,"nodeType":864},{},[]," intercepted by Push arrive outside of email, through channels where most security controls don't exist. Evidence of the growth of browser-based attack methods enabled by AI tooling abounds:",{"data":3223,"content":3224,"nodeType":941},{},[3225,3247,3269],{"data":3226,"content":3227,"nodeType":945},{},[3228],{"data":3229,"content":3230,"nodeType":860},{},[3231,3235,3243],{"data":3232,"marks":3233,"value":3234,"nodeType":864},{},[],"CrowdStrike's 2026 Global Threat Report documented a ",{"data":3236,"content":3238,"nodeType":883},{"uri":3237},"https://www.crowdstrike.com/explore/2026-global-threat-report",[3239],{"data":3240,"marks":3241,"value":3242,"nodeType":864},{},[],"563% increase in ClickFix lures",{"data":3244,"marks":3245,"value":3246,"nodeType":864},{},[]," — fake CAPTCHA pages that trick users into executing malicious commands on their own machines.",{"data":3248,"content":3249,"nodeType":945},{},[3250],{"data":3251,"content":3252,"nodeType":860},{},[3253,3257,3265],{"data":3254,"marks":3255,"value":3256,"nodeType":864},{},[],"Push has tracked a ",{"data":3258,"content":3260,"nodeType":883},{"uri":3259},"https://pushsecurity.com/blog/device-code-phishing/",[3261],{"data":3262,"marks":3263,"value":3264,"nodeType":864},{},[],"37x increase in device code phishing",{"data":3266,"marks":3267,"value":3268,"nodeType":864},{},[]," since the start of 2026, with 18+ distinct kits now offering the technique.",{"data":3270,"content":3271,"nodeType":945},{},[3272],{"data":3273,"content":3274,"nodeType":860},{},[3275,3278,3287,3291,3296,3300,3305],{"data":3276,"marks":3277,"value":21,"nodeType":864},{},[],{"data":3279,"content":3281,"nodeType":883},{"uri":3280},"https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack",[3282],{"data":3283,"marks":3284,"value":3286,"nodeType":864},{},[3285],{"type":1455},"Anthropic",{"data":3288,"marks":3289,"value":3290,"nodeType":864},{},[]," identified ",{"data":3292,"marks":3293,"value":3295,"nodeType":864},{},[3294],{"type":899},"793 threat actors using AI",{"data":3297,"marks":3298,"value":3299,"nodeType":864},{},[]," for malicious cybersecurity purposes between March 2025 and February 2026, with the 2026 Verizon DBIR finding that ",{"data":3301,"marks":3302,"value":3304,"nodeType":864},{},[3303],{"type":899},"44% of AI-assisted initial access was phishing-related",{"data":3306,"marks":3307,"value":2924,"nodeType":864},{},[],{"data":3309,"content":3310,"nodeType":860},{},[3311],{"data":3312,"marks":3313,"value":3314,"nodeType":864},{},[],"Attackers are already vibecoding phishing kits, rotating infrastructure daily, and exploiting identity flows that traditional endpoint and network tools can't see.",{"data":3316,"content":3317,"nodeType":860},{},[3318],{"data":3319,"marks":3320,"value":3321,"nodeType":864},{},[],"The SANS model makes the speed argument a central focus at Stage 4: Detection built for human-pace adversaries is increasingly insufficient when threats operate at machine speed. For organizations investing exclusively in AI governance, AI-enabled threats represent an entire category of risk that is not being addressed.",{"data":3323,"content":3324,"nodeType":1005},{},[],{"data":3326,"content":3327,"nodeType":1312},{},[3328],{"data":3329,"marks":3330,"value":3332,"nodeType":864},{},[3331],{"type":899},"Why governance alone can't close the gap",{"data":3334,"content":3335,"nodeType":860},{},[3336,3340,3345],{"data":3337,"marks":3338,"value":3339,"nodeType":864},{},[],"An organization can have an AI policy, shadow AI discovery, data classification, and usage controls, and ",{"data":3341,"marks":3342,"value":3344,"nodeType":864},{},[3343],{"type":2246},"still",{"data":3346,"marks":3347,"value":3348,"nodeType":864},{},[]," be exposed. When an employee hits a device code phishing page or a ClickFix lure, the governance program documented the risk perfectly. It just couldn't stop the attack. The policy existed but the detection (and ideally, mitigation) didn't.",{"data":3350,"content":3351,"nodeType":860},{},[3352],{"data":3353,"marks":3354,"value":3355,"nodeType":864},{},[],"The reverse is equally true, and it's why the SANS model treats the pillars as interdependent rather than sequential. Detection capabilities that fire into a void with no policy to act on findings, no classification to assess exposure, and no governance body to shape proactive policy just create alerts, not security. ",{"data":3357,"content":3358,"nodeType":860},{},[3359],{"data":3360,"marks":3361,"value":3362,"nodeType":864},{},[],"Yet most organizations are only investing heavily in one side of the solution, which is almost always Govern. The maturity model is explicit about the risks of this approach: Governance with no attack detection leaves a critical gap. ",{"data":3364,"content":3365,"nodeType":860},{},[3366],{"data":3367,"marks":3368,"value":3370,"nodeType":864},{},[3369],{"type":899},"Closing the gap requires a control point where both problems are visible and addressable.",{"data":3372,"content":3373,"nodeType":1005},{},[],{"data":3375,"content":3376,"nodeType":1009},{},[3377],{"data":3378,"marks":3379,"value":3381,"nodeType":864},{},[3380],{"type":899},"Crossing the chasm requires addressing both pillars at once",{"data":3383,"content":3384,"nodeType":860},{},[3385,3389,3396],{"data":3386,"marks":3387,"value":3388,"nodeType":864},{},[],"The bottleneck for most security programs ",{"data":3390,"content":3391,"nodeType":883},{"uri":3210},[3392],{"data":3393,"marks":3394,"value":3395,"nodeType":864},{},[],"isn't frameworks or strategy — it's data quality",{"data":3397,"marks":3398,"value":3399,"nodeType":864},{},[],". For teams taking on the dual problems of shadow AI and AI-enabled attacks, browser telemetry is the foundation to any meaningful solution. That’s because both problems converge in the same place.",{"data":3401,"content":3402,"nodeType":860},{},[3403],{"data":3404,"marks":3405,"value":3406,"nodeType":864},{},[],"AI-enabled phishing attacks, credential theft, malicious browser extensions, and OAuth exploitation happen in the browser. So do shadow AI adoption, sensitive data pasted into AI prompts, file uploads to unapproved tools, and unauthorized integrations. The browser is where external attacks and internal misuse are both visible and stoppable.",{"data":3408,"content":3409,"nodeType":860},{},[3410],{"data":3411,"marks":3412,"value":3413,"nodeType":864},{},[],"For the security team trying to advance past the Framework of No, browser telemetry replaces the blunt instrument of network-level blocking with actual visibility:",{"data":3415,"content":3416,"nodeType":941},{},[3417,3427,3437],{"data":3418,"content":3419,"nodeType":945},{},[3420],{"data":3421,"content":3422,"nodeType":860},{},[3423],{"data":3424,"marks":3425,"value":3426,"nodeType":864},{},[],"which AI apps are in use (including personal account usage)",{"data":3428,"content":3429,"nodeType":945},{},[3430],{"data":3431,"content":3432,"nodeType":860},{},[3433],{"data":3434,"marks":3435,"value":3436,"nodeType":864},{},[],"what data is moving into them (file uploads, clipboard activity)",{"data":3438,"content":3439,"nodeType":945},{},[3440],{"data":3441,"content":3442,"nodeType":860},{},[3443],{"data":3444,"marks":3445,"value":3446,"nodeType":864},{},[],"graduated controls - per-app, per-user group, per-content pattern - that can monitor, warn, or block based on context rather than allow/deny",{"data":3448,"content":3449,"nodeType":860},{},[3450],{"data":3451,"marks":3452,"value":3453,"nodeType":864},{},[],"The same browser-layer instrumentation can also provide real-time detection of credential phishing, ClickFix, adversary-in-the-middle attacks, and device code phishing. And it can detect and disable malicious browser extensions based on confirmed threat intelligence, monitor OAuth integrations, and generate the identity attack surface data (login behaviors, MFA gaps, SSO coverage) that the Protect pillar requires at Stage 3 maturity and beyond.",{"data":3455,"content":3456,"nodeType":860},{},[3457],{"data":3458,"marks":3459,"value":3460,"nodeType":864},{},[],"We built Push around this insight: that the browser is where both problems converge, and a single deployment can advance AI security maturity in both areas simultaneously. The SANS model makes the same argument.",{"data":3462,"content":3463,"nodeType":1005},{},[],{"data":3465,"content":3466,"nodeType":1009},{},[3467],{"data":3468,"marks":3469,"value":3471,"nodeType":864},{},[3470],{"type":899},"Where to start: 5 steps to maturity with Push",{"data":3473,"content":3474,"nodeType":860},{},[3475],{"data":3476,"marks":3477,"value":3478,"nodeType":864},{},[],"The chasm closes when organizations make meaningful strides forward in both AI governance and proactive defense against AI-enabled attacks. Here's the starting plan that I'd recommend, and Push can provide the tooling to automate these steps:",{"data":3480,"content":3481,"nodeType":860},{},[3482,3487],{"data":3483,"marks":3484,"value":3486,"nodeType":864},{},[3485],{"type":899},"1. Build an AI inventory automatically.",{"data":3488,"marks":3489,"value":3490,"nodeType":864},{},[]," Every stage transition in the SANS model starts with knowing what's in your environment. A manual survey won't cut it; employees won't self-report the tools they're not sure they're allowed to use, and may overlook apps where AI is a feature but not the core function (AI-enabled apps). Instead, organizations should deploy automated discovery for AI apps, browser extensions, and OAuth integrations across the workforce - including the ones using personal accounts. Until this inventory exists, every policy decision is based on incomplete information.",{"data":3492,"content":3496,"nodeType":996},{"target":3493},{"sys":3494},{"id":3495,"type":1001,"linkType":1002},"2t3u0NydllImv6NzvAY058",[],{"data":3498,"content":3499,"nodeType":860},{},[3500,3505],{"data":3501,"marks":3502,"value":3504,"nodeType":864},{},[3503],{"type":899},"2. Classify what you find.",{"data":3506,"marks":3507,"value":3508,"nodeType":864},{},[]," Not all AI usage carries the same risk. A developer pasting code into ChatGPT and a salesperson using an AI notetaker are different problems. Once you can see the tools, categorize them by data sensitivity, authorization status, and access scope. The SANS model calls out data classification as a critical prerequisite; you can't write an effective AI policy without knowing where sensitive data lives.",{"data":3510,"content":3511,"nodeType":860},{},[3512,3517],{"data":3513,"marks":3514,"value":3516,"nodeType":864},{},[3515],{"type":899},"3. Turn on browser-layer detection.",{"data":3518,"marks":3519,"value":3520,"nodeType":864},{},[]," This is the step most organizations skip, and it's why addressing only the Protect pillar will keep you at Stage 1. AI-enabled phishing, ClickFix attacks, device code phishing, malicious extension updates, and OAuth exploitation all execute in the browser. Without detection in that layer, there's no visibility into the fastest-growing attack category, and no path to advancing beyond basic AI usage awareness.",{"data":3522,"content":3526,"nodeType":996},{"target":3523},{"sys":3524},{"id":3525,"type":1001,"linkType":1002},"1fzuGjA6VSbVl1p7vM1mt7",[],{"data":3528,"content":3529,"nodeType":860},{},[3530,3535],{"data":3531,"marks":3532,"value":3534,"nodeType":864},{},[3533],{"type":899},"4. Move from blocking to graduated controls.",{"data":3536,"marks":3537,"value":3538,"nodeType":864},{},[]," The Framework of No fails because it's binary: allow or deny, with nothing in between. Organizations that cross the chasm adopt monitor, warn, and block modes — per app, per user group, per content pattern. Monitor first to see what's happening, warn to change behavior without disrupting workflows, and block only where the risk justifies it. This is the operational difference between Stage 2 and Stage 3.",{"data":3540,"content":3541,"nodeType":860},{},[3542,3547,3551,3557],{"data":3543,"marks":3544,"value":3546,"nodeType":864},{},[3545],{"type":899},"5. Assess yourself honestly against evidence, not aspiration.",{"data":3548,"marks":3549,"value":3550,"nodeType":864},{},[]," The ",{"data":3552,"content":3553,"nodeType":883},{"uri":2852},[3554],{"data":3555,"marks":3556,"value":1108,"nodeType":864},{},[],{"data":3558,"marks":3559,"value":3560,"nodeType":864},{},[]," includes a self-assessment and industry-specific weighting profiles. The value isn't in the score, but in identifying which pillar is keeping you from advancing.",{"data":3562,"content":3563,"nodeType":860},{},[3564],{"data":3565,"marks":3566,"value":3567,"nodeType":864},{},[],"The organizations that cross the AI security chasm will be the ones that recognize early that AI security isn't one problem with one solution. It's two problems that happen to share a control point. The most efficient path forward is a platform that addresses both.",{"data":3569,"content":3570,"nodeType":1005},{},[],{"data":3572,"content":3573,"nodeType":1009},{},[3574],{"data":3575,"marks":3576,"value":3578,"nodeType":864},{},[3577],{"type":899},"Learn more about Push",{"data":3580,"content":3581,"nodeType":860},{},[3582],{"data":3583,"marks":3584,"value":3585,"nodeType":864},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser - high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":3587,"content":3588,"nodeType":860},{},[3589],{"data":3590,"marks":3591,"value":1689,"nodeType":864},{},[],{"data":3593,"content":3594,"nodeType":860},{},[3595,3598,3605],{"data":3596,"marks":3597,"value":2707,"nodeType":864},{},[],{"data":3599,"content":3600,"nodeType":883},{"uri":1700},[3601],{"data":3602,"marks":3603,"value":2715,"nodeType":864},{},[3604],{"type":1455},{"data":3606,"marks":3607,"value":2719,"nodeType":864},{},[],"Crossing the AI security chasm with the SANS AI security maturity model","Most organizations know they have an AI security problem. A new SANS framework shows why so few are making progress - and what it actually takes to get unstuck.","2026-06-24T00:00:00.000Z","crossing-the-ai-security-chasm-sans-security-maturity-model",{"items":3613},[3614,3616],{"sys":3615,"name":297},{"id":2732},{"sys":3617,"name":2729},{"id":2728},{"items":3619},[3620],{"fullName":3621,"firstName":3622,"jobTitle":3623,"profilePicture":3624},"Mark Orlando","Mark","Field CTO",{"url":3625},"https://images.ctfassets.net/y1cdw1ablpvd/592PMwIQQFaa24k5SKBEKF/a33090d0ad95d1e3081f5d16a46ba826/image__68_.png",{"__typename":2059,"sys":3627,"content":3629,"title":4865,"synopsis":4866,"hashTags":59,"publishedDate":4867,"slug":4868,"tagsCollection":4869,"authorsCollection":4875},{"id":3628},"6MoHWfQlVildcFYKSbfMcE",{"json":3630},{"data":3631,"content":3632,"nodeType":856},{},[3633,3649,3655,3662,3669,3675,3678,3686,3694,3713,3761,3767,3782,3785,3793,3800,3828,3869,3876,3879,3887,3895,3902,3908,3915,3918,3926,3933,3975,4011,4018,4021,4029,4036,4061,4068,4113,4120,4123,4131,4139,4184,4191,4197,4200,4208,4216,4248,4255,4261,4268,4271,4279,4287,4316,4323,4330,4337,4340,4348,4356,4363,4369,4376,4399,4428,4431,4439,4447,4454,4461,4464,4472,4534,4537,4545,4552,4846,4849],{"data":3634,"content":3635,"nodeType":860},{},[3636,3640,3645],{"data":3637,"marks":3638,"value":3639,"nodeType":864},{},[],"Browser security solutions are one of the most significant additions to the enterprise security stack in recent years — and the data shows it. The browser is where ",{"data":3641,"marks":3642,"value":3644,"nodeType":864},{},[3643],{"type":899},"85% of work now happens",{"data":3646,"marks":3647,"value":3648,"nodeType":864},{},[],", where AI tools are accessed, and where attackers increasingly choose to strike.",{"data":3650,"content":3654,"nodeType":996},{"target":3651},{"sys":3652},{"id":3653,"type":1001,"linkType":1002},"5P6PyFbn4EakRNlIWtNzyL",[],{"data":3656,"content":3657,"nodeType":860},{},[3658],{"data":3659,"marks":3660,"value":3661,"nodeType":864},{},[],"But browser security is a nascent category. Getting a clear picture of which solution is right for your team, and how to get the most out of it, isn't straightforward. Current solutions on the market serve a wide range of IT and security use cases, with varying degrees of depth and differentiation across them. Not all use cases are equal in terms of their security value, and not all of them are best addressed in the browser.",{"data":3663,"content":3664,"nodeType":860},{},[3665],{"data":3666,"marks":3667,"value":3668,"nodeType":864},{},[],"This article ranks the security problems that browser security solutions can address by the value they deliver: a combination of the risk reduction on offer, and the degree to which the browser is genuinely the best (or only) layer to solve the problem. ",{"data":3670,"content":3674,"nodeType":996},{"target":3671},{"sys":3672},{"id":3673,"type":1001,"linkType":1002},"6SJPvEHizSYk29lEvVVNj",[],{"data":3676,"content":3677,"nodeType":1005},{},[],{"data":3679,"content":3680,"nodeType":1009},{},[3681],{"data":3682,"marks":3683,"value":3685,"nodeType":864},{},[3684],{"type":899},"#1 — Account takeover prevention: detecting credential attacks across all vectors",{"data":3687,"content":3688,"nodeType":860},{},[3689],{"data":3690,"marks":3691,"value":3693,"nodeType":864},{},[3692],{"type":899},"Security value: Very high | Browser fit: Uniquely suited",{"data":3695,"content":3696,"nodeType":860},{},[3697,3701,3709],{"data":3698,"marks":3699,"value":3700,"nodeType":864},{},[],"Account takeover (ATO) is the dominant entry point for enterprise breaches: ",{"data":3702,"content":3704,"nodeType":883},{"uri":3703},"https://www.crowdstrike.com/en-gb/resources/infographics/identity-security-risk-review/",[3705],{"data":3706,"marks":3707,"value":3708,"nodeType":864},{},[],"80% of all modern breaches involve compromised or stolen identities",{"data":3710,"marks":3711,"value":3712,"nodeType":864},{},[],". The attack surface is far wider than most identity tooling can see: credential stuffing, password spraying, ghost logins (password-based fallback authentication that persists after SSO is configured), weak or reused credentials on shadow SaaS apps, and accounts where MFA was never enforced.",{"data":3714,"content":3715,"nodeType":860},{},[3716,3720,3728,3732,3737,3740,3745,3749,3757],{"data":3717,"marks":3718,"value":3719,"nodeType":864},{},[],"According to ",{"data":3721,"content":3723,"nodeType":883},{"uri":3722},"https://cf-assets.www.cloudflare.com/slt3lc6tev37/sWDBUMNVtEJB9ZFLt1dUU/8d69e92de2edfb3bf59e7d21d57e7e1a/Cloudflare-2026-threat-report.pdf",[3724],{"data":3725,"marks":3726,"value":3727,"nodeType":864},{},[],"Cloudflare's 2026 Threat Report",{"data":3729,"marks":3730,"value":3731,"nodeType":864},{},[],", ",{"data":3733,"marks":3734,"value":3736,"nodeType":864},{},[3735],{"type":899},"63% of all human logins involve credentials already compromised elsewhere",{"data":3738,"marks":3739,"value":2232,"nodeType":864},{},[],{"data":3741,"marks":3742,"value":3744,"nodeType":864},{},[3743],{"type":899},"94% of all login attempts originate from bots",{"data":3746,"marks":3747,"value":3748,"nodeType":864},{},[],". The ",{"data":3750,"content":3752,"nodeType":883},{"uri":3751},"https://pushsecurity.com/blog/snowflake-retro/",[3753],{"data":3754,"marks":3755,"value":3756,"nodeType":864},{},[],"Snowflake breach",{"data":3758,"marks":3759,"value":3760,"nodeType":864},{},[]," — 165+ organizations compromised, 1 billion+ records stolen — was powered almost entirely by ghost logins: accounts missing MFA that were susceptible to credential stuffing. It's particularly telling that 80% of the accounts impacted had prior breach exposure.",{"data":3762,"content":3766,"nodeType":996},{"target":3763},{"sys":3764},{"id":3765,"type":1001,"linkType":1002},"HbZ66kp5DiAZtwNGFJK7d",[],{"data":3768,"content":3769,"nodeType":860},{},[3770,3774,3779],{"data":3771,"marks":3772,"value":3773,"nodeType":864},{},[],"For organizations with contractors and BYOD users, the browser extension is also the only enterprise control deployable on devices that can't be MDM-enrolled — extending ATO detection to exactly the place where, per Verizon DBIR 2025, ",{"data":3775,"marks":3776,"value":3778,"nodeType":864},{},[3777],{"type":899},"46% of infostealer infections originate",{"data":3780,"marks":3781,"value":2924,"nodeType":864},{},[],{"data":3783,"content":3784,"nodeType":1005},{},[],{"data":3786,"content":3787,"nodeType":1009},{},[3788],{"data":3789,"marks":3790,"value":3792,"nodeType":864},{},[3791],{"type":899},"#2 — Detecting and stopping advanced phishing: AiTM, multi-channel delivery, and zero-day lures",{"data":3794,"content":3795,"nodeType":860},{},[3796],{"data":3797,"marks":3798,"value":3693,"nodeType":864},{},[3799],{"type":899},{"data":3801,"content":3802,"nodeType":860},{},[3803,3807,3815,3819,3824],{"data":3804,"marks":3805,"value":3806,"nodeType":864},{},[],"Adversary-in-the-Middle (AiTM) phishing — where an attacker's reverse proxy intercepts credentials and session tokens in real time — has become the standard technique for bypassing MFA at scale. ",{"data":3808,"content":3810,"nodeType":883},{"uri":3809},"https://www.esentire.com/resources/library/2026-threat-report",[3811],{"data":3812,"marks":3813,"value":3814,"nodeType":864},{},[],"eSentire's 2026 Threat Report",{"data":3816,"marks":3817,"value":3818,"nodeType":864},{},[]," attributes ",{"data":3820,"marks":3821,"value":3823,"nodeType":864},{},[3822],{"type":899},"63% of account compromise incidents to PhaaS kits",{"data":3825,"marks":3826,"value":3827,"nodeType":864},{},[],", with account compromise surging 389% year-over-year.",{"data":3829,"content":3830,"nodeType":860},{},[3831,3835,3843,3847,3852,3856,3865],{"data":3832,"marks":3833,"value":3834,"nodeType":864},{},[],"Traditional phishing controls are also no longer in the right place to intercept these attacks. The delivery channel has shifted decisively away from email: ",{"data":3836,"content":3838,"nodeType":883},{"uri":3837},"https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026",[3839],{"data":3840,"marks":3841,"value":3842,"nodeType":864},{},[],"Mandiant M-Trends 2026",{"data":3844,"marks":3845,"value":3846,"nodeType":864},{},[]," found email phishing dropped from 14% to 6% as an infection vector, and Push data shows ",{"data":3848,"marks":3849,"value":3851,"nodeType":864},{},[3850],{"type":899},"roughly 1 in 3 phishing payloads intercepted were delivered outside email entirely",{"data":3853,"marks":3854,"value":3855,"nodeType":864},{},[]," — via search engine malvertising, social platforms, and compromised websites. Meanwhile, ",{"data":3857,"content":3859,"nodeType":883},{"uri":3858},"https://www.spamhaus.com/resource-center/supporting-researchers-with-passive-dns/",[3860],{"data":3861,"marks":3862,"value":3864,"nodeType":864},{},[3863],{"type":899},"89% of phishing domains are active for less than two days",{"data":3866,"marks":3867,"value":3868,"nodeType":864},{},[],", making blocklist-based detection structurally too slow — attackers can spin up, tear down, and move on before blocklists can catch up.",{"data":3870,"content":3871,"nodeType":860},{},[3872],{"data":3873,"marks":3874,"value":3875,"nodeType":864},{},[],"Modern phishing plays out entirely inside the browser session. The only detection layer that can see the phishing page structure, the credential entry, and the anomalous token context is the browser itself. Browser-native detection analyses page behavior rather than matching known-bad domains, which means it fires on zero-day kits regardless of how recently the infrastructure was stood up. Controls like credential entry guardrails add an additional layer — blocking corporate passwords from being submitted to unauthorized domains independently of content and behavior-based detections.",{"data":3877,"content":3878,"nodeType":1005},{},[],{"data":3880,"content":3881,"nodeType":1009},{},[3882],{"data":3883,"marks":3884,"value":3886,"nodeType":864},{},[3885],{"type":899},"#3 — Identity posture hardening: enforcing security across the apps your IdP doesn't manage",{"data":3888,"content":3889,"nodeType":860},{},[3890],{"data":3891,"marks":3892,"value":3894,"nodeType":864},{},[3893],{"type":899},"Security value: High | Browser fit: Uniquely suited",{"data":3896,"content":3897,"nodeType":860},{},[3898],{"data":3899,"marks":3900,"value":3901,"nodeType":864},{},[],"The first challenge is knowing what you're protecting. Every identity an employee creates — every app they sign up to, every password they set, every login that bypasses SSO — is an authentication event that happens inside a browser session. The browser is the only layer that observes all of these events regardless of whether the app is sanctioned, managed, or even known to IT. Solutions that rely on API-level integrations with known apps, network traffic inspection, or email sign-up notifications can only ever build a partial picture, because they can only see apps they already know about. The browser sees the login itself, which means it discovers the identity at the moment it's created or used — authentication method, password strength, MFA status, and all.",{"data":3903,"content":3907,"nodeType":996},{"target":3904},{"sys":3905},{"id":3906,"type":1001,"linkType":1002},"HETvBCPsKGkqLVtaasXH0",[],{"data":3909,"content":3910,"nodeType":860},{},[3911],{"data":3912,"marks":3913,"value":3914,"nodeType":864},{},[],"But discovery without enforcement is just an inventory problem. Being in the browser means that you're in a great position to act on what it finds at the moment of authentication. Browser-native guardrails that prompt MFA enrollment, guide users toward stronger credentials, and redirect to SSO login paths close the gap at scale, on every app, including those the IdP has never seen. They also produce the continuous, auditable evidence of MFA coverage and credential hygiene across the full application estate that regulators, insurers, and auditors increasingly require — evidence that no IdP-centric tool can provide for apps outside its scope.",{"data":3916,"content":3917,"nodeType":1005},{},[],{"data":3919,"content":3920,"nodeType":1009},{},[3921],{"data":3922,"marks":3923,"value":3925,"nodeType":864},{},[3924],{"type":899},"#4 — Browser extension security",{"data":3927,"content":3928,"nodeType":860},{},[3929],{"data":3930,"marks":3931,"value":3894,"nodeType":864},{},[3932],{"type":899},{"data":3934,"content":3935,"nodeType":860},{},[3936,3940,3949,3952,3960,3963,3971],{"data":3937,"marks":3938,"value":3939,"nodeType":864},{},[],"Browser extensions have become one of the most talked-about attack surfaces in security over the past 18 months, and understandably so — a string of high-profile supply chain compromises have collectively impacted tens of millions of users since late 2024 (",{"data":3941,"content":3943,"nodeType":883},{"uri":3942},"https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it",[3944],{"data":3945,"marks":3946,"value":3948,"nodeType":864},{},[3947],{"type":1455},"Cyberhaven",{"data":3950,"marks":3951,"value":3731,"nodeType":864},{},[],{"data":3953,"content":3955,"nodeType":883},{"uri":3954},"https://thehackernews.com/2025/12/darkspectre-browser-extension-campaigns.html",[3956],{"data":3957,"marks":3958,"value":3959,"nodeType":864},{},[],"DarkSpectre",{"data":3961,"marks":3962,"value":3731,"nodeType":864},{},[],{"data":3964,"content":3966,"nodeType":883},{"uri":3965},"https://thehackernews.com/2025/12/trust-wallet-chrome-extension-hack.html",[3967],{"data":3968,"marks":3969,"value":3970,"nodeType":864},{},[],"Trust Wallet",{"data":3972,"marks":3973,"value":3974,"nodeType":864},{},[],", among many others).",{"data":3976,"content":3977,"nodeType":860},{},[3978,3981,3989,3993,3998,4002,4007],{"data":3979,"marks":3980,"value":21,"nodeType":864},{},[],{"data":3982,"content":3983,"nodeType":883},{"uri":2411},[3984],{"data":3985,"marks":3986,"value":3988,"nodeType":864},{},[3987],{"type":1455},"Analysis of 20,000+ extensions across Push customers",{"data":3990,"marks":3991,"value":3992,"nodeType":864},{},[]," found ",{"data":3994,"marks":3995,"value":3997,"nodeType":864},{},[3996],{"type":899},"46.76% have the permission combinations needed to perform account takeover with no user interaction",{"data":3999,"marks":4000,"value":4001,"nodeType":864},{},[],", making permissions-based risk scoring effectively useless as a triage tool. The real threat model is not malicious extensions at install time — it's legitimate extensions that ",{"data":4003,"marks":4004,"value":4006,"nodeType":864},{},[4005],{"type":2246},"become",{"data":4008,"marks":4009,"value":4010,"nodeType":864},{},[]," malicious after an ownership transfer, developer account compromise, or silent update push. Every major extension supply chain breach of the past 18 months scored as low-risk immediately before compromise.",{"data":4012,"content":4013,"nodeType":860},{},[4014],{"data":4015,"marks":4016,"value":4017,"nodeType":864},{},[],"SWGs and network tools are structurally blind to this attack surface: a malicious extension exfiltrating session tokens generates no anomalous network signal — its traffic is indistinguishable from normal browsing. Endpoint agents have no visibility into extension behavior at the session level. Extension inventory, supply chain change monitoring — ownership transfers, permission escalations, developer contact changes — and enforcement all require browser-layer access by definition.",{"data":4019,"content":4020,"nodeType":1005},{},[],{"data":4022,"content":4023,"nodeType":1009},{},[4024],{"data":4025,"marks":4026,"value":4028,"nodeType":864},{},[4027],{"type":899},"#5 — Shadow SaaS discovery and OAuth integration governance",{"data":4030,"content":4031,"nodeType":860},{},[4032],{"data":4033,"marks":4034,"value":3894,"nodeType":864},{},[4035],{"type":899},{"data":4037,"content":4038,"nodeType":860},{},[4039,4043,4048,4052,4057],{"data":4040,"marks":4041,"value":4042,"nodeType":864},{},[],"Shadow SaaS discovery shares DNA with identity posture hardening (#3) — both start with the same browser-native visibility into login events that no other layer can replicate. Where identity posture focuses on hardening ",{"data":4044,"marks":4045,"value":4047,"nodeType":864},{},[4046],{"type":2246},"how",{"data":4049,"marks":4050,"value":4051,"nodeType":864},{},[]," employees authenticate, shadow SaaS discovery focuses on ",{"data":4053,"marks":4054,"value":4056,"nodeType":864},{},[4055],{"type":2246},"what",{"data":4058,"marks":4059,"value":4060,"nodeType":864},{},[]," they authenticate to: surfacing the full estate of applications in use across the organization, including those that IT has never sanctioned or even heard of.",{"data":4062,"content":4063,"nodeType":860},{},[4064],{"data":4065,"marks":4066,"value":4067,"nodeType":864},{},[],"OAuth integration governance is the component of shadow SaaS that is both the most potentially damaging and the hardest to surface through other means. The SaaS-to-SaaS OAuth pivot is now an industrialized attack pattern.",{"data":4069,"content":4070,"nodeType":941},{},[4071,4092],{"data":4072,"content":4073,"nodeType":945},{},[4074],{"data":4075,"content":4076,"nodeType":860},{},[4077,4080,4088],{"data":4078,"marks":4079,"value":2761,"nodeType":864},{},[],{"data":4081,"content":4083,"nodeType":883},{"uri":4082},"https://pushsecurity.com/blog/analyzing-the-instructure-breach/",[4084],{"data":4085,"marks":4086,"value":4087,"nodeType":864},{},[],"ShinyHunters",{"data":4089,"marks":4090,"value":4091,"nodeType":864},{},[]," Salesforce campaign — which compromised 1,000+ organizations and 1.5 billion records — demonstrated the full chain: the attacker didn't stop at stealing customer data but harvested OAuth tokens, AWS access keys, and Snowflake tokens from breached tenants and pivoted through connected services like Salesloft, Drift, and Gainsight to reach hundreds more organizations.",{"data":4093,"content":4094,"nodeType":945},{},[4095],{"data":4096,"content":4097,"nodeType":860},{},[4098,4101,4109],{"data":4099,"marks":4100,"value":2761,"nodeType":864},{},[],{"data":4102,"content":4104,"nodeType":883},{"uri":4103},"https://pushsecurity.com/blog/unpacking-the-vercel-breach/",[4105],{"data":4106,"marks":4107,"value":4108,"nodeType":864},{},[],"Context.ai → Vercel",{"data":4110,"marks":4111,"value":4112,"nodeType":864},{},[]," chain followed the same logic — stored OAuth tokens from a forgotten AI app trial provided the bridge into Google Workspace, internal dashboards, and API keys. These are not isolated incidents; they are the repeatable playbook for extracting maximum value from a single compromise through the trust relationships that OAuth connections encode.",{"data":4114,"content":4115,"nodeType":860},{},[4116],{"data":4117,"marks":4118,"value":4119,"nodeType":864},{},[],"Every OAuth consent grant transits the browser — the authorization prompt, the scope disclosure, the user's approval click, and the redirect that completes the grant all happen inside a browser session — which makes the browser the only layer where an unwanted grant can be intercepted before the token is issued and the persistent access path is created. Once a token exists, the damage is done: it survives password resets, MFA changes, and session revocations, and revoking it after the fact requires first knowing it was granted, which most organizations do not.",{"data":4121,"content":4122,"nodeType":1005},{},[],{"data":4124,"content":4125,"nodeType":1009},{},[4126],{"data":4127,"marks":4128,"value":4130,"nodeType":864},{},[4129],{"type":899},"#6 — Blocking ClickFix and social engineering-based malware delivery",{"data":4132,"content":4133,"nodeType":860},{},[4134],{"data":4135,"marks":4136,"value":4138,"nodeType":864},{},[4137],{"type":899},"Security value: High | Browser fit: Strong for interception — shared with endpoint security for execution. ConsentFix is a browser-native exception that is T1-aligned.",{"data":4140,"content":4141,"nodeType":860},{},[4142,4146,4151,4155,4162,4166,4171,4175,4180],{"data":4143,"marks":4144,"value":4145,"nodeType":864},{},[],"ClickFix was the most common initial access vector reported by Microsoft in 2025, accounting for ",{"data":4147,"marks":4148,"value":4150,"nodeType":864},{},[4149],{"type":899},"47% of observed attacks",{"data":4152,"marks":4153,"value":4154,"nodeType":864},{},[],". CrowdStrike's ",{"data":4156,"content":4157,"nodeType":883},{"uri":3237},[4158],{"data":4159,"marks":4160,"value":4161,"nodeType":864},{},[],"2026 Global Threat Report",{"data":4163,"marks":4164,"value":4165,"nodeType":864},{},[]," identified fake CAPTCHA lures as the most common malware download type, increasing ",{"data":4167,"marks":4168,"value":4170,"nodeType":864},{},[4169],{"type":899},"563% year-over-year",{"data":4172,"marks":4173,"value":4174,"nodeType":864},{},[],". The technique writes a malicious command to the victim's clipboard and social-engineers them into executing it. It is fileless (bypassing download scanning), user-executed (bypassing endpoint behavioral detections), and ",{"data":4176,"marks":4177,"value":4179,"nodeType":864},{},[4178],{"type":899},"4 in 5 ClickFix payloads intercepted by Push arrived via search engines",{"data":4181,"marks":4182,"value":4183,"nodeType":864},{},[]," — not email (bypassing email anti-phishing controls).",{"data":4185,"content":4186,"nodeType":860},{},[4187],{"data":4188,"marks":4189,"value":4190,"nodeType":864},{},[],"The browser is the earliest and most effective intervention point — detecting the clipboard injection and social engineering lure before anything reaches the endpoint in executable form. But the problem doesn't end at the browser boundary: once the command has been pasted and run, detection and remediation become endpoint problems, and a mature defense requires both layers. The broader *Fix family — FileFix, InstallFix, and similar derivatives — follows the same pattern, with the browser providing the critical early-warning layer within a defense that spans browser and endpoint.",{"data":4192,"content":4196,"nodeType":996},{"target":4193},{"sys":4194},{"id":4195,"type":1001,"linkType":1002},"39alMHtw9FPHbQINqbAgBN",[],{"data":4198,"content":4199,"nodeType":1005},{},[],{"data":4201,"content":4202,"nodeType":1009},{},[4203],{"data":4204,"marks":4205,"value":4207,"nodeType":864},{},[4206],{"type":899},"#7 — AI visibility and control: enforcing which AI tools employees can use and how",{"data":4209,"content":4210,"nodeType":860},{},[4211],{"data":4212,"marks":4213,"value":4215,"nodeType":864},{},[4214],{"type":899},"Security value: High | Browser fit: Strong for access enforcement — but AI governance is not a new security problem so much as a force multiplier on existing ones",{"data":4217,"content":4218,"nodeType":860},{},[4219,4223,4231,4235,4244],{"data":4220,"marks":4221,"value":4222,"nodeType":864},{},[],"AI adoption is outpacing security governance at nearly every organization, and ",{"data":4224,"content":4225,"nodeType":883},{"uri":2561},[4226],{"data":4227,"marks":4228,"value":4230,"nodeType":864},{},[4229],{"type":899},"71% of organizations are concerned about data leakage via unsanctioned AI apps",{"data":4232,"marks":4233,"value":4234,"nodeType":864},{},[],". But the security problems that AI creates are not, for the most part, novel — they are existing Tier 1 problems amplified by a new category of tooling. Shadow AI apps are shadow SaaS (#5). AI OAuth integrations are OAuth governance (#5). AI browser extensions are extension security (#4). The risk of employees using personal AI accounts — ",{"data":4236,"content":4238,"nodeType":883},{"uri":4237},"https://keepaware.com/blog/46-of-sensitive-data-bypasses-your-dlp",[4239],{"data":4240,"marks":4241,"value":4243,"nodeType":864},{},[4242],{"type":899},"46% of sensitive inputs to AI tools are sent via personal accounts",{"data":4245,"marks":4246,"value":4247,"nodeType":864},{},[]," — is an identity posture problem (#3).",{"data":4249,"content":4250,"nodeType":860},{},[4251],{"data":4252,"marks":4253,"value":4254,"nodeType":864},{},[],"The component parts that allow you to govern AI are individually Tier 1 capabilities, and the browser is the best single layer for gaining visibility and control over AI usage — it sees the apps, the OAuth grants, the extensions, and the account context. But a complete end-to-end solution also requires a presence on the endpoint layer (for local AI tools, IDE-integrated agents, and API-level usage that never touches the browser), and prompt-level DLP on sanctioned tools is better handled by platform-native controls than by browser-layer observation.",{"data":4256,"content":4260,"nodeType":996},{"target":4257},{"sys":4258},{"id":4259,"type":1001,"linkType":1002},"6Py3z9VgjhKrchmYvhmbsq",[],{"data":4262,"content":4263,"nodeType":860},{},[4264],{"data":4265,"marks":4266,"value":4267,"nodeType":864},{},[],"The browser is what makes platform controls effective — if employees are using personal accounts, there are no enterprise audit logs to inspect. And for the growing category of AI agents, agentic browsers, and MCP-connected tools that operate through OAuth grants rather than direct user interaction, the browser is where the consent decisions that authorize those agents are made.",{"data":4269,"content":4270,"nodeType":1005},{},[],{"data":4272,"content":4273,"nodeType":1009},{},[4274],{"data":4275,"marks":4276,"value":4278,"nodeType":864},{},[4277],{"type":899},"#8 — Investigation acceleration and incident response: closing the missing middle",{"data":4280,"content":4281,"nodeType":860},{},[4282],{"data":4283,"marks":4284,"value":4286,"nodeType":864},{},[4285],{"type":899},"Security value: High | Browser fit: Strong — fills a structural gap complementary to endpoint, network, and identity telemetry",{"data":4288,"content":4289,"nodeType":860},{},[4290,4294,4299,4303,4312],{"data":4291,"marks":4292,"value":4293,"nodeType":864},{},[],"Endpoint logs show what processes executed. Network logs show traffic destinations. IdP logs show authentication events. None of them show what happened ",{"data":4295,"marks":4296,"value":4298,"nodeType":864},{},[4297],{"type":2246},"inside the browser session",{"data":4300,"marks":4301,"value":4302,"nodeType":864},{},[]," — the phishing page the user saw, the credentials they entered, the malicious OAuth consent grant, the data uploaded or pasted to an unsanctioned service. This is the missing middle of modern incident investigations, and for the ",{"data":4304,"content":4306,"nodeType":883},{"uri":4305},"https://www.paloaltonetworks.co.uk/resources/research/unit-42-incident-response-report",[4307],{"data":4308,"marks":4309,"value":4311,"nodeType":864},{},[4310],{"type":899},"48% of intrusions involving browser-based activity",{"data":4313,"marks":4314,"value":4315,"nodeType":864},{},[],", the absence of browser telemetry is a significant investigative gap.",{"data":4317,"content":4318,"nodeType":860},{},[4319],{"data":4320,"marks":4321,"value":4322,"nodeType":864},{},[],"Browser-layer telemetry fills that gap with a fundamentally different quality of signal: what users actually clicked, what pages loaded and how they behaved, what credentials were entered, what session activity followed — structured, high-fidelity data from inside the session where the attack played out. That's the difference between inferring what happened and seeing it directly, and it determines scope, drives containment decisions, and provides the direct evidential record that neither endpoint DLP nor network monitoring can supply for browser-native attacks.",{"data":4324,"content":4325,"nodeType":860},{},[4326],{"data":4327,"marks":4328,"value":4329,"nodeType":864},{},[],"Browser telemetry is a key addition to the investigative picture. Investigations are inherently multi-source — without browser data, reconstructing an incident from EDR, network, and IdP logs won't tell you the full picture (particularly when attacks are increasingly delivered outside of email, intercepting users as they browse the internet normally).",{"data":4331,"content":4332,"nodeType":860},{},[4333],{"data":4334,"marks":4335,"value":4336,"nodeType":864},{},[],"The browser provides the causal link that other sources miss: the bridge between \"a user visited a URL\" and \"credentials were submitted to a phishing page that issued a session token now being replayed from an attacker-controlled browser.\" Integrated with SIEM and SOAR platforms, that signal enables automated response workflows to execute on high-confidence detections without waiting for manual triage.",{"data":4338,"content":4339,"nodeType":1005},{},[],{"data":4341,"content":4342,"nodeType":1009},{},[4343],{"data":4344,"marks":4345,"value":4347,"nodeType":864},{},[4346],{"type":899},"#9 — Infostealer defense: detecting exposure and blocking delivery",{"data":4349,"content":4350,"nodeType":860},{},[4351],{"data":4352,"marks":4353,"value":4355,"nodeType":864},{},[4354],{"type":899},"Security value: High | Browser fit: Strong for delivery interception and stolen factor detection — complementary to endpoint security for execution",{"data":4357,"content":4358,"nodeType":860},{},[4359],{"data":4360,"marks":4361,"value":4362,"nodeType":864},{},[],"Infostealers are the upstream supply chain for a disproportionate share of the most damaging enterprise attacks — harvesting credentials, session cookies, and browser profile data en masse from infected devices, then selling the outputs on infostealer markets for use in credential stuffing, ATO, and ransomware campaigns.",{"data":4364,"content":4368,"nodeType":996},{"target":4365},{"sys":4366},{"id":4367,"type":1001,"linkType":1002},"5NF1afwu3zFGThZTtStVQA",[],{"data":4370,"content":4371,"nodeType":860},{},[4372],{"data":4373,"marks":4374,"value":4375,"nodeType":864},{},[],"The browser is relevant at two points in the infostealer kill chain. First, delivery interception: ClickFix (covered in #6) is now the primary infostealer delivery mechanism, and the browser is the only layer that can intercept it before execution. Second, detecting stolen factors when attackers attempt to use them — and infostealers produce two categories of stolen factor that the browser can guard against.",{"data":4377,"content":4378,"nodeType":941},{},[4379,4389],{"data":4380,"content":4381,"nodeType":945},{},[4382],{"data":4383,"content":4384,"nodeType":860},{},[4385],{"data":4386,"marks":4387,"value":4388,"nodeType":864},{},[],"Stolen credentials can be identified at the point of login: browser-layer detection flags credentials that appear in known breach datasets, catching infostealer-harvested passwords being replayed in credential stuffing campaigns before the account is compromised.",{"data":4390,"content":4391,"nodeType":945},{},[4392],{"data":4393,"content":4394,"nodeType":860},{},[4395],{"data":4396,"marks":4397,"value":4398,"nodeType":864},{},[],"Stolen session tokens are caught through a different mechanism: sessions originating in instrumented browsers carry a marker, and when a token subsequently appears in an un-instrumented browser it is a confirmed stolen session — catching infostealer-harvested cookies being replayed regardless of how or where the token was originally harvested.",{"data":4400,"content":4401,"nodeType":860},{},[4402,4406,4415,4419,4424],{"data":4403,"marks":4404,"value":4405,"nodeType":864},{},[],"This is particularly critical for the ",{"data":4407,"content":4409,"nodeType":883},{"uri":4408},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[4410],{"data":4411,"marks":4412,"value":4414,"nodeType":864},{},[4413],{"type":899},"46% of infected devices that are unmanaged",{"data":4416,"marks":4417,"value":4418,"nodeType":864},{},[]," where EDR is absent and the stolen credentials and session tokens will never be detected at the endpoint. Infostealer ",{"data":4420,"marks":4421,"value":4423,"nodeType":864},{},[4422],{"type":2246},"execution",{"data":4425,"marks":4426,"value":4427,"nodeType":864},{},[]," remains an endpoint problem; the browser closes the delivery and replay gaps that endpoint tools miss.",{"data":4429,"content":4430,"nodeType":1005},{},[],{"data":4432,"content":4433,"nodeType":1009},{},[4434],{"data":4435,"marks":4436,"value":4438,"nodeType":864},{},[4437],{"type":899},"#10 — Data loss prevention: a key component of effective DLP, but not the full picture",{"data":4440,"content":4441,"nodeType":860},{},[4442],{"data":4443,"marks":4444,"value":4446,"nodeType":864},{},[4445],{"type":899},"Security value: Medium-high | Browser fit: Partial — complementary to dedicated DLP",{"data":4448,"content":4449,"nodeType":860},{},[4450],{"data":4451,"marks":4452,"value":4453,"nodeType":864},{},[],"File uploads to unsanctioned services, sensitive data pasted into AI tools, and exfiltration through personal accounts are genuine and growing risks that traditional email and endpoint-centric DLP tools were not designed to catch. Browser-layer controls provide real value here — particularly for BYOD users and contractors, where endpoint DLP agents cannot be deployed and the browser is the only available data loss visibility.",{"data":4455,"content":4456,"nodeType":860},{},[4457],{"data":4458,"marks":4459,"value":4460,"nodeType":864},{},[],"The honest scope: browser-layer DLP does not cover email-based loss, endpoint-to-endpoint transfers, or cloud API exfiltration. It closes specific and important gaps within a broader DLP strategy, not a replacement for one. A further distinction for organizations evaluating browser DLP for secure third-party access: full-stack enterprise browsers can enforce deeper output controls — watermarking, obfuscation, screenshot and print restrictions — at the OS rendering level that browser extensions cannot reliably replicate. Extension-based browser DLP is strongest for upload, input, and access control use cases rather than OS-level output restriction.",{"data":4462,"content":4463,"nodeType":1005},{},[],{"data":4465,"content":4466,"nodeType":1009},{},[4467],{"data":4468,"marks":4469,"value":4471,"nodeType":864},{},[4470],{"type":899},"Tier 3 — Lower Value: A problem best addressed outside of the browser",{"data":4473,"content":4474,"nodeType":941},{},[4475,4490,4505,4520],{"data":4476,"content":4477,"nodeType":945},{},[4478],{"data":4479,"content":4480,"nodeType":860},{},[4481,4486],{"data":4482,"marks":4483,"value":4485,"nodeType":864},{},[4484],{"type":899},"Browser exploit protection",{"data":4487,"marks":4488,"value":4489,"nodeType":864},{},[]," (narrow RCE/sandbox sense) ranks lower because browser zero-days represent just 9% of all zero-days reported to Google, and 82% of attack detections are now malware-free (CrowdStrike 2026). This is a problem for browser vendors to solve, and it's not a big enough problem to warrant enterprises investing in additional mitigating controls.",{"data":4491,"content":4492,"nodeType":945},{},[4493],{"data":4494,"content":4495,"nodeType":860},{},[4496,4501],{"data":4497,"marks":4498,"value":4500,"nodeType":864},{},[4499],{"type":899},"Domain and URL category controls",{"data":4502,"marks":4503,"value":4504,"nodeType":864},{},[]," offer genuine browser-layer value but are commoditized by SWG and DNS filtering tools most organizations already operate. This can be provided in the browser, sure (and it's something we do at Push) but offers limited security value in terms of making a difference against modern attacks that quickly rotate these kinds of indicators and are designed to blend in.",{"data":4506,"content":4507,"nodeType":945},{},[4508],{"data":4509,"content":4510,"nodeType":860},{},[4511,4516],{"data":4512,"marks":4513,"value":4515,"nodeType":864},{},[4514],{"type":899},"Access management",{"data":4517,"marks":4518,"value":4519,"nodeType":864},{},[]," — ZTNA, VPN replacement, PAM, BYOD access control — is an IT infrastructure and access architecture problem, not a security operations problem, and belongs to a different buyer with a different evaluation frame. There are numerous (typically full-stack) Enterprise Browser solutions on the market that address IT use cases like this well.",{"data":4521,"content":4522,"nodeType":945},{},[4523],{"data":4524,"content":4525,"nodeType":860},{},[4526,4530],{"data":4527,"marks":4528,"value":781,"nodeType":864},{},[4529],{"type":899},{"data":4531,"marks":4532,"value":4533,"nodeType":864},{},[]," addresses browser exploit risk rather than the identity-first attacks that represent the majority of current enterprise browser risk, and introduces UX friction that limits deployment at scale. When it triggers, it introduces latency but still fails to detect and stop browser-native attacks.",{"data":4535,"content":4536,"nodeType":1005},{},[],{"data":4538,"content":4539,"nodeType":1009},{},[4540],{"data":4541,"marks":4542,"value":4544,"nodeType":864},{},[4543],{"type":899},"How Push Security maps to the highest-value security use cases",{"data":4546,"content":4547,"nodeType":860},{},[4548],{"data":4549,"marks":4550,"value":4551,"nodeType":864},{},[],"Push is purpose-built to address all of these problems using a flexible browser extension — plug into any browser with no migration, no host agent deployment, and no IT overhead — that delivers telemetry and control from day one, and extends coverage to every enrolled browser regardless of device ownership.",{"data":4553,"content":4554,"nodeType":4845},{},[4555,4582,4606,4630,4654,4678,4702,4726,4750,4774,4798,4822],{"data":4556,"content":4557,"nodeType":4581},{},[4558,4570],{"data":4559,"content":4560,"nodeType":4569},{},[4561],{"data":4562,"content":4563,"nodeType":860},{},[4564],{"data":4565,"marks":4566,"value":4568,"nodeType":864},{},[4567],{"type":899},"Security use case","table-cell",{"data":4571,"content":4572,"nodeType":4569},{},[4573],{"data":4574,"content":4575,"nodeType":860},{},[4576],{"data":4577,"marks":4578,"value":4580,"nodeType":864},{},[4579],{"type":899},"How Push addresses it","table-row",{"data":4583,"content":4584,"nodeType":4581},{},[4585,4596],{"data":4586,"content":4587,"nodeType":4569},{},[4588],{"data":4589,"content":4590,"nodeType":860},{},[4591],{"data":4592,"marks":4593,"value":4595,"nodeType":864},{},[4594],{"type":899},"Account takeover prevention",{"data":4597,"content":4598,"nodeType":4569},{},[4599],{"data":4600,"content":4601,"nodeType":860},{},[4602],{"data":4603,"marks":4604,"value":4605,"nodeType":864},{},[],"Surfaces and fixes ghost logins, weak and breached credentials and missing MFA controls across every app and device — including shadow SaaS and unmanaged devices invisible to the IdP. Push also detects and stops the attack techniques that typically lead to ATO early in the kill chain and before an account can be compromised.",{"data":4607,"content":4608,"nodeType":4581},{},[4609,4620],{"data":4610,"content":4611,"nodeType":4569},{},[4612],{"data":4613,"content":4614,"nodeType":860},{},[4615],{"data":4616,"marks":4617,"value":4619,"nodeType":864},{},[4618],{"type":899},"Advanced phishing detection",{"data":4621,"content":4622,"nodeType":4569},{},[4623],{"data":4624,"content":4625,"nodeType":860},{},[4626],{"data":4627,"marks":4628,"value":4629,"nodeType":864},{},[],"Behavioral page analysis detects phishing kits regardless of whether the domain is known-bad. Credential entry guardrails block corporate passwords from being submitted to unauthorized domains. TTP-based detection remains effective as attacker infrastructure rotates.",{"data":4631,"content":4632,"nodeType":4581},{},[4633,4644],{"data":4634,"content":4635,"nodeType":4569},{},[4636],{"data":4637,"content":4638,"nodeType":860},{},[4639],{"data":4640,"marks":4641,"value":4643,"nodeType":864},{},[4642],{"type":899},"Identity posture hardening",{"data":4645,"content":4646,"nodeType":4569},{},[4647],{"data":4648,"content":4649,"nodeType":860},{},[4650],{"data":4651,"marks":4652,"value":4653,"nodeType":864},{},[],"Enforces MFA, strong credentials, and SSO adoption across every app the IdP doesn't manage. Produces continuous, auditable MFA coverage and credential hygiene evidence across the full application and device estate.",{"data":4655,"content":4656,"nodeType":4581},{},[4657,4668],{"data":4658,"content":4659,"nodeType":4569},{},[4660],{"data":4661,"content":4662,"nodeType":860},{},[4663],{"data":4664,"marks":4665,"value":4667,"nodeType":864},{},[4666],{"type":899},"Browser extension security",{"data":4669,"content":4670,"nodeType":4569},{},[4671],{"data":4672,"content":4673,"nodeType":860},{},[4674],{"data":4675,"marks":4676,"value":4677,"nodeType":864},{},[],"Live extension inventory with supply chain change event monitoring — ownership transfers, permission escalations, developer contact changes — rather than static risk scoring. Supports default-deny allowlisting and remote extension removal. Blocks known-bad malicious extensions automatically.",{"data":4679,"content":4680,"nodeType":4581},{},[4681,4692],{"data":4682,"content":4683,"nodeType":4569},{},[4684],{"data":4685,"content":4686,"nodeType":860},{},[4687],{"data":4688,"marks":4689,"value":4691,"nodeType":864},{},[4690],{"type":899},"Shadow SaaS and OAuth governance",{"data":4693,"content":4694,"nodeType":4569},{},[4695],{"data":4696,"content":4697,"nodeType":860},{},[4698],{"data":4699,"marks":4700,"value":4701,"nodeType":864},{},[],"Discovers shadow SaaS from actual login events with full authentication context. Monitors and blocks OAuth consent flows — including AI and MCP integrations — in real time before persistent access paths are created.",{"data":4703,"content":4704,"nodeType":4581},{},[4705,4716],{"data":4706,"content":4707,"nodeType":4569},{},[4708],{"data":4709,"content":4710,"nodeType":860},{},[4711],{"data":4712,"marks":4713,"value":4715,"nodeType":864},{},[4714],{"type":899},"ClickFix and the *Fix family",{"data":4717,"content":4718,"nodeType":4569},{},[4719],{"data":4720,"content":4721,"nodeType":860},{},[4722],{"data":4723,"marks":4724,"value":4725,"nodeType":864},{},[],"Detects and blocks ClickFix lures, clipboard injection, and browser-native variants like ConsentFix in real time — before the payload executes or OAuth key material is captured.",{"data":4727,"content":4728,"nodeType":4581},{},[4729,4740],{"data":4730,"content":4731,"nodeType":4569},{},[4732],{"data":4733,"content":4734,"nodeType":860},{},[4735],{"data":4736,"marks":4737,"value":4739,"nodeType":864},{},[4738],{"type":899},"AI visibility & control",{"data":4741,"content":4742,"nodeType":4569},{},[4743],{"data":4744,"content":4745,"nodeType":860},{},[4746],{"data":4747,"marks":4748,"value":4749,"nodeType":864},{},[],"Enforces which AI tools employees can access and routes usage to corporate tenants. Governs AI browser extensions and blocks OAuth consent grants to unapproved AI applications — drawing on the same Tier 1 capabilities (OAuth governance, extension security, shadow SaaS discovery) that make this possible.",{"data":4751,"content":4752,"nodeType":4581},{},[4753,4764],{"data":4754,"content":4755,"nodeType":4569},{},[4756],{"data":4757,"content":4758,"nodeType":860},{},[4759],{"data":4760,"marks":4761,"value":4763,"nodeType":864},{},[4762],{"type":899},"Security investigations & incident response",{"data":4765,"content":4766,"nodeType":4569},{},[4767],{"data":4768,"content":4769,"nodeType":860},{},[4770],{"data":4771,"marks":4772,"value":4773,"nodeType":864},{},[],"High-fidelity session telemetry — page loads, credential entries, DOM changes, OAuth grants — fills the missing middle that endpoint, network, and IdP logs leave open. Feeds directly into SIEM and SOAR for automated response.",{"data":4775,"content":4776,"nodeType":4581},{},[4777,4788],{"data":4778,"content":4779,"nodeType":4569},{},[4780],{"data":4781,"content":4782,"nodeType":860},{},[4783],{"data":4784,"marks":4785,"value":4787,"nodeType":864},{},[4786],{"type":899},"Infostealer defense",{"data":4789,"content":4790,"nodeType":4569},{},[4791],{"data":4792,"content":4793,"nodeType":860},{},[4794],{"data":4795,"marks":4796,"value":4797,"nodeType":864},{},[],"Intercepts ClickFix-based infostealer delivery before execution. Detects token replay in unenrolled browser contexts — catching post-theft abuse from AiTM-sourced tokens and infostealer-harvested cookies, including from unmanaged devices.",{"data":4799,"content":4800,"nodeType":4581},{},[4801,4812],{"data":4802,"content":4803,"nodeType":4569},{},[4804],{"data":4805,"content":4806,"nodeType":860},{},[4807],{"data":4808,"marks":4809,"value":4811,"nodeType":864},{},[4810],{"type":899},"Data loss prevention",{"data":4813,"content":4814,"nodeType":4569},{},[4815],{"data":4816,"content":4817,"nodeType":860},{},[4818],{"data":4819,"marks":4820,"value":4821,"nodeType":864},{},[],"Observes file uploads, downloads, and sensitive data inputs across all applications. Extends data loss visibility to BYOD and contractor devices where endpoint DLP cannot reach.",{"data":4823,"content":4824,"nodeType":4581},{},[4825,4835],{"data":4826,"content":4827,"nodeType":4569},{},[4828],{"data":4829,"content":4830,"nodeType":860},{},[4831],{"data":4832,"marks":4833,"value":4500,"nodeType":864},{},[4834],{"type":899},{"data":4836,"content":4837,"nodeType":4569},{},[4838],{"data":4839,"content":4840,"nodeType":860},{},[4841],{"data":4842,"marks":4843,"value":4844,"nodeType":864},{},[],"Custom URL blocklists with wildcard support and REST API management for threat intelligence feed sync. Application category blocking restricts access to classes of apps (file-sharing, unsanctioned AI tools) configurable by user group. Domain categorization bringing SWG-style category blocking natively to the browser without a network proxy.","table",{"data":4847,"content":4848,"nodeType":1005},{},[],{"data":4850,"content":4851,"nodeType":860},{},[4852,4856,4862],{"data":4853,"marks":4854,"value":4855,"nodeType":864},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":4857,"content":4858,"nodeType":883},{"uri":1700},[4859],{"data":4860,"marks":4861,"value":1703,"nodeType":864},{},[],{"data":4863,"marks":4864,"value":21,"nodeType":864},{},[],"The top 10 security problems you can solve in the browser — ranked by value","Ranking the security problems you can solve in the browser by security value and browser fit.","2026-05-14T00:00:00.000Z","the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",{"items":4870},[4871,4873],{"sys":4872,"name":297},{"id":2732},{"sys":4874,"name":2729},{"id":2728},{"items":4876},[4877],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":4880},"Alex Henshall","Alex",{"url":4881},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg","shadow-ai-how-to-discover-govern-and-secure-ai-apps","blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps","Why you need paved paths, not barricades, for secure AI adoption",{"json":4886},{"data":4887,"content":4888,"nodeType":856},{},[4889],{"data":4890,"content":4891,"nodeType":860},{},[4892],{"data":4893,"marks":4894,"value":4895,"nodeType":864},{},[],"Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.",{"id":4897,"publishedAt":4898},"7MB9tEe6mrdNXbkYVhgyWn","2026-08-13T13:06:46.644Z",{"items":4900},[4901,4905],{"sys":4902,"name":4904},{"id":4903},"3SA5H01UkKauuiTdt0KC6q","Shadow IT",{"sys":4906,"name":545},{"id":4907},"7ohk9lIkxMvJMwnp2Lhuad",{"items":4909},[4910,4912,4914,4916,4918,4920,4922,4924,4926,4928,4930,4932,4934,4936,4938,4940],{"sys":4911,"name":580,"slug":581,"tier":45},{"id":577},{"sys":4913,"name":589,"slug":590,"tier":45},{"id":586},{"sys":4915,"name":633,"slug":634,"tier":45},{"id":630},{"sys":4917,"name":624,"slug":625,"tier":45},{"id":621},{"sys":4919,"name":545,"slug":546,"tier":31},{"id":542},{"sys":4921,"name":484,"slug":485,"tier":45},{"id":481},{"sys":4923,"name":431,"slug":432,"tier":45},{"id":428},{"sys":4925,"name":413,"slug":414,"tier":31},{"id":410},{"sys":4927,"name":368,"slug":369,"tier":45},{"id":365},{"sys":4929,"name":351,"slug":352,"tier":45},{"id":348},{"sys":4931,"name":306,"slug":307,"tier":45},{"id":303},{"sys":4933,"name":288,"slug":289,"tier":45},{"id":285},{"sys":4935,"name":297,"slug":298,"tier":31},{"id":294},{"sys":4937,"name":252,"slug":253,"tier":45},{"id":249},{"sys":4939,"name":235,"slug":236,"tier":31},{"id":232},{"sys":4941,"name":244,"slug":245,"tier":45},{"id":241},"Zx6fn8UdirkncRHJf51fcJD_Tl5wsbmvST1BUx0fsQ8",{"id":4944,"title":3608,"authorsCollection":4945,"content":4949,"extension":228,"faqItemsCollection":5722,"faqTitle":59,"featured":6,"hashTags":59,"meta":5724,"metaTitle":5725,"ogImage":59,"postType":5726,"publishedDate":3610,"relatedBlogPostsCollection":5727,"slug":3611,"stem":8785,"subtitle":59,"summary":8786,"synopsis":3609,"sys":8797,"tagsCollection":8799,"topicsCollection":8805,"__hash__":8833},"blog/blog/crossing-the-ai-security-chasm-sans-security-maturity-model.json",{"items":4946},[4947],{"fullName":3621,"firstName":3622,"jobTitle":3623,"socialLinks":59,"profilePicture":4948},{"url":3625},{"json":4950,"links":5690},{"data":4951,"content":4952,"nodeType":856},{},[4953,4959,4983,4998,5003,5009,5022,5025,5032,5047,5102,5108,5113,5119,5192,5198,5204,5217,5220,5227,5233,5239,5246,5252,5262,5267,5273,5279,5285,5288,5295,5308,5321,5327,5333,5339,5356,5428,5434,5440,5443,5450,5463,5469,5475,5482,5485,5492,5507,5513,5519,5549,5555,5561,5564,5571,5577,5587,5592,5602,5612,5617,5627,5646,5652,5655,5662,5668,5674],{"data":4954,"content":4955,"nodeType":860},{},[4956],{"data":4957,"marks":4958,"value":2754,"nodeType":864},{},[],{"data":4960,"content":4961,"nodeType":860},{},[4962,4965,4971,4974,4980],{"data":4963,"marks":4964,"value":2761,"nodeType":864},{},[],{"data":4966,"content":4967,"nodeType":883},{"uri":2764},[4968],{"data":4969,"marks":4970,"value":2769,"nodeType":864},{},[],{"data":4972,"marks":4973,"value":2773,"nodeType":864},{},[],{"data":4975,"content":4976,"nodeType":883},{"uri":2776},[4977],{"data":4978,"marks":4979,"value":2781,"nodeType":864},{},[],{"data":4981,"marks":4982,"value":2785,"nodeType":864},{},[],{"data":4984,"content":4985,"nodeType":860},{},[4986,4989,4995],{"data":4987,"marks":4988,"value":2792,"nodeType":864},{},[],{"data":4990,"content":4991,"nodeType":883},{"uri":2776},[4992],{"data":4993,"marks":4994,"value":2799,"nodeType":864},{},[],{"data":4996,"marks":4997,"value":2803,"nodeType":864},{},[],{"data":4999,"content":5002,"nodeType":996},{"target":5000},{"sys":5001},{"id":1040,"type":1001,"linkType":1002},[],{"data":5004,"content":5005,"nodeType":860},{},[5006],{"data":5007,"marks":5008,"value":2815,"nodeType":864},{},[],{"data":5010,"content":5011,"nodeType":860},{},[5012,5015,5019],{"data":5013,"marks":5014,"value":2822,"nodeType":864},{},[],{"data":5016,"marks":5017,"value":2827,"nodeType":864},{},[5018],{"type":2246},{"data":5020,"marks":5021,"value":2831,"nodeType":864},{},[],{"data":5023,"content":5024,"nodeType":1005},{},[],{"data":5026,"content":5027,"nodeType":1009},{},[5028],{"data":5029,"marks":5030,"value":2842,"nodeType":864},{},[5031],{"type":899},{"data":5033,"content":5034,"nodeType":860},{},[5035,5038,5044],{"data":5036,"marks":5037,"value":2849,"nodeType":864},{},[],{"data":5039,"content":5040,"nodeType":883},{"uri":2852},[5041],{"data":5042,"marks":5043,"value":1108,"nodeType":864},{},[],{"data":5045,"marks":5046,"value":2860,"nodeType":864},{},[],{"data":5048,"content":5049,"nodeType":941},{},[5050,5064,5078],{"data":5051,"content":5052,"nodeType":945},{},[5053],{"data":5054,"content":5055,"nodeType":860},{},[5056,5061],{"data":5057,"marks":5058,"value":2875,"nodeType":864},{},[5059,5060],{"type":899},{"type":1455},{"data":5062,"marks":5063,"value":2879,"nodeType":864},{},[],{"data":5065,"content":5066,"nodeType":945},{},[5067],{"data":5068,"content":5069,"nodeType":860},{},[5070,5075],{"data":5071,"marks":5072,"value":2891,"nodeType":864},{},[5073,5074],{"type":899},{"type":1455},{"data":5076,"marks":5077,"value":2895,"nodeType":864},{},[],{"data":5079,"content":5080,"nodeType":945},{},[5081],{"data":5082,"content":5083,"nodeType":860},{},[5084,5089,5092,5099],{"data":5085,"marks":5086,"value":2907,"nodeType":864},{},[5087,5088],{"type":899},{"type":1455},{"data":5090,"marks":5091,"value":2911,"nodeType":864},{},[],{"data":5093,"content":5094,"nodeType":883},{"uri":2914},[5095],{"data":5096,"marks":5097,"value":2920,"nodeType":864},{},[5098],{"type":1455},{"data":5100,"marks":5101,"value":2924,"nodeType":864},{},[],{"data":5103,"content":5104,"nodeType":860},{},[5105],{"data":5106,"marks":5107,"value":2931,"nodeType":864},{},[],{"data":5109,"content":5112,"nodeType":996},{"target":5110},{"sys":5111},{"id":2936,"type":1001,"linkType":1002},[],{"data":5114,"content":5115,"nodeType":860},{},[5116],{"data":5117,"marks":5118,"value":2944,"nodeType":864},{},[],{"data":5120,"content":5121,"nodeType":941},{},[5122,5136,5150,5164,5178],{"data":5123,"content":5124,"nodeType":945},{},[5125],{"data":5126,"content":5127,"nodeType":860},{},[5128,5133],{"data":5129,"marks":5130,"value":2959,"nodeType":864},{},[5131,5132],{"type":899},{"type":1455},{"data":5134,"marks":5135,"value":2963,"nodeType":864},{},[],{"data":5137,"content":5138,"nodeType":945},{},[5139],{"data":5140,"content":5141,"nodeType":860},{},[5142,5147],{"data":5143,"marks":5144,"value":2975,"nodeType":864},{},[5145,5146],{"type":899},{"type":1455},{"data":5148,"marks":5149,"value":2979,"nodeType":864},{},[],{"data":5151,"content":5152,"nodeType":945},{},[5153],{"data":5154,"content":5155,"nodeType":860},{},[5156,5161],{"data":5157,"marks":5158,"value":2991,"nodeType":864},{},[5159,5160],{"type":899},{"type":1455},{"data":5162,"marks":5163,"value":2995,"nodeType":864},{},[],{"data":5165,"content":5166,"nodeType":945},{},[5167],{"data":5168,"content":5169,"nodeType":860},{},[5170,5175],{"data":5171,"marks":5172,"value":3007,"nodeType":864},{},[5173,5174],{"type":899},{"type":1455},{"data":5176,"marks":5177,"value":3011,"nodeType":864},{},[],{"data":5179,"content":5180,"nodeType":945},{},[5181],{"data":5182,"content":5183,"nodeType":860},{},[5184,5189],{"data":5185,"marks":5186,"value":3023,"nodeType":864},{},[5187,5188],{"type":899},{"type":1455},{"data":5190,"marks":5191,"value":3027,"nodeType":864},{},[],{"data":5193,"content":5194,"nodeType":860},{},[5195],{"data":5196,"marks":5197,"value":3034,"nodeType":864},{},[],{"data":5199,"content":5200,"nodeType":860},{},[5201],{"data":5202,"marks":5203,"value":3041,"nodeType":864},{},[],{"data":5205,"content":5206,"nodeType":860},{},[5207,5210,5214],{"data":5208,"marks":5209,"value":3048,"nodeType":864},{},[],{"data":5211,"marks":5212,"value":3053,"nodeType":864},{},[5213],{"type":2246},{"data":5215,"marks":5216,"value":3057,"nodeType":864},{},[],{"data":5218,"content":5219,"nodeType":1005},{},[],{"data":5221,"content":5222,"nodeType":1009},{},[5223],{"data":5224,"marks":5225,"value":3068,"nodeType":864},{},[5226],{"type":899},{"data":5228,"content":5229,"nodeType":860},{},[5230],{"data":5231,"marks":5232,"value":3075,"nodeType":864},{},[],{"data":5234,"content":5235,"nodeType":860},{},[5236],{"data":5237,"marks":5238,"value":3082,"nodeType":864},{},[],{"data":5240,"content":5241,"nodeType":860},{},[5242],{"data":5243,"marks":5244,"value":3090,"nodeType":864},{},[5245],{"type":899},{"data":5247,"content":5248,"nodeType":860},{},[5249],{"data":5250,"marks":5251,"value":3097,"nodeType":864},{},[],{"data":5253,"content":5254,"nodeType":860},{},[5255,5259],{"data":5256,"marks":5257,"value":3105,"nodeType":864},{},[5258],{"type":2246},{"data":5260,"marks":5261,"value":3109,"nodeType":864},{},[],{"data":5263,"content":5266,"nodeType":996},{"target":5264},{"sys":5265},{"id":3114,"type":1001,"linkType":1002},[],{"data":5268,"content":5269,"nodeType":860},{},[5270],{"data":5271,"marks":5272,"value":3122,"nodeType":864},{},[],{"data":5274,"content":5275,"nodeType":860},{},[5276],{"data":5277,"marks":5278,"value":3129,"nodeType":864},{},[],{"data":5280,"content":5281,"nodeType":860},{},[5282],{"data":5283,"marks":5284,"value":3136,"nodeType":864},{},[],{"data":5286,"content":5287,"nodeType":1005},{},[],{"data":5289,"content":5290,"nodeType":1009},{},[5291],{"data":5292,"marks":5293,"value":3147,"nodeType":864},{},[5294],{"type":899},{"data":5296,"content":5297,"nodeType":860},{},[5298,5301,5305],{"data":5299,"marks":5300,"value":3154,"nodeType":864},{},[],{"data":5302,"marks":5303,"value":3159,"nodeType":864},{},[5304],{"type":899},{"data":5306,"marks":5307,"value":3163,"nodeType":864},{},[],{"data":5309,"content":5310,"nodeType":860},{},[5311,5314,5318],{"data":5312,"marks":5313,"value":3170,"nodeType":864},{},[],{"data":5315,"marks":5316,"value":3175,"nodeType":864},{},[5317],{"type":899},{"data":5319,"marks":5320,"value":3179,"nodeType":864},{},[],{"data":5322,"content":5323,"nodeType":860},{},[5324],{"data":5325,"marks":5326,"value":3186,"nodeType":864},{},[],{"data":5328,"content":5329,"nodeType":860},{},[5330],{"data":5331,"marks":5332,"value":3193,"nodeType":864},{},[],{"data":5334,"content":5335,"nodeType":860},{},[5336],{"data":5337,"marks":5338,"value":3200,"nodeType":864},{},[],{"data":5340,"content":5341,"nodeType":860},{},[5342,5345,5353],{"data":5343,"marks":5344,"value":3207,"nodeType":864},{},[],{"data":5346,"content":5347,"nodeType":883},{"uri":3210},[5348],{"data":5349,"marks":5350,"value":3217,"nodeType":864},{},[5351,5352],{"type":1455},{"type":899},{"data":5354,"marks":5355,"value":3221,"nodeType":864},{},[],{"data":5357,"content":5358,"nodeType":941},{},[5359,5377,5395],{"data":5360,"content":5361,"nodeType":945},{},[5362],{"data":5363,"content":5364,"nodeType":860},{},[5365,5368,5374],{"data":5366,"marks":5367,"value":3234,"nodeType":864},{},[],{"data":5369,"content":5370,"nodeType":883},{"uri":3237},[5371],{"data":5372,"marks":5373,"value":3242,"nodeType":864},{},[],{"data":5375,"marks":5376,"value":3246,"nodeType":864},{},[],{"data":5378,"content":5379,"nodeType":945},{},[5380],{"data":5381,"content":5382,"nodeType":860},{},[5383,5386,5392],{"data":5384,"marks":5385,"value":3256,"nodeType":864},{},[],{"data":5387,"content":5388,"nodeType":883},{"uri":3259},[5389],{"data":5390,"marks":5391,"value":3264,"nodeType":864},{},[],{"data":5393,"marks":5394,"value":3268,"nodeType":864},{},[],{"data":5396,"content":5397,"nodeType":945},{},[5398],{"data":5399,"content":5400,"nodeType":860},{},[5401,5404,5411,5414,5418,5421,5425],{"data":5402,"marks":5403,"value":21,"nodeType":864},{},[],{"data":5405,"content":5406,"nodeType":883},{"uri":3280},[5407],{"data":5408,"marks":5409,"value":3286,"nodeType":864},{},[5410],{"type":1455},{"data":5412,"marks":5413,"value":3290,"nodeType":864},{},[],{"data":5415,"marks":5416,"value":3295,"nodeType":864},{},[5417],{"type":899},{"data":5419,"marks":5420,"value":3299,"nodeType":864},{},[],{"data":5422,"marks":5423,"value":3304,"nodeType":864},{},[5424],{"type":899},{"data":5426,"marks":5427,"value":2924,"nodeType":864},{},[],{"data":5429,"content":5430,"nodeType":860},{},[5431],{"data":5432,"marks":5433,"value":3314,"nodeType":864},{},[],{"data":5435,"content":5436,"nodeType":860},{},[5437],{"data":5438,"marks":5439,"value":3321,"nodeType":864},{},[],{"data":5441,"content":5442,"nodeType":1005},{},[],{"data":5444,"content":5445,"nodeType":1312},{},[5446],{"data":5447,"marks":5448,"value":3332,"nodeType":864},{},[5449],{"type":899},{"data":5451,"content":5452,"nodeType":860},{},[5453,5456,5460],{"data":5454,"marks":5455,"value":3339,"nodeType":864},{},[],{"data":5457,"marks":5458,"value":3344,"nodeType":864},{},[5459],{"type":2246},{"data":5461,"marks":5462,"value":3348,"nodeType":864},{},[],{"data":5464,"content":5465,"nodeType":860},{},[5466],{"data":5467,"marks":5468,"value":3355,"nodeType":864},{},[],{"data":5470,"content":5471,"nodeType":860},{},[5472],{"data":5473,"marks":5474,"value":3362,"nodeType":864},{},[],{"data":5476,"content":5477,"nodeType":860},{},[5478],{"data":5479,"marks":5480,"value":3370,"nodeType":864},{},[5481],{"type":899},{"data":5483,"content":5484,"nodeType":1005},{},[],{"data":5486,"content":5487,"nodeType":1009},{},[5488],{"data":5489,"marks":5490,"value":3381,"nodeType":864},{},[5491],{"type":899},{"data":5493,"content":5494,"nodeType":860},{},[5495,5498,5504],{"data":5496,"marks":5497,"value":3388,"nodeType":864},{},[],{"data":5499,"content":5500,"nodeType":883},{"uri":3210},[5501],{"data":5502,"marks":5503,"value":3395,"nodeType":864},{},[],{"data":5505,"marks":5506,"value":3399,"nodeType":864},{},[],{"data":5508,"content":5509,"nodeType":860},{},[5510],{"data":5511,"marks":5512,"value":3406,"nodeType":864},{},[],{"data":5514,"content":5515,"nodeType":860},{},[5516],{"data":5517,"marks":5518,"value":3413,"nodeType":864},{},[],{"data":5520,"content":5521,"nodeType":941},{},[5522,5531,5540],{"data":5523,"content":5524,"nodeType":945},{},[5525],{"data":5526,"content":5527,"nodeType":860},{},[5528],{"data":5529,"marks":5530,"value":3426,"nodeType":864},{},[],{"data":5532,"content":5533,"nodeType":945},{},[5534],{"data":5535,"content":5536,"nodeType":860},{},[5537],{"data":5538,"marks":5539,"value":3436,"nodeType":864},{},[],{"data":5541,"content":5542,"nodeType":945},{},[5543],{"data":5544,"content":5545,"nodeType":860},{},[5546],{"data":5547,"marks":5548,"value":3446,"nodeType":864},{},[],{"data":5550,"content":5551,"nodeType":860},{},[5552],{"data":5553,"marks":5554,"value":3453,"nodeType":864},{},[],{"data":5556,"content":5557,"nodeType":860},{},[5558],{"data":5559,"marks":5560,"value":3460,"nodeType":864},{},[],{"data":5562,"content":5563,"nodeType":1005},{},[],{"data":5565,"content":5566,"nodeType":1009},{},[5567],{"data":5568,"marks":5569,"value":3471,"nodeType":864},{},[5570],{"type":899},{"data":5572,"content":5573,"nodeType":860},{},[5574],{"data":5575,"marks":5576,"value":3478,"nodeType":864},{},[],{"data":5578,"content":5579,"nodeType":860},{},[5580,5584],{"data":5581,"marks":5582,"value":3486,"nodeType":864},{},[5583],{"type":899},{"data":5585,"marks":5586,"value":3490,"nodeType":864},{},[],{"data":5588,"content":5591,"nodeType":996},{"target":5589},{"sys":5590},{"id":3495,"type":1001,"linkType":1002},[],{"data":5593,"content":5594,"nodeType":860},{},[5595,5599],{"data":5596,"marks":5597,"value":3504,"nodeType":864},{},[5598],{"type":899},{"data":5600,"marks":5601,"value":3508,"nodeType":864},{},[],{"data":5603,"content":5604,"nodeType":860},{},[5605,5609],{"data":5606,"marks":5607,"value":3516,"nodeType":864},{},[5608],{"type":899},{"data":5610,"marks":5611,"value":3520,"nodeType":864},{},[],{"data":5613,"content":5616,"nodeType":996},{"target":5614},{"sys":5615},{"id":3525,"type":1001,"linkType":1002},[],{"data":5618,"content":5619,"nodeType":860},{},[5620,5624],{"data":5621,"marks":5622,"value":3534,"nodeType":864},{},[5623],{"type":899},{"data":5625,"marks":5626,"value":3538,"nodeType":864},{},[],{"data":5628,"content":5629,"nodeType":860},{},[5630,5634,5637,5643],{"data":5631,"marks":5632,"value":3546,"nodeType":864},{},[5633],{"type":899},{"data":5635,"marks":5636,"value":3550,"nodeType":864},{},[],{"data":5638,"content":5639,"nodeType":883},{"uri":2852},[5640],{"data":5641,"marks":5642,"value":1108,"nodeType":864},{},[],{"data":5644,"marks":5645,"value":3560,"nodeType":864},{},[],{"data":5647,"content":5648,"nodeType":860},{},[5649],{"data":5650,"marks":5651,"value":3567,"nodeType":864},{},[],{"data":5653,"content":5654,"nodeType":1005},{},[],{"data":5656,"content":5657,"nodeType":1009},{},[5658],{"data":5659,"marks":5660,"value":3578,"nodeType":864},{},[5661],{"type":899},{"data":5663,"content":5664,"nodeType":860},{},[5665],{"data":5666,"marks":5667,"value":3585,"nodeType":864},{},[],{"data":5669,"content":5670,"nodeType":860},{},[5671],{"data":5672,"marks":5673,"value":1689,"nodeType":864},{},[],{"data":5675,"content":5676,"nodeType":860},{},[5677,5680,5687],{"data":5678,"marks":5679,"value":2707,"nodeType":864},{},[],{"data":5681,"content":5682,"nodeType":883},{"uri":1700},[5683],{"data":5684,"marks":5685,"value":2715,"nodeType":864},{},[5686],{"type":1455},{"data":5688,"marks":5689,"value":2719,"nodeType":864},{},[],{"entries":5691},{"hyperlink":5692,"inline":5693,"block":5694},[],[],[5695,5698,5704,5710,5716],{"sys":5696,"__typename":1724,"title":1725,"caption":1726,"layoutMode":59,"file":5697},{"id":1040},{"url":1728,"width":1729,"height":1730},{"sys":5699,"__typename":1724,"title":5700,"caption":5700,"layoutMode":59,"file":5701},{"id":2936},"SANS AI Security Maturity Model. Credit: SANS Institute",{"url":5702,"width":1736,"height":5703},"https://images.ctfassets.net/y1cdw1ablpvd/7a9wgGdzZdS8c0nAzrlJqk/85657448d9d1bb34e126ba85e79ce27c/image2.png",1489,{"sys":5705,"__typename":1724,"title":5706,"caption":5706,"layoutMode":59,"file":5707},{"id":3114},"Crossing the AI security chasm requires focusing both on AI governance, and protection against AI-enabled attacks.",{"url":5708,"width":1736,"height":5709},"https://images.ctfassets.net/y1cdw1ablpvd/749gGzgSPy9n58LU9WFZ02/7c1327e38b1be213013f102f0dccc306/image4.png",1106,{"sys":5711,"__typename":1724,"title":5712,"caption":5712,"layoutMode":59,"file":5713},{"id":3495},"Push automatically inventories apps accessed by your employees and categorizes them.",{"url":5714,"width":1736,"height":5715},"https://images.ctfassets.net/y1cdw1ablpvd/6HZ0uOS63oeT1KmnRu0rWB/db9a27ff0a230237d3e5bfda56386592/image5.png",1138,{"sys":5717,"__typename":1724,"title":5718,"caption":5718,"layoutMode":59,"file":5719},{"id":3525},"Sample detection details in the Push admin console for a blocked phishing event",{"url":5720,"width":1736,"height":5721},"https://images.ctfassets.net/y1cdw1ablpvd/vIFT3CvEkR3MPQdI5DIoa/4f59424365c3c90c232e287dac85bf2c/image3.png",766,{"items":5723},[],{},"Crossing the chasm with the SANS AI security maturity model","thought-leadership",{"items":5728},[5729,6768,7704],{"__typename":2059,"sys":5730,"content":5732,"title":6750,"synopsis":6751,"hashTags":59,"publishedDate":6752,"slug":6753,"tagsCollection":6754,"authorsCollection":6760},{"id":5731},"19QvRR4NcSe3PHQEhID42Q",{"json":5733},{"data":5734,"content":5735,"nodeType":856},{},[5736,5744,5751,5759,6333,6339,6346,6353,6356,6364,6371,6379,6386,6392,6397,6405,6421,6429,6436,6444,6451,6457,6465,6472,6478,6481,6489,6508,6528,6547,6554,6557,6565,6572,6583,6590,6601,6608,6614,6625,6632,6643,6650,6657,6663,6674,6681,6684,6692,6699,6706,6713,6719,6722,6728,6734],{"data":5737,"content":5738,"nodeType":1009},{},[5739],{"data":5740,"marks":5741,"value":5743,"nodeType":864},{},[5742],{"type":899},"The AI regulatory landscape is moving fast",{"data":5745,"content":5746,"nodeType":860},{},[5747],{"data":5748,"marks":5749,"value":5750,"nodeType":864},{},[],"The regulatory landscape around AI has shifted from theoretical to operational faster than most compliance teams expected. Several regulations are already in force, presenting not just a legal but also significant operational challenge to organizations covered by these regulations. ",{"data":5752,"content":5753,"nodeType":860},{},[5754],{"data":5755,"marks":5756,"value":5758,"nodeType":864},{},[5757],{"type":899},"First, here's a summary of the key frameworks and what they require:",{"data":5760,"content":5761,"nodeType":4845},{},[5762,5809,5899,5965,6020,6144,6199,6266],{"data":5763,"content":5764,"nodeType":4581},{},[5765,5776,5787,5798],{"data":5766,"content":5767,"nodeType":4569},{},[5768],{"data":5769,"content":5770,"nodeType":860},{},[5771],{"data":5772,"marks":5773,"value":5775,"nodeType":864},{},[5774],{"type":899},"Regulation",{"data":5777,"content":5778,"nodeType":4569},{},[5779],{"data":5780,"content":5781,"nodeType":860},{},[5782],{"data":5783,"marks":5784,"value":5786,"nodeType":864},{},[5785],{"type":899},"Jurisdiction",{"data":5788,"content":5789,"nodeType":4569},{},[5790],{"data":5791,"content":5792,"nodeType":860},{},[5793],{"data":5794,"marks":5795,"value":5797,"nodeType":864},{},[5796],{"type":899},"What it requires for AI",{"data":5799,"content":5800,"nodeType":4569},{},[5801],{"data":5802,"content":5803,"nodeType":860},{},[5804],{"data":5805,"marks":5806,"value":5808,"nodeType":864},{},[5807],{"type":899},"Status",{"data":5810,"content":5811,"nodeType":4581},{},[5812,5834,5844,5878],{"data":5813,"content":5814,"nodeType":4569},{},[5815],{"data":5816,"content":5817,"nodeType":860},{},[5818,5821,5831],{"data":5819,"marks":5820,"value":21,"nodeType":864},{},[],{"data":5822,"content":5824,"nodeType":883},{"uri":5823},"https://artificialintelligenceact.eu/",[5825],{"data":5826,"marks":5827,"value":5830,"nodeType":864},{},[5828,5829],{"type":1455},{"type":899},"EU AI Act",{"data":5832,"marks":5833,"value":21,"nodeType":864},{},[],{"data":5835,"content":5836,"nodeType":4569},{},[5837],{"data":5838,"content":5839,"nodeType":860},{},[5840],{"data":5841,"marks":5842,"value":5843,"nodeType":864},{},[],"EU",{"data":5845,"content":5846,"nodeType":4569},{},[5847],{"data":5848,"content":5849,"nodeType":860},{},[5850,5854,5862,5866,5874],{"data":5851,"marks":5852,"value":5853,"nodeType":864},{},[],"AI system inventory and risk classification; ",{"data":5855,"content":5857,"nodeType":883},{"uri":5856},"https://artificialintelligenceact.eu/article/4/",[5858],{"data":5859,"marks":5860,"value":5861,"nodeType":864},{},[],"AI literacy",{"data":5863,"marks":5864,"value":5865,"nodeType":864},{},[]," for all staff; ",{"data":5867,"content":5869,"nodeType":883},{"uri":5868},"https://artificialintelligenceact.eu/article/15/",[5870],{"data":5871,"marks":5872,"value":5873,"nodeType":864},{},[],"cybersecurity resilience",{"data":5875,"marks":5876,"value":5877,"nodeType":864},{},[]," for high-risk AI; transparency and human oversight",{"data":5879,"content":5880,"nodeType":4569},{},[5881],{"data":5882,"content":5883,"nodeType":860},{},[5884,5887,5895],{"data":5885,"marks":5886,"value":21,"nodeType":864},{},[],{"data":5888,"content":5889,"nodeType":883},{"uri":5856},[5890],{"data":5891,"marks":5892,"value":5894,"nodeType":864},{},[5893],{"type":1455},"Art. 4",{"data":5896,"marks":5897,"value":5898,"nodeType":864},{},[]," (literacy) in force Feb 2025; high-risk obligations Aug 2026",{"data":5900,"content":5901,"nodeType":4581},{},[5902,5924,5934,5955],{"data":5903,"content":5904,"nodeType":4569},{},[5905],{"data":5906,"content":5907,"nodeType":860},{},[5908,5911,5921],{"data":5909,"marks":5910,"value":21,"nodeType":864},{},[],{"data":5912,"content":5914,"nodeType":883},{"uri":5913},"https://eur-lex.europa.eu/eli/reg/2022/2554/oj",[5915],{"data":5916,"marks":5917,"value":5920,"nodeType":864},{},[5918,5919],{"type":1455},{"type":899},"DORA",{"data":5922,"marks":5923,"value":21,"nodeType":864},{},[],{"data":5925,"content":5926,"nodeType":4569},{},[5927],{"data":5928,"content":5929,"nodeType":860},{},[5930],{"data":5931,"marks":5932,"value":5933,"nodeType":864},{},[],"EU financial services",{"data":5935,"content":5936,"nodeType":4569},{},[5937],{"data":5938,"content":5939,"nodeType":860},{},[5940,5944,5951],{"data":5941,"marks":5942,"value":5943,"nodeType":864},{},[],"AI tools in ICT risk framework; AI providers in ",{"data":5945,"content":5946,"nodeType":883},{"uri":5913},[5947],{"data":5948,"marks":5949,"value":5950,"nodeType":864},{},[],"third-party risk registers",{"data":5952,"marks":5953,"value":5954,"nodeType":864},{},[],"; resilience testing covering AI-enhanced attacks",{"data":5956,"content":5957,"nodeType":4569},{},[5958],{"data":5959,"content":5960,"nodeType":860},{},[5961],{"data":5962,"marks":5963,"value":5964,"nodeType":864},{},[],"In force Jan 2025",{"data":5966,"content":5967,"nodeType":4581},{},[5968,5990,6000,6010],{"data":5969,"content":5970,"nodeType":4569},{},[5971],{"data":5972,"content":5973,"nodeType":860},{},[5974,5977,5987],{"data":5975,"marks":5976,"value":21,"nodeType":864},{},[],{"data":5978,"content":5980,"nodeType":883},{"uri":5979},"https://eur-lex.europa.eu/eli/reg/2024/2847/oj",[5981],{"data":5982,"marks":5983,"value":5986,"nodeType":864},{},[5984,5985],{"type":1455},{"type":899},"EU Cyber Resilience Act",{"data":5988,"marks":5989,"value":21,"nodeType":864},{},[],{"data":5991,"content":5992,"nodeType":4569},{},[5993],{"data":5994,"content":5995,"nodeType":860},{},[5996],{"data":5997,"marks":5998,"value":5999,"nodeType":864},{},[],"EU digital products",{"data":6001,"content":6002,"nodeType":4569},{},[6003],{"data":6004,"content":6005,"nodeType":860},{},[6006],{"data":6007,"marks":6008,"value":6009,"nodeType":864},{},[],"AI-enabled software must meet essential cybersecurity requirements; vulnerability management and incident reporting",{"data":6011,"content":6012,"nodeType":4569},{},[6013],{"data":6014,"content":6015,"nodeType":860},{},[6016],{"data":6017,"marks":6018,"value":6019,"nodeType":864},{},[],"Reporting Sep 2026; full compliance Dec 2027",{"data":6021,"content":6022,"nodeType":4581},{},[6023,6045,6055,6104],{"data":6024,"content":6025,"nodeType":4569},{},[6026],{"data":6027,"content":6028,"nodeType":860},{},[6029,6032,6042],{"data":6030,"marks":6031,"value":21,"nodeType":864},{},[],{"data":6033,"content":6035,"nodeType":883},{"uri":6034},"https://www.dfs.ny.gov/industry_guidance/cybersecurity",[6036],{"data":6037,"marks":6038,"value":6041,"nodeType":864},{},[6039,6040],{"type":1455},{"type":899},"NYDFS 23 NYCRR 500",{"data":6043,"marks":6044,"value":21,"nodeType":864},{},[],{"data":6046,"content":6047,"nodeType":4569},{},[6048],{"data":6049,"content":6050,"nodeType":860},{},[6051],{"data":6052,"marks":6053,"value":6054,"nodeType":864},{},[],"US (NY financial services)",{"data":6056,"content":6057,"nodeType":4569},{},[6058],{"data":6059,"content":6060,"nodeType":860},{},[6061,6064,6073,6077,6085,6089,6101],{"data":6062,"marks":6063,"value":21,"nodeType":864},{},[],{"data":6065,"content":6067,"nodeType":883},{"uri":6066},"https://www.dfs.ny.gov/industry-guidance/industry-letters/il20241016-cyber-risks-ai-and-strategies-combat-related-risks",[6068],{"data":6069,"marks":6070,"value":6072,"nodeType":864},{},[6071],{"type":1455},"AI-resistant MFA",{"data":6074,"marks":6075,"value":6076,"nodeType":864},{},[],"; employee training on AI threats; ",{"data":6078,"content":6080,"nodeType":883},{"uri":6079},"https://www.dfs.ny.gov/industry-guidance/industry-letters/il20251021-guidance-managing-risks-third-party",[6081],{"data":6082,"marks":6083,"value":6084,"nodeType":864},{},[],"third-party AI risk assessment",{"data":6086,"marks":6087,"value":6088,"nodeType":864},{},[],";",{"data":6090,"content":6092,"nodeType":883},{"uri":6091},"https://www.dfs.ny.gov/industry-guidance/industry-letters/20260521-heightened-cybersecurity-risks-assoc-with-frontier-ai-models",[6093,6096],{"data":6094,"marks":6095,"value":1171,"nodeType":864},{},[],{"data":6097,"marks":6098,"value":6100,"nodeType":864},{},[6099],{"type":1455},"frontier AI model defenses",{"data":6102,"marks":6103,"value":21,"nodeType":864},{},[],{"data":6105,"content":6106,"nodeType":4569},{},[6107],{"data":6108,"content":6109,"nodeType":860},{},[6110,6114,6121,6124,6131,6134,6141],{"data":6111,"marks":6112,"value":6113,"nodeType":864},{},[],"Phased 2023–2025; AI-specific guidance issued ",{"data":6115,"content":6116,"nodeType":883},{"uri":6066},[6117],{"data":6118,"marks":6119,"value":6120,"nodeType":864},{},[],"Oct 2024",{"data":6122,"marks":6123,"value":3731,"nodeType":864},{},[],{"data":6125,"content":6126,"nodeType":883},{"uri":6079},[6127],{"data":6128,"marks":6129,"value":6130,"nodeType":864},{},[],"Oct 2025",{"data":6132,"marks":6133,"value":3731,"nodeType":864},{},[],{"data":6135,"content":6136,"nodeType":883},{"uri":6091},[6137],{"data":6138,"marks":6139,"value":6140,"nodeType":864},{},[],"May 2026",{"data":6142,"marks":6143,"value":21,"nodeType":864},{},[],{"data":6145,"content":6146,"nodeType":4581},{},[6147,6169,6179,6189],{"data":6148,"content":6149,"nodeType":4569},{},[6150],{"data":6151,"content":6152,"nodeType":860},{},[6153,6156,6166],{"data":6154,"marks":6155,"value":21,"nodeType":864},{},[],{"data":6157,"content":6159,"nodeType":883},{"uri":6158},"https://www.ncsl.org/technology-and-communication/2025-state-privacy-legislation-tracker",[6160],{"data":6161,"marks":6162,"value":6165,"nodeType":864},{},[6163,6164],{"type":1455},{"type":899},"US State Privacy laws",{"data":6167,"marks":6168,"value":21,"nodeType":864},{},[],{"data":6170,"content":6171,"nodeType":4569},{},[6172],{"data":6173,"content":6174,"nodeType":860},{},[6175],{"data":6176,"marks":6177,"value":6178,"nodeType":864},{},[],"US (20+ states)",{"data":6180,"content":6181,"nodeType":4569},{},[6182],{"data":6183,"content":6184,"nodeType":860},{},[6185],{"data":6186,"marks":6187,"value":6188,"nodeType":864},{},[],"Automated decision-making transparency, opt-out rights, and impact assessments; AI and children's data protections",{"data":6190,"content":6191,"nodeType":4569},{},[6192],{"data":6193,"content":6194,"nodeType":860},{},[6195],{"data":6196,"marks":6197,"value":6198,"nodeType":864},{},[],"Rolling 2024–2027 (CA, CO, CT leading)",{"data":6200,"content":6201,"nodeType":4581},{},[6202,6224,6234,6244],{"data":6203,"content":6204,"nodeType":4569},{},[6205],{"data":6206,"content":6207,"nodeType":860},{},[6208,6211,6221],{"data":6209,"marks":6210,"value":21,"nodeType":864},{},[],{"data":6212,"content":6214,"nodeType":883},{"uri":6213},"https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html",[6215],{"data":6216,"marks":6217,"value":6220,"nodeType":864},{},[6218,6219],{"type":1455},{"type":899},"HIPAA Security Rule",{"data":6222,"marks":6223,"value":21,"nodeType":864},{},[],{"data":6225,"content":6226,"nodeType":4569},{},[6227],{"data":6228,"content":6229,"nodeType":860},{},[6230],{"data":6231,"marks":6232,"value":6233,"nodeType":864},{},[],"US healthcare",{"data":6235,"content":6236,"nodeType":4569},{},[6237],{"data":6238,"content":6239,"nodeType":860},{},[6240],{"data":6241,"marks":6242,"value":6243,"nodeType":864},{},[],"AI tools in mandatory technology asset inventory; mandatory encryption covering AI; AI-enhanced attack preparedness",{"data":6245,"content":6246,"nodeType":4569},{},[6247],{"data":6248,"content":6249,"nodeType":860},{},[6250,6253,6262],{"data":6251,"marks":6252,"value":21,"nodeType":864},{},[],{"data":6254,"content":6256,"nodeType":883},{"uri":6255},"https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html",[6257],{"data":6258,"marks":6259,"value":6261,"nodeType":864},{},[6260],{"type":1455},"Final rule",{"data":6263,"marks":6264,"value":6265,"nodeType":864},{},[]," expected 2026",{"data":6267,"content":6268,"nodeType":4581},{},[6269,6291,6301,6323],{"data":6270,"content":6271,"nodeType":4569},{},[6272],{"data":6273,"content":6274,"nodeType":860},{},[6275,6278,6288],{"data":6276,"marks":6277,"value":21,"nodeType":864},{},[],{"data":6279,"content":6281,"nodeType":883},{"uri":6280},"https://www.legislation.gov.uk/ukpga/2025/18",[6282],{"data":6283,"marks":6284,"value":6287,"nodeType":864},{},[6285,6286],{"type":1455},{"type":899},"UK Data (Use and Access) Act",{"data":6289,"marks":6290,"value":21,"nodeType":864},{},[],{"data":6292,"content":6293,"nodeType":4569},{},[6294],{"data":6295,"content":6296,"nodeType":860},{},[6297],{"data":6298,"marks":6299,"value":6300,"nodeType":864},{},[],"UK",{"data":6302,"content":6303,"nodeType":4569},{},[6304],{"data":6305,"content":6306,"nodeType":860},{},[6307,6311,6319],{"data":6308,"marks":6309,"value":6310,"nodeType":864},{},[],"Reformed ",{"data":6312,"content":6314,"nodeType":883},{"uri":6313},"https://www.legislation.gov.uk/ukpga/2025/18/section/80",[6315],{"data":6316,"marks":6317,"value":6318,"nodeType":864},{},[],"automated decision-making rules",{"data":6320,"marks":6321,"value":6322,"nodeType":864},{},[]," (new Arts. 22A-22D UK GDPR): meaningful information about decisions, right to make representations, human intervention and contestation rights; stricter controls for special category data; new complaints-handling duty with 30-day response clock (from June 2026)",{"data":6324,"content":6325,"nodeType":4569},{},[6326],{"data":6327,"content":6328,"nodeType":860},{},[6329],{"data":6330,"marks":6331,"value":6332,"nodeType":864},{},[],"Main provisions Feb 2026; complaints duty June 2026",{"data":6334,"content":6338,"nodeType":996},{"target":6335},{"sys":6336},{"id":6337,"type":1001,"linkType":1002},"1J7nJKJ5XDLLiicX9cD4H1",[],{"data":6340,"content":6341,"nodeType":860},{},[6342],{"data":6343,"marks":6344,"value":6345,"nodeType":864},{},[],"Even if your organization isn't yet subject to these specific regulations, the direction of travel matters. The EU has a track record of setting global regulatory standards: GDPR reshaped data privacy practices worldwide, and the Digital Markets Act is influencing antitrust enforcement well beyond European borders.",{"data":6347,"content":6348,"nodeType":860},{},[6349],{"data":6350,"marks":6351,"value":6352,"nodeType":864},{},[],"The EU AI Act is the world's first comprehensive AI law, and the pattern of obligation categories it establishes is already visible in NYDFS guidance, US state privacy legislation, and the UK's reformed automated decision-making framework. Organizations that build the operational foundations to meet these obligations now will be ahead of whatever comes next, regardless of jurisdiction.",{"data":6354,"content":6355,"nodeType":1005},{},[],{"data":6357,"content":6358,"nodeType":1009},{},[6359],{"data":6360,"marks":6361,"value":6363,"nodeType":864},{},[6362],{"type":899},"Five obligation categories appear across frameworks",{"data":6365,"content":6366,"nodeType":860},{},[6367],{"data":6368,"marks":6369,"value":6370,"nodeType":864},{},[],"Across these frameworks, the AI-specific obligations cluster into five categories. Individual regulations word them differently and scope them to different sectors, but the compliance actions they require are largely the same.",{"data":6372,"content":6373,"nodeType":1312},{},[6374],{"data":6375,"marks":6376,"value":6378,"nodeType":864},{},[6377],{"type":899},"1. AI inventory and classification",{"data":6380,"content":6381,"nodeType":860},{},[6382],{"data":6383,"marks":6384,"value":6385,"nodeType":864},{},[],"You can't classify AI systems by risk level if you don't know which ones your employees are using. Multiple regulations now require organizations to maintain a complete inventory of AI tools in their environment — whether as part of risk classification, asset management, or third-party risk registers.",{"data":6387,"content":6391,"nodeType":996},{"target":6388},{"sys":6389},{"id":6390,"type":1001,"linkType":1002},"6MEapKaazFTulp7Ql0m7H1",[],{"data":6393,"content":6396,"nodeType":996},{"target":6394},{"sys":6395},{"id":1040,"type":1001,"linkType":1002},[],{"data":6398,"content":6399,"nodeType":1312},{},[6400],{"data":6401,"marks":6402,"value":6404,"nodeType":864},{},[6403],{"type":899},"2. AI literacy and employee guidance",{"data":6406,"content":6407,"nodeType":860},{},[6408,6412,6417],{"data":6409,"marks":6410,"value":6411,"nodeType":864},{},[],"Regulators increasingly expect organizations to demonstrate that employees understand the AI tools they use — not through annual training alone, but through continuous, contextual guidance at the point of interaction. Several frameworks now require auditable evidence that staff have been educated about AI risks and acceptable use policies. The common thread is the need for ",{"data":6413,"marks":6414,"value":6416,"nodeType":864},{},[6415],{"type":899},"ongoing",{"data":6418,"marks":6419,"value":6420,"nodeType":864},{},[]," education, not as a one-off compliance exercise, but continuously at the point of interaction.",{"data":6422,"content":6423,"nodeType":1312},{},[6424],{"data":6425,"marks":6426,"value":6428,"nodeType":864},{},[6427],{"type":899},"3. AI data governance and exposure control",{"data":6430,"content":6431,"nodeType":860},{},[6432],{"data":6433,"marks":6434,"value":6435,"nodeType":864},{},[],"Regulations are converging on the requirement for controls over what data enters AI tools. This includes sensitive personal data, health data, and data subject to automated decision-making. Organizations need to know where personal data is being processed by AI and have mechanisms to prevent unauthorized exposure.",{"data":6437,"content":6438,"nodeType":1312},{},[6439],{"data":6440,"marks":6441,"value":6443,"nodeType":864},{},[6442],{"type":899},"4. AI-resistant authentication and phishing defense",{"data":6445,"content":6446,"nodeType":860},{},[6447],{"data":6448,"marks":6449,"value":6450,"nodeType":864},{},[],"AI is making phishing attacks more convincing and harder to detect through traditional means. Several frameworks now require authentication methods that can withstand AI-enhanced attacks, specifically naming phishing-resistant options like digital certificates and security keys over SMS or voice-based authentication. Beyond authentication, organizations need defenses against AI-powered phishing that bypasses the lure-quality signals users were trained to spot.",{"data":6452,"content":6456,"nodeType":996},{"target":6453},{"sys":6454},{"id":6455,"type":1001,"linkType":1002},"6v3l0lGH6twfYi2JaM5fKt",[],{"data":6458,"content":6459,"nodeType":1312},{},[6460],{"data":6461,"marks":6462,"value":6464,"nodeType":864},{},[6463],{"type":899},"5. Third-party AI risk and supply chain governance",{"data":6466,"content":6467,"nodeType":860},{},[6468],{"data":6469,"marks":6470,"value":6471,"nodeType":864},{},[],"Employees adopt AI tools faster than procurement can track them, and each one that connects to corporate systems via OAuth creates a persistent trust relationship. Regulators now require organizations to know which third-party AI services they depend on, what permissions those services hold, and whether they introduce concentration risk. ",{"data":6473,"content":6477,"nodeType":996},{"target":6474},{"sys":6475},{"id":6476,"type":1001,"linkType":1002},"7xx2yYRJXBY55qTqBTTZcp",[],{"data":6479,"content":6480,"nodeType":1005},{},[],{"data":6482,"content":6483,"nodeType":1009},{},[6484],{"data":6485,"marks":6486,"value":6488,"nodeType":864},{},[6487],{"type":899},"How the regulations will be enforced",{"data":6490,"content":6491,"nodeType":860},{},[6492,6496,6504],{"data":6493,"marks":6494,"value":6495,"nodeType":864},{},[],"The consequences extend well beyond fines. EU AI Act penalties reach ",{"data":6497,"content":6499,"nodeType":883},{"uri":6498},"https://artificialintelligenceact.eu/article/99/",[6500],{"data":6501,"marks":6502,"value":6503,"nodeType":864},{},[],"€35 million or 7% of global turnover",{"data":6505,"marks":6506,"value":6507,"nodeType":864},{},[]," for prohibited practices, but the operational impact may bite harder: non-compliant AI systems cannot be placed on the EU market, and providers bear direct responsibility for conformity under Articles 16 and 26 — meaning the CISO who signed off on an AI deployment that turns out to be non-compliant has personal exposure, not just a budget line item.",{"data":6509,"content":6510,"nodeType":860},{},[6511,6515,6524],{"data":6512,"marks":6513,"value":6514,"nodeType":864},{},[],"Italy's implementation law (",{"data":6516,"content":6518,"nodeType":883},{"uri":6517},"https://www.nortonrosefulbright.com/en/knowledge/publications/9bfedfea/italy-enacts-law-no-132-2025-on-artificial-intelligence-sector-rules-and-next-steps",[6519],{"data":6520,"marks":6521,"value":6523,"nodeType":864},{},[6522],{"type":1455},"Law No. 132/2025",{"data":6525,"marks":6526,"value":6527,"nodeType":864},{},[],") goes further, introducing criminal penalties including imprisonment for AI-related offenses like deepfake dissemination.",{"data":6529,"content":6530,"nodeType":860},{},[6531,6535,6543],{"data":6532,"marks":6533,"value":6534,"nodeType":864},{},[],"NYDFS penalties accumulate at $2,500 per day per violation, and the regulator has been aggressive: it levied ",{"data":6536,"content":6538,"nodeType":883},{"uri":6537},"https://pushsecurity.com/blog/what-the-expansion-of-nydfs-nycrr-part-500-means-for-mfa-compliance/",[6539],{"data":6540,"marks":6541,"value":6542,"nodeType":864},{},[],"$14 million in fines",{"data":6544,"marks":6545,"value":6546,"nodeType":864},{},[]," from companies with inadequate MFA. CISOs sign annual compliance certifications under §500.17 where false certification carries personal liability.",{"data":6548,"content":6549,"nodeType":860},{},[6550],{"data":6551,"marks":6552,"value":6553,"nodeType":864},{},[],"The UK's Data (Use and Access) Act preserves ICO enforcement powers with fines up to £17.5 million or 4% of global turnover, and introduces a new statutory right for individuals to complain directly to controllers about automated decisions, with a 30-day response clock.",{"data":6555,"content":6556,"nodeType":1005},{},[],{"data":6558,"content":6559,"nodeType":1009},{},[6560],{"data":6561,"marks":6562,"value":6564,"nodeType":864},{},[6563],{"type":899},"Where Push maps to these obligations",{"data":6566,"content":6567,"nodeType":860},{},[6568],{"data":6569,"marks":6570,"value":6571,"nodeType":864},{},[],"The five obligation categories above map to specific Push capabilities, some directly, others as supporting evidence. Push's relevance to AI regulation isn't a new product direction. The same capabilities that security teams already use for shadow SaaS discovery, phishing defense, and identity posture hardening are what compliance teams need to demonstrate AI governance.",{"data":6573,"content":6574,"nodeType":1312},{},[6575,6580],{"data":6576,"marks":6577,"value":6579,"nodeType":864},{},[6578],{"type":899},"AI inventory and shadow AI discovery.",{"data":6581,"marks":6582,"value":1171,"nodeType":864},{},[],{"data":6584,"content":6585,"nodeType":860},{},[6586],{"data":6587,"marks":6588,"value":6589,"nodeType":864},{},[],"Push identifies every AI app, AI browser extension, and AI OAuth integration in use across the organization, not from network traffic patterns or procurement records, but from actual observed usage in the browser.",{"data":6591,"content":6592,"nodeType":1312},{},[6593,6598],{"data":6594,"marks":6595,"value":6597,"nodeType":864},{},[6596],{"type":899},"AI usage policy enforcement and literacy evidence.",{"data":6599,"marks":6600,"value":1171,"nodeType":864},{},[],{"data":6602,"content":6603,"nodeType":860},{},[6604],{"data":6605,"marks":6606,"value":6607,"nodeType":864},{},[],"Push's custom app banners deliver contextual policy guidance the moment an employee accesses an AI tool: linking to approved usage policies, data handling guidelines, or approved alternatives. Banners are fully customizable: they can include specific instructions, link to AI policy documents or approved alternatives, and messages from the security team tailored to the tool or user group. ",{"data":6609,"content":6613,"nodeType":996},{"target":6610},{"sys":6611},{"id":6612,"type":1001,"linkType":1002},"4bt65QXDiyTi1eq7wnbHUh",[],{"data":6615,"content":6616,"nodeType":1312},{},[6617,6622],{"data":6618,"marks":6619,"value":6621,"nodeType":864},{},[6620],{"type":899},"AI data exposure controls.",{"data":6623,"marks":6624,"value":1171,"nodeType":864},{},[],{"data":6626,"content":6627,"nodeType":860},{},[6628],{"data":6629,"marks":6630,"value":6631,"nodeType":864},{},[],"Push observes what users type, paste, and upload into AI tools, and can apply real-time controls, warning or blocking when sensitive patterns are detected. This is browser-layer DLP scoped to the AI interaction surface: it won't replace a dedicated DLP platform, but it closes the specific gap that most DLP tools miss because they lack visibility into browser-based AI interactions. Push provides the detection and enforcement layer at the point where the data actually leaves the organization.",{"data":6633,"content":6634,"nodeType":1312},{},[6635,6640],{"data":6636,"marks":6637,"value":6639,"nodeType":864},{},[6638],{"type":899},"MFA verification and phishing defense.",{"data":6641,"marks":6642,"value":1171,"nodeType":864},{},[],{"data":6644,"content":6645,"nodeType":860},{},[6646],{"data":6647,"marks":6648,"value":6649,"nodeType":864},{},[],"Push detects where MFA is missing and identifies the type of MFA in use, directly supporting the push toward phishing-resistant authentication methods.",{"data":6651,"content":6652,"nodeType":860},{},[6653],{"data":6654,"marks":6655,"value":6656,"nodeType":864},{},[],"Push's behavioral phishing detection stops AiTM phishing, credential harvesting, device code phishing, and ClickFix attacks because Push detects malicious behavior in the browser, making it effective against even AI-powered phishing attacks, or those that are delivered over traditionally unmonitored channels such as search engines, social media, or even via phone call.",{"data":6658,"content":6662,"nodeType":996},{"target":6659},{"sys":6660},{"id":6661,"type":1001,"linkType":1002},"3hqv1nql8FvB8j7uRiddqB",[],{"data":6664,"content":6665,"nodeType":1312},{},[6666,6671],{"data":6667,"marks":6668,"value":6670,"nodeType":864},{},[6669],{"type":899},"Third-party AI risk visibility.",{"data":6672,"marks":6673,"value":1171,"nodeType":864},{},[],{"data":6675,"content":6676,"nodeType":860},{},[6677],{"data":6678,"marks":6679,"value":6680,"nodeType":864},{},[],"Push maps exactly which AI services employees have accessed and used, connected to other business apps via OAuth, what permissions those integrations hold, and who authorized them. This surfaces the AI providers that procurement never approved but employees adopted anyway, before they become a compliance finding or a breach vector.",{"data":6682,"content":6683,"nodeType":1005},{},[],{"data":6685,"content":6686,"nodeType":1009},{},[6687],{"data":6688,"marks":6689,"value":6691,"nodeType":864},{},[6690],{"type":899},"The compliance gap is an observability gap",{"data":6693,"content":6694,"nodeType":860},{},[6695],{"data":6696,"marks":6697,"value":6698,"nodeType":864},{},[],"The common failure mode across all five obligation categories is the same: the organization has a policy but can't demonstrate enforcement, because the tooling that would provide evidence operates at the wrong layer. IdP logs show managed authentication but not shadow AI logins. Network tools see traffic to AI domains but not the OAuth consent grants or the data in the clipboard. Annual training records exist but can't prove that an employee received guidance at the point of AI interaction.",{"data":6700,"content":6701,"nodeType":860},{},[6702],{"data":6703,"marks":6704,"value":6705,"nodeType":864},{},[],"Browser-layer telemetry closes each of these gaps because it's where the regulated activity actually happens, and where (with Push) you can observe and control it too.",{"data":6707,"content":6708,"nodeType":860},{},[6709],{"data":6710,"marks":6711,"value":6712,"nodeType":864},{},[],"The regulations covered here are the current landscape, but they aren't the final one. AI governance requirements are accelerating: NIST's AI cybersecurity framework profile is expected this summer, CISA's Five Eyes agentic AI guidance landed in May, and EU member states are still building out their national enforcement regimes.",{"data":6714,"content":6718,"nodeType":996},{"target":6715},{"sys":6716},{"id":6717,"type":1001,"linkType":1002},"OThPeKuFnpoo1e1FAGsFP",[],{"data":6720,"content":6721,"nodeType":1005},{},[],{"data":6723,"content":6724,"nodeType":860},{},[6725],{"data":6726,"marks":6727,"value":1682,"nodeType":864},{},[],{"data":6729,"content":6730,"nodeType":860},{},[6731],{"data":6732,"marks":6733,"value":1689,"nodeType":864},{},[],{"data":6735,"content":6736,"nodeType":860},{},[6737,6740,6747],{"data":6738,"marks":6739,"value":21,"nodeType":864},{},[],{"data":6741,"content":6742,"nodeType":883},{"uri":1700},[6743],{"data":6744,"marks":6745,"value":1703,"nodeType":864},{},[6746],{"type":1455},{"data":6748,"marks":6749,"value":21,"nodeType":864},{},[],"AI regulation is here: how browser visibility and control can achieve compliance","AI regulations across the US, EU, and UK are converging on obligations that most organizations can't meet without browser visibility into AI tool use.","2026-06-02T00:00:00.000Z","browser-visibility-and-control-can-achieve-ai-compliance",{"items":6755},[6756,6758],{"sys":6757,"name":2729},{"id":2728},{"sys":6759,"name":297},{"id":2732},{"items":6761},[6762],{"fullName":6763,"firstName":6764,"jobTitle":6765,"profilePicture":6766},"John Creaton","John","Head of Legal",{"url":6767},"https://images.ctfassets.net/y1cdw1ablpvd/ykgZqhGCFFxufznVsqTiM/6bd977c68dd504642f0064bdb90ebdee/1774636973277.jpeg",{"__typename":2059,"sys":6769,"content":6771,"title":7691,"synopsis":7692,"hashTags":59,"publishedDate":6752,"slug":7693,"tagsCollection":7694,"authorsCollection":7700},{"id":6770},"I5SoVIYsYVgutpLIzZRpC",{"json":6772},{"data":6773,"content":6774,"nodeType":856},{},[6775,6782,6789,6810,6817,6824,6827,6835,6842,6849,6872,6879,6886,6892,6895,6903,6910,6916,6923,6931,6963,6982,6988,6996,7003,7009,7029,7037,7044,7075,7081,7096,7099,7107,7114,7119,7135,7142,7149,7161,7181,7188,7195,7203,7210,7228,7234,7241,7247,7253,7256,7264,7271,7278,7341,7348,7355,7362,7369,7385,7392,7399,7406,7413,7420,7427,7434,7441,7448,7455,7462,7469,7476,7479,7487,7494,7506,7513,7520,7527,7534,7658,7664,7670,7673],{"data":6776,"content":6777,"nodeType":860},{},[6778],{"data":6779,"marks":6780,"value":6781,"nodeType":864},{},[],"When is a fork not a fork? When it's a browser security platform built to solve both problems of the AI era.",{"data":6783,"content":6784,"nodeType":860},{},[6785],{"data":6786,"marks":6787,"value":6788,"nodeType":864},{},[],"Many security leaders are rightly worried about two big problems in the age of AI: AI-enabled attacks targeting their employees via the browser; and employees introducing the risk of data loss through their use of AI tools.",{"data":6790,"content":6791,"nodeType":860},{},[6792,6797,6801,6806],{"data":6793,"marks":6794,"value":6796,"nodeType":864},{},[6795],{"type":899},"For security teams researching browser-based solutions to these challenges, the decision at first looks like a fork in the road: ",{"data":6798,"marks":6799,"value":6800,"nodeType":864},{},[],"Choose a solution that's purpose-built to detect and respond to modern browser-based attacks like AI-enabled phish kits, ClickFix and other *Fix-style attacks, malicious browser extensions, device code phishing, and others; ",{"data":6802,"marks":6803,"value":6805,"nodeType":864},{},[6804],{"type":2246},"or",{"data":6807,"marks":6808,"value":6809,"nodeType":864},{},[]," select an AI governance tool to enforce sensible policies for sensitive data in the browser.",{"data":6811,"content":6812,"nodeType":860},{},[6813],{"data":6814,"marks":6815,"value":6816,"nodeType":864},{},[],"Push solves both of these problems. One platform, one SKU.",{"data":6818,"content":6819,"nodeType":860},{},[6820],{"data":6821,"marks":6822,"value":6823,"nodeType":864},{},[],"In this article, we'll take a look at the two big AI security and data governance problems that security teams are facing and outline how Push solves them in a single solution. We’ll cover what questions to ask as you evaluate browser security solutions, and describe Push's focus on providing foundational telemetry, detections, and controls that allow you to answer the question “What actually happened here?” not just “What policy was violated?”",{"data":6825,"content":6826,"nodeType":1005},{},[],{"data":6828,"content":6829,"nodeType":1009},{},[6830],{"data":6831,"marks":6832,"value":6834,"nodeType":864},{},[6833],{"type":899},"The AI risks every security team is now responsible for",{"data":6836,"content":6837,"nodeType":860},{},[6838],{"data":6839,"marks":6840,"value":6841,"nodeType":864},{},[],"AI is an amplifier, for adversaries and for your employees. Whatever they could do before, they can now do faster, more powerfully, and at scale.",{"data":6843,"content":6844,"nodeType":860},{},[6845],{"data":6846,"marks":6847,"value":6848,"nodeType":864},{},[],"The two risks that every security team now must manage: ",{"data":6850,"content":6851,"nodeType":941},{},[6852,6862],{"data":6853,"content":6854,"nodeType":945},{},[6855],{"data":6856,"content":6857,"nodeType":860},{},[6858],{"data":6859,"marks":6860,"value":6861,"nodeType":864},{},[],"AI is making browser-based attacks faster, cheaper, and harder to detect.",{"data":6863,"content":6864,"nodeType":945},{},[6865],{"data":6866,"content":6867,"nodeType":860},{},[6868],{"data":6869,"marks":6870,"value":6871,"nodeType":864},{},[],"Employee AI adoption is creating data exposure faster than security teams can respond.",{"data":6873,"content":6874,"nodeType":860},{},[6875],{"data":6876,"marks":6877,"value":6878,"nodeType":864},{},[],"Both of these challenges intersect in the same place: The browser. It's the place where adversaries target employees with modern attacks designed to accomplish account takeover and data exfiltration. It's also the place where workers discover and use new AI-enabled apps and introduce risk into the business in the form of data loss, shadow apps, risky browser extensions, and shadow integrations.",{"data":6880,"content":6881,"nodeType":860},{},[6882],{"data":6883,"marks":6884,"value":6885,"nodeType":864},{},[],"To address both problems, security teams need visibility and control in the browser.",{"data":6887,"content":6891,"nodeType":996},{"target":6888},{"sys":6889},{"id":6890,"type":1001,"linkType":1002},"1U2Hmn4XrFpdcxyjxY3aCc",[],{"data":6893,"content":6894,"nodeType":1005},{},[],{"data":6896,"content":6897,"nodeType":1009},{},[6898],{"data":6899,"marks":6900,"value":6902,"nodeType":864},{},[6901],{"type":899},"How AI is transforming attacks",{"data":6904,"content":6905,"nodeType":860},{},[6906],{"data":6907,"marks":6908,"value":6909,"nodeType":864},{},[],"On the adversary side of the equation, adversaries are using AI tooling to rapidly iterate on new attack types or new iterations of existing browser-based TTPs that target employees to achieve account or endpoint compromise — usually with the end goal of harvesting valuable corporate identities in order to exfiltrate data or hold it for ransom.",{"data":6911,"content":6915,"nodeType":996},{"target":6912},{"sys":6913},{"id":6914,"type":1001,"linkType":1002},"G8xv1seFz1wJnY5HpfV6z",[],{"data":6917,"content":6918,"nodeType":860},{},[6919],{"data":6920,"marks":6921,"value":6922,"nodeType":864},{},[],"AI is changing attacks in three key ways.",{"data":6924,"content":6925,"nodeType":1312},{},[6926],{"data":6927,"marks":6928,"value":6930,"nodeType":864},{},[6929],{"type":899},"AI has supercharged the iteration and evolution of adversary tools and techniques",{"data":6932,"content":6933,"nodeType":860},{},[6934,6938,6947,6951,6959],{"data":6935,"marks":6936,"value":6937,"nodeType":864},{},[],"Attackers are using the same AI capabilities as any other engineer who wants to multiply their output. That translates to an array of new attack techniques: multiple increasingly sophisticated variations of the ",{"data":6939,"content":6941,"nodeType":883},{"uri":6940},"https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit/",[6942],{"data":6943,"marks":6944,"value":6946,"nodeType":864},{},[6945],{"type":1455},"ClickFix-style attacks",{"data":6948,"marks":6949,"value":6950,"nodeType":864},{},[]," that use social engineering techniques to get users to unknowingly install malware via malicious scripts; as well as creative ",{"data":6952,"content":6953,"nodeType":883},{"uri":3259},[6954],{"data":6955,"marks":6956,"value":6958,"nodeType":864},{},[6957],{"type":1455},"exploitation of device codes",{"data":6960,"marks":6961,"value":6962,"nodeType":864},{},[],", a legitimate authentication mechanism, that allows attackers to phish access post-authentication.",{"data":6964,"content":6965,"nodeType":860},{},[6966,6970,6978],{"data":6967,"marks":6968,"value":6969,"nodeType":864},{},[],"Device code phishing in particular demonstrates the rapid growth of new techniques, with early documented appearances of the TTP occurring in 2024, and by early the next year, the method had been packaged as a PhaaS offering with GPT-enhanced spear-phishing and customized landing pages. The ",{"data":6971,"content":6973,"nodeType":883},{"uri":6972},"https://www.huntress.com/blog/device-code-phishing-ai-mfa-bypass",[6974],{"data":6975,"marks":6976,"value":6977,"nodeType":864},{},[],"campaign",{"data":6979,"marks":6980,"value":6981,"nodeType":864},{},[]," targeted more than 340 organizations across five countries in March 2026, using personalized AI-generated lures at a scale that would have been impractical to produce manually.",{"data":6983,"content":6987,"nodeType":996},{"target":6984},{"sys":6985},{"id":6986,"type":1001,"linkType":1002},"eNUpU2GtGOcXRrHBKHnLN",[],{"data":6989,"content":6990,"nodeType":1312},{},[6991],{"data":6992,"marks":6993,"value":6995,"nodeType":864},{},[6994],{"type":899},"Infrastructure-based detections are increasingly degraded by AI-enabled approaches",{"data":6997,"content":6998,"nodeType":860},{},[6999],{"data":7000,"marks":7001,"value":7002,"nodeType":864},{},[],"AI has also collapsed the cost and time it takes to build convincing phishing infrastructure: Attackers can vibecode a convincing phishing page in minutes, burn the domain, and regenerate another one before any blocklist updates. ",{"data":7004,"content":7008,"nodeType":996},{"target":7005},{"sys":7006},{"id":7007,"type":1001,"linkType":1002},"2obvOhMWjy64h94tEIbx04",[],{"data":7010,"content":7011,"nodeType":860},{},[7012,7016,7025],{"data":7013,"marks":7014,"value":7015,"nodeType":864},{},[],"The impact on IOC-based detections that rely on infrastructure elements is severe: When elements constantly change, every phishing attack is essentially a zero-day. Complicating the picture further is the increasing use of legitimate cloud platforms like ",{"data":7017,"content":7019,"nodeType":883},{"uri":7018},"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign",[7020],{"data":7021,"marks":7022,"value":7024,"nodeType":864},{},[7023],{"type":1455},"Railway",{"data":7026,"marks":7027,"value":7028,"nodeType":864},{},[],", Cloudflare Workers, and Vercel, which attackers use to host and dynamically rotate attack infrastructure.",{"data":7030,"content":7031,"nodeType":1312},{},[7032],{"data":7033,"marks":7034,"value":7036,"nodeType":864},{},[7035],{"type":899},"AI is making it easier to build and run omni-channel campaigns",{"data":7038,"content":7039,"nodeType":860},{},[7040],{"data":7041,"marks":7042,"value":7043,"nodeType":864},{},[],"Push researchers have written extensively over the last year about malvertising campaigns that serve malicious pages to users via search engine results, enticing them to visit sites designed to steal credentials or deliver malware. ",{"data":7045,"content":7046,"nodeType":860},{},[7047,7051,7060,7064,7071],{"data":7048,"marks":7049,"value":7050,"nodeType":864},{},[],"We've tracked ",{"data":7052,"content":7054,"nodeType":883},{"uri":7053},"https://pushsecurity.com/blog/cyber-criminal-ecosystem-analysis/",[7055],{"data":7056,"marks":7057,"value":7059,"nodeType":864},{},[7058],{"type":1455},"sustained campaigns",{"data":7061,"marks":7062,"value":7063,"nodeType":864},{},[]," impersonating Onfido, TradingView, Ahrefs, Semrush, and others. These campaigns are part of a self-reinforcing criminal ecosystem: Malvertising campaigns paid for by stolen ad accounts, with credential theft that funds the next round of credential theft. And the recent ",{"data":7065,"content":7067,"nodeType":883},{"uri":7066},"https://pushsecurity.com/blog/llmshare-malvertising-campaign/",[7068],{"data":7069,"marks":7070,"value":1555,"nodeType":864},{},[],{"data":7072,"marks":7073,"value":7074,"nodeType":864},{},[]," campaign identified by Push shows how attackers are combining their abuse of AI tools of AI-assisted phishing page creation with malvertising, helping them to spin up lookalike pages quickly and cheaply to serve as convincing lures.",{"data":7076,"content":7080,"nodeType":996},{"target":7077},{"sys":7078},{"id":7079,"type":1001,"linkType":1002},"2Gwj25KBjClQ5u8uiEYuYR",[],{"data":7082,"content":7083,"nodeType":860},{},[7084,7088,7093],{"data":7085,"marks":7086,"value":7087,"nodeType":864},{},[],"These are just a few examples of how phishing has moved beyond the inbox, targeting users through malvertising, SEO poisoning, and social media DMs. Over the last year, Push researchers found that ",{"data":7089,"marks":7090,"value":7092,"nodeType":864},{},[7091],{"type":899},"1 in 3 payloads intercepted by the platform were sent outside of email",{"data":7094,"marks":7095,"value":2924,"nodeType":864},{},[],{"data":7097,"content":7098,"nodeType":1005},{},[],{"data":7100,"content":7101,"nodeType":1009},{},[7102],{"data":7103,"marks":7104,"value":7106,"nodeType":864},{},[7105],{"type":899},"How AI is creating risky employee behaviors ",{"data":7108,"content":7109,"nodeType":860},{},[7110],{"data":7111,"marks":7112,"value":7113,"nodeType":864},{},[],"Meanwhile, on the employee side of the equation, there are three other key concerns that security teams should be paying attention to when it comes to the risks associated with AI use.",{"data":7115,"content":7118,"nodeType":996},{"target":7116},{"sys":7117},{"id":1040,"type":1001,"linkType":1002},[],{"data":7120,"content":7121,"nodeType":1312},{},[7122,7127,7130],{"data":7123,"marks":7124,"value":7126,"nodeType":864},{},[7125],{"type":899},"Data leaving the business via shadow AI",{"data":7128,"marks":7129,"value":1171,"nodeType":864},{},[],{"data":7131,"marks":7132,"value":7134,"nodeType":864},{},[7133],{"type":899},"and AI extensions",{"data":7136,"content":7137,"nodeType":860},{},[7138],{"data":7139,"marks":7140,"value":7141,"nodeType":864},{},[],"Employees are signing up to AI tools directly, beyond the bounds of procurement or security review. That means security teams can't see sensitive data going into LLMs — clipboard pastes of API keys, file uploads to coding assistants, customer data in uploaded spreadsheets, etc.",{"data":7143,"content":7144,"nodeType":860},{},[7145],{"data":7146,"marks":7147,"value":7148,"nodeType":864},{},[],"Most teams also don't have visibility of AI browser extensions, another avenue for data to leave the business. Extensions are also an attack surface in their own right, as previously benign extensions can be compromised by threat actors through account takeover of the extension developer.",{"data":7150,"content":7151,"nodeType":1312},{},[7152,7157],{"data":7153,"marks":7154,"value":7156,"nodeType":864},{},[7155],{"type":899},"Employees using personal accounts on corporate AI app tenants",{"data":7158,"marks":7159,"value":7160,"nodeType":864},{},[]," ",{"data":7162,"content":7163,"nodeType":860},{},[7164,7168,7177],{"data":7165,"marks":7166,"value":7167,"nodeType":864},{},[],"The 2026 ",{"data":7169,"content":7171,"nodeType":883},{"uri":7170},"https://www.verizon.com/business/resources/reports/dbir/",[7172],{"data":7173,"marks":7174,"value":7176,"nodeType":864},{},[7175],{"type":1455},"Verizon DBIR",{"data":7178,"marks":7179,"value":7180,"nodeType":864},{},[]," found that 67% of GenAI users on corporate devices are using non-corporate accounts, and our own data shows that 38% of file uploads to AI tools are made from shadow accounts rather than approved organizational ones.",{"data":7182,"content":7183,"nodeType":860},{},[7184],{"data":7185,"marks":7186,"value":7187,"nodeType":864},{},[],"That means a large number of employees in most organizations are using AI apps with personal accounts, outside of organizational data governance, retention policies, access controls, or basic security oversight. ",{"data":7189,"content":7190,"nodeType":860},{},[7191],{"data":7192,"marks":7193,"value":7194,"nodeType":864},{},[],"The compounding risk is that personal accounts are typically protected by weaker passwords, inconsistent MFA, and credential reuse from other personal services — meaning a compromise of the personal account could give an attacker access to corporate data and tools.",{"data":7196,"content":7197,"nodeType":1312},{},[7198],{"data":7199,"marks":7200,"value":7202,"nodeType":864},{},[7201],{"type":899},"Shadow integrations between AI tools and corporate systems",{"data":7204,"content":7205,"nodeType":860},{},[7206],{"data":7207,"marks":7208,"value":7209,"nodeType":864},{},[],"App-to-app connections accomplished through OAuth are also proliferating faster than most teams can observe and review them. For the average organization, Push sees 17 unique AI app OAuth integrations connected just to Microsoft and Google corporate tenants.",{"data":7211,"content":7212,"nodeType":860},{},[7213,7216,7224],{"data":7214,"marks":7215,"value":2761,"nodeType":864},{},[],{"data":7217,"content":7218,"nodeType":883},{"uri":4103},[7219],{"data":7220,"marks":7221,"value":7223,"nodeType":864},{},[7222],{"type":1455},"recent Vercel breach",{"data":7225,"marks":7226,"value":7227,"nodeType":864},{},[]," illustrates the risks of even a single OAuth connection from a compromised third-party AI SaaS provider. This isn't really a new AI threat so much as a shadow SaaS problem that's accelerating alongside AI adoption, given that AI apps are specifically designed to pull data from one system, analyze it in another, and present it in a third — with MCP connections now creating the same kind of persistent, permissioned access through an authentication protocol (OAuth) that most organizations have no process to review.",{"data":7229,"content":7233,"nodeType":996},{"target":7230},{"sys":7231},{"id":7232,"type":1001,"linkType":1002},"1t2jn4fLxMlH0adMyQqkXk",[],{"data":7235,"content":7236,"nodeType":860},{},[7237],{"data":7238,"marks":7239,"value":7240,"nodeType":864},{},[],"This is the same web of OAuth-connected apps that is being exposed at scale through AI tool integrations. For many organizations, AI tools are now the hub of modern activity that orchestrates and automates across the mesh of cloud apps, which adds a useful perspective on what's changed. ",{"data":7242,"content":7246,"nodeType":996},{"target":7243},{"sys":7244},{"id":7245,"type":1001,"linkType":1002},"6cRnPkGdwWXRWcct6LfMzo",[],{"data":7248,"content":7252,"nodeType":996},{"target":7249},{"sys":7250},{"id":7251,"type":1001,"linkType":1002},"5WQZNpnPETWeys1VqubVW",[],{"data":7254,"content":7255,"nodeType":1005},{},[],{"data":7257,"content":7258,"nodeType":1009},{},[7259],{"data":7260,"marks":7261,"value":7263,"nodeType":864},{},[7262],{"type":899},"What to ask when evaluating browser-based AI visibility and control solutions",{"data":7265,"content":7266,"nodeType":860},{},[7267],{"data":7268,"marks":7269,"value":7270,"nodeType":864},{},[],"When you're evaluating AI visibility and control platforms that operate in the browser, there are two lines of questioning that can be useful to unpack.",{"data":7272,"content":7273,"nodeType":860},{},[7274],{"data":7275,"marks":7276,"value":7277,"nodeType":864},{},[],"The first is the tactical basics: What use cases does the product cover, and how quickly will you see value? In this category, you'll likely be looking for:",{"data":7279,"content":7280,"nodeType":941},{},[7281,7296,7311,7326],{"data":7282,"content":7283,"nodeType":945},{},[7284],{"data":7285,"content":7286,"nodeType":860},{},[7287,7292],{"data":7288,"marks":7289,"value":7291,"nodeType":864},{},[7290],{"type":899},"Depth of visibility:",{"data":7293,"marks":7294,"value":7295,"nodeType":864},{},[]," Can the solution observe both corporate and personal account usage of AI apps? Does the solution work with all major browsers, including emerging AI browsers? Does the solution automatically classify AI apps and automatically discover shadow AI?",{"data":7297,"content":7298,"nodeType":945},{},[7299],{"data":7300,"content":7301,"nodeType":860},{},[7302,7307],{"data":7303,"marks":7304,"value":7306,"nodeType":864},{},[7305],{"type":899},"Granularity of controls:",{"data":7308,"marks":7309,"value":7310,"nodeType":864},{},[]," Does the solution support visibility and control over clipboard interactions, allowing you to identify sensitive data strings like personal access tokens (PATs) or API keys? Does the solution allow you to set multiple enforcement modes (monitor, warn, block) and carve out exceptions for tools, teams and individuals where necessary? ",{"data":7312,"content":7313,"nodeType":945},{},[7314],{"data":7315,"content":7316,"nodeType":860},{},[7317,7322],{"data":7318,"marks":7319,"value":7321,"nodeType":864},{},[7320],{"type":899},"Ease of deployment:",{"data":7323,"marks":7324,"value":7325,"nodeType":864},{},[]," How is the solution deployed? Browser extension-based solutions like Push can be deployed at scale in an hour. Solutions that require an endpoint agent or a complete browser replacement will be a heavier lift.",{"data":7327,"content":7328,"nodeType":945},{},[7329],{"data":7330,"content":7331,"nodeType":860},{},[7332,7337],{"data":7333,"marks":7334,"value":7336,"nodeType":864},{},[7335],{"type":899},"Scope of coverage:",{"data":7338,"marks":7339,"value":7340,"nodeType":864},{},[]," Does the solution only enforce policy around AI usage, or does it also prevent AI-enabled attacks in the browser? ",{"data":7342,"content":7343,"nodeType":860},{},[7344],{"data":7345,"marks":7346,"value":7347,"nodeType":864},{},[],"The second set of questions is more about the underlying architectural choices a product has made, and how those translate into actionable intelligence for security teams — or where there may be blind spots. In this category, you will want to ask:",{"data":7349,"content":7350,"nodeType":1312},{},[7351],{"data":7352,"marks":7353,"value":7354,"nodeType":864},{},[],"Does the tool capture AI interactions that didn’t trigger a policy violation — or only the ones it blocked?",{"data":7356,"content":7357,"nodeType":860},{},[7358],{"data":7359,"marks":7360,"value":7361,"nodeType":864},{},[],"This is the most useful diagnostic if you're focused on understanding the wider security meaning and impact of an AI interaction, not just whether it violated a policy. ",{"data":7363,"content":7364,"nodeType":860},{},[7365],{"data":7366,"marks":7367,"value":7368,"nodeType":864},{},[],"Enforcement-first tools record what they stopped: blocked uploads, attempted usage of unapproved apps, flagged file names, etc. ",{"data":7370,"content":7371,"nodeType":860},{},[7372,7376,7381],{"data":7373,"marks":7374,"value":7375,"nodeType":864},{},[],"That's useful for compliance reporting but incomplete for security investigation, because ",{"data":7377,"marks":7378,"value":7380,"nodeType":864},{},[7379],{"type":899},"the most significant events are often the ones that looked normal at the time",{"data":7382,"marks":7383,"value":7384,"nodeType":864},{},[],": A user whose behavior shifted gradually over weeks before a resignation. An approved AI browser extension that updates its permissions, putting it in risky territory. An OAuth consent grant that was technically permitted but shouldn't have been.",{"data":7386,"content":7387,"nodeType":860},{},[7388],{"data":7389,"marks":7390,"value":7391,"nodeType":864},{},[],"Ask whether the tool can collect user behavior telemetry, file upload and download activity, and AI usage logs for permitted events — not just policy violations — and whether that telemetry can be forwarded to your SIEM. ",{"data":7393,"content":7394,"nodeType":860},{},[7395],{"data":7396,"marks":7397,"value":7398,"nodeType":864},{},[],"One approach gives you an investigation tool. The other gives you compliance alerts without deeper context.",{"data":7400,"content":7401,"nodeType":1312},{},[7402],{"data":7403,"marks":7404,"value":7405,"nodeType":864},{},[],"When an AI agent requests OAuth permissions to access your organization's data, does the tool capture the consent flow — what scopes were requested on which app, which user initiated the consent, and what was the outcome?",{"data":7407,"content":7408,"nodeType":860},{},[7409],{"data":7410,"marks":7411,"value":7412,"nodeType":864},{},[],"Most enforcement-first tools treat OAuth as a binary: approved app or blocked app. That was a reasonable model when OAuth grants were primarily app-to-app integrations managed by IT. It isn't sufficient for agentic AI.",{"data":7414,"content":7415,"nodeType":860},{},[7416],{"data":7417,"marks":7418,"value":7419,"nodeType":864},{},[],"AI agents request OAuth permissions to access organizational data on behalf of users. These are user-initiated consent grants that happen inside browser sessions, often with broad scopes, and frequently without security team awareness. The right tool needs to capture the consent event itself: what permissions were requested, what scopes were granted, who approved them, and what application received them. ",{"data":7421,"content":7422,"nodeType":860},{},[7423],{"data":7424,"marks":7425,"value":7426,"nodeType":864},{},[],"Ask whether the tool monitors OAuth consent flows across authorization servers, whether it can warn or block consent grants in real time based on policy, and whether that coverage extends to AI-enabled apps and MCP connections.",{"data":7428,"content":7429,"nodeType":1312},{},[7430],{"data":7431,"marks":7432,"value":7433,"nodeType":864},{},[],"When a new browser attack technique emerges that no tool has a signature for, how long does it take the platform to detect it — and can you show a specific example?",{"data":7435,"content":7436,"nodeType":860},{},[7437],{"data":7438,"marks":7439,"value":7440,"nodeType":864},{},[],"Attackers are rotating infrastructure in hours and using AI to generate new lures and phishing pages at scale. A detection model built on blocklists, reputation feeds, and known-bad indicators is architecturally behind any novel technique because by the time the indicator appears on a feed, the attacker has already moved on.",{"data":7442,"content":7443,"nodeType":860},{},[7444],{"data":7445,"marks":7446,"value":7447,"nodeType":864},{},[],"Ask vendors to show you a specific detection that fired on a novel technique before the infrastructure appeared on any threat feed.",{"data":7449,"content":7450,"nodeType":1312},{},[7451],{"data":7452,"marks":7453,"value":7454,"nodeType":864},{},[],"What browser telemetry reaches your SIEM — just alerts, or the underlying session data that makes those alerts investigable?",{"data":7456,"content":7457,"nodeType":860},{},[7458],{"data":7459,"marks":7460,"value":7461,"nodeType":864},{},[],"Ask to see a sample SIEM event from a real detection. Many browser security tools integrate with SIEMs, but the depth of what they forward varies a lot. ",{"data":7463,"content":7464,"nodeType":860},{},[7465],{"data":7466,"marks":7467,"value":7468,"nodeType":864},{},[],"Some send alert metadata that captures policy violations, timestamps, and involved users. Others forward a broader set of telemetry for deeper context — credential reuse, app logins, newly installed extensions, detected phishing kits, file uploads, clipboard activity, OAuth consent flows, file downloads, etc. ",{"data":7470,"content":7471,"nodeType":860},{},[7472],{"data":7473,"marks":7474,"value":7475,"nodeType":864},{},[],"The difference determines whether your SOC team can easily correlate signals from the browser-based tool with other layers of their stack and begin an investigation from the SIEM event itself — or whether they need to pivot back into the vendor's console for the actual evidence.",{"data":7477,"content":7478,"nodeType":1005},{},[],{"data":7480,"content":7481,"nodeType":1009},{},[7482],{"data":7483,"marks":7484,"value":7486,"nodeType":864},{},[7485],{"type":899},"AI visibility and control is a feature of the right browser security platform, not a separate purchase",{"data":7488,"content":7489,"nodeType":860},{},[7490],{"data":7491,"marks":7492,"value":7493,"nodeType":864},{},[],"Ultimately, the choice of browser platform for solving the two big problems of the AI era comes down to whether you need broader attack coverage and telemetry context in order to secure your organization, or whether a policy-based approach is enough. ",{"data":7495,"content":7496,"nodeType":860},{},[7497,7501],{"data":7498,"marks":7499,"value":7500,"nodeType":864},{},[],"Push treats the challenges of stopping AI-enabled attacks and providing visibility and control over AI usage as features that extend naturally from the platform's underlying architectural model: Rich browser-layer telemetry in ",{"data":7502,"marks":7503,"value":7505,"nodeType":864},{},[7504],{"type":899},"a single tool that helps security teams answer the question “What actually happened here?” not just “What policy was violated?”",{"data":7507,"content":7508,"nodeType":860},{},[7509],{"data":7510,"marks":7511,"value":7512,"nodeType":864},{},[],"This unified architecture matters because the AI control problem and the browser threat detection problem share a root cause: Security-relevant activity is happening inside browser sessions that most tools can't see. ",{"data":7514,"content":7515,"nodeType":860},{},[7516],{"data":7517,"marks":7518,"value":7519,"nodeType":864},{},[],"A standalone AI governance tool can tell you which AI apps are in use and whether employees violated a usage policy. It can't tell you whether the OAuth grant an AI agent just received was part of a broader pattern that includes credential entry on an unfamiliar domain, a clipboard paste from an internal document, and a login to a shadow SaaS app — all in the same session, all visible in the same telemetry stream. ",{"data":7521,"content":7522,"nodeType":860},{},[7523],{"data":7524,"marks":7525,"value":7526,"nodeType":864},{},[],"Separating AI governance from browser security means maintaining two tools that each only see half the picture. ",{"data":7528,"content":7529,"nodeType":1312},{},[7530],{"data":7531,"marks":7532,"value":7533,"nodeType":864},{},[],"How Push can help",{"data":7535,"content":7536,"nodeType":941},{},[7537,7560,7583,7605,7615,7625,7635],{"data":7538,"content":7539,"nodeType":945},{},[7540],{"data":7541,"content":7542,"nodeType":860},{},[7543,7547,7556],{"data":7544,"marks":7545,"value":7546,"nodeType":864},{},[],"Block emerging ",{"data":7548,"content":7550,"nodeType":883},{"uri":7549},"https://pushsecurity.com/blog/introducing-the-browser-and-identity-attacks-matrix/",[7551],{"data":7552,"marks":7553,"value":7555,"nodeType":864},{},[7554],{"type":1455},"browser-based attack techniques",{"data":7557,"marks":7558,"value":7559,"nodeType":864},{},[],", including AI-enabled phishing and quickly evolving *Fix-style attacks.",{"data":7561,"content":7562,"nodeType":945},{},[7563],{"data":7564,"content":7565,"nodeType":860},{},[7566,7570,7579],{"data":7567,"marks":7568,"value":7569,"nodeType":864},{},[],"Benefit from Push's ",{"data":7571,"content":7573,"nodeType":883},{"uri":7572},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline/",[7574],{"data":7575,"marks":7576,"value":7578,"nodeType":864},{},[7577],{"type":1455},"agentic detection pipeline",{"data":7580,"marks":7581,"value":7582,"nodeType":864},{},[],", which continuously hunts across customer environments to identify emerging threats and ship new detections.",{"data":7584,"content":7585,"nodeType":945},{},[7586],{"data":7587,"content":7588,"nodeType":860},{},[7589,7592,7601],{"data":7590,"marks":7591,"value":21,"nodeType":864},{},[],{"data":7593,"content":7595,"nodeType":883},{"uri":7594},"https://pushsecurity.com/help/audience/engineering/rest-v1",[7596],{"data":7597,"marks":7598,"value":7600,"nodeType":864},{},[7599],{"type":1455},"Stream telemetry",{"data":7602,"marks":7603,"value":7604,"nodeType":864},{},[]," to your SIEM for a wide variety of events, including attack detections; newly installed browser extensions or newly adopted apps; updates to extension permissions; file uploads and downloads; clipboard pastes; app logins; credential reuse; OAuth consents; and more.",{"data":7606,"content":7607,"nodeType":945},{},[7608],{"data":7609,"content":7610,"nodeType":860},{},[7611],{"data":7612,"marks":7613,"value":7614,"nodeType":864},{},[],"Block file uploads and downloads.",{"data":7616,"content":7617,"nodeType":945},{},[7618],{"data":7619,"content":7620,"nodeType":860},{},[7621],{"data":7622,"marks":7623,"value":7624,"nodeType":864},{},[],"Block clipboard pastes of sensitive data, with regex-based patterns you can define.",{"data":7626,"content":7627,"nodeType":945},{},[7628],{"data":7629,"content":7630,"nodeType":860},{},[7631],{"data":7632,"marks":7633,"value":7634,"nodeType":864},{},[],"Monitor for or block unauthorized MCP connections.",{"data":7636,"content":7637,"nodeType":945},{},[7638],{"data":7639,"content":7640,"nodeType":860},{},[7641,7645,7654],{"data":7642,"marks":7643,"value":7644,"nodeType":864},{},[],"Write your own ",{"data":7646,"content":7648,"nodeType":883},{"uri":7647},"https://pushsecurity.com/help/audience/engineering/resources/custom-detections",[7649],{"data":7650,"marks":7651,"value":7653,"nodeType":864},{},[7652],{"type":1455},"custom YAML rules",{"data":7655,"marks":7656,"value":7657,"nodeType":864},{},[]," targeting specific elements of the page DOM, web requests and responses, HTTP headers such as cookies, and a lot more.",{"data":7659,"content":7660,"nodeType":860},{},[7661],{"data":7662,"marks":7663,"value":21,"nodeType":864},{},[],{"data":7665,"content":7669,"nodeType":996},{"target":7666},{"sys":7667},{"id":7668,"type":1001,"linkType":1002},"7AwQv7bLbARq6mdAgv7uGq",[],{"data":7671,"content":7672,"nodeType":1005},{},[],{"data":7674,"content":7675,"nodeType":860},{},[7676,7680,7688],{"data":7677,"marks":7678,"value":7679,"nodeType":864},{},[],"If you'd like to learn more about Push, ",{"data":7681,"content":7682,"nodeType":883},{"uri":1700},[7683],{"data":7684,"marks":7685,"value":7687,"nodeType":864},{},[7686],{"type":1455},"book a live demo",{"data":7689,"marks":7690,"value":2924,"nodeType":864},{},[],"Why you can't control AI without being in the browser","Why the right browser security tool makes a separate AI visibility and control purchase unnecessary — and how to decide what you actually need.","why-you-cant-control-ai-without-being-in-the-browser",{"items":7695},[7696,7698],{"sys":7697,"name":297},{"id":2732},{"sys":7699,"name":2729},{"id":2728},{"items":7701},[7702],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":7703},{"url":853},{"__typename":2059,"sys":7705,"content":7706,"title":4865,"synopsis":4866,"hashTags":59,"publishedDate":4867,"slug":4868,"tagsCollection":8775,"authorsCollection":8781},{"id":3628},{"json":7707},{"data":7708,"content":7709,"nodeType":856},{},[7710,7723,7728,7734,7740,7745,7748,7755,7762,7777,7815,7820,7833,7836,7843,7850,7872,7904,7910,7913,7920,7927,7933,7938,7944,7947,7954,7961,7995,8025,8031,8034,8041,8048,8068,8074,8113,8119,8122,8129,8136,8172,8178,8183,8186,8193,8200,8226,8232,8237,8243,8246,8253,8260,8283,8289,8295,8301,8304,8311,8318,8324,8329,8335,8356,8379,8382,8389,8396,8402,8408,8411,8418,8473,8476,8483,8489,8757,8760],{"data":7711,"content":7712,"nodeType":860},{},[7713,7716,7720],{"data":7714,"marks":7715,"value":3639,"nodeType":864},{},[],{"data":7717,"marks":7718,"value":3644,"nodeType":864},{},[7719],{"type":899},{"data":7721,"marks":7722,"value":3648,"nodeType":864},{},[],{"data":7724,"content":7727,"nodeType":996},{"target":7725},{"sys":7726},{"id":3653,"type":1001,"linkType":1002},[],{"data":7729,"content":7730,"nodeType":860},{},[7731],{"data":7732,"marks":7733,"value":3661,"nodeType":864},{},[],{"data":7735,"content":7736,"nodeType":860},{},[7737],{"data":7738,"marks":7739,"value":3668,"nodeType":864},{},[],{"data":7741,"content":7744,"nodeType":996},{"target":7742},{"sys":7743},{"id":3673,"type":1001,"linkType":1002},[],{"data":7746,"content":7747,"nodeType":1005},{},[],{"data":7749,"content":7750,"nodeType":1009},{},[7751],{"data":7752,"marks":7753,"value":3685,"nodeType":864},{},[7754],{"type":899},{"data":7756,"content":7757,"nodeType":860},{},[7758],{"data":7759,"marks":7760,"value":3693,"nodeType":864},{},[7761],{"type":899},{"data":7763,"content":7764,"nodeType":860},{},[7765,7768,7774],{"data":7766,"marks":7767,"value":3700,"nodeType":864},{},[],{"data":7769,"content":7770,"nodeType":883},{"uri":3703},[7771],{"data":7772,"marks":7773,"value":3708,"nodeType":864},{},[],{"data":7775,"marks":7776,"value":3712,"nodeType":864},{},[],{"data":7778,"content":7779,"nodeType":860},{},[7780,7783,7789,7792,7796,7799,7803,7806,7812],{"data":7781,"marks":7782,"value":3719,"nodeType":864},{},[],{"data":7784,"content":7785,"nodeType":883},{"uri":3722},[7786],{"data":7787,"marks":7788,"value":3727,"nodeType":864},{},[],{"data":7790,"marks":7791,"value":3731,"nodeType":864},{},[],{"data":7793,"marks":7794,"value":3736,"nodeType":864},{},[7795],{"type":899},{"data":7797,"marks":7798,"value":2232,"nodeType":864},{},[],{"data":7800,"marks":7801,"value":3744,"nodeType":864},{},[7802],{"type":899},{"data":7804,"marks":7805,"value":3748,"nodeType":864},{},[],{"data":7807,"content":7808,"nodeType":883},{"uri":3751},[7809],{"data":7810,"marks":7811,"value":3756,"nodeType":864},{},[],{"data":7813,"marks":7814,"value":3760,"nodeType":864},{},[],{"data":7816,"content":7819,"nodeType":996},{"target":7817},{"sys":7818},{"id":3765,"type":1001,"linkType":1002},[],{"data":7821,"content":7822,"nodeType":860},{},[7823,7826,7830],{"data":7824,"marks":7825,"value":3773,"nodeType":864},{},[],{"data":7827,"marks":7828,"value":3778,"nodeType":864},{},[7829],{"type":899},{"data":7831,"marks":7832,"value":2924,"nodeType":864},{},[],{"data":7834,"content":7835,"nodeType":1005},{},[],{"data":7837,"content":7838,"nodeType":1009},{},[7839],{"data":7840,"marks":7841,"value":3792,"nodeType":864},{},[7842],{"type":899},{"data":7844,"content":7845,"nodeType":860},{},[7846],{"data":7847,"marks":7848,"value":3693,"nodeType":864},{},[7849],{"type":899},{"data":7851,"content":7852,"nodeType":860},{},[7853,7856,7862,7865,7869],{"data":7854,"marks":7855,"value":3806,"nodeType":864},{},[],{"data":7857,"content":7858,"nodeType":883},{"uri":3809},[7859],{"data":7860,"marks":7861,"value":3814,"nodeType":864},{},[],{"data":7863,"marks":7864,"value":3818,"nodeType":864},{},[],{"data":7866,"marks":7867,"value":3823,"nodeType":864},{},[7868],{"type":899},{"data":7870,"marks":7871,"value":3827,"nodeType":864},{},[],{"data":7873,"content":7874,"nodeType":860},{},[7875,7878,7884,7887,7891,7894,7901],{"data":7876,"marks":7877,"value":3834,"nodeType":864},{},[],{"data":7879,"content":7880,"nodeType":883},{"uri":3837},[7881],{"data":7882,"marks":7883,"value":3842,"nodeType":864},{},[],{"data":7885,"marks":7886,"value":3846,"nodeType":864},{},[],{"data":7888,"marks":7889,"value":3851,"nodeType":864},{},[7890],{"type":899},{"data":7892,"marks":7893,"value":3855,"nodeType":864},{},[],{"data":7895,"content":7896,"nodeType":883},{"uri":3858},[7897],{"data":7898,"marks":7899,"value":3864,"nodeType":864},{},[7900],{"type":899},{"data":7902,"marks":7903,"value":3868,"nodeType":864},{},[],{"data":7905,"content":7906,"nodeType":860},{},[7907],{"data":7908,"marks":7909,"value":3875,"nodeType":864},{},[],{"data":7911,"content":7912,"nodeType":1005},{},[],{"data":7914,"content":7915,"nodeType":1009},{},[7916],{"data":7917,"marks":7918,"value":3886,"nodeType":864},{},[7919],{"type":899},{"data":7921,"content":7922,"nodeType":860},{},[7923],{"data":7924,"marks":7925,"value":3894,"nodeType":864},{},[7926],{"type":899},{"data":7928,"content":7929,"nodeType":860},{},[7930],{"data":7931,"marks":7932,"value":3901,"nodeType":864},{},[],{"data":7934,"content":7937,"nodeType":996},{"target":7935},{"sys":7936},{"id":3906,"type":1001,"linkType":1002},[],{"data":7939,"content":7940,"nodeType":860},{},[7941],{"data":7942,"marks":7943,"value":3914,"nodeType":864},{},[],{"data":7945,"content":7946,"nodeType":1005},{},[],{"data":7948,"content":7949,"nodeType":1009},{},[7950],{"data":7951,"marks":7952,"value":3925,"nodeType":864},{},[7953],{"type":899},{"data":7955,"content":7956,"nodeType":860},{},[7957],{"data":7958,"marks":7959,"value":3894,"nodeType":864},{},[7960],{"type":899},{"data":7962,"content":7963,"nodeType":860},{},[7964,7967,7974,7977,7983,7986,7992],{"data":7965,"marks":7966,"value":3939,"nodeType":864},{},[],{"data":7968,"content":7969,"nodeType":883},{"uri":3942},[7970],{"data":7971,"marks":7972,"value":3948,"nodeType":864},{},[7973],{"type":1455},{"data":7975,"marks":7976,"value":3731,"nodeType":864},{},[],{"data":7978,"content":7979,"nodeType":883},{"uri":3954},[7980],{"data":7981,"marks":7982,"value":3959,"nodeType":864},{},[],{"data":7984,"marks":7985,"value":3731,"nodeType":864},{},[],{"data":7987,"content":7988,"nodeType":883},{"uri":3965},[7989],{"data":7990,"marks":7991,"value":3970,"nodeType":864},{},[],{"data":7993,"marks":7994,"value":3974,"nodeType":864},{},[],{"data":7996,"content":7997,"nodeType":860},{},[7998,8001,8008,8011,8015,8018,8022],{"data":7999,"marks":8000,"value":21,"nodeType":864},{},[],{"data":8002,"content":8003,"nodeType":883},{"uri":2411},[8004],{"data":8005,"marks":8006,"value":3988,"nodeType":864},{},[8007],{"type":1455},{"data":8009,"marks":8010,"value":3992,"nodeType":864},{},[],{"data":8012,"marks":8013,"value":3997,"nodeType":864},{},[8014],{"type":899},{"data":8016,"marks":8017,"value":4001,"nodeType":864},{},[],{"data":8019,"marks":8020,"value":4006,"nodeType":864},{},[8021],{"type":2246},{"data":8023,"marks":8024,"value":4010,"nodeType":864},{},[],{"data":8026,"content":8027,"nodeType":860},{},[8028],{"data":8029,"marks":8030,"value":4017,"nodeType":864},{},[],{"data":8032,"content":8033,"nodeType":1005},{},[],{"data":8035,"content":8036,"nodeType":1009},{},[8037],{"data":8038,"marks":8039,"value":4028,"nodeType":864},{},[8040],{"type":899},{"data":8042,"content":8043,"nodeType":860},{},[8044],{"data":8045,"marks":8046,"value":3894,"nodeType":864},{},[8047],{"type":899},{"data":8049,"content":8050,"nodeType":860},{},[8051,8054,8058,8061,8065],{"data":8052,"marks":8053,"value":4042,"nodeType":864},{},[],{"data":8055,"marks":8056,"value":4047,"nodeType":864},{},[8057],{"type":2246},{"data":8059,"marks":8060,"value":4051,"nodeType":864},{},[],{"data":8062,"marks":8063,"value":4056,"nodeType":864},{},[8064],{"type":2246},{"data":8066,"marks":8067,"value":4060,"nodeType":864},{},[],{"data":8069,"content":8070,"nodeType":860},{},[8071],{"data":8072,"marks":8073,"value":4067,"nodeType":864},{},[],{"data":8075,"content":8076,"nodeType":941},{},[8077,8095],{"data":8078,"content":8079,"nodeType":945},{},[8080],{"data":8081,"content":8082,"nodeType":860},{},[8083,8086,8092],{"data":8084,"marks":8085,"value":2761,"nodeType":864},{},[],{"data":8087,"content":8088,"nodeType":883},{"uri":4082},[8089],{"data":8090,"marks":8091,"value":4087,"nodeType":864},{},[],{"data":8093,"marks":8094,"value":4091,"nodeType":864},{},[],{"data":8096,"content":8097,"nodeType":945},{},[8098],{"data":8099,"content":8100,"nodeType":860},{},[8101,8104,8110],{"data":8102,"marks":8103,"value":2761,"nodeType":864},{},[],{"data":8105,"content":8106,"nodeType":883},{"uri":4103},[8107],{"data":8108,"marks":8109,"value":4108,"nodeType":864},{},[],{"data":8111,"marks":8112,"value":4112,"nodeType":864},{},[],{"data":8114,"content":8115,"nodeType":860},{},[8116],{"data":8117,"marks":8118,"value":4119,"nodeType":864},{},[],{"data":8120,"content":8121,"nodeType":1005},{},[],{"data":8123,"content":8124,"nodeType":1009},{},[8125],{"data":8126,"marks":8127,"value":4130,"nodeType":864},{},[8128],{"type":899},{"data":8130,"content":8131,"nodeType":860},{},[8132],{"data":8133,"marks":8134,"value":4138,"nodeType":864},{},[8135],{"type":899},{"data":8137,"content":8138,"nodeType":860},{},[8139,8142,8146,8149,8155,8158,8162,8165,8169],{"data":8140,"marks":8141,"value":4145,"nodeType":864},{},[],{"data":8143,"marks":8144,"value":4150,"nodeType":864},{},[8145],{"type":899},{"data":8147,"marks":8148,"value":4154,"nodeType":864},{},[],{"data":8150,"content":8151,"nodeType":883},{"uri":3237},[8152],{"data":8153,"marks":8154,"value":4161,"nodeType":864},{},[],{"data":8156,"marks":8157,"value":4165,"nodeType":864},{},[],{"data":8159,"marks":8160,"value":4170,"nodeType":864},{},[8161],{"type":899},{"data":8163,"marks":8164,"value":4174,"nodeType":864},{},[],{"data":8166,"marks":8167,"value":4179,"nodeType":864},{},[8168],{"type":899},{"data":8170,"marks":8171,"value":4183,"nodeType":864},{},[],{"data":8173,"content":8174,"nodeType":860},{},[8175],{"data":8176,"marks":8177,"value":4190,"nodeType":864},{},[],{"data":8179,"content":8182,"nodeType":996},{"target":8180},{"sys":8181},{"id":4195,"type":1001,"linkType":1002},[],{"data":8184,"content":8185,"nodeType":1005},{},[],{"data":8187,"content":8188,"nodeType":1009},{},[8189],{"data":8190,"marks":8191,"value":4207,"nodeType":864},{},[8192],{"type":899},{"data":8194,"content":8195,"nodeType":860},{},[8196],{"data":8197,"marks":8198,"value":4215,"nodeType":864},{},[8199],{"type":899},{"data":8201,"content":8202,"nodeType":860},{},[8203,8206,8213,8216,8223],{"data":8204,"marks":8205,"value":4222,"nodeType":864},{},[],{"data":8207,"content":8208,"nodeType":883},{"uri":2561},[8209],{"data":8210,"marks":8211,"value":4230,"nodeType":864},{},[8212],{"type":899},{"data":8214,"marks":8215,"value":4234,"nodeType":864},{},[],{"data":8217,"content":8218,"nodeType":883},{"uri":4237},[8219],{"data":8220,"marks":8221,"value":4243,"nodeType":864},{},[8222],{"type":899},{"data":8224,"marks":8225,"value":4247,"nodeType":864},{},[],{"data":8227,"content":8228,"nodeType":860},{},[8229],{"data":8230,"marks":8231,"value":4254,"nodeType":864},{},[],{"data":8233,"content":8236,"nodeType":996},{"target":8234},{"sys":8235},{"id":4259,"type":1001,"linkType":1002},[],{"data":8238,"content":8239,"nodeType":860},{},[8240],{"data":8241,"marks":8242,"value":4267,"nodeType":864},{},[],{"data":8244,"content":8245,"nodeType":1005},{},[],{"data":8247,"content":8248,"nodeType":1009},{},[8249],{"data":8250,"marks":8251,"value":4278,"nodeType":864},{},[8252],{"type":899},{"data":8254,"content":8255,"nodeType":860},{},[8256],{"data":8257,"marks":8258,"value":4286,"nodeType":864},{},[8259],{"type":899},{"data":8261,"content":8262,"nodeType":860},{},[8263,8266,8270,8273,8280],{"data":8264,"marks":8265,"value":4293,"nodeType":864},{},[],{"data":8267,"marks":8268,"value":4298,"nodeType":864},{},[8269],{"type":2246},{"data":8271,"marks":8272,"value":4302,"nodeType":864},{},[],{"data":8274,"content":8275,"nodeType":883},{"uri":4305},[8276],{"data":8277,"marks":8278,"value":4311,"nodeType":864},{},[8279],{"type":899},{"data":8281,"marks":8282,"value":4315,"nodeType":864},{},[],{"data":8284,"content":8285,"nodeType":860},{},[8286],{"data":8287,"marks":8288,"value":4322,"nodeType":864},{},[],{"data":8290,"content":8291,"nodeType":860},{},[8292],{"data":8293,"marks":8294,"value":4329,"nodeType":864},{},[],{"data":8296,"content":8297,"nodeType":860},{},[8298],{"data":8299,"marks":8300,"value":4336,"nodeType":864},{},[],{"data":8302,"content":8303,"nodeType":1005},{},[],{"data":8305,"content":8306,"nodeType":1009},{},[8307],{"data":8308,"marks":8309,"value":4347,"nodeType":864},{},[8310],{"type":899},{"data":8312,"content":8313,"nodeType":860},{},[8314],{"data":8315,"marks":8316,"value":4355,"nodeType":864},{},[8317],{"type":899},{"data":8319,"content":8320,"nodeType":860},{},[8321],{"data":8322,"marks":8323,"value":4362,"nodeType":864},{},[],{"data":8325,"content":8328,"nodeType":996},{"target":8326},{"sys":8327},{"id":4367,"type":1001,"linkType":1002},[],{"data":8330,"content":8331,"nodeType":860},{},[8332],{"data":8333,"marks":8334,"value":4375,"nodeType":864},{},[],{"data":8336,"content":8337,"nodeType":941},{},[8338,8347],{"data":8339,"content":8340,"nodeType":945},{},[8341],{"data":8342,"content":8343,"nodeType":860},{},[8344],{"data":8345,"marks":8346,"value":4388,"nodeType":864},{},[],{"data":8348,"content":8349,"nodeType":945},{},[8350],{"data":8351,"content":8352,"nodeType":860},{},[8353],{"data":8354,"marks":8355,"value":4398,"nodeType":864},{},[],{"data":8357,"content":8358,"nodeType":860},{},[8359,8362,8369,8372,8376],{"data":8360,"marks":8361,"value":4405,"nodeType":864},{},[],{"data":8363,"content":8364,"nodeType":883},{"uri":4408},[8365],{"data":8366,"marks":8367,"value":4414,"nodeType":864},{},[8368],{"type":899},{"data":8370,"marks":8371,"value":4418,"nodeType":864},{},[],{"data":8373,"marks":8374,"value":4423,"nodeType":864},{},[8375],{"type":2246},{"data":8377,"marks":8378,"value":4427,"nodeType":864},{},[],{"data":8380,"content":8381,"nodeType":1005},{},[],{"data":8383,"content":8384,"nodeType":1009},{},[8385],{"data":8386,"marks":8387,"value":4438,"nodeType":864},{},[8388],{"type":899},{"data":8390,"content":8391,"nodeType":860},{},[8392],{"data":8393,"marks":8394,"value":4446,"nodeType":864},{},[8395],{"type":899},{"data":8397,"content":8398,"nodeType":860},{},[8399],{"data":8400,"marks":8401,"value":4453,"nodeType":864},{},[],{"data":8403,"content":8404,"nodeType":860},{},[8405],{"data":8406,"marks":8407,"value":4460,"nodeType":864},{},[],{"data":8409,"content":8410,"nodeType":1005},{},[],{"data":8412,"content":8413,"nodeType":1009},{},[8414],{"data":8415,"marks":8416,"value":4471,"nodeType":864},{},[8417],{"type":899},{"data":8419,"content":8420,"nodeType":941},{},[8421,8434,8447,8460],{"data":8422,"content":8423,"nodeType":945},{},[8424],{"data":8425,"content":8426,"nodeType":860},{},[8427,8431],{"data":8428,"marks":8429,"value":4485,"nodeType":864},{},[8430],{"type":899},{"data":8432,"marks":8433,"value":4489,"nodeType":864},{},[],{"data":8435,"content":8436,"nodeType":945},{},[8437],{"data":8438,"content":8439,"nodeType":860},{},[8440,8444],{"data":8441,"marks":8442,"value":4500,"nodeType":864},{},[8443],{"type":899},{"data":8445,"marks":8446,"value":4504,"nodeType":864},{},[],{"data":8448,"content":8449,"nodeType":945},{},[8450],{"data":8451,"content":8452,"nodeType":860},{},[8453,8457],{"data":8454,"marks":8455,"value":4515,"nodeType":864},{},[8456],{"type":899},{"data":8458,"marks":8459,"value":4519,"nodeType":864},{},[],{"data":8461,"content":8462,"nodeType":945},{},[8463],{"data":8464,"content":8465,"nodeType":860},{},[8466,8470],{"data":8467,"marks":8468,"value":781,"nodeType":864},{},[8469],{"type":899},{"data":8471,"marks":8472,"value":4533,"nodeType":864},{},[],{"data":8474,"content":8475,"nodeType":1005},{},[],{"data":8477,"content":8478,"nodeType":1009},{},[8479],{"data":8480,"marks":8481,"value":4544,"nodeType":864},{},[8482],{"type":899},{"data":8484,"content":8485,"nodeType":860},{},[8486],{"data":8487,"marks":8488,"value":4551,"nodeType":864},{},[],{"data":8490,"content":8491,"nodeType":4845},{},[8492,8515,8537,8559,8581,8603,8625,8647,8669,8691,8713,8735],{"data":8493,"content":8494,"nodeType":4581},{},[8495,8505],{"data":8496,"content":8497,"nodeType":4569},{},[8498],{"data":8499,"content":8500,"nodeType":860},{},[8501],{"data":8502,"marks":8503,"value":4568,"nodeType":864},{},[8504],{"type":899},{"data":8506,"content":8507,"nodeType":4569},{},[8508],{"data":8509,"content":8510,"nodeType":860},{},[8511],{"data":8512,"marks":8513,"value":4580,"nodeType":864},{},[8514],{"type":899},{"data":8516,"content":8517,"nodeType":4581},{},[8518,8528],{"data":8519,"content":8520,"nodeType":4569},{},[8521],{"data":8522,"content":8523,"nodeType":860},{},[8524],{"data":8525,"marks":8526,"value":4595,"nodeType":864},{},[8527],{"type":899},{"data":8529,"content":8530,"nodeType":4569},{},[8531],{"data":8532,"content":8533,"nodeType":860},{},[8534],{"data":8535,"marks":8536,"value":4605,"nodeType":864},{},[],{"data":8538,"content":8539,"nodeType":4581},{},[8540,8550],{"data":8541,"content":8542,"nodeType":4569},{},[8543],{"data":8544,"content":8545,"nodeType":860},{},[8546],{"data":8547,"marks":8548,"value":4619,"nodeType":864},{},[8549],{"type":899},{"data":8551,"content":8552,"nodeType":4569},{},[8553],{"data":8554,"content":8555,"nodeType":860},{},[8556],{"data":8557,"marks":8558,"value":4629,"nodeType":864},{},[],{"data":8560,"content":8561,"nodeType":4581},{},[8562,8572],{"data":8563,"content":8564,"nodeType":4569},{},[8565],{"data":8566,"content":8567,"nodeType":860},{},[8568],{"data":8569,"marks":8570,"value":4643,"nodeType":864},{},[8571],{"type":899},{"data":8573,"content":8574,"nodeType":4569},{},[8575],{"data":8576,"content":8577,"nodeType":860},{},[8578],{"data":8579,"marks":8580,"value":4653,"nodeType":864},{},[],{"data":8582,"content":8583,"nodeType":4581},{},[8584,8594],{"data":8585,"content":8586,"nodeType":4569},{},[8587],{"data":8588,"content":8589,"nodeType":860},{},[8590],{"data":8591,"marks":8592,"value":4667,"nodeType":864},{},[8593],{"type":899},{"data":8595,"content":8596,"nodeType":4569},{},[8597],{"data":8598,"content":8599,"nodeType":860},{},[8600],{"data":8601,"marks":8602,"value":4677,"nodeType":864},{},[],{"data":8604,"content":8605,"nodeType":4581},{},[8606,8616],{"data":8607,"content":8608,"nodeType":4569},{},[8609],{"data":8610,"content":8611,"nodeType":860},{},[8612],{"data":8613,"marks":8614,"value":4691,"nodeType":864},{},[8615],{"type":899},{"data":8617,"content":8618,"nodeType":4569},{},[8619],{"data":8620,"content":8621,"nodeType":860},{},[8622],{"data":8623,"marks":8624,"value":4701,"nodeType":864},{},[],{"data":8626,"content":8627,"nodeType":4581},{},[8628,8638],{"data":8629,"content":8630,"nodeType":4569},{},[8631],{"data":8632,"content":8633,"nodeType":860},{},[8634],{"data":8635,"marks":8636,"value":4715,"nodeType":864},{},[8637],{"type":899},{"data":8639,"content":8640,"nodeType":4569},{},[8641],{"data":8642,"content":8643,"nodeType":860},{},[8644],{"data":8645,"marks":8646,"value":4725,"nodeType":864},{},[],{"data":8648,"content":8649,"nodeType":4581},{},[8650,8660],{"data":8651,"content":8652,"nodeType":4569},{},[8653],{"data":8654,"content":8655,"nodeType":860},{},[8656],{"data":8657,"marks":8658,"value":4739,"nodeType":864},{},[8659],{"type":899},{"data":8661,"content":8662,"nodeType":4569},{},[8663],{"data":8664,"content":8665,"nodeType":860},{},[8666],{"data":8667,"marks":8668,"value":4749,"nodeType":864},{},[],{"data":8670,"content":8671,"nodeType":4581},{},[8672,8682],{"data":8673,"content":8674,"nodeType":4569},{},[8675],{"data":8676,"content":8677,"nodeType":860},{},[8678],{"data":8679,"marks":8680,"value":4763,"nodeType":864},{},[8681],{"type":899},{"data":8683,"content":8684,"nodeType":4569},{},[8685],{"data":8686,"content":8687,"nodeType":860},{},[8688],{"data":8689,"marks":8690,"value":4773,"nodeType":864},{},[],{"data":8692,"content":8693,"nodeType":4581},{},[8694,8704],{"data":8695,"content":8696,"nodeType":4569},{},[8697],{"data":8698,"content":8699,"nodeType":860},{},[8700],{"data":8701,"marks":8702,"value":4787,"nodeType":864},{},[8703],{"type":899},{"data":8705,"content":8706,"nodeType":4569},{},[8707],{"data":8708,"content":8709,"nodeType":860},{},[8710],{"data":8711,"marks":8712,"value":4797,"nodeType":864},{},[],{"data":8714,"content":8715,"nodeType":4581},{},[8716,8726],{"data":8717,"content":8718,"nodeType":4569},{},[8719],{"data":8720,"content":8721,"nodeType":860},{},[8722],{"data":8723,"marks":8724,"value":4811,"nodeType":864},{},[8725],{"type":899},{"data":8727,"content":8728,"nodeType":4569},{},[8729],{"data":8730,"content":8731,"nodeType":860},{},[8732],{"data":8733,"marks":8734,"value":4821,"nodeType":864},{},[],{"data":8736,"content":8737,"nodeType":4581},{},[8738,8748],{"data":8739,"content":8740,"nodeType":4569},{},[8741],{"data":8742,"content":8743,"nodeType":860},{},[8744],{"data":8745,"marks":8746,"value":4500,"nodeType":864},{},[8747],{"type":899},{"data":8749,"content":8750,"nodeType":4569},{},[8751],{"data":8752,"content":8753,"nodeType":860},{},[8754],{"data":8755,"marks":8756,"value":4844,"nodeType":864},{},[],{"data":8758,"content":8759,"nodeType":1005},{},[],{"data":8761,"content":8762,"nodeType":860},{},[8763,8766,8772],{"data":8764,"marks":8765,"value":4855,"nodeType":864},{},[],{"data":8767,"content":8768,"nodeType":883},{"uri":1700},[8769],{"data":8770,"marks":8771,"value":1703,"nodeType":864},{},[],{"data":8773,"marks":8774,"value":21,"nodeType":864},{},[],{"items":8776},[8777,8779],{"sys":8778,"name":297},{"id":2732},{"sys":8780,"name":2729},{"id":2728},{"items":8782},[8783],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":8784},{"url":4881},"blog/crossing-the-ai-security-chasm-sans-security-maturity-model",{"json":8787},{"data":8788,"content":8789,"nodeType":856},{},[8790],{"data":8791,"content":8792,"nodeType":860},{},[8793],{"data":8794,"marks":8795,"value":8796,"nodeType":864},{},[],"Most organizations know they have an AI security problem. A new SANS framework shows why so few are making progress – and what it actually takes to get unstuck.",{"id":2743,"publishedAt":8798},"2026-08-12T12:00:43.789Z",{"items":8800},[8801,8803],{"sys":8802,"name":297},{"id":2732},{"sys":8804,"name":2729},{"id":2728},{"items":8806},[8807,8809,8811,8813,8815,8817,8819,8821,8823,8825,8827,8829,8831],{"sys":8808,"name":235,"slug":236,"tier":31},{"id":232},{"sys":8810,"name":297,"slug":298,"tier":31},{"id":294},{"sys":8812,"name":279,"slug":280,"tier":31},{"id":276},{"sys":8814,"name":519,"slug":520,"tier":31},{"id":516},{"sys":8816,"name":580,"slug":581,"tier":45},{"id":577},{"sys":8818,"name":252,"slug":253,"tier":45},{"id":249},{"sys":8820,"name":315,"slug":316,"tier":45},{"id":312},{"sys":8822,"name":360,"slug":361,"tier":45},{"id":357},{"sys":8824,"name":261,"slug":262,"tier":45},{"id":258},{"sys":8826,"name":288,"slug":289,"tier":45},{"id":285},{"sys":8828,"name":484,"slug":485,"tier":45},{"id":481},{"sys":8830,"name":368,"slug":369,"tier":45},{"id":365},{"sys":8832,"name":457,"slug":458,"tier":45},{"id":454},"9MwsjcrxUUVzXns3KGAsw5P2iaR5ftXXtYxjz2_kW4o",{"id":8835,"title":6750,"authorsCollection":8836,"content":8840,"extension":228,"faqItemsCollection":9904,"faqTitle":59,"featured":6,"hashTags":59,"meta":9906,"metaTitle":9907,"ogImage":59,"postType":9908,"publishedDate":6752,"relatedBlogPostsCollection":9909,"slug":6753,"stem":11994,"subtitle":59,"summary":11995,"synopsis":6751,"sys":12006,"tagsCollection":12008,"topicsCollection":12014,"__hash__":12034},"blog/blog/browser-visibility-and-control-can-achieve-ai-compliance.json",{"items":8837},[8838],{"fullName":6763,"firstName":6764,"jobTitle":6765,"socialLinks":59,"profilePicture":8839},{"url":6767},{"json":8841,"links":9738},{"data":8842,"content":8843,"nodeType":856},{},[8844,8851,8857,8864,9375,9380,9386,9392,9395,9402,9408,9415,9421,9426,9431,9438,9451,9458,9464,9471,9477,9482,9489,9495,9500,9503,9510,9525,9541,9556,9562,9565,9572,9578,9588,9594,9604,9610,9615,9625,9631,9641,9647,9653,9658,9668,9674,9677,9684,9690,9696,9702,9707,9710,9716,9722],{"data":8845,"content":8846,"nodeType":1009},{},[8847],{"data":8848,"marks":8849,"value":5743,"nodeType":864},{},[8850],{"type":899},{"data":8852,"content":8853,"nodeType":860},{},[8854],{"data":8855,"marks":8856,"value":5750,"nodeType":864},{},[],{"data":8858,"content":8859,"nodeType":860},{},[8860],{"data":8861,"marks":8862,"value":5758,"nodeType":864},{},[8863],{"type":899},{"data":8865,"content":8866,"nodeType":4845},{},[8867,8910,8988,9047,9097,9206,9256,9316],{"data":8868,"content":8869,"nodeType":4581},{},[8870,8880,8890,8900],{"data":8871,"content":8872,"nodeType":4569},{},[8873],{"data":8874,"content":8875,"nodeType":860},{},[8876],{"data":8877,"marks":8878,"value":5775,"nodeType":864},{},[8879],{"type":899},{"data":8881,"content":8882,"nodeType":4569},{},[8883],{"data":8884,"content":8885,"nodeType":860},{},[8886],{"data":8887,"marks":8888,"value":5786,"nodeType":864},{},[8889],{"type":899},{"data":8891,"content":8892,"nodeType":4569},{},[8893],{"data":8894,"content":8895,"nodeType":860},{},[8896],{"data":8897,"marks":8898,"value":5797,"nodeType":864},{},[8899],{"type":899},{"data":8901,"content":8902,"nodeType":4569},{},[8903],{"data":8904,"content":8905,"nodeType":860},{},[8906],{"data":8907,"marks":8908,"value":5808,"nodeType":864},{},[8909],{"type":899},{"data":8911,"content":8912,"nodeType":4581},{},[8913,8933,8942,8969],{"data":8914,"content":8915,"nodeType":4569},{},[8916],{"data":8917,"content":8918,"nodeType":860},{},[8919,8922,8930],{"data":8920,"marks":8921,"value":21,"nodeType":864},{},[],{"data":8923,"content":8924,"nodeType":883},{"uri":5823},[8925],{"data":8926,"marks":8927,"value":5830,"nodeType":864},{},[8928,8929],{"type":1455},{"type":899},{"data":8931,"marks":8932,"value":21,"nodeType":864},{},[],{"data":8934,"content":8935,"nodeType":4569},{},[8936],{"data":8937,"content":8938,"nodeType":860},{},[8939],{"data":8940,"marks":8941,"value":5843,"nodeType":864},{},[],{"data":8943,"content":8944,"nodeType":4569},{},[8945],{"data":8946,"content":8947,"nodeType":860},{},[8948,8951,8957,8960,8966],{"data":8949,"marks":8950,"value":5853,"nodeType":864},{},[],{"data":8952,"content":8953,"nodeType":883},{"uri":5856},[8954],{"data":8955,"marks":8956,"value":5861,"nodeType":864},{},[],{"data":8958,"marks":8959,"value":5865,"nodeType":864},{},[],{"data":8961,"content":8962,"nodeType":883},{"uri":5868},[8963],{"data":8964,"marks":8965,"value":5873,"nodeType":864},{},[],{"data":8967,"marks":8968,"value":5877,"nodeType":864},{},[],{"data":8970,"content":8971,"nodeType":4569},{},[8972],{"data":8973,"content":8974,"nodeType":860},{},[8975,8978,8985],{"data":8976,"marks":8977,"value":21,"nodeType":864},{},[],{"data":8979,"content":8980,"nodeType":883},{"uri":5856},[8981],{"data":8982,"marks":8983,"value":5894,"nodeType":864},{},[8984],{"type":1455},{"data":8986,"marks":8987,"value":5898,"nodeType":864},{},[],{"data":8989,"content":8990,"nodeType":4581},{},[8991,9011,9020,9038],{"data":8992,"content":8993,"nodeType":4569},{},[8994],{"data":8995,"content":8996,"nodeType":860},{},[8997,9000,9008],{"data":8998,"marks":8999,"value":21,"nodeType":864},{},[],{"data":9001,"content":9002,"nodeType":883},{"uri":5913},[9003],{"data":9004,"marks":9005,"value":5920,"nodeType":864},{},[9006,9007],{"type":1455},{"type":899},{"data":9009,"marks":9010,"value":21,"nodeType":864},{},[],{"data":9012,"content":9013,"nodeType":4569},{},[9014],{"data":9015,"content":9016,"nodeType":860},{},[9017],{"data":9018,"marks":9019,"value":5933,"nodeType":864},{},[],{"data":9021,"content":9022,"nodeType":4569},{},[9023],{"data":9024,"content":9025,"nodeType":860},{},[9026,9029,9035],{"data":9027,"marks":9028,"value":5943,"nodeType":864},{},[],{"data":9030,"content":9031,"nodeType":883},{"uri":5913},[9032],{"data":9033,"marks":9034,"value":5950,"nodeType":864},{},[],{"data":9036,"marks":9037,"value":5954,"nodeType":864},{},[],{"data":9039,"content":9040,"nodeType":4569},{},[9041],{"data":9042,"content":9043,"nodeType":860},{},[9044],{"data":9045,"marks":9046,"value":5964,"nodeType":864},{},[],{"data":9048,"content":9049,"nodeType":4581},{},[9050,9070,9079,9088],{"data":9051,"content":9052,"nodeType":4569},{},[9053],{"data":9054,"content":9055,"nodeType":860},{},[9056,9059,9067],{"data":9057,"marks":9058,"value":21,"nodeType":864},{},[],{"data":9060,"content":9061,"nodeType":883},{"uri":5979},[9062],{"data":9063,"marks":9064,"value":5986,"nodeType":864},{},[9065,9066],{"type":1455},{"type":899},{"data":9068,"marks":9069,"value":21,"nodeType":864},{},[],{"data":9071,"content":9072,"nodeType":4569},{},[9073],{"data":9074,"content":9075,"nodeType":860},{},[9076],{"data":9077,"marks":9078,"value":5999,"nodeType":864},{},[],{"data":9080,"content":9081,"nodeType":4569},{},[9082],{"data":9083,"content":9084,"nodeType":860},{},[9085],{"data":9086,"marks":9087,"value":6009,"nodeType":864},{},[],{"data":9089,"content":9090,"nodeType":4569},{},[9091],{"data":9092,"content":9093,"nodeType":860},{},[9094],{"data":9095,"marks":9096,"value":6019,"nodeType":864},{},[],{"data":9098,"content":9099,"nodeType":4581},{},[9100,9120,9129,9170],{"data":9101,"content":9102,"nodeType":4569},{},[9103],{"data":9104,"content":9105,"nodeType":860},{},[9106,9109,9117],{"data":9107,"marks":9108,"value":21,"nodeType":864},{},[],{"data":9110,"content":9111,"nodeType":883},{"uri":6034},[9112],{"data":9113,"marks":9114,"value":6041,"nodeType":864},{},[9115,9116],{"type":1455},{"type":899},{"data":9118,"marks":9119,"value":21,"nodeType":864},{},[],{"data":9121,"content":9122,"nodeType":4569},{},[9123],{"data":9124,"content":9125,"nodeType":860},{},[9126],{"data":9127,"marks":9128,"value":6054,"nodeType":864},{},[],{"data":9130,"content":9131,"nodeType":4569},{},[9132],{"data":9133,"content":9134,"nodeType":860},{},[9135,9138,9145,9148,9154,9157,9167],{"data":9136,"marks":9137,"value":21,"nodeType":864},{},[],{"data":9139,"content":9140,"nodeType":883},{"uri":6066},[9141],{"data":9142,"marks":9143,"value":6072,"nodeType":864},{},[9144],{"type":1455},{"data":9146,"marks":9147,"value":6076,"nodeType":864},{},[],{"data":9149,"content":9150,"nodeType":883},{"uri":6079},[9151],{"data":9152,"marks":9153,"value":6084,"nodeType":864},{},[],{"data":9155,"marks":9156,"value":6088,"nodeType":864},{},[],{"data":9158,"content":9159,"nodeType":883},{"uri":6091},[9160,9163],{"data":9161,"marks":9162,"value":1171,"nodeType":864},{},[],{"data":9164,"marks":9165,"value":6100,"nodeType":864},{},[9166],{"type":1455},{"data":9168,"marks":9169,"value":21,"nodeType":864},{},[],{"data":9171,"content":9172,"nodeType":4569},{},[9173],{"data":9174,"content":9175,"nodeType":860},{},[9176,9179,9185,9188,9194,9197,9203],{"data":9177,"marks":9178,"value":6113,"nodeType":864},{},[],{"data":9180,"content":9181,"nodeType":883},{"uri":6066},[9182],{"data":9183,"marks":9184,"value":6120,"nodeType":864},{},[],{"data":9186,"marks":9187,"value":3731,"nodeType":864},{},[],{"data":9189,"content":9190,"nodeType":883},{"uri":6079},[9191],{"data":9192,"marks":9193,"value":6130,"nodeType":864},{},[],{"data":9195,"marks":9196,"value":3731,"nodeType":864},{},[],{"data":9198,"content":9199,"nodeType":883},{"uri":6091},[9200],{"data":9201,"marks":9202,"value":6140,"nodeType":864},{},[],{"data":9204,"marks":9205,"value":21,"nodeType":864},{},[],{"data":9207,"content":9208,"nodeType":4581},{},[9209,9229,9238,9247],{"data":9210,"content":9211,"nodeType":4569},{},[9212],{"data":9213,"content":9214,"nodeType":860},{},[9215,9218,9226],{"data":9216,"marks":9217,"value":21,"nodeType":864},{},[],{"data":9219,"content":9220,"nodeType":883},{"uri":6158},[9221],{"data":9222,"marks":9223,"value":6165,"nodeType":864},{},[9224,9225],{"type":1455},{"type":899},{"data":9227,"marks":9228,"value":21,"nodeType":864},{},[],{"data":9230,"content":9231,"nodeType":4569},{},[9232],{"data":9233,"content":9234,"nodeType":860},{},[9235],{"data":9236,"marks":9237,"value":6178,"nodeType":864},{},[],{"data":9239,"content":9240,"nodeType":4569},{},[9241],{"data":9242,"content":9243,"nodeType":860},{},[9244],{"data":9245,"marks":9246,"value":6188,"nodeType":864},{},[],{"data":9248,"content":9249,"nodeType":4569},{},[9250],{"data":9251,"content":9252,"nodeType":860},{},[9253],{"data":9254,"marks":9255,"value":6198,"nodeType":864},{},[],{"data":9257,"content":9258,"nodeType":4581},{},[9259,9279,9288,9297],{"data":9260,"content":9261,"nodeType":4569},{},[9262],{"data":9263,"content":9264,"nodeType":860},{},[9265,9268,9276],{"data":9266,"marks":9267,"value":21,"nodeType":864},{},[],{"data":9269,"content":9270,"nodeType":883},{"uri":6213},[9271],{"data":9272,"marks":9273,"value":6220,"nodeType":864},{},[9274,9275],{"type":1455},{"type":899},{"data":9277,"marks":9278,"value":21,"nodeType":864},{},[],{"data":9280,"content":9281,"nodeType":4569},{},[9282],{"data":9283,"content":9284,"nodeType":860},{},[9285],{"data":9286,"marks":9287,"value":6233,"nodeType":864},{},[],{"data":9289,"content":9290,"nodeType":4569},{},[9291],{"data":9292,"content":9293,"nodeType":860},{},[9294],{"data":9295,"marks":9296,"value":6243,"nodeType":864},{},[],{"data":9298,"content":9299,"nodeType":4569},{},[9300],{"data":9301,"content":9302,"nodeType":860},{},[9303,9306,9313],{"data":9304,"marks":9305,"value":21,"nodeType":864},{},[],{"data":9307,"content":9308,"nodeType":883},{"uri":6255},[9309],{"data":9310,"marks":9311,"value":6261,"nodeType":864},{},[9312],{"type":1455},{"data":9314,"marks":9315,"value":6265,"nodeType":864},{},[],{"data":9317,"content":9318,"nodeType":4581},{},[9319,9339,9348,9366],{"data":9320,"content":9321,"nodeType":4569},{},[9322],{"data":9323,"content":9324,"nodeType":860},{},[9325,9328,9336],{"data":9326,"marks":9327,"value":21,"nodeType":864},{},[],{"data":9329,"content":9330,"nodeType":883},{"uri":6280},[9331],{"data":9332,"marks":9333,"value":6287,"nodeType":864},{},[9334,9335],{"type":1455},{"type":899},{"data":9337,"marks":9338,"value":21,"nodeType":864},{},[],{"data":9340,"content":9341,"nodeType":4569},{},[9342],{"data":9343,"content":9344,"nodeType":860},{},[9345],{"data":9346,"marks":9347,"value":6300,"nodeType":864},{},[],{"data":9349,"content":9350,"nodeType":4569},{},[9351],{"data":9352,"content":9353,"nodeType":860},{},[9354,9357,9363],{"data":9355,"marks":9356,"value":6310,"nodeType":864},{},[],{"data":9358,"content":9359,"nodeType":883},{"uri":6313},[9360],{"data":9361,"marks":9362,"value":6318,"nodeType":864},{},[],{"data":9364,"marks":9365,"value":6322,"nodeType":864},{},[],{"data":9367,"content":9368,"nodeType":4569},{},[9369],{"data":9370,"content":9371,"nodeType":860},{},[9372],{"data":9373,"marks":9374,"value":6332,"nodeType":864},{},[],{"data":9376,"content":9379,"nodeType":996},{"target":9377},{"sys":9378},{"id":6337,"type":1001,"linkType":1002},[],{"data":9381,"content":9382,"nodeType":860},{},[9383],{"data":9384,"marks":9385,"value":6345,"nodeType":864},{},[],{"data":9387,"content":9388,"nodeType":860},{},[9389],{"data":9390,"marks":9391,"value":6352,"nodeType":864},{},[],{"data":9393,"content":9394,"nodeType":1005},{},[],{"data":9396,"content":9397,"nodeType":1009},{},[9398],{"data":9399,"marks":9400,"value":6363,"nodeType":864},{},[9401],{"type":899},{"data":9403,"content":9404,"nodeType":860},{},[9405],{"data":9406,"marks":9407,"value":6370,"nodeType":864},{},[],{"data":9409,"content":9410,"nodeType":1312},{},[9411],{"data":9412,"marks":9413,"value":6378,"nodeType":864},{},[9414],{"type":899},{"data":9416,"content":9417,"nodeType":860},{},[9418],{"data":9419,"marks":9420,"value":6385,"nodeType":864},{},[],{"data":9422,"content":9425,"nodeType":996},{"target":9423},{"sys":9424},{"id":6390,"type":1001,"linkType":1002},[],{"data":9427,"content":9430,"nodeType":996},{"target":9428},{"sys":9429},{"id":1040,"type":1001,"linkType":1002},[],{"data":9432,"content":9433,"nodeType":1312},{},[9434],{"data":9435,"marks":9436,"value":6404,"nodeType":864},{},[9437],{"type":899},{"data":9439,"content":9440,"nodeType":860},{},[9441,9444,9448],{"data":9442,"marks":9443,"value":6411,"nodeType":864},{},[],{"data":9445,"marks":9446,"value":6416,"nodeType":864},{},[9447],{"type":899},{"data":9449,"marks":9450,"value":6420,"nodeType":864},{},[],{"data":9452,"content":9453,"nodeType":1312},{},[9454],{"data":9455,"marks":9456,"value":6428,"nodeType":864},{},[9457],{"type":899},{"data":9459,"content":9460,"nodeType":860},{},[9461],{"data":9462,"marks":9463,"value":6435,"nodeType":864},{},[],{"data":9465,"content":9466,"nodeType":1312},{},[9467],{"data":9468,"marks":9469,"value":6443,"nodeType":864},{},[9470],{"type":899},{"data":9472,"content":9473,"nodeType":860},{},[9474],{"data":9475,"marks":9476,"value":6450,"nodeType":864},{},[],{"data":9478,"content":9481,"nodeType":996},{"target":9479},{"sys":9480},{"id":6455,"type":1001,"linkType":1002},[],{"data":9483,"content":9484,"nodeType":1312},{},[9485],{"data":9486,"marks":9487,"value":6464,"nodeType":864},{},[9488],{"type":899},{"data":9490,"content":9491,"nodeType":860},{},[9492],{"data":9493,"marks":9494,"value":6471,"nodeType":864},{},[],{"data":9496,"content":9499,"nodeType":996},{"target":9497},{"sys":9498},{"id":6476,"type":1001,"linkType":1002},[],{"data":9501,"content":9502,"nodeType":1005},{},[],{"data":9504,"content":9505,"nodeType":1009},{},[9506],{"data":9507,"marks":9508,"value":6488,"nodeType":864},{},[9509],{"type":899},{"data":9511,"content":9512,"nodeType":860},{},[9513,9516,9522],{"data":9514,"marks":9515,"value":6495,"nodeType":864},{},[],{"data":9517,"content":9518,"nodeType":883},{"uri":6498},[9519],{"data":9520,"marks":9521,"value":6503,"nodeType":864},{},[],{"data":9523,"marks":9524,"value":6507,"nodeType":864},{},[],{"data":9526,"content":9527,"nodeType":860},{},[9528,9531,9538],{"data":9529,"marks":9530,"value":6514,"nodeType":864},{},[],{"data":9532,"content":9533,"nodeType":883},{"uri":6517},[9534],{"data":9535,"marks":9536,"value":6523,"nodeType":864},{},[9537],{"type":1455},{"data":9539,"marks":9540,"value":6527,"nodeType":864},{},[],{"data":9542,"content":9543,"nodeType":860},{},[9544,9547,9553],{"data":9545,"marks":9546,"value":6534,"nodeType":864},{},[],{"data":9548,"content":9549,"nodeType":883},{"uri":6537},[9550],{"data":9551,"marks":9552,"value":6542,"nodeType":864},{},[],{"data":9554,"marks":9555,"value":6546,"nodeType":864},{},[],{"data":9557,"content":9558,"nodeType":860},{},[9559],{"data":9560,"marks":9561,"value":6553,"nodeType":864},{},[],{"data":9563,"content":9564,"nodeType":1005},{},[],{"data":9566,"content":9567,"nodeType":1009},{},[9568],{"data":9569,"marks":9570,"value":6564,"nodeType":864},{},[9571],{"type":899},{"data":9573,"content":9574,"nodeType":860},{},[9575],{"data":9576,"marks":9577,"value":6571,"nodeType":864},{},[],{"data":9579,"content":9580,"nodeType":1312},{},[9581,9585],{"data":9582,"marks":9583,"value":6579,"nodeType":864},{},[9584],{"type":899},{"data":9586,"marks":9587,"value":1171,"nodeType":864},{},[],{"data":9589,"content":9590,"nodeType":860},{},[9591],{"data":9592,"marks":9593,"value":6589,"nodeType":864},{},[],{"data":9595,"content":9596,"nodeType":1312},{},[9597,9601],{"data":9598,"marks":9599,"value":6597,"nodeType":864},{},[9600],{"type":899},{"data":9602,"marks":9603,"value":1171,"nodeType":864},{},[],{"data":9605,"content":9606,"nodeType":860},{},[9607],{"data":9608,"marks":9609,"value":6607,"nodeType":864},{},[],{"data":9611,"content":9614,"nodeType":996},{"target":9612},{"sys":9613},{"id":6612,"type":1001,"linkType":1002},[],{"data":9616,"content":9617,"nodeType":1312},{},[9618,9622],{"data":9619,"marks":9620,"value":6621,"nodeType":864},{},[9621],{"type":899},{"data":9623,"marks":9624,"value":1171,"nodeType":864},{},[],{"data":9626,"content":9627,"nodeType":860},{},[9628],{"data":9629,"marks":9630,"value":6631,"nodeType":864},{},[],{"data":9632,"content":9633,"nodeType":1312},{},[9634,9638],{"data":9635,"marks":9636,"value":6639,"nodeType":864},{},[9637],{"type":899},{"data":9639,"marks":9640,"value":1171,"nodeType":864},{},[],{"data":9642,"content":9643,"nodeType":860},{},[9644],{"data":9645,"marks":9646,"value":6649,"nodeType":864},{},[],{"data":9648,"content":9649,"nodeType":860},{},[9650],{"data":9651,"marks":9652,"value":6656,"nodeType":864},{},[],{"data":9654,"content":9657,"nodeType":996},{"target":9655},{"sys":9656},{"id":6661,"type":1001,"linkType":1002},[],{"data":9659,"content":9660,"nodeType":1312},{},[9661,9665],{"data":9662,"marks":9663,"value":6670,"nodeType":864},{},[9664],{"type":899},{"data":9666,"marks":9667,"value":1171,"nodeType":864},{},[],{"data":9669,"content":9670,"nodeType":860},{},[9671],{"data":9672,"marks":9673,"value":6680,"nodeType":864},{},[],{"data":9675,"content":9676,"nodeType":1005},{},[],{"data":9678,"content":9679,"nodeType":1009},{},[9680],{"data":9681,"marks":9682,"value":6691,"nodeType":864},{},[9683],{"type":899},{"data":9685,"content":9686,"nodeType":860},{},[9687],{"data":9688,"marks":9689,"value":6698,"nodeType":864},{},[],{"data":9691,"content":9692,"nodeType":860},{},[9693],{"data":9694,"marks":9695,"value":6705,"nodeType":864},{},[],{"data":9697,"content":9698,"nodeType":860},{},[9699],{"data":9700,"marks":9701,"value":6712,"nodeType":864},{},[],{"data":9703,"content":9706,"nodeType":996},{"target":9704},{"sys":9705},{"id":6717,"type":1001,"linkType":1002},[],{"data":9708,"content":9709,"nodeType":1005},{},[],{"data":9711,"content":9712,"nodeType":860},{},[9713],{"data":9714,"marks":9715,"value":1682,"nodeType":864},{},[],{"data":9717,"content":9718,"nodeType":860},{},[9719],{"data":9720,"marks":9721,"value":1689,"nodeType":864},{},[],{"data":9723,"content":9724,"nodeType":860},{},[9725,9728,9735],{"data":9726,"marks":9727,"value":21,"nodeType":864},{},[],{"data":9729,"content":9730,"nodeType":883},{"uri":1700},[9731],{"data":9732,"marks":9733,"value":1703,"nodeType":864},{},[9734],{"type":1455},{"data":9736,"marks":9737,"value":21,"nodeType":864},{},[],{"entries":9739},{"hyperlink":9740,"inline":9741,"block":9742},[],[],[9743,9751,9776,9779,9806,9832,9846,9890],{"sys":9744,"__typename":1724,"title":9745,"caption":9746,"layoutMode":59,"file":9747},{"id":6337},"ai regulation matrix","Map of how different regulations map to AI control requirements.",{"url":9748,"width":9749,"height":9750},"https://images.ctfassets.net/y1cdw1ablpvd/3rfEWb5FXvXR07jdPdoht6/42f1c515e62fcc58aa0e270a424cfacc/ai_regulation_matrix_3x__4_.png",2550,1806,{"sys":9752,"__typename":1740,"content":9753,"name":9775,"title":59},{"id":6390},{"json":9754},{"nodeType":856,"data":9755,"content":9756},{},[9757],{"nodeType":860,"data":9758,"content":9759},{},[9760,9764,9771],{"nodeType":864,"value":9761,"marks":9762,"data":9763},"Most organizations are dealing with uncontrolled ",[],{},{"nodeType":883,"data":9765,"content":9766},{"uri":885},[9767],{"nodeType":864,"value":9768,"marks":9769,"data":9770},"Shadow AI sprawl",[],{},{"nodeType":864,"value":9772,"marks":9773,"data":9774},". We find that the average organization has 16 unique AI apps in active use, 17 unique AI browser extensions, and 17 unique AI OAuth integrations connected into just Google Workspace and Microsoft 365 — with some organizations reaching as high as 40 unique AI apps, 163 AI extensions, and 55 OAuth connections to AI apps respectively. At the other end, the smallest organization with the lowest adoption level is actively using two. ",[],{},"AI regulation IB1",{"sys":9777,"__typename":1724,"title":1725,"caption":1726,"layoutMode":59,"file":9778},{"id":1040},{"url":1728,"width":1729,"height":1730},{"sys":9780,"__typename":1740,"content":9781,"name":9805,"title":59},{"id":6455},{"json":9782},{"data":9783,"content":9784,"nodeType":856},{},[9785],{"data":9786,"content":9787,"nodeType":860},{},[9788,9792,9801],{"data":9789,"marks":9790,"value":9791,"nodeType":864},{},[],"In the UK, ",{"data":9793,"content":9795,"nodeType":883},{"uri":9794},"https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/five-steps-to-protect-your-organisation-from-AI-powered-cyber-threats/",[9796],{"data":9797,"marks":9798,"value":9800,"nodeType":864},{},[9799],{"type":1455},"the ICO's May 2026 blog",{"data":9802,"marks":9803,"value":9804,"nodeType":864},{},[]," names AI-generated phishing, deepfake social engineering, and credential stuffing as specific threats organisations must address under UK GDPR Article 32. It calls for multi-factor authentication on all remote access, admin accounts, and email, alongside layered defences that assume foundational controls alone are insufficient against AI-powered attacks.","ai regulation IB2",{"sys":9807,"__typename":1740,"content":9808,"name":9831,"title":59},{"id":6476},{"json":9809},{"nodeType":856,"data":9810,"content":9811},{},[9812],{"nodeType":860,"data":9813,"content":9814},{},[9815,9819,9827],{"nodeType":864,"value":9816,"marks":9817,"data":9818},"In May 2026, ",[],{},{"nodeType":883,"data":9820,"content":9822},{"uri":9821},"https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services",[9823],{"nodeType":864,"value":9824,"marks":9825,"data":9826},"CISA and Five Eyes partners published the first multinational guidance on agentic AI adoption",[],{},{"nodeType":864,"value":9828,"marks":9829,"data":9830},", identifying privilege escalation and accountability gaps as core risks — a signal that AI agent governance will soon move from best practice to regulatory expectation. ",[],{},"ai regulation IB3",{"sys":9833,"__typename":1740,"content":9834,"name":9845,"title":59},{"id":6612},{"json":9835},{"nodeType":856,"data":9836,"content":9837},{},[9838],{"nodeType":860,"data":9839,"content":9840},{},[9841],{"nodeType":864,"value":9842,"marks":9843,"data":9844},"When an employee clicks through or acknowledges the banner, Push generates auditable telemetry, creating a documented, timestamped record that the employee received policy guidance at the exact point of AI interaction (not just in a training session six months prior).",[],{},"ai regulation ib6",{"sys":9847,"__typename":1740,"content":9848,"name":9889,"title":59},{"id":6661},{"json":9849},{"nodeType":856,"data":9850,"content":9851},{},[9852,9871],{"nodeType":860,"data":9853,"content":9854},{},[9855,9859,9867],{"nodeType":864,"value":9856,"marks":9857,"data":9858},"Attackers are ",[],{},{"nodeType":883,"data":9860,"content":9862},{"uri":9861},"https://pushsecurity.com/blog/the-pyramid-of-pain-in-the-ai-era/",[9863],{"nodeType":864,"value":9864,"marks":9865,"data":9866},"increasingly leveraging AI in their phishing campaigns",[],{},{"nodeType":864,"value":9868,"marks":9869,"data":9870},", creating new and derivative phishing kits, adding new capabilities, and finding ways to increase the speed and scale of their operations. But Push's vantage point in the browser means that regardless of the tooling or infrastructure used, Push intercepts the attack at the point of interaction. ",[],{},{"nodeType":860,"data":9872,"content":9873},{},[9874,9878,9885],{"nodeType":864,"value":9875,"marks":9876,"data":9877},"This even applies to AI-powered voice and video faking attacks: since ",[],{},{"nodeType":883,"data":9879,"content":9880},{"uri":4082},[9881],{"nodeType":864,"value":9882,"marks":9883,"data":9884},"most voice-based attacks still result in a user being directed to interact with a browser payload",[],{},{"nodeType":864,"value":9886,"marks":9887,"data":9888},", Push can still intercept them at the point that the caller is lured to a malicious web page or resource.",[],{},"ai regulation IB4",{"sys":9891,"__typename":1740,"content":9892,"name":9903,"title":59},{"id":6717},{"json":9893},{"data":9894,"content":9895,"nodeType":856},{},[9896],{"data":9897,"content":9898,"nodeType":860},{},[9899],{"data":9900,"marks":9901,"value":9902,"nodeType":864},{},[],"The five obligation categories we've identified aren't artifacts of any single regulation; they reflect a durable regulatory consensus about what responsible AI governance requires. Building the operational capability to meet them now — continuous AI inventory, demonstrable employee guidance, data exposure controls, phishing-resistant authentication, and third-party risk visibility — means you're prepared for future frameworks.","ai regulation ib5",{"items":9905},[],{},"How browser visibility and control can achieve AI compliance","regulation-and-compliance",{"items":9910},[9911,10484,11284],{"__typename":2059,"sys":9912,"content":9913,"title":2720,"synopsis":2721,"hashTags":59,"publishedDate":2722,"slug":2723,"tagsCollection":10474,"authorsCollection":10480},{"id":2061},{"json":9914},{"data":9915,"content":9916,"nodeType":856},{},[9917,9923,9929,9935,9940,9943,9950,9956,9985,9991,10015,10020,10023,10030,10036,10043,10077,10082,10088,10093,10096,10103,10109,10116,10122,10128,10141,10148,10168,10174,10179,10185,10192,10205,10227,10232,10247,10252,10259,10265,10285,10291,10297,10303,10308,10311,10318,10324,10330,10345,10352,10358,10365,10384,10394,10399,10402,10409,10415,10421,10427,10443,10446,10452,10458],{"data":9918,"content":9919,"nodeType":860},{},[9920],{"data":9921,"marks":9922,"value":2072,"nodeType":864},{},[],{"data":9924,"content":9925,"nodeType":860},{},[9926],{"data":9927,"marks":9928,"value":2079,"nodeType":864},{},[],{"data":9930,"content":9931,"nodeType":860},{},[9932],{"data":9933,"marks":9934,"value":2086,"nodeType":864},{},[],{"data":9936,"content":9939,"nodeType":996},{"target":9937},{"sys":9938},{"id":2091,"type":1001,"linkType":1002},[],{"data":9941,"content":9942,"nodeType":1005},{},[],{"data":9944,"content":9945,"nodeType":1009},{},[9946],{"data":9947,"marks":9948,"value":2103,"nodeType":864},{},[9949],{"type":899},{"data":9951,"content":9952,"nodeType":860},{},[9953],{"data":9954,"marks":9955,"value":2110,"nodeType":864},{},[],{"data":9957,"content":9958,"nodeType":941},{},[9959,9972],{"data":9960,"content":9961,"nodeType":945},{},[9962],{"data":9963,"content":9964,"nodeType":860},{},[9965,9969],{"data":9966,"marks":9967,"value":2124,"nodeType":864},{},[9968],{"type":899},{"data":9970,"marks":9971,"value":2128,"nodeType":864},{},[],{"data":9973,"content":9974,"nodeType":945},{},[9975],{"data":9976,"content":9977,"nodeType":860},{},[9978,9982],{"data":9979,"marks":9980,"value":2139,"nodeType":864},{},[9981],{"type":899},{"data":9983,"marks":9984,"value":2143,"nodeType":864},{},[],{"data":9986,"content":9987,"nodeType":860},{},[9988],{"data":9989,"marks":9990,"value":2150,"nodeType":864},{},[],{"data":9992,"content":9993,"nodeType":860},{},[9994,9997,10003,10006,10012],{"data":9995,"marks":9996,"value":2157,"nodeType":864},{},[],{"data":9998,"content":9999,"nodeType":883},{"uri":1543},[10000],{"data":10001,"marks":10002,"value":1758,"nodeType":864},{},[],{"data":10004,"marks":10005,"value":1762,"nodeType":864},{},[],{"data":10007,"content":10008,"nodeType":883},{"uri":1765},[10009],{"data":10010,"marks":10011,"value":1770,"nodeType":864},{},[],{"data":10013,"marks":10014,"value":1774,"nodeType":864},{},[],{"data":10016,"content":10019,"nodeType":996},{"target":10017},{"sys":10018},{"id":2180,"type":1001,"linkType":1002},[],{"data":10021,"content":10022,"nodeType":1005},{},[],{"data":10024,"content":10025,"nodeType":1009},{},[10026],{"data":10027,"marks":10028,"value":2192,"nodeType":864},{},[10029],{"type":899},{"data":10031,"content":10032,"nodeType":860},{},[10033],{"data":10034,"marks":10035,"value":2199,"nodeType":864},{},[],{"data":10037,"content":10038,"nodeType":860},{},[10039],{"data":10040,"marks":10041,"value":2207,"nodeType":864},{},[10042],{"type":899},{"data":10044,"content":10045,"nodeType":860},{},[10046,10049,10053,10056,10060,10063,10067,10070,10074],{"data":10047,"marks":10048,"value":2214,"nodeType":864},{},[],{"data":10050,"marks":10051,"value":2219,"nodeType":864},{},[10052],{"type":899},{"data":10054,"marks":10055,"value":2223,"nodeType":864},{},[],{"data":10057,"marks":10058,"value":2228,"nodeType":864},{},[10059],{"type":899},{"data":10061,"marks":10062,"value":2232,"nodeType":864},{},[],{"data":10064,"marks":10065,"value":2237,"nodeType":864},{},[10066],{"type":899},{"data":10068,"marks":10069,"value":2241,"nodeType":864},{},[],{"data":10071,"marks":10072,"value":2247,"nodeType":864},{},[10073],{"type":2246},{"data":10075,"marks":10076,"value":2251,"nodeType":864},{},[],{"data":10078,"content":10081,"nodeType":996},{"target":10079},{"sys":10080},{"id":2256,"type":1001,"linkType":1002},[],{"data":10083,"content":10084,"nodeType":860},{},[10085],{"data":10086,"marks":10087,"value":2264,"nodeType":864},{},[],{"data":10089,"content":10092,"nodeType":996},{"target":10090},{"sys":10091},{"id":1040,"type":1001,"linkType":1002},[],{"data":10094,"content":10095,"nodeType":1005},{},[],{"data":10097,"content":10098,"nodeType":1009},{},[10099],{"data":10100,"marks":10101,"value":2280,"nodeType":864},{},[10102],{"type":899},{"data":10104,"content":10105,"nodeType":860},{},[10106],{"data":10107,"marks":10108,"value":2287,"nodeType":864},{},[],{"data":10110,"content":10111,"nodeType":1312},{},[10112],{"data":10113,"marks":10114,"value":2295,"nodeType":864},{},[10115],{"type":899},{"data":10117,"content":10118,"nodeType":860},{},[10119],{"data":10120,"marks":10121,"value":2302,"nodeType":864},{},[],{"data":10123,"content":10124,"nodeType":860},{},[10125],{"data":10126,"marks":10127,"value":2309,"nodeType":864},{},[],{"data":10129,"content":10130,"nodeType":860},{},[10131,10134,10138],{"data":10132,"marks":10133,"value":2316,"nodeType":864},{},[],{"data":10135,"marks":10136,"value":2321,"nodeType":864},{},[10137],{"type":899},{"data":10139,"marks":10140,"value":2325,"nodeType":864},{},[],{"data":10142,"content":10143,"nodeType":1312},{},[10144],{"data":10145,"marks":10146,"value":2333,"nodeType":864},{},[10147],{"type":899},{"data":10149,"content":10150,"nodeType":860},{},[10151,10154,10158,10161,10165],{"data":10152,"marks":10153,"value":2340,"nodeType":864},{},[],{"data":10155,"marks":10156,"value":2345,"nodeType":864},{},[10157],{"type":899},{"data":10159,"marks":10160,"value":2349,"nodeType":864},{},[],{"data":10162,"marks":10163,"value":2354,"nodeType":864},{},[10164],{"type":899},{"data":10166,"marks":10167,"value":2358,"nodeType":864},{},[],{"data":10169,"content":10170,"nodeType":860},{},[10171],{"data":10172,"marks":10173,"value":2365,"nodeType":864},{},[],{"data":10175,"content":10178,"nodeType":996},{"target":10176},{"sys":10177},{"id":2370,"type":1001,"linkType":1002},[],{"data":10180,"content":10181,"nodeType":860},{},[10182],{"data":10183,"marks":10184,"value":2378,"nodeType":864},{},[],{"data":10186,"content":10187,"nodeType":1312},{},[10188],{"data":10189,"marks":10190,"value":2386,"nodeType":864},{},[10191],{"type":899},{"data":10193,"content":10194,"nodeType":860},{},[10195,10198,10202],{"data":10196,"marks":10197,"value":2393,"nodeType":864},{},[],{"data":10199,"marks":10200,"value":2228,"nodeType":864},{},[10201],{"type":899},{"data":10203,"marks":10204,"value":2401,"nodeType":864},{},[],{"data":10206,"content":10207,"nodeType":860},{},[10208,10211,10217,10220,10224],{"data":10209,"marks":10210,"value":2408,"nodeType":864},{},[],{"data":10212,"content":10213,"nodeType":883},{"uri":2411},[10214],{"data":10215,"marks":10216,"value":2416,"nodeType":864},{},[],{"data":10218,"marks":10219,"value":2420,"nodeType":864},{},[],{"data":10221,"marks":10222,"value":2425,"nodeType":864},{},[10223],{"type":899},{"data":10225,"marks":10226,"value":2429,"nodeType":864},{},[],{"data":10228,"content":10231,"nodeType":996},{"target":10229},{"sys":10230},{"id":2434,"type":1001,"linkType":1002},[],{"data":10233,"content":10234,"nodeType":860},{},[10235,10238,10244],{"data":10236,"marks":10237,"value":2442,"nodeType":864},{},[],{"data":10239,"content":10240,"nodeType":883},{"uri":2411},[10241],{"data":10242,"marks":10243,"value":2449,"nodeType":864},{},[],{"data":10245,"marks":10246,"value":2453,"nodeType":864},{},[],{"data":10248,"content":10251,"nodeType":996},{"target":10249},{"sys":10250},{"id":2458,"type":1001,"linkType":1002},[],{"data":10253,"content":10254,"nodeType":1312},{},[10255],{"data":10256,"marks":10257,"value":2467,"nodeType":864},{},[10258],{"type":899},{"data":10260,"content":10261,"nodeType":860},{},[10262],{"data":10263,"marks":10264,"value":2474,"nodeType":864},{},[],{"data":10266,"content":10267,"nodeType":860},{},[10268,10271,10275,10278,10282],{"data":10269,"marks":10270,"value":2481,"nodeType":864},{},[],{"data":10272,"marks":10273,"value":2486,"nodeType":864},{},[10274],{"type":899},{"data":10276,"marks":10277,"value":2490,"nodeType":864},{},[],{"data":10279,"marks":10280,"value":2495,"nodeType":864},{},[10281],{"type":2246},{"data":10283,"marks":10284,"value":2499,"nodeType":864},{},[],{"data":10286,"content":10287,"nodeType":860},{},[10288],{"data":10289,"marks":10290,"value":2506,"nodeType":864},{},[],{"data":10292,"content":10293,"nodeType":860},{},[10294],{"data":10295,"marks":10296,"value":2513,"nodeType":864},{},[],{"data":10298,"content":10299,"nodeType":860},{},[10300],{"data":10301,"marks":10302,"value":2520,"nodeType":864},{},[],{"data":10304,"content":10307,"nodeType":996},{"target":10305},{"sys":10306},{"id":2525,"type":1001,"linkType":1002},[],{"data":10309,"content":10310,"nodeType":1005},{},[],{"data":10312,"content":10313,"nodeType":1009},{},[10314],{"data":10315,"marks":10316,"value":2537,"nodeType":864},{},[10317],{"type":899},{"data":10319,"content":10320,"nodeType":860},{},[10321],{"data":10322,"marks":10323,"value":2544,"nodeType":864},{},[],{"data":10325,"content":10326,"nodeType":860},{},[10327],{"data":10328,"marks":10329,"value":2551,"nodeType":864},{},[],{"data":10331,"content":10332,"nodeType":860},{},[10333,10336,10342],{"data":10334,"marks":10335,"value":2558,"nodeType":864},{},[],{"data":10337,"content":10338,"nodeType":883},{"uri":2561},[10339],{"data":10340,"marks":10341,"value":2566,"nodeType":864},{},[],{"data":10343,"marks":10344,"value":2570,"nodeType":864},{},[],{"data":10346,"content":10347,"nodeType":1312},{},[10348],{"data":10349,"marks":10350,"value":2578,"nodeType":864},{},[10351],{"type":899},{"data":10353,"content":10354,"nodeType":860},{},[10355],{"data":10356,"marks":10357,"value":2585,"nodeType":864},{},[],{"data":10359,"content":10360,"nodeType":860},{},[10361],{"data":10362,"marks":10363,"value":2593,"nodeType":864},{},[10364],{"type":899},{"data":10366,"content":10367,"nodeType":860},{},[10368,10372,10375,10381],{"data":10369,"marks":10370,"value":2601,"nodeType":864},{},[10371],{"type":899},{"data":10373,"marks":10374,"value":2605,"nodeType":864},{},[],{"data":10376,"content":10377,"nodeType":883},{"uri":2411},[10378],{"data":10379,"marks":10380,"value":2612,"nodeType":864},{},[],{"data":10382,"marks":10383,"value":2616,"nodeType":864},{},[],{"data":10385,"content":10386,"nodeType":860},{},[10387,10391],{"data":10388,"marks":10389,"value":2624,"nodeType":864},{},[10390],{"type":899},{"data":10392,"marks":10393,"value":2628,"nodeType":864},{},[],{"data":10395,"content":10398,"nodeType":996},{"target":10396},{"sys":10397},{"id":2633,"type":1001,"linkType":1002},[],{"data":10400,"content":10401,"nodeType":1005},{},[],{"data":10403,"content":10404,"nodeType":1009},{},[10405],{"data":10406,"marks":10407,"value":2645,"nodeType":864},{},[10408],{"type":899},{"data":10410,"content":10411,"nodeType":860},{},[10412],{"data":10413,"marks":10414,"value":2652,"nodeType":864},{},[],{"data":10416,"content":10417,"nodeType":860},{},[10418],{"data":10419,"marks":10420,"value":2659,"nodeType":864},{},[],{"data":10422,"content":10423,"nodeType":860},{},[10424],{"data":10425,"marks":10426,"value":2666,"nodeType":864},{},[],{"data":10428,"content":10429,"nodeType":860},{},[10430,10433,10440],{"data":10431,"marks":10432,"value":2673,"nodeType":864},{},[],{"data":10434,"content":10435,"nodeType":883},{"uri":2676},[10436],{"data":10437,"marks":10438,"value":580,"nodeType":864},{},[10439],{"type":1455},{"data":10441,"marks":10442,"value":2685,"nodeType":864},{},[],{"data":10444,"content":10445,"nodeType":1005},{},[],{"data":10447,"content":10448,"nodeType":860},{},[10449],{"data":10450,"marks":10451,"value":1682,"nodeType":864},{},[],{"data":10453,"content":10454,"nodeType":860},{},[10455],{"data":10456,"marks":10457,"value":1689,"nodeType":864},{},[],{"data":10459,"content":10460,"nodeType":860},{},[10461,10464,10471],{"data":10462,"marks":10463,"value":2707,"nodeType":864},{},[],{"data":10465,"content":10466,"nodeType":883},{"uri":1700},[10467],{"data":10468,"marks":10469,"value":2715,"nodeType":864},{},[10470],{"type":1455},{"data":10472,"marks":10473,"value":2719,"nodeType":864},{},[],{"items":10475},[10476,10478],{"sys":10477,"name":2729},{"id":2728},{"sys":10479,"name":297},{"id":2732},{"items":10481},[10482],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":10483},{"url":2740},{"__typename":2059,"sys":10485,"content":10486,"title":7691,"synopsis":7692,"hashTags":59,"publishedDate":6752,"slug":7693,"tagsCollection":11274,"authorsCollection":11280},{"id":6770},{"json":10487},{"data":10488,"content":10489,"nodeType":856},{},[10490,10496,10502,10519,10525,10531,10534,10541,10547,10553,10574,10580,10586,10591,10594,10601,10607,10612,10618,10625,10651,10666,10671,10678,10684,10689,10705,10712,10718,10743,10748,10761,10764,10771,10777,10782,10796,10802,10808,10818,10834,10840,10846,10853,10859,10875,10880,10886,10891,10896,10899,10906,10912,10918,10973,10979,10985,10991,10997,11010,11016,11022,11028,11034,11040,11046,11052,11058,11064,11070,11076,11082,11088,11091,11098,11104,11114,11120,11126,11132,11138,11244,11250,11255,11258],{"data":10491,"content":10492,"nodeType":860},{},[10493],{"data":10494,"marks":10495,"value":6781,"nodeType":864},{},[],{"data":10497,"content":10498,"nodeType":860},{},[10499],{"data":10500,"marks":10501,"value":6788,"nodeType":864},{},[],{"data":10503,"content":10504,"nodeType":860},{},[10505,10509,10512,10516],{"data":10506,"marks":10507,"value":6796,"nodeType":864},{},[10508],{"type":899},{"data":10510,"marks":10511,"value":6800,"nodeType":864},{},[],{"data":10513,"marks":10514,"value":6805,"nodeType":864},{},[10515],{"type":2246},{"data":10517,"marks":10518,"value":6809,"nodeType":864},{},[],{"data":10520,"content":10521,"nodeType":860},{},[10522],{"data":10523,"marks":10524,"value":6816,"nodeType":864},{},[],{"data":10526,"content":10527,"nodeType":860},{},[10528],{"data":10529,"marks":10530,"value":6823,"nodeType":864},{},[],{"data":10532,"content":10533,"nodeType":1005},{},[],{"data":10535,"content":10536,"nodeType":1009},{},[10537],{"data":10538,"marks":10539,"value":6834,"nodeType":864},{},[10540],{"type":899},{"data":10542,"content":10543,"nodeType":860},{},[10544],{"data":10545,"marks":10546,"value":6841,"nodeType":864},{},[],{"data":10548,"content":10549,"nodeType":860},{},[10550],{"data":10551,"marks":10552,"value":6848,"nodeType":864},{},[],{"data":10554,"content":10555,"nodeType":941},{},[10556,10565],{"data":10557,"content":10558,"nodeType":945},{},[10559],{"data":10560,"content":10561,"nodeType":860},{},[10562],{"data":10563,"marks":10564,"value":6861,"nodeType":864},{},[],{"data":10566,"content":10567,"nodeType":945},{},[10568],{"data":10569,"content":10570,"nodeType":860},{},[10571],{"data":10572,"marks":10573,"value":6871,"nodeType":864},{},[],{"data":10575,"content":10576,"nodeType":860},{},[10577],{"data":10578,"marks":10579,"value":6878,"nodeType":864},{},[],{"data":10581,"content":10582,"nodeType":860},{},[10583],{"data":10584,"marks":10585,"value":6885,"nodeType":864},{},[],{"data":10587,"content":10590,"nodeType":996},{"target":10588},{"sys":10589},{"id":6890,"type":1001,"linkType":1002},[],{"data":10592,"content":10593,"nodeType":1005},{},[],{"data":10595,"content":10596,"nodeType":1009},{},[10597],{"data":10598,"marks":10599,"value":6902,"nodeType":864},{},[10600],{"type":899},{"data":10602,"content":10603,"nodeType":860},{},[10604],{"data":10605,"marks":10606,"value":6909,"nodeType":864},{},[],{"data":10608,"content":10611,"nodeType":996},{"target":10609},{"sys":10610},{"id":6914,"type":1001,"linkType":1002},[],{"data":10613,"content":10614,"nodeType":860},{},[10615],{"data":10616,"marks":10617,"value":6922,"nodeType":864},{},[],{"data":10619,"content":10620,"nodeType":1312},{},[10621],{"data":10622,"marks":10623,"value":6930,"nodeType":864},{},[10624],{"type":899},{"data":10626,"content":10627,"nodeType":860},{},[10628,10631,10638,10641,10648],{"data":10629,"marks":10630,"value":6937,"nodeType":864},{},[],{"data":10632,"content":10633,"nodeType":883},{"uri":6940},[10634],{"data":10635,"marks":10636,"value":6946,"nodeType":864},{},[10637],{"type":1455},{"data":10639,"marks":10640,"value":6950,"nodeType":864},{},[],{"data":10642,"content":10643,"nodeType":883},{"uri":3259},[10644],{"data":10645,"marks":10646,"value":6958,"nodeType":864},{},[10647],{"type":1455},{"data":10649,"marks":10650,"value":6962,"nodeType":864},{},[],{"data":10652,"content":10653,"nodeType":860},{},[10654,10657,10663],{"data":10655,"marks":10656,"value":6969,"nodeType":864},{},[],{"data":10658,"content":10659,"nodeType":883},{"uri":6972},[10660],{"data":10661,"marks":10662,"value":6977,"nodeType":864},{},[],{"data":10664,"marks":10665,"value":6981,"nodeType":864},{},[],{"data":10667,"content":10670,"nodeType":996},{"target":10668},{"sys":10669},{"id":6986,"type":1001,"linkType":1002},[],{"data":10672,"content":10673,"nodeType":1312},{},[10674],{"data":10675,"marks":10676,"value":6995,"nodeType":864},{},[10677],{"type":899},{"data":10679,"content":10680,"nodeType":860},{},[10681],{"data":10682,"marks":10683,"value":7002,"nodeType":864},{},[],{"data":10685,"content":10688,"nodeType":996},{"target":10686},{"sys":10687},{"id":7007,"type":1001,"linkType":1002},[],{"data":10690,"content":10691,"nodeType":860},{},[10692,10695,10702],{"data":10693,"marks":10694,"value":7015,"nodeType":864},{},[],{"data":10696,"content":10697,"nodeType":883},{"uri":7018},[10698],{"data":10699,"marks":10700,"value":7024,"nodeType":864},{},[10701],{"type":1455},{"data":10703,"marks":10704,"value":7028,"nodeType":864},{},[],{"data":10706,"content":10707,"nodeType":1312},{},[10708],{"data":10709,"marks":10710,"value":7036,"nodeType":864},{},[10711],{"type":899},{"data":10713,"content":10714,"nodeType":860},{},[10715],{"data":10716,"marks":10717,"value":7043,"nodeType":864},{},[],{"data":10719,"content":10720,"nodeType":860},{},[10721,10724,10731,10734,10740],{"data":10722,"marks":10723,"value":7050,"nodeType":864},{},[],{"data":10725,"content":10726,"nodeType":883},{"uri":7053},[10727],{"data":10728,"marks":10729,"value":7059,"nodeType":864},{},[10730],{"type":1455},{"data":10732,"marks":10733,"value":7063,"nodeType":864},{},[],{"data":10735,"content":10736,"nodeType":883},{"uri":7066},[10737],{"data":10738,"marks":10739,"value":1555,"nodeType":864},{},[],{"data":10741,"marks":10742,"value":7074,"nodeType":864},{},[],{"data":10744,"content":10747,"nodeType":996},{"target":10745},{"sys":10746},{"id":7079,"type":1001,"linkType":1002},[],{"data":10749,"content":10750,"nodeType":860},{},[10751,10754,10758],{"data":10752,"marks":10753,"value":7087,"nodeType":864},{},[],{"data":10755,"marks":10756,"value":7092,"nodeType":864},{},[10757],{"type":899},{"data":10759,"marks":10760,"value":2924,"nodeType":864},{},[],{"data":10762,"content":10763,"nodeType":1005},{},[],{"data":10765,"content":10766,"nodeType":1009},{},[10767],{"data":10768,"marks":10769,"value":7106,"nodeType":864},{},[10770],{"type":899},{"data":10772,"content":10773,"nodeType":860},{},[10774],{"data":10775,"marks":10776,"value":7113,"nodeType":864},{},[],{"data":10778,"content":10781,"nodeType":996},{"target":10779},{"sys":10780},{"id":1040,"type":1001,"linkType":1002},[],{"data":10783,"content":10784,"nodeType":1312},{},[10785,10789,10792],{"data":10786,"marks":10787,"value":7126,"nodeType":864},{},[10788],{"type":899},{"data":10790,"marks":10791,"value":1171,"nodeType":864},{},[],{"data":10793,"marks":10794,"value":7134,"nodeType":864},{},[10795],{"type":899},{"data":10797,"content":10798,"nodeType":860},{},[10799],{"data":10800,"marks":10801,"value":7141,"nodeType":864},{},[],{"data":10803,"content":10804,"nodeType":860},{},[10805],{"data":10806,"marks":10807,"value":7148,"nodeType":864},{},[],{"data":10809,"content":10810,"nodeType":1312},{},[10811,10815],{"data":10812,"marks":10813,"value":7156,"nodeType":864},{},[10814],{"type":899},{"data":10816,"marks":10817,"value":7160,"nodeType":864},{},[],{"data":10819,"content":10820,"nodeType":860},{},[10821,10824,10831],{"data":10822,"marks":10823,"value":7167,"nodeType":864},{},[],{"data":10825,"content":10826,"nodeType":883},{"uri":7170},[10827],{"data":10828,"marks":10829,"value":7176,"nodeType":864},{},[10830],{"type":1455},{"data":10832,"marks":10833,"value":7180,"nodeType":864},{},[],{"data":10835,"content":10836,"nodeType":860},{},[10837],{"data":10838,"marks":10839,"value":7187,"nodeType":864},{},[],{"data":10841,"content":10842,"nodeType":860},{},[10843],{"data":10844,"marks":10845,"value":7194,"nodeType":864},{},[],{"data":10847,"content":10848,"nodeType":1312},{},[10849],{"data":10850,"marks":10851,"value":7202,"nodeType":864},{},[10852],{"type":899},{"data":10854,"content":10855,"nodeType":860},{},[10856],{"data":10857,"marks":10858,"value":7209,"nodeType":864},{},[],{"data":10860,"content":10861,"nodeType":860},{},[10862,10865,10872],{"data":10863,"marks":10864,"value":2761,"nodeType":864},{},[],{"data":10866,"content":10867,"nodeType":883},{"uri":4103},[10868],{"data":10869,"marks":10870,"value":7223,"nodeType":864},{},[10871],{"type":1455},{"data":10873,"marks":10874,"value":7227,"nodeType":864},{},[],{"data":10876,"content":10879,"nodeType":996},{"target":10877},{"sys":10878},{"id":7232,"type":1001,"linkType":1002},[],{"data":10881,"content":10882,"nodeType":860},{},[10883],{"data":10884,"marks":10885,"value":7240,"nodeType":864},{},[],{"data":10887,"content":10890,"nodeType":996},{"target":10888},{"sys":10889},{"id":7245,"type":1001,"linkType":1002},[],{"data":10892,"content":10895,"nodeType":996},{"target":10893},{"sys":10894},{"id":7251,"type":1001,"linkType":1002},[],{"data":10897,"content":10898,"nodeType":1005},{},[],{"data":10900,"content":10901,"nodeType":1009},{},[10902],{"data":10903,"marks":10904,"value":7263,"nodeType":864},{},[10905],{"type":899},{"data":10907,"content":10908,"nodeType":860},{},[10909],{"data":10910,"marks":10911,"value":7270,"nodeType":864},{},[],{"data":10913,"content":10914,"nodeType":860},{},[10915],{"data":10916,"marks":10917,"value":7277,"nodeType":864},{},[],{"data":10919,"content":10920,"nodeType":941},{},[10921,10934,10947,10960],{"data":10922,"content":10923,"nodeType":945},{},[10924],{"data":10925,"content":10926,"nodeType":860},{},[10927,10931],{"data":10928,"marks":10929,"value":7291,"nodeType":864},{},[10930],{"type":899},{"data":10932,"marks":10933,"value":7295,"nodeType":864},{},[],{"data":10935,"content":10936,"nodeType":945},{},[10937],{"data":10938,"content":10939,"nodeType":860},{},[10940,10944],{"data":10941,"marks":10942,"value":7306,"nodeType":864},{},[10943],{"type":899},{"data":10945,"marks":10946,"value":7310,"nodeType":864},{},[],{"data":10948,"content":10949,"nodeType":945},{},[10950],{"data":10951,"content":10952,"nodeType":860},{},[10953,10957],{"data":10954,"marks":10955,"value":7321,"nodeType":864},{},[10956],{"type":899},{"data":10958,"marks":10959,"value":7325,"nodeType":864},{},[],{"data":10961,"content":10962,"nodeType":945},{},[10963],{"data":10964,"content":10965,"nodeType":860},{},[10966,10970],{"data":10967,"marks":10968,"value":7336,"nodeType":864},{},[10969],{"type":899},{"data":10971,"marks":10972,"value":7340,"nodeType":864},{},[],{"data":10974,"content":10975,"nodeType":860},{},[10976],{"data":10977,"marks":10978,"value":7347,"nodeType":864},{},[],{"data":10980,"content":10981,"nodeType":1312},{},[10982],{"data":10983,"marks":10984,"value":7354,"nodeType":864},{},[],{"data":10986,"content":10987,"nodeType":860},{},[10988],{"data":10989,"marks":10990,"value":7361,"nodeType":864},{},[],{"data":10992,"content":10993,"nodeType":860},{},[10994],{"data":10995,"marks":10996,"value":7368,"nodeType":864},{},[],{"data":10998,"content":10999,"nodeType":860},{},[11000,11003,11007],{"data":11001,"marks":11002,"value":7375,"nodeType":864},{},[],{"data":11004,"marks":11005,"value":7380,"nodeType":864},{},[11006],{"type":899},{"data":11008,"marks":11009,"value":7384,"nodeType":864},{},[],{"data":11011,"content":11012,"nodeType":860},{},[11013],{"data":11014,"marks":11015,"value":7391,"nodeType":864},{},[],{"data":11017,"content":11018,"nodeType":860},{},[11019],{"data":11020,"marks":11021,"value":7398,"nodeType":864},{},[],{"data":11023,"content":11024,"nodeType":1312},{},[11025],{"data":11026,"marks":11027,"value":7405,"nodeType":864},{},[],{"data":11029,"content":11030,"nodeType":860},{},[11031],{"data":11032,"marks":11033,"value":7412,"nodeType":864},{},[],{"data":11035,"content":11036,"nodeType":860},{},[11037],{"data":11038,"marks":11039,"value":7419,"nodeType":864},{},[],{"data":11041,"content":11042,"nodeType":860},{},[11043],{"data":11044,"marks":11045,"value":7426,"nodeType":864},{},[],{"data":11047,"content":11048,"nodeType":1312},{},[11049],{"data":11050,"marks":11051,"value":7433,"nodeType":864},{},[],{"data":11053,"content":11054,"nodeType":860},{},[11055],{"data":11056,"marks":11057,"value":7440,"nodeType":864},{},[],{"data":11059,"content":11060,"nodeType":860},{},[11061],{"data":11062,"marks":11063,"value":7447,"nodeType":864},{},[],{"data":11065,"content":11066,"nodeType":1312},{},[11067],{"data":11068,"marks":11069,"value":7454,"nodeType":864},{},[],{"data":11071,"content":11072,"nodeType":860},{},[11073],{"data":11074,"marks":11075,"value":7461,"nodeType":864},{},[],{"data":11077,"content":11078,"nodeType":860},{},[11079],{"data":11080,"marks":11081,"value":7468,"nodeType":864},{},[],{"data":11083,"content":11084,"nodeType":860},{},[11085],{"data":11086,"marks":11087,"value":7475,"nodeType":864},{},[],{"data":11089,"content":11090,"nodeType":1005},{},[],{"data":11092,"content":11093,"nodeType":1009},{},[11094],{"data":11095,"marks":11096,"value":7486,"nodeType":864},{},[11097],{"type":899},{"data":11099,"content":11100,"nodeType":860},{},[11101],{"data":11102,"marks":11103,"value":7493,"nodeType":864},{},[],{"data":11105,"content":11106,"nodeType":860},{},[11107,11110],{"data":11108,"marks":11109,"value":7500,"nodeType":864},{},[],{"data":11111,"marks":11112,"value":7505,"nodeType":864},{},[11113],{"type":899},{"data":11115,"content":11116,"nodeType":860},{},[11117],{"data":11118,"marks":11119,"value":7512,"nodeType":864},{},[],{"data":11121,"content":11122,"nodeType":860},{},[11123],{"data":11124,"marks":11125,"value":7519,"nodeType":864},{},[],{"data":11127,"content":11128,"nodeType":860},{},[11129],{"data":11130,"marks":11131,"value":7526,"nodeType":864},{},[],{"data":11133,"content":11134,"nodeType":1312},{},[11135],{"data":11136,"marks":11137,"value":7533,"nodeType":864},{},[],{"data":11139,"content":11140,"nodeType":941},{},[11141,11160,11179,11198,11207,11216,11225],{"data":11142,"content":11143,"nodeType":945},{},[11144],{"data":11145,"content":11146,"nodeType":860},{},[11147,11150,11157],{"data":11148,"marks":11149,"value":7546,"nodeType":864},{},[],{"data":11151,"content":11152,"nodeType":883},{"uri":7549},[11153],{"data":11154,"marks":11155,"value":7555,"nodeType":864},{},[11156],{"type":1455},{"data":11158,"marks":11159,"value":7559,"nodeType":864},{},[],{"data":11161,"content":11162,"nodeType":945},{},[11163],{"data":11164,"content":11165,"nodeType":860},{},[11166,11169,11176],{"data":11167,"marks":11168,"value":7569,"nodeType":864},{},[],{"data":11170,"content":11171,"nodeType":883},{"uri":7572},[11172],{"data":11173,"marks":11174,"value":7578,"nodeType":864},{},[11175],{"type":1455},{"data":11177,"marks":11178,"value":7582,"nodeType":864},{},[],{"data":11180,"content":11181,"nodeType":945},{},[11182],{"data":11183,"content":11184,"nodeType":860},{},[11185,11188,11195],{"data":11186,"marks":11187,"value":21,"nodeType":864},{},[],{"data":11189,"content":11190,"nodeType":883},{"uri":7594},[11191],{"data":11192,"marks":11193,"value":7600,"nodeType":864},{},[11194],{"type":1455},{"data":11196,"marks":11197,"value":7604,"nodeType":864},{},[],{"data":11199,"content":11200,"nodeType":945},{},[11201],{"data":11202,"content":11203,"nodeType":860},{},[11204],{"data":11205,"marks":11206,"value":7614,"nodeType":864},{},[],{"data":11208,"content":11209,"nodeType":945},{},[11210],{"data":11211,"content":11212,"nodeType":860},{},[11213],{"data":11214,"marks":11215,"value":7624,"nodeType":864},{},[],{"data":11217,"content":11218,"nodeType":945},{},[11219],{"data":11220,"content":11221,"nodeType":860},{},[11222],{"data":11223,"marks":11224,"value":7634,"nodeType":864},{},[],{"data":11226,"content":11227,"nodeType":945},{},[11228],{"data":11229,"content":11230,"nodeType":860},{},[11231,11234,11241],{"data":11232,"marks":11233,"value":7644,"nodeType":864},{},[],{"data":11235,"content":11236,"nodeType":883},{"uri":7647},[11237],{"data":11238,"marks":11239,"value":7653,"nodeType":864},{},[11240],{"type":1455},{"data":11242,"marks":11243,"value":7657,"nodeType":864},{},[],{"data":11245,"content":11246,"nodeType":860},{},[11247],{"data":11248,"marks":11249,"value":21,"nodeType":864},{},[],{"data":11251,"content":11254,"nodeType":996},{"target":11252},{"sys":11253},{"id":7668,"type":1001,"linkType":1002},[],{"data":11256,"content":11257,"nodeType":1005},{},[],{"data":11259,"content":11260,"nodeType":860},{},[11261,11264,11271],{"data":11262,"marks":11263,"value":7679,"nodeType":864},{},[],{"data":11265,"content":11266,"nodeType":883},{"uri":1700},[11267],{"data":11268,"marks":11269,"value":7687,"nodeType":864},{},[11270],{"type":1455},{"data":11272,"marks":11273,"value":2924,"nodeType":864},{},[],{"items":11275},[11276,11278],{"sys":11277,"name":297},{"id":2732},{"sys":11279,"name":2729},{"id":2728},{"items":11281},[11282],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":11283},{"url":853},{"__typename":2059,"sys":11285,"content":11287,"title":11980,"synopsis":11981,"hashTags":59,"publishedDate":11982,"slug":11983,"tagsCollection":11984,"authorsCollection":11990},{"id":11286},"1ThCW6Cx8Zcq2flramQdoj",{"json":11288},{"data":11289,"content":11290,"nodeType":856},{},[11291,11298,11305,11327,11334,11341,11348,11351,11359,11366,11384,11391,11398,11446,11453,11461,11468,11475,11482,11485,11493,11500,11512,11519,11527,11547,11553,11594,11600,11607,11619,11625,11632,11650,11658,11665,11685,11691,11699,11706,11865,11868,11876,11883,11890,11893,11901,11908,11920,11932,11944,11956,11963],{"data":11292,"content":11293,"nodeType":860},{},[11294],{"data":11295,"marks":11296,"value":11297,"nodeType":864},{},[],"At first, it may seem like an obvious choice, partly because the category name \"Secure Enterprise Browser\" implies the answer is a full-stack browser. Plus, the most visible vendors in the space have spent the past few years marketing that exact choice as the only one. ",{"data":11299,"content":11300,"nodeType":860},{},[11301],{"data":11302,"marks":11303,"value":11304,"nodeType":864},{},[],"But the market tells a different story. The majority of vendors Gartner places in the SEB category are now extensions rather than full browsers, and Gartner explicitly notes that extensions have become the preferred option. ",{"data":11306,"content":11307,"nodeType":1116},{},[11308],{"data":11309,"content":11310,"nodeType":860},{},[11311,11315,11323],{"data":11312,"marks":11313,"value":11314,"nodeType":864},{},[],"The buyer-side data tells the same story: In ",{"data":11316,"content":11317,"nodeType":883},{"uri":2561},[11318],{"data":11319,"marks":11320,"value":11322,"nodeType":864},{},[11321],{"type":1455},"Omdia's 2026 survey of 400 IT and security professionals",{"data":11324,"marks":11325,"value":11326,"nodeType":864},{},[],", 48% of organizations cited the ability to use their existing browsers as an important attribute in a secure browsing solution.",{"data":11328,"content":11329,"nodeType":860},{},[11330],{"data":11331,"marks":11332,"value":11333,"nodeType":864},{},[],"The truth is: Full-stack enterprise browsers and browser security extensions like Push aren’t competing products. They serve different needs for different teams, though they often get evaluated against each other.",{"data":11335,"content":11336,"nodeType":860},{},[11337],{"data":11338,"marks":11339,"value":11340,"nodeType":864},{},[],"Full-stack enterprise browsers serve the IT team's need to control the workspace. Browser security extensions like Push meet the security team's need to protect their users as they work in their browsers — a fundamentally different problem. ",{"data":11342,"content":11343,"nodeType":860},{},[11344],{"data":11345,"marks":11346,"value":11347,"nodeType":864},{},[],"In this article, we’ll cover why a feature-by-feature checklist is the wrong approach when selecting a secure browser platform, and what questions to consider instead. We’ll also discuss what each type of solution excels at, where Push fits in, and how to map your needs to the right solution.",{"data":11349,"content":11350,"nodeType":1005},{},[],{"data":11352,"content":11353,"nodeType":1009},{},[11354],{"data":11355,"marks":11356,"value":11358,"nodeType":864},{},[11357],{"type":899},"Full-stack enterprise browsers meet the IT team's need to control a workspace",{"data":11360,"content":11361,"nodeType":860},{},[11362],{"data":11363,"marks":11364,"value":11365,"nodeType":864},{},[],"Full-stack enterprise browsers like Island, Prisma Browser, and SURF Security are best understood as managed workspace platforms rather than browsers in the conventional sense. ",{"data":11367,"content":11368,"nodeType":1116},{},[11369],{"data":11370,"content":11371,"nodeType":860},{},[11372,11376,11381],{"data":11373,"marks":11374,"value":11375,"nodeType":864},{},[],"Island's own CEO Mike Fey has described the company's strategy as transforming the browser into ",{"data":11377,"marks":11378,"value":11380,"nodeType":864},{},[11379],{"type":2246},"\"a centralized, enterprise-grade platform, eliminating layers of legacy IT infrastructure by building more functionality in the browser.\"",{"data":11382,"marks":11383,"value":7160,"nodeType":864},{},[],{"data":11385,"content":11386,"nodeType":860},{},[11387],{"data":11388,"marks":11389,"value":11390,"nodeType":864},{},[],"Chrome Enterprise and Edge for Business occupy a related space as productivity-suite browsers extended with native security controls, sold as part of the broader Google and Microsoft workplace stacks. Different products with different lineage, but all of them converge on the same owner: an IT organization solving for workspace control.",{"data":11392,"content":11393,"nodeType":860},{},[11394],{"data":11395,"marks":11396,"value":11397,"nodeType":864},{},[],"The IT team is trying to achieve workspace policy compliance and access governance. Their primary use case is typically reducing reliance on legacy IT tools like VDI, VPN, remote browser isolation, DaaS, web filtering, and CASBs. In this world, the use cases look like: ",{"data":11399,"content":11400,"nodeType":941},{},[11401,11416,11431],{"data":11402,"content":11403,"nodeType":945},{},[11404],{"data":11405,"content":11406,"nodeType":860},{},[11407,11412],{"data":11408,"marks":11409,"value":11411,"nodeType":864},{},[11410],{"type":899},"Securing third-party contractors or BYOD",{"data":11413,"marks":11414,"value":11415,"nodeType":864},{},[]," where the workspace itself is the access control. ",{"data":11417,"content":11418,"nodeType":945},{},[11419],{"data":11420,"content":11421,"nodeType":860},{},[11422,11427],{"data":11423,"marks":11424,"value":11426,"nodeType":864},{},[11425],{"type":899},"Regulated populations",{"data":11428,"marks":11429,"value":11430,"nodeType":864},{},[]," like call centers, BPO workforces, finance teams handling sensitive material, where output controls like watermarking, screenshot restriction, and print blocking need to be enforced at the OS rendering layer. ",{"data":11432,"content":11433,"nodeType":945},{},[11434],{"data":11435,"content":11436,"nodeType":860},{},[11437,11442],{"data":11438,"marks":11439,"value":11441,"nodeType":864},{},[11440],{"type":899},"Legacy app support",{"data":11443,"marks":11444,"value":11445,"nodeType":864},{},[]," including IE-mode rendering for applications that have never been modernized. ",{"data":11447,"content":11448,"nodeType":860},{},[11449],{"data":11450,"marks":11451,"value":11452,"nodeType":864},{},[],"For these use cases, the architecture is well-suited, and there are numerous full-stack SEB solutions that address them well. Where the full-stack approach runs into trouble is in getting users to migrate onto a new browser and in justifying the cost of doing so. Both problems scale with the size of the workforce. ",{"data":11454,"content":11455,"nodeType":1312},{},[11456],{"data":11457,"marks":11458,"value":11460,"nodeType":864},{},[11459],{"type":899},"Cost of deployment is a significant blocker for full-stack browsers",{"data":11462,"content":11463,"nodeType":860},{},[11464],{"data":11465,"marks":11466,"value":11467,"nodeType":864},{},[],"The migration costs are easy to predict: deployment and configuration effort, help desk volume and — biggest of all — user resistance. But it’s the license cost that limits deployments in many organizations going from a free consumer browser to a paid replacement for the first time. ",{"data":11469,"content":11470,"nodeType":860},{},[11471],{"data":11472,"marks":11473,"value":11474,"nodeType":864},{},[],"In fact, Gartner notes that most buyers start with a single use case like covering contractors and rarely pursue organization-wide deployment for a full-stack enterprise browser. ",{"data":11476,"content":11477,"nodeType":860},{},[11478],{"data":11479,"marks":11480,"value":11481,"nodeType":864},{},[],"For organizations that do achieve a full-coverage deployment for these full-stack browsers, the need to manage drift in employee behavior over time gets harder. Agentic browsers like Comet, Atlas, and Dia are already starting to pull users toward AI-native workflows that consumer browsers don’t offer and full-stack enterprise browsers don’t currently match.",{"data":11483,"content":11484,"nodeType":1005},{},[],{"data":11486,"content":11487,"nodeType":1009},{},[11488],{"data":11489,"marks":11490,"value":11492,"nodeType":864},{},[11491],{"type":899},"What a browser security extension built for the security team looks like",{"data":11494,"content":11495,"nodeType":860},{},[11496],{"data":11497,"marks":11498,"value":11499,"nodeType":864},{},[],"Most browser security extensions on the market were built to address this migration hurdle. They attempt to take as many of the features of a full-stack browser as possible, but make it possible to deploy into users’ existing browsers, sidestepping a lot of the cost and rollout problems.",{"data":11501,"content":11502,"nodeType":860},{},[11503,11507],{"data":11504,"marks":11505,"value":11506,"nodeType":864},{},[],"LayerX, Seraphic, SquareX, and Keep Aware have all at some point echoed this approach in their product descriptions with the line ",{"data":11508,"marks":11509,"value":11511,"nodeType":864},{},[11510],{"type":2246},"\"make any browser an enterprise browser.\"",{"data":11513,"content":11514,"nodeType":860},{},[11515],{"data":11516,"marks":11517,"value":11518,"nodeType":864},{},[],"Ultimately, that approach is still aimed at solving problems for the IT team more than the security team.",{"data":11520,"content":11521,"nodeType":1312},{},[11522],{"data":11523,"marks":11524,"value":11526,"nodeType":864},{},[11525],{"type":899},"Push is different — we built a browser extension to meet the security team's needs",{"data":11528,"content":11529,"nodeType":860},{},[11530,11534,11543],{"data":11531,"marks":11532,"value":11533,"nodeType":864},{},[],"Push set out to meet a different need. Our team's background has always been in defending organizations against advanced attacks. We spent our careers working in red and blue teams throughout the network and endpoint eras of cyber attacks. The mission we started with in 2022 was to defend organizations against the ",{"data":11535,"content":11537,"nodeType":883},{"uri":11536},"https://pushsecurity.com/thank-you/browser-attacks-report",[11538],{"data":11539,"marks":11540,"value":11542,"nodeType":864},{},[11541],{"type":1455},"new era of damaging cyber attacks that originate in the browser",{"data":11544,"marks":11545,"value":11546,"nodeType":864},{},[],". ",{"data":11548,"content":11552,"nodeType":996},{"target":11549},{"sys":11550},{"id":11551,"type":1001,"linkType":1002},"6BwJl8ZkiMore2o1BKx2w6",[],{"data":11554,"content":11555,"nodeType":860},{},[11556,11560,11569,11573,11578,11582,11591],{"data":11557,"marks":11558,"value":11559,"nodeType":864},{},[],"We chose a browser extension as the approach for our solution, not because we wanted to build an easier-to-deploy enterprise browser, but so we could use it as a security agent to collect high-fidelity telemetry for TTP-based detections, and apply real-time controls to stop attacks at the earliest opportunity in the modern  — ",{"data":11561,"content":11563,"nodeType":883},{"uri":11562},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/",[11564],{"data":11565,"marks":11566,"value":11568,"nodeType":864},{},[11567],{"type":1455},"browser and identity native",{"data":11570,"marks":11571,"value":11572,"nodeType":864},{},[],"  — kill chain. ",{"data":11574,"marks":11575,"value":11577,"nodeType":864},{},[11576],{"type":899},"In effect, we created EDR, but for the browser. ",{"data":11579,"marks":11580,"value":11581,"nodeType":864},{},[],"This is what gives Push the edge compared to other Secure Enterprise Browser solutions when it comes to tackling the highest priority threats in the browser — ",{"data":11583,"content":11585,"nodeType":883},{"uri":11584},"https://pushsecurity.com/blog/how-to-avoid-the-browser-security-buyers-trap/",[11586],{"data":11587,"marks":11588,"value":11590,"nodeType":864},{},[11589],{"type":1455},"we’re optimized for this problem area",{"data":11592,"marks":11593,"value":11546,"nodeType":864},{},[],{"data":11595,"content":11599,"nodeType":996},{"target":11596},{"sys":11597},{"id":11598,"type":1001,"linkType":1002},"4nGzT9cNG0Yid93uUCCuTt",[],{"data":11601,"content":11602,"nodeType":860},{},[11603],{"data":11604,"marks":11605,"value":11606,"nodeType":864},{},[],"For a security team using Push’s extension, this means attacks get stopped at the earliest opportunity in the kill chain and before they cause harm. ",{"data":11608,"content":11609,"nodeType":860},{},[11610,11614],{"data":11611,"marks":11612,"value":11613,"nodeType":864},{},[],"When a user lands on a phishing page built to harvest their credentials, Push sees the page rendering and the JavaScript executing inside the DOM, and can block the credential submission before the form posts. When a user is being walked through a ClickFix or ConsentFix social engineering flow, Push sees the clipboard writes and the OAuth consent flow parameters being prepared, and can intervene before the user completes the action. When a session token is stolen and replayed against a different device, Push sees the session activity and surfaces the compromise. ",{"data":11615,"marks":11616,"value":11618,"nodeType":864},{},[11617],{"type":899},"Push does all of this from a browser extension, without needing to replace the user's browser. ",{"data":11620,"content":11624,"nodeType":996},{"target":11621},{"sys":11622},{"id":11623,"type":1001,"linkType":1002},"1FZEbn0K80d1jHRRTk7kL7",[],{"data":11626,"content":11627,"nodeType":860},{},[11628],{"data":11629,"marks":11630,"value":11631,"nodeType":864},{},[],"The same underlying technology also addresses other high-value security use cases: Visibility and control over AI usage; hardening identities and surfacing shadow IT; and supporting insider investigations and preventing data loss. ",{"data":11633,"content":11634,"nodeType":860},{},[11635,11638,11646],{"data":11636,"marks":11637,"value":2761,"nodeType":864},{},[],{"data":11639,"content":11641,"nodeType":883},{"uri":11640},"https://pushsecurity.com/blog/the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value/",[11642],{"data":11643,"marks":11644,"value":11645,"nodeType":864},{},[],"highest-value use cases",{"data":11647,"marks":11648,"value":11649,"nodeType":864},{},[]," the browser can address are all powered by the same underlying technical capability, which is why Push's single extension can address four major security use cases rather than four separate tools needing four separate deployments. The success metric for security teams using Push is attacks averted or stopped, cyber risk reduced, and security posture and resilience strengthened — not workspace policy compliance.",{"data":11651,"content":11652,"nodeType":1312},{},[11653],{"data":11654,"marks":11655,"value":11657,"nodeType":864},{},[11656],{"type":899},"Proven at scale: What security leaders are saying",{"data":11659,"content":11660,"nodeType":860},{},[11661],{"data":11662,"marks":11663,"value":11664,"nodeType":864},{},[],"Push launched its browser extension in 2022, making it one of the first and longest-running browser security extensions in the category, and it is now deployed across more than three million browsers worldwide.",{"data":11666,"content":11667,"nodeType":860},{},[11668,11672,11681],{"data":11669,"marks":11670,"value":11671,"nodeType":864},{},[],"Many ",{"data":11673,"content":11675,"nodeType":883},{"uri":11674},"https://pushsecurity.com/customer-stories",[11676],{"data":11677,"marks":11678,"value":11680,"nodeType":864},{},[11679],{"type":1455},"Push customers",{"data":11682,"marks":11683,"value":11684,"nodeType":864},{},[]," were initially considering full-stack enterprise browsers, but found that Push provided all the visibility and control they needed without the migration headache.",{"data":11686,"content":11690,"nodeType":996},{"target":11687},{"sys":11688},{"id":11689,"type":1001,"linkType":1002},"4RDIOAuVN10mZCtjltJCB4",[],{"data":11692,"content":11693,"nodeType":1312},{},[11694],{"data":11695,"marks":11696,"value":11698,"nodeType":864},{},[11697],{"type":899},"The extension matters, but it's what we built around it that really counts",{"data":11700,"content":11701,"nodeType":860},{},[11702],{"data":11703,"marks":11704,"value":11705,"nodeType":864},{},[],"The extension is the most visible part of the Push platform, but what Push has built around it makes the solution the most powerful security tool in the browser:",{"data":11707,"content":11708,"nodeType":941},{},[11709,11759,11796,11835,11850],{"data":11710,"content":11711,"nodeType":945},{},[11712],{"data":11713,"content":11714,"nodeType":860},{},[11715,11720,11724,11732,11736,11744,11748,11755],{"data":11716,"marks":11717,"value":11719,"nodeType":864},{},[11718],{"type":899},"In-house threat research that discovers attack techniques as they emerge.",{"data":11721,"marks":11722,"value":11723,"nodeType":864},{},[]," Push researchers track real-world adversary activity and discover new techniques as they appear, including ",{"data":11725,"content":11727,"nodeType":883},{"uri":11726},"https://pushsecurity.com/blog/consentfix/",[11728],{"data":11729,"marks":11730,"value":11731,"nodeType":864},{},[],"ConsentFix",{"data":11733,"marks":11734,"value":11735,"nodeType":864},{},[],",",{"data":11737,"content":11739,"nodeType":883},{"uri":11738},"https://pushsecurity.com/blog/installfix/",[11740],{"data":11741,"marks":11742,"value":11743,"nodeType":864},{},[]," InstallFix",{"data":11745,"marks":11746,"value":11747,"nodeType":864},{},[],", and creating the ",{"data":11749,"content":11750,"nodeType":883},{"uri":7549},[11751],{"data":11752,"marks":11753,"value":11754,"nodeType":864},{},[],"Browser & Identity Attacks Matrix",{"data":11756,"marks":11757,"value":11758,"nodeType":864},{},[],". Detection is only as good as the threat understanding behind it, and research is what keeps that understanding ahead of what attackers are doing in the wild.",{"data":11760,"content":11761,"nodeType":945},{},[11762],{"data":11763,"content":11764,"nodeType":860},{},[11765,11770,11774,11780,11784,11792],{"data":11766,"marks":11767,"value":11769,"nodeType":864},{},[11768],{"type":899},"Agentic threat hunting and detection engineering at machine speed.",{"data":11771,"marks":11772,"value":11773,"nodeType":864},{},[]," Push's ",{"data":11775,"content":11776,"nodeType":883},{"uri":7572},[11777],{"data":11778,"marks":11779,"value":7578,"nodeType":864},{},[],{"data":11781,"marks":11782,"value":11783,"nodeType":864},{},[]," operationalizes the research, generating new behavioral detections in minutes rather than quarterly releases — covering the ",{"data":11785,"content":11787,"nodeType":883},{"uri":11786},"https://pushsecurity.com/blog/how-the-browser-became-the-main-cyber-battleground/",[11788],{"data":11789,"marks":11790,"value":11791,"nodeType":864},{},[],"techniques behind the Scattered Spider, Scattered Lapsus$ Hunters, and ShinyHunters breaches",{"data":11793,"marks":11794,"value":11795,"nodeType":864},{},[]," of the past three years. Attackers are using AI to accelerate the pace at which they generate new lures, kits, and infrastructure; Push keeps security teams in front by advancing the capability at machine speed and scale.",{"data":11797,"content":11798,"nodeType":945},{},[11799],{"data":11800,"content":11801,"nodeType":860},{},[11802,11807,11811,11819,11823,11831],{"data":11803,"marks":11804,"value":11806,"nodeType":864},{},[11805],{"type":899},"Collecting the right telemetry to surface both attacker behavior and risky user action.",{"data":11808,"marks":11809,"value":11810,"nodeType":864},{},[]," Telemetry by itself is just data — the value comes from knowing what to collect, why it matters, and how to turn it into detections and controls. Push combines deep instrumentation of the browser with the expertise to use what we collect: the same browser-layer telemetry that detects AiTM kits, ClickFix and ConsentFix lures, and session token replay also surfaces what users are pasting into AI tools, which ",{"data":11812,"content":11814,"nodeType":883},{"uri":11813},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[11815],{"data":11816,"marks":11817,"value":11818,"nodeType":864},{},[],"SaaS apps they're logging into outside the IdP",{"data":11820,"marks":11821,"value":11822,"nodeType":864},{},[],", which OAuth grants are being made, and which ",{"data":11824,"content":11826,"nodeType":883},{"uri":11825},"https://pushsecurity.com/blog/browser-extension-management-guide/",[11827],{"data":11828,"marks":11829,"value":11830,"nodeType":864},{},[],"extensions are running in their browsers",{"data":11832,"marks":11833,"value":11834,"nodeType":864},{},[],". The threat detection and the identity, AI, and DLP use cases are not separate features — they are different applications of the same underlying telemetry, surfaced because Push knows what to look for.",{"data":11836,"content":11837,"nodeType":945},{},[11838],{"data":11839,"content":11840,"nodeType":860},{},[11841,11846],{"data":11842,"marks":11843,"value":11845,"nodeType":864},{},[11844],{"type":899},"Enforcing the right controls at the right place at the right moment.",{"data":11847,"marks":11848,"value":11849,"nodeType":864},{},[]," Visibility without actionability is only half a solution. Push turns the browser into a strong control point for stopping attacks and risky user behaviors in real time — reusing passwords, intercepting credential submission to non-IdP domains, blocking ClickFix clipboard payloads before paste-execute, prompting MFA enrollment at the point of login, warning on weak or breached passwords at credential entry, and surfacing app banners that communicate policy at the moment of use. The same control surface that stops attackers stops the user's mistakes that lead to the next breach.",{"data":11851,"content":11852,"nodeType":945},{},[11853],{"data":11854,"content":11855,"nodeType":860},{},[11856,11861],{"data":11857,"marks":11858,"value":11860,"nodeType":864},{},[11859],{"type":899},"Balancing security and privacy.",{"data":11862,"marks":11863,"value":11864,"nodeType":864},{},[]," Push is designed to give security teams the telemetry they need without monitoring personal browsing. By default, only logins to configured corporate domains are observed; personal browsing is not collected. (Though administrators have the option to observe personal account logins to work apps, and identify where browsers are being synced to personal accounts, which can result in password loss.) Plaintext passwords and form inputs are never transmitted — passwords are analyzed locally using salted partial hashes. Broader browser metadata is stored on the device and only transmitted when it matches a detection rule. Push does not train AI models on customer telemetry.",{"data":11866,"content":11867,"nodeType":1005},{},[],{"data":11869,"content":11870,"nodeType":1009},{},[11871],{"data":11872,"marks":11873,"value":11875,"nodeType":864},{},[11874],{"type":899},"Full-stack enterprise browsers and Push’s browser extension are not mutually exclusive",{"data":11877,"content":11878,"nodeType":860},{},[11879],{"data":11880,"marks":11881,"value":11882,"nodeType":864},{},[],"It’s worth pausing on a point that often gets lost in the way the market discusses this choice. Full-stack enterprise browsers and Push’s extension-based solution are not mutually exclusive. They do different things for different teams, and they run together. ",{"data":11884,"content":11885,"nodeType":860},{},[11886],{"data":11887,"marks":11888,"value":11889,"nodeType":864},{},[],"Push supports enterprise browsers like Island and Prisma Browser. Many of Push’s customers use a full-stack browser for the contractor population or regulated workload where the IT team needs workspace controls, and Push across the rest of the workforce to provide the deep security capabilities that the IT team is not measured on but the security team is. The right framing for many enterprises is not whether to choose full-stack or extension. It is full-stack for the IT use cases that need it, and Push everywhere else.",{"data":11891,"content":11892,"nodeType":1005},{},[],{"data":11894,"content":11895,"nodeType":1009},{},[11896],{"data":11897,"marks":11898,"value":11900,"nodeType":864},{},[11899],{"type":899},"Which one is right for your security team?",{"data":11902,"content":11903,"nodeType":860},{},[11904],{"data":11905,"marks":11906,"value":11907,"nodeType":864},{},[],"The answer follows from the need you are trying to meet. The scenarios below cover the most common real-world situations and the approach that fits each.",{"data":11909,"content":11910,"nodeType":860},{},[11911,11916],{"data":11912,"marks":11913,"value":11915,"nodeType":864},{},[11914],{"type":899},"Is your priority detecting and stopping attacks in the browser?",{"data":11917,"marks":11918,"value":11919,"nodeType":864},{},[]," Go with Push. Push detects and stops the threats actually breaching enterprises — AiTM phishing, ClickFix, OAuth abuse, malicious browser extensions. It also provides valuable additional insight during investigations to understand incidents better and decide how to respond to them. ",{"data":11921,"content":11922,"nodeType":860},{},[11923,11928],{"data":11924,"marks":11925,"value":11927,"nodeType":864},{},[11926],{"type":899},"Do you have a large contractor or third-party population needing locked-down workspace controls?",{"data":11929,"marks":11930,"value":11931,"nodeType":864},{},[]," Use a full-stack enterprise browser for that population and Push for everyone else. Watermarking, screenshot blocking and print restriction are OS-level controls that extensions cannot reliably replicate.",{"data":11933,"content":11934,"nodeType":860},{},[11935,11940],{"data":11936,"marks":11937,"value":11939,"nodeType":864},{},[11938],{"type":899},"Do you have a multi-browser estate including a mix of consumer and agentic browsers?",{"data":11941,"marks":11942,"value":11943,"nodeType":864},{},[]," Push will provide the coverage you need to secure users. The browser options are growing, and locking your workforce into a single corporate browser becomes harder every time a new productivity-shaping browser ships. Push regularly adds support for emerging browsers.",{"data":11945,"content":11946,"nodeType":860},{},[11947,11952],{"data":11948,"marks":11949,"value":11951,"nodeType":864},{},[11950],{"type":899},"Is significant BYOD or unmanaged-device coverage required.",{"data":11953,"marks":11954,"value":11955,"nodeType":864},{},[]," Push is a great option, particularly if you also have Chromebooks that fall outside of your EDR coverage. The extension can easily be installed via email or landing page self-enrollment, with options to enforce coverage through conditional access policies. This provides full threat detection and policy enforcement on devices the organization does not own.",{"data":11957,"content":11958,"nodeType":860},{},[11959],{"data":11960,"marks":11961,"value":11962,"nodeType":864},{},[],"In short, if you are solving for workspace control, the right tool is a full-stack enterprise browser. If you’re solving for protecting users as they work in their browsers, Push is the tool built specifically for that need — with the research depth, detection engineering, and operational scale to do the job.",{"data":11964,"content":11965,"nodeType":860},{},[11966,11969,11977],{"data":11967,"marks":11968,"value":21,"nodeType":864},{},[],{"data":11970,"content":11971,"nodeType":883},{"uri":1700},[11972],{"data":11973,"marks":11974,"value":11976,"nodeType":864},{},[11975],{"type":1455},"Book a live demo to learn more",{"data":11978,"marks":11979,"value":2924,"nodeType":864},{},[],"Enterprise browser vs. browser extension: Which should your security team choose?","If you're building a shortlist of browser security vendors, do you need a full-stack enterprise browser, or browser security extension? ","2026-05-21T00:00:00.000Z","enterprise-browser-vs-browser-extension-which-should-your-security-team-choose",{"items":11985},[11986,11988],{"sys":11987,"name":297},{"id":2732},{"sys":11989,"name":2729},{"id":2728},{"items":11991},[11992],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":11993},{"url":4881},"blog/browser-visibility-and-control-can-achieve-ai-compliance",{"json":11996},{"data":11997,"content":11998,"nodeType":856},{},[11999],{"data":12000,"content":12001,"nodeType":860},{},[12002],{"data":12003,"marks":12004,"value":12005,"nodeType":864},{},[],"AI regulations across the US, EU, and UK are converging on five categories of obligation that most organizations cannot meet without browser-layer visibility into how employees actually use AI tools.",{"id":5731,"publishedAt":12007},"2026-08-12T12:00:45.359Z",{"items":12009},[12010,12012],{"sys":12011,"name":2729},{"id":2728},{"sys":12013,"name":297},{"id":2732},{"items":12015},[12016,12018,12020,12022,12024,12026,12028,12030,12032],{"sys":12017,"name":235,"slug":236,"tier":31},{"id":232},{"sys":12019,"name":297,"slug":298,"tier":31},{"id":294},{"sys":12021,"name":252,"slug":253,"tier":45},{"id":249},{"sys":12023,"name":580,"slug":581,"tier":45},{"id":577},{"sys":12025,"name":457,"slug":458,"tier":45},{"id":454},{"sys":12027,"name":484,"slug":485,"tier":45},{"id":481},{"sys":12029,"name":288,"slug":289,"tier":45},{"id":285},{"sys":12031,"name":368,"slug":369,"tier":45},{"id":365},{"sys":12033,"name":633,"slug":634,"tier":45},{"id":630},"ax7t5LR08xIdyOvvNuQpkG1-GJUNpnmhM9jsM-xV8f8",{"id":12036,"title":7691,"authorsCollection":12037,"content":12041,"extension":228,"faqItemsCollection":13003,"faqTitle":59,"featured":6,"hashTags":59,"meta":13005,"metaTitle":13006,"ogImage":59,"postType":5726,"publishedDate":6752,"relatedBlogPostsCollection":13007,"slug":7693,"stem":15164,"subtitle":15165,"summary":15166,"synopsis":7692,"sys":15176,"tagsCollection":15178,"topicsCollection":15184,"__hash__":15224},"blog/blog/why-you-cant-control-ai-without-being-in-the-browser.json",{"items":12038},[12039],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":59,"profilePicture":12040},{"url":853},{"json":12042,"links":12829},{"data":12043,"content":12044,"nodeType":856},{},[12045,12051,12057,12074,12080,12086,12089,12096,12102,12108,12129,12135,12141,12146,12149,12156,12162,12167,12173,12180,12206,12221,12226,12233,12239,12244,12260,12267,12273,12298,12303,12316,12319,12326,12332,12337,12351,12357,12363,12373,12389,12395,12401,12408,12414,12430,12435,12441,12446,12451,12454,12461,12467,12473,12528,12534,12540,12546,12552,12565,12571,12577,12583,12589,12595,12601,12607,12613,12619,12625,12631,12637,12643,12646,12653,12659,12669,12675,12681,12687,12693,12799,12805,12810,12813],{"data":12046,"content":12047,"nodeType":860},{},[12048],{"data":12049,"marks":12050,"value":6781,"nodeType":864},{},[],{"data":12052,"content":12053,"nodeType":860},{},[12054],{"data":12055,"marks":12056,"value":6788,"nodeType":864},{},[],{"data":12058,"content":12059,"nodeType":860},{},[12060,12064,12067,12071],{"data":12061,"marks":12062,"value":6796,"nodeType":864},{},[12063],{"type":899},{"data":12065,"marks":12066,"value":6800,"nodeType":864},{},[],{"data":12068,"marks":12069,"value":6805,"nodeType":864},{},[12070],{"type":2246},{"data":12072,"marks":12073,"value":6809,"nodeType":864},{},[],{"data":12075,"content":12076,"nodeType":860},{},[12077],{"data":12078,"marks":12079,"value":6816,"nodeType":864},{},[],{"data":12081,"content":12082,"nodeType":860},{},[12083],{"data":12084,"marks":12085,"value":6823,"nodeType":864},{},[],{"data":12087,"content":12088,"nodeType":1005},{},[],{"data":12090,"content":12091,"nodeType":1009},{},[12092],{"data":12093,"marks":12094,"value":6834,"nodeType":864},{},[12095],{"type":899},{"data":12097,"content":12098,"nodeType":860},{},[12099],{"data":12100,"marks":12101,"value":6841,"nodeType":864},{},[],{"data":12103,"content":12104,"nodeType":860},{},[12105],{"data":12106,"marks":12107,"value":6848,"nodeType":864},{},[],{"data":12109,"content":12110,"nodeType":941},{},[12111,12120],{"data":12112,"content":12113,"nodeType":945},{},[12114],{"data":12115,"content":12116,"nodeType":860},{},[12117],{"data":12118,"marks":12119,"value":6861,"nodeType":864},{},[],{"data":12121,"content":12122,"nodeType":945},{},[12123],{"data":12124,"content":12125,"nodeType":860},{},[12126],{"data":12127,"marks":12128,"value":6871,"nodeType":864},{},[],{"data":12130,"content":12131,"nodeType":860},{},[12132],{"data":12133,"marks":12134,"value":6878,"nodeType":864},{},[],{"data":12136,"content":12137,"nodeType":860},{},[12138],{"data":12139,"marks":12140,"value":6885,"nodeType":864},{},[],{"data":12142,"content":12145,"nodeType":996},{"target":12143},{"sys":12144},{"id":6890,"type":1001,"linkType":1002},[],{"data":12147,"content":12148,"nodeType":1005},{},[],{"data":12150,"content":12151,"nodeType":1009},{},[12152],{"data":12153,"marks":12154,"value":6902,"nodeType":864},{},[12155],{"type":899},{"data":12157,"content":12158,"nodeType":860},{},[12159],{"data":12160,"marks":12161,"value":6909,"nodeType":864},{},[],{"data":12163,"content":12166,"nodeType":996},{"target":12164},{"sys":12165},{"id":6914,"type":1001,"linkType":1002},[],{"data":12168,"content":12169,"nodeType":860},{},[12170],{"data":12171,"marks":12172,"value":6922,"nodeType":864},{},[],{"data":12174,"content":12175,"nodeType":1312},{},[12176],{"data":12177,"marks":12178,"value":6930,"nodeType":864},{},[12179],{"type":899},{"data":12181,"content":12182,"nodeType":860},{},[12183,12186,12193,12196,12203],{"data":12184,"marks":12185,"value":6937,"nodeType":864},{},[],{"data":12187,"content":12188,"nodeType":883},{"uri":6940},[12189],{"data":12190,"marks":12191,"value":6946,"nodeType":864},{},[12192],{"type":1455},{"data":12194,"marks":12195,"value":6950,"nodeType":864},{},[],{"data":12197,"content":12198,"nodeType":883},{"uri":3259},[12199],{"data":12200,"marks":12201,"value":6958,"nodeType":864},{},[12202],{"type":1455},{"data":12204,"marks":12205,"value":6962,"nodeType":864},{},[],{"data":12207,"content":12208,"nodeType":860},{},[12209,12212,12218],{"data":12210,"marks":12211,"value":6969,"nodeType":864},{},[],{"data":12213,"content":12214,"nodeType":883},{"uri":6972},[12215],{"data":12216,"marks":12217,"value":6977,"nodeType":864},{},[],{"data":12219,"marks":12220,"value":6981,"nodeType":864},{},[],{"data":12222,"content":12225,"nodeType":996},{"target":12223},{"sys":12224},{"id":6986,"type":1001,"linkType":1002},[],{"data":12227,"content":12228,"nodeType":1312},{},[12229],{"data":12230,"marks":12231,"value":6995,"nodeType":864},{},[12232],{"type":899},{"data":12234,"content":12235,"nodeType":860},{},[12236],{"data":12237,"marks":12238,"value":7002,"nodeType":864},{},[],{"data":12240,"content":12243,"nodeType":996},{"target":12241},{"sys":12242},{"id":7007,"type":1001,"linkType":1002},[],{"data":12245,"content":12246,"nodeType":860},{},[12247,12250,12257],{"data":12248,"marks":12249,"value":7015,"nodeType":864},{},[],{"data":12251,"content":12252,"nodeType":883},{"uri":7018},[12253],{"data":12254,"marks":12255,"value":7024,"nodeType":864},{},[12256],{"type":1455},{"data":12258,"marks":12259,"value":7028,"nodeType":864},{},[],{"data":12261,"content":12262,"nodeType":1312},{},[12263],{"data":12264,"marks":12265,"value":7036,"nodeType":864},{},[12266],{"type":899},{"data":12268,"content":12269,"nodeType":860},{},[12270],{"data":12271,"marks":12272,"value":7043,"nodeType":864},{},[],{"data":12274,"content":12275,"nodeType":860},{},[12276,12279,12286,12289,12295],{"data":12277,"marks":12278,"value":7050,"nodeType":864},{},[],{"data":12280,"content":12281,"nodeType":883},{"uri":7053},[12282],{"data":12283,"marks":12284,"value":7059,"nodeType":864},{},[12285],{"type":1455},{"data":12287,"marks":12288,"value":7063,"nodeType":864},{},[],{"data":12290,"content":12291,"nodeType":883},{"uri":7066},[12292],{"data":12293,"marks":12294,"value":1555,"nodeType":864},{},[],{"data":12296,"marks":12297,"value":7074,"nodeType":864},{},[],{"data":12299,"content":12302,"nodeType":996},{"target":12300},{"sys":12301},{"id":7079,"type":1001,"linkType":1002},[],{"data":12304,"content":12305,"nodeType":860},{},[12306,12309,12313],{"data":12307,"marks":12308,"value":7087,"nodeType":864},{},[],{"data":12310,"marks":12311,"value":7092,"nodeType":864},{},[12312],{"type":899},{"data":12314,"marks":12315,"value":2924,"nodeType":864},{},[],{"data":12317,"content":12318,"nodeType":1005},{},[],{"data":12320,"content":12321,"nodeType":1009},{},[12322],{"data":12323,"marks":12324,"value":7106,"nodeType":864},{},[12325],{"type":899},{"data":12327,"content":12328,"nodeType":860},{},[12329],{"data":12330,"marks":12331,"value":7113,"nodeType":864},{},[],{"data":12333,"content":12336,"nodeType":996},{"target":12334},{"sys":12335},{"id":1040,"type":1001,"linkType":1002},[],{"data":12338,"content":12339,"nodeType":1312},{},[12340,12344,12347],{"data":12341,"marks":12342,"value":7126,"nodeType":864},{},[12343],{"type":899},{"data":12345,"marks":12346,"value":1171,"nodeType":864},{},[],{"data":12348,"marks":12349,"value":7134,"nodeType":864},{},[12350],{"type":899},{"data":12352,"content":12353,"nodeType":860},{},[12354],{"data":12355,"marks":12356,"value":7141,"nodeType":864},{},[],{"data":12358,"content":12359,"nodeType":860},{},[12360],{"data":12361,"marks":12362,"value":7148,"nodeType":864},{},[],{"data":12364,"content":12365,"nodeType":1312},{},[12366,12370],{"data":12367,"marks":12368,"value":7156,"nodeType":864},{},[12369],{"type":899},{"data":12371,"marks":12372,"value":7160,"nodeType":864},{},[],{"data":12374,"content":12375,"nodeType":860},{},[12376,12379,12386],{"data":12377,"marks":12378,"value":7167,"nodeType":864},{},[],{"data":12380,"content":12381,"nodeType":883},{"uri":7170},[12382],{"data":12383,"marks":12384,"value":7176,"nodeType":864},{},[12385],{"type":1455},{"data":12387,"marks":12388,"value":7180,"nodeType":864},{},[],{"data":12390,"content":12391,"nodeType":860},{},[12392],{"data":12393,"marks":12394,"value":7187,"nodeType":864},{},[],{"data":12396,"content":12397,"nodeType":860},{},[12398],{"data":12399,"marks":12400,"value":7194,"nodeType":864},{},[],{"data":12402,"content":12403,"nodeType":1312},{},[12404],{"data":12405,"marks":12406,"value":7202,"nodeType":864},{},[12407],{"type":899},{"data":12409,"content":12410,"nodeType":860},{},[12411],{"data":12412,"marks":12413,"value":7209,"nodeType":864},{},[],{"data":12415,"content":12416,"nodeType":860},{},[12417,12420,12427],{"data":12418,"marks":12419,"value":2761,"nodeType":864},{},[],{"data":12421,"content":12422,"nodeType":883},{"uri":4103},[12423],{"data":12424,"marks":12425,"value":7223,"nodeType":864},{},[12426],{"type":1455},{"data":12428,"marks":12429,"value":7227,"nodeType":864},{},[],{"data":12431,"content":12434,"nodeType":996},{"target":12432},{"sys":12433},{"id":7232,"type":1001,"linkType":1002},[],{"data":12436,"content":12437,"nodeType":860},{},[12438],{"data":12439,"marks":12440,"value":7240,"nodeType":864},{},[],{"data":12442,"content":12445,"nodeType":996},{"target":12443},{"sys":12444},{"id":7245,"type":1001,"linkType":1002},[],{"data":12447,"content":12450,"nodeType":996},{"target":12448},{"sys":12449},{"id":7251,"type":1001,"linkType":1002},[],{"data":12452,"content":12453,"nodeType":1005},{},[],{"data":12455,"content":12456,"nodeType":1009},{},[12457],{"data":12458,"marks":12459,"value":7263,"nodeType":864},{},[12460],{"type":899},{"data":12462,"content":12463,"nodeType":860},{},[12464],{"data":12465,"marks":12466,"value":7270,"nodeType":864},{},[],{"data":12468,"content":12469,"nodeType":860},{},[12470],{"data":12471,"marks":12472,"value":7277,"nodeType":864},{},[],{"data":12474,"content":12475,"nodeType":941},{},[12476,12489,12502,12515],{"data":12477,"content":12478,"nodeType":945},{},[12479],{"data":12480,"content":12481,"nodeType":860},{},[12482,12486],{"data":12483,"marks":12484,"value":7291,"nodeType":864},{},[12485],{"type":899},{"data":12487,"marks":12488,"value":7295,"nodeType":864},{},[],{"data":12490,"content":12491,"nodeType":945},{},[12492],{"data":12493,"content":12494,"nodeType":860},{},[12495,12499],{"data":12496,"marks":12497,"value":7306,"nodeType":864},{},[12498],{"type":899},{"data":12500,"marks":12501,"value":7310,"nodeType":864},{},[],{"data":12503,"content":12504,"nodeType":945},{},[12505],{"data":12506,"content":12507,"nodeType":860},{},[12508,12512],{"data":12509,"marks":12510,"value":7321,"nodeType":864},{},[12511],{"type":899},{"data":12513,"marks":12514,"value":7325,"nodeType":864},{},[],{"data":12516,"content":12517,"nodeType":945},{},[12518],{"data":12519,"content":12520,"nodeType":860},{},[12521,12525],{"data":12522,"marks":12523,"value":7336,"nodeType":864},{},[12524],{"type":899},{"data":12526,"marks":12527,"value":7340,"nodeType":864},{},[],{"data":12529,"content":12530,"nodeType":860},{},[12531],{"data":12532,"marks":12533,"value":7347,"nodeType":864},{},[],{"data":12535,"content":12536,"nodeType":1312},{},[12537],{"data":12538,"marks":12539,"value":7354,"nodeType":864},{},[],{"data":12541,"content":12542,"nodeType":860},{},[12543],{"data":12544,"marks":12545,"value":7361,"nodeType":864},{},[],{"data":12547,"content":12548,"nodeType":860},{},[12549],{"data":12550,"marks":12551,"value":7368,"nodeType":864},{},[],{"data":12553,"content":12554,"nodeType":860},{},[12555,12558,12562],{"data":12556,"marks":12557,"value":7375,"nodeType":864},{},[],{"data":12559,"marks":12560,"value":7380,"nodeType":864},{},[12561],{"type":899},{"data":12563,"marks":12564,"value":7384,"nodeType":864},{},[],{"data":12566,"content":12567,"nodeType":860},{},[12568],{"data":12569,"marks":12570,"value":7391,"nodeType":864},{},[],{"data":12572,"content":12573,"nodeType":860},{},[12574],{"data":12575,"marks":12576,"value":7398,"nodeType":864},{},[],{"data":12578,"content":12579,"nodeType":1312},{},[12580],{"data":12581,"marks":12582,"value":7405,"nodeType":864},{},[],{"data":12584,"content":12585,"nodeType":860},{},[12586],{"data":12587,"marks":12588,"value":7412,"nodeType":864},{},[],{"data":12590,"content":12591,"nodeType":860},{},[12592],{"data":12593,"marks":12594,"value":7419,"nodeType":864},{},[],{"data":12596,"content":12597,"nodeType":860},{},[12598],{"data":12599,"marks":12600,"value":7426,"nodeType":864},{},[],{"data":12602,"content":12603,"nodeType":1312},{},[12604],{"data":12605,"marks":12606,"value":7433,"nodeType":864},{},[],{"data":12608,"content":12609,"nodeType":860},{},[12610],{"data":12611,"marks":12612,"value":7440,"nodeType":864},{},[],{"data":12614,"content":12615,"nodeType":860},{},[12616],{"data":12617,"marks":12618,"value":7447,"nodeType":864},{},[],{"data":12620,"content":12621,"nodeType":1312},{},[12622],{"data":12623,"marks":12624,"value":7454,"nodeType":864},{},[],{"data":12626,"content":12627,"nodeType":860},{},[12628],{"data":12629,"marks":12630,"value":7461,"nodeType":864},{},[],{"data":12632,"content":12633,"nodeType":860},{},[12634],{"data":12635,"marks":12636,"value":7468,"nodeType":864},{},[],{"data":12638,"content":12639,"nodeType":860},{},[12640],{"data":12641,"marks":12642,"value":7475,"nodeType":864},{},[],{"data":12644,"content":12645,"nodeType":1005},{},[],{"data":12647,"content":12648,"nodeType":1009},{},[12649],{"data":12650,"marks":12651,"value":7486,"nodeType":864},{},[12652],{"type":899},{"data":12654,"content":12655,"nodeType":860},{},[12656],{"data":12657,"marks":12658,"value":7493,"nodeType":864},{},[],{"data":12660,"content":12661,"nodeType":860},{},[12662,12665],{"data":12663,"marks":12664,"value":7500,"nodeType":864},{},[],{"data":12666,"marks":12667,"value":7505,"nodeType":864},{},[12668],{"type":899},{"data":12670,"content":12671,"nodeType":860},{},[12672],{"data":12673,"marks":12674,"value":7512,"nodeType":864},{},[],{"data":12676,"content":12677,"nodeType":860},{},[12678],{"data":12679,"marks":12680,"value":7519,"nodeType":864},{},[],{"data":12682,"content":12683,"nodeType":860},{},[12684],{"data":12685,"marks":12686,"value":7526,"nodeType":864},{},[],{"data":12688,"content":12689,"nodeType":1312},{},[12690],{"data":12691,"marks":12692,"value":7533,"nodeType":864},{},[],{"data":12694,"content":12695,"nodeType":941},{},[12696,12715,12734,12753,12762,12771,12780],{"data":12697,"content":12698,"nodeType":945},{},[12699],{"data":12700,"content":12701,"nodeType":860},{},[12702,12705,12712],{"data":12703,"marks":12704,"value":7546,"nodeType":864},{},[],{"data":12706,"content":12707,"nodeType":883},{"uri":7549},[12708],{"data":12709,"marks":12710,"value":7555,"nodeType":864},{},[12711],{"type":1455},{"data":12713,"marks":12714,"value":7559,"nodeType":864},{},[],{"data":12716,"content":12717,"nodeType":945},{},[12718],{"data":12719,"content":12720,"nodeType":860},{},[12721,12724,12731],{"data":12722,"marks":12723,"value":7569,"nodeType":864},{},[],{"data":12725,"content":12726,"nodeType":883},{"uri":7572},[12727],{"data":12728,"marks":12729,"value":7578,"nodeType":864},{},[12730],{"type":1455},{"data":12732,"marks":12733,"value":7582,"nodeType":864},{},[],{"data":12735,"content":12736,"nodeType":945},{},[12737],{"data":12738,"content":12739,"nodeType":860},{},[12740,12743,12750],{"data":12741,"marks":12742,"value":21,"nodeType":864},{},[],{"data":12744,"content":12745,"nodeType":883},{"uri":7594},[12746],{"data":12747,"marks":12748,"value":7600,"nodeType":864},{},[12749],{"type":1455},{"data":12751,"marks":12752,"value":7604,"nodeType":864},{},[],{"data":12754,"content":12755,"nodeType":945},{},[12756],{"data":12757,"content":12758,"nodeType":860},{},[12759],{"data":12760,"marks":12761,"value":7614,"nodeType":864},{},[],{"data":12763,"content":12764,"nodeType":945},{},[12765],{"data":12766,"content":12767,"nodeType":860},{},[12768],{"data":12769,"marks":12770,"value":7624,"nodeType":864},{},[],{"data":12772,"content":12773,"nodeType":945},{},[12774],{"data":12775,"content":12776,"nodeType":860},{},[12777],{"data":12778,"marks":12779,"value":7634,"nodeType":864},{},[],{"data":12781,"content":12782,"nodeType":945},{},[12783],{"data":12784,"content":12785,"nodeType":860},{},[12786,12789,12796],{"data":12787,"marks":12788,"value":7644,"nodeType":864},{},[],{"data":12790,"content":12791,"nodeType":883},{"uri":7647},[12792],{"data":12793,"marks":12794,"value":7653,"nodeType":864},{},[12795],{"type":1455},{"data":12797,"marks":12798,"value":7657,"nodeType":864},{},[],{"data":12800,"content":12801,"nodeType":860},{},[12802],{"data":12803,"marks":12804,"value":21,"nodeType":864},{},[],{"data":12806,"content":12809,"nodeType":996},{"target":12807},{"sys":12808},{"id":7668,"type":1001,"linkType":1002},[],{"data":12811,"content":12812,"nodeType":1005},{},[],{"data":12814,"content":12815,"nodeType":860},{},[12816,12819,12826],{"data":12817,"marks":12818,"value":7679,"nodeType":864},{},[],{"data":12820,"content":12821,"nodeType":883},{"uri":1700},[12822],{"data":12823,"marks":12824,"value":7687,"nodeType":864},{},[12825],{"type":1455},{"data":12827,"marks":12828,"value":2924,"nodeType":864},{},[],{"entries":12830},{"hyperlink":12831,"inline":12832,"block":12833},[],[],[12834,12840,12864,12891,12916,12923,12926,12953,12960,12997],{"sys":12835,"__typename":1724,"title":12836,"caption":12836,"layoutMode":59,"file":12837},{"id":6890},"The browser is the natural control point for both AI-enabled attacks targeting employees and AI tool usage that introduces risk into organizations. ",{"url":12838,"width":1736,"height":12839},"https://images.ctfassets.net/y1cdw1ablpvd/3vtPqgrZRuVxkVKw9sGLor/ce1d265590cfc23848e25b03fb3ed5a2/image4.png",1142,{"sys":12841,"__typename":1740,"content":12842,"name":12863,"title":59},{"id":6914},{"json":12843},{"data":12844,"content":12845,"nodeType":856},{},[12846],{"data":12847,"content":12848,"nodeType":860},{},[12849,12853,12860],{"data":12850,"marks":12851,"value":12852,"nodeType":864},{},[],"Learn how AI-enabled attacks are making infrastructure-based detection increasingly ineffective in our ",{"data":12854,"content":12855,"nodeType":883},{"uri":9861},[12856],{"data":12857,"marks":12858,"value":12859,"nodeType":864},{},[],"update on the Pyramid of Pain concept for 2026",{"data":12861,"marks":12862,"value":2924,"nodeType":864},{},[],"AI Browser Control IB1",{"sys":12865,"__typename":1740,"content":12866,"name":12890,"title":59},{"id":6986},{"json":12867},{"data":12868,"content":12869,"nodeType":856},{},[12870],{"data":12871,"content":12872,"nodeType":860},{},[12873,12877,12886],{"data":12874,"marks":12875,"value":12876,"nodeType":864},{},[],"Nearly every phishing toolkit that Push encounters in the wild today displays the fingerprints of AI use. Check out our ",{"data":12878,"content":12880,"nodeType":883},{"uri":12879},"https://pushsecurity.com/blog/inside-criminal-phishing-panel/",[12881],{"data":12882,"marks":12883,"value":12885,"nodeType":864},{},[12884],{"type":1455},"recent analysis",{"data":12887,"marks":12888,"value":12889,"nodeType":864},{},[]," of Doko's Panel, a real-time vishing and AiTM kit, for a under-the-hood look at this. ","AI Browser Control IB3",{"sys":12892,"__typename":1740,"content":12893,"name":12915,"title":59},{"id":7007},{"json":12894},{"data":12895,"content":12896,"nodeType":856},{},[12897],{"data":12898,"content":12899,"nodeType":860},{},[12900,12903,12911],{"data":12901,"marks":12902,"value":3719,"nodeType":864},{},[],{"data":12904,"content":12905,"nodeType":883},{"uri":3858},[12906],{"data":12907,"marks":12908,"value":12910,"nodeType":864},{},[12909],{"type":1455},"Spamhaus",{"data":12912,"marks":12913,"value":12914,"nodeType":864},{},[],", 89% of phishing domains are active for fewer than two days, with just 6.5% surviving past 15 days. That means that if you're primarily looking at static indicators, you're already behind. IOC-based detections can't keep up with how quickly attackers can rotate infrastructure.","AI Browser Control IB2",{"sys":12917,"__typename":1724,"title":12918,"caption":12919,"layoutMode":59,"file":12920},{"id":7079},"LLMShare example","The recent LLMShare campaign shows how attackers are abusing AI tools, legitimate pages, and malvertising. ",{"url":12921,"width":1736,"height":12922},"https://images.ctfassets.net/y1cdw1ablpvd/7u7yyvyg3P9jepZi7iIwxf/d2c42d257d2e7ac4dfe28c37aa69a4b3/image4.png",875,{"sys":12924,"__typename":1724,"title":1725,"caption":1726,"layoutMode":59,"file":12925},{"id":1040},{"url":1728,"width":1729,"height":1730},{"sys":12927,"__typename":1740,"content":12928,"name":12952,"title":59},{"id":7232},{"json":12929},{"nodeType":856,"data":12930,"content":12931},{},[12932],{"nodeType":860,"data":12933,"content":12934},{},[12935,12939,12948],{"nodeType":864,"value":12936,"marks":12937,"data":12938},"The Vercel breach isn't an isolated incident. ShinyHunters demonstrated the breadth and scale of ",[],{},{"nodeType":883,"data":12940,"content":12942},{"uri":12941},"https://pushsecurity.com/blog/analyzing-the-instructure-breach/#id-vector-3-oauth-supply-chain-attacks-through-compromised-integrators",[12943],{"nodeType":864,"value":12944,"marks":12945,"data":12947},"OAuth-targeted attacks last year",[12946],{"type":1455},{},{"nodeType":864,"value":12949,"marks":12950,"data":12951},", impacting more than 1,000 organizations in targeted campaigns against Salesloft/Drift. Adversaries compromised Salesloft’s GitHub environment, stole Drift OAuth tokens, and used them to access downstream Salesforce environments. The same pattern was later repeated at Gainsight.",[],{},"AI Browser Control IB5",{"sys":12954,"__typename":1724,"title":12955,"caption":12955,"layoutMode":59,"file":12956},{"id":7245},"AI tools are the hub of the modern workplace. ",{"url":12957,"width":12958,"height":12959},"https://images.ctfassets.net/y1cdw1ablpvd/7mRgALIClC1R2Cmuu7xKse/cdaf8cbb26a54ad75b7d52a8c92b1f84/Group_737.png",6824,4280,{"sys":12961,"__typename":1740,"content":12962,"name":12996,"title":59},{"id":7251},{"json":12963},{"nodeType":856,"data":12964,"content":12965},{},[12966,12978,12985],{"nodeType":860,"data":12967,"content":12968},{},[12969,12974],{"nodeType":864,"value":12970,"marks":12971,"data":12973},"A word on prompt injection: ",[12972],{"type":899},{},{"nodeType":864,"value":12975,"marks":12976,"data":12977},"Prompt injection is a serious and structurally difficult to solve problem, and one AI researchers and the security industry are still working out how to defend against. ",[],{},{"nodeType":860,"data":12979,"content":12980},{},[12981],{"nodeType":864,"value":12982,"marks":12983,"data":12984},"High-impact attacks of this kind are still rare in the wild, but the building blocks are all demonstrated and the attack surface is growing as agentic browsers and in-app AI features proliferate. The threat is evolving quickly and detections are still limited, so it pays to start with the controls that hold up regardless of how attacks evolve. ",[],{},{"nodeType":860,"data":12986,"content":12987},{},[12988,12992],{"nodeType":864,"value":12989,"marks":12990,"data":12991},"This starts with k",[],{},{"nodeType":864,"value":12993,"marks":12994,"data":12995},"nowing which AI browsers, extensions, and assistants employees are using, which SaaS apps have AI features enabled, and what OAuth scopes those AIs have been granted. The blast radius of any successful prompt injection is exactly the data and actions those grants permit, so visibility into AI tooling and AI-connected identity is the foundation that any further defense builds on.",[],{},"AI Browser Control IB4",{"sys":12998,"__typename":12999,"title":13000,"arcadeDemoUrl":13001,"playText":13002},{"id":7668},"ArcadeDemo","Secure AI apps demo","https://demo.arcade.software/ibou7WyNSvBX4uRpK25H?embed","2 mins",{"items":13004},[],{},"Why browser visibility and control is key to AI security",{"items":13008},[13009,13784,14591],{"__typename":2059,"sys":13010,"content":13012,"title":13767,"synopsis":13768,"hashTags":59,"publishedDate":13769,"slug":13770,"tagsCollection":13771,"authorsCollection":13780},{"id":13011},"5RDOpmzJolwT1hk0fNIxzf",{"json":13013},{"data":13014,"content":13015,"nodeType":856},{},[13016,13035,13041,13048,13055,13058,13066,13085,13104,13111,13117,13124,13130,13137,13145,13152,13170,13199,13205,13211,13219,13226,13244,13274,13306,13313,13319,13327,13334,13345,13352,13391,13397,13438,13475,13481,13484,13492,13499,13505,13512,13519,13525,13532,13539,13566,13569,13577,13584,13592,13599,13606,13625,13632,13638,13645,13653,13660,13678,13685,13703,13706,13714,13721,13728,13735,13738,13744,13750],{"data":13017,"content":13018,"nodeType":860},{},[13019,13023,13031],{"data":13020,"marks":13021,"value":13022,"nodeType":864},{},[],"Back in 2024, we wrote about ",{"data":13024,"content":13026,"nodeType":883},{"uri":13025},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[13027],{"data":13028,"marks":13029,"value":13030,"nodeType":864},{},[],"how the Pyramid of Pain shapes Push's detection philosophy",{"data":13032,"marks":13033,"value":13034,"nodeType":864},{},[]," — detections targeting indicators that are easy for attackers to change deliver diminishing returns, while detections targeting attacker techniques impose a cost that's hard to absorb. Two years on, every force that made IoC-based detection fragile has intensified.",{"data":13036,"content":13040,"nodeType":996},{"target":13037},{"sys":13038},{"id":13039,"type":1001,"linkType":1002},"1iuLYxwI8T1wDUIFSom0G0",[],{"data":13042,"content":13043,"nodeType":860},{},[13044],{"data":13045,"marks":13046,"value":13047,"nodeType":864},{},[],"AI hasn't introduced a new problem so much as it's compressed the timelines on an existing one — attackers can generate infrastructure, iterate on tooling, and industrialize newly discovered techniques faster than before. The bottom layers of the Pyramid are collapsing under the weight of machine-speed operations, and the middle layers are starting to buckle too.",{"data":13049,"content":13050,"nodeType":860},{},[13051],{"data":13052,"marks":13053,"value":13054,"nodeType":864},{},[],"These changes mean that technique-level detection is more important than ever. In this article, we’ll dig into how the Pyramid is changing, and what this means for our detection philosophy at Push (TL;DR — it reinforces the path we’re already on: building detections at the top of the Pyramid by harnessing browser visibility). ",{"data":13056,"content":13057,"nodeType":1005},{},[],{"data":13059,"content":13060,"nodeType":1009},{},[13061],{"data":13062,"marks":13063,"value":13065,"nodeType":864},{},[13064],{"type":899},"The bottom of the Pyramid was already crumbling",{"data":13067,"content":13068,"nodeType":860},{},[13069,13073,13081],{"data":13070,"marks":13071,"value":13072,"nodeType":864},{},[],"The case against indicator-based detection didn't need AI to be compelling. ",{"data":13074,"content":13076,"nodeType":883},{"uri":13075},"https://www.spamhaus.org/",[13077],{"data":13078,"marks":13079,"value":13080,"nodeType":864},{},[],"89% of phishing domains are active for fewer than two days",{"data":13082,"marks":13083,"value":13084,"nodeType":864},{},[],", with just 6.5% surviving past 15 days — by the time a domain makes it onto a blocklist, the campaign has moved on.",{"data":13086,"content":13087,"nodeType":860},{},[13088,13092,13100],{"data":13089,"marks":13090,"value":13091,"nodeType":864},{},[],"We've ",{"data":13093,"content":13095,"nodeType":883},{"uri":13094},"https://pushsecurity.com/blog/why-most-phishing-attacks-feel-like-a-zero-day/",[13096],{"data":13097,"marks":13098,"value":13099,"nodeType":864},{},[],"written before",{"data":13101,"marks":13102,"value":13103,"nodeType":864},{},[]," about how this makes every phishing attack effectively a zero-day for organizations relying on known-bad detection. The phishing kit's behavior — its page structure, script signatures, malicious payload mechanics — is the only detection target that outlasts a single campaign.",{"data":13105,"content":13106,"nodeType":860},{},[13107],{"data":13108,"marks":13109,"value":13110,"nodeType":864},{},[],"When we blogged about the Pyramid of Pain for modern attacks that happen predominantly over the internet, with minimal (or zero) endpoint contact, it first looked like this: ",{"data":13112,"content":13116,"nodeType":996},{"target":13113},{"sys":13114},{"id":13115,"type":1001,"linkType":1002},"2N04ycJ6RKGfHdX5X1TwU3",[],{"data":13118,"content":13119,"nodeType":860},{},[13120],{"data":13121,"marks":13122,"value":13123,"nodeType":864},{},[],"Now, it looks more like this:",{"data":13125,"content":13129,"nodeType":996},{"target":13126},{"sys":13127},{"id":13128,"type":1001,"linkType":1002},"mfhP4WToOQkrHnVkXU0tX",[],{"data":13131,"content":13132,"nodeType":860},{},[13133],{"data":13134,"marks":13135,"value":13136,"nodeType":864},{},[],"Let’s explore why. ",{"data":13138,"content":13139,"nodeType":1312},{},[13140],{"data":13141,"marks":13142,"value":13144,"nodeType":864},{},[13143],{"type":899},"AI is accelerating phishing rotation and delivery",{"data":13146,"content":13147,"nodeType":860},{},[13148],{"data":13149,"marks":13150,"value":13151,"nodeType":864},{},[],"Attackers are harnessing AI at every stage, speeding up the process of creating, rotating, and replacing phishing infrastructure at every level, as well as capitalizing on AI adoption itself to enhance their lures. The operational signature is more domains, shorter lifespans, more variation, and fewer of the reuse patterns that blocklists depend on.",{"data":13153,"content":13154,"nodeType":860},{},[13155,13159,13166],{"data":13156,"marks":13157,"value":13158,"nodeType":864},{},[],"Attackers can ",{"data":13160,"content":13161,"nodeType":883},{"uri":7572},[13162],{"data":13163,"marks":13164,"value":13165,"nodeType":864},{},[],"vibe-code entire phishing pages in minutes",{"data":13167,"marks":13168,"value":13169,"nodeType":864},{},[]," — not just cloning legitimate login pages but vibe-cloning them, feeding an AI a screenshot and having it rebuild a convincing frontend with a completely unique backend. ",{"data":13171,"content":13172,"nodeType":860},{},[13173,13177,13185,13189,13195],{"data":13174,"marks":13175,"value":13176,"nodeType":864},{},[],"We've seen attackers clone free SaaS tools like background removers and PDF converters, then inject phishing components or ClickFix payloads into what looks like a functional utility. We’ve even seen attackers distributing malware using AI-generated pages shared using ",{"data":13178,"content":13179,"nodeType":883},{"uri":7066},[13180],{"data":13181,"marks":13182,"value":13184,"nodeType":864},{},[13183],{"type":1455},"LLM tool sharing functionality",{"data":13186,"marks":13187,"value":13188,"nodeType":864},{},[],", resulting in phishing delivery pages hosted on real claude.ai and chatgpt.com. And legitimate cloud platforms like ",{"data":13190,"content":13191,"nodeType":883},{"uri":7018},[13192],{"data":13193,"marks":13194,"value":7024,"nodeType":864},{},[],{"data":13196,"marks":13197,"value":13198,"nodeType":864},{},[],", Cloudflare Workers, and Vercel host and dynamically rotate attack infrastructure, so the domains feeding into blocklists often belong to reputable services that can't simply be blocked. ",{"data":13200,"content":13204,"nodeType":996},{"target":13201},{"sys":13202},{"id":13203,"type":1001,"linkType":1002},"5yoLmqysyQazfzLITCUTfc",[],{"data":13206,"content":13210,"nodeType":996},{"target":13207},{"sys":13208},{"id":13209,"type":1001,"linkType":1002},"5XK5qZMQU19xlA8L2T5y0Z",[],{"data":13212,"content":13213,"nodeType":1312},{},[13214],{"data":13215,"marks":13216,"value":13218,"nodeType":864},{},[13217],{"type":899},"The kit ecosystem is fragmenting faster than anyone can track",{"data":13220,"content":13221,"nodeType":860},{},[13222],{"data":13223,"marks":13224,"value":13225,"nodeType":864},{},[],"What we see across our install base is a huge and growing variation in phishing kits — new kits, derivative kits of known platforms, derivatives of those derivatives — appearing on a weekly basis.",{"data":13227,"content":13228,"nodeType":860},{},[13229,13233,13240],{"data":13230,"marks":13231,"value":13232,"nodeType":864},{},[],"As we reported in our ",{"data":13234,"content":13235,"nodeType":883},{"uri":11536},[13236],{"data":13237,"marks":13238,"value":13239,"nodeType":864},{},[],"Browser Attacks Report",{"data":13241,"marks":13242,"value":13243,"nodeType":864},{},[],", the most common AiTM kits we detected over the last year were Tycoon 2FA (59% of detections), followed by Sneaky 2FA, FlowerStorm, Evilginx (nominally a red team tool, but widely abused by attackers), NakedPages, Gabagool, and dozens more — but those established names are just the visible layer.",{"data":13245,"content":13246,"nodeType":860},{},[13247,13251,13259,13263,13270],{"data":13248,"marks":13249,"value":13250,"nodeType":864},{},[],"Code is forked, modified, and redeployed across kits in a pattern that ",{"data":13252,"content":13254,"nodeType":883},{"uri":13253},"https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere",[13255],{"data":13256,"marks":13257,"value":13258,"nodeType":864},{},[],"resembles open-source development",{"data":13260,"marks":13261,"value":13262,"nodeType":864},{},[]," more than traditional criminal enterprise, and the rate at which new variants appear is accelerating. The ",{"data":13264,"content":13265,"nodeType":883},{"uri":3259},[13266],{"data":13267,"marks":13268,"value":13269,"nodeType":864},{},[],"Venom kit",{"data":13271,"marks":13272,"value":13273,"nodeType":864},{},[]," reuses Sneaky 2FA's AiTM infrastructure but carries different branding and adds device code phishing — whether it's the same developers, stolen code, or a deliberate fork is unclear.",{"data":13275,"content":13276,"nodeType":860},{},[13277,13281,13289,13293,13302],{"data":13278,"marks":13279,"value":13280,"nodeType":864},{},[],"Tycoon 2FA illustrates the scale of the evolution. The kit evolves continuously, addingnew capabilities, new evasion techniques, and hybridizing with other platforms. Even when Sekoia and Microsoft seized 330+ Tycoon domains in March 2026, the techniques it popularized were already embedded across competitors, and the slack was taken up by rival platforms within days. And in any case, Tycoon was back to ",{"data":13282,"content":13284,"nodeType":883},{"uri":13283},"https://www.crowdstrike.com/en-us/blog/tycoon2fa-phishing-as-a-service-platform-persists-following-takedown/",[13285],{"data":13286,"marks":13287,"value":13288,"nodeType":864},{},[],"normal levels of operation",{"data":13290,"marks":13291,"value":13292,"nodeType":864},{},[]," shortly after. It has also been observed ",{"data":13294,"content":13296,"nodeType":883},{"uri":13295},"https://www.okta.com/en-nl/blog/threat-intelligence/tycoon_2fa_phishing_actors_scatter/",[13297],{"data":13298,"marks":13299,"value":13301,"nodeType":864},{},[13300],{"type":1455},"pivoting to add new device code phishing capabilities",{"data":13303,"marks":13304,"value":13305,"nodeType":864},{},[]," (more on that below). ",{"data":13307,"content":13308,"nodeType":860},{},[13309],{"data":13310,"marks":13311,"value":13312,"nodeType":864},{},[],"Tear one down and there are many more to take its place — and meanwhile the original is already evolving into something new.",{"data":13314,"content":13318,"nodeType":996},{"target":13315},{"sys":13316},{"id":13317,"type":1001,"linkType":1002},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":13320,"content":13321,"nodeType":1312},{},[13322],{"data":13323,"marks":13324,"value":13326,"nodeType":864},{},[13325],{"type":899},"New techniques are being industrialized faster than ever",{"data":13328,"content":13329,"nodeType":860},{},[13330],{"data":13331,"marks":13332,"value":13333,"nodeType":864},{},[],"As well as the fragmentation of existing kits, we’re seeing new techniques added at an accelerating rate. ",{"data":13335,"content":13336,"nodeType":860},{},[13337,13341],{"data":13338,"marks":13339,"value":360,"nodeType":864},{},[13340],{"type":899},{"data":13342,"marks":13343,"value":13344,"nodeType":864},{},[]," is the clearest case study. From early nation state adoption in 2024, it took until 2026 for criminal adoption to really take off, but the take-up this year is unprecedented. The EvilTokens kit packaged device code phishing into a PhaaS offering with GPT-powered spear-phishing and adaptive landing pages, hitting 340+ organizations across five countries in March 2026. ",{"data":13346,"content":13347,"nodeType":860},{},[13348],{"data":13349,"marks":13350,"value":13351,"nodeType":864},{},[],"Now, device code functionality is now a core phish kit component. We’re tracking 18+ kits with device code phishing capabilities and a 37.5x increase in device code phishing detections this year alone, with the technique moving from state-sponsored exclusivity to something any PhaaS customer can rent.",{"data":13353,"content":13354,"nodeType":860},{},[13355,13359,13367,13371,13376,13380,13388],{"data":13356,"marks":13357,"value":13358,"nodeType":864},{},[],"Similarly, when we ",{"data":13360,"content":13362,"nodeType":883},{"uri":13361},"https://pushsecurity.com/blog/inside-criminal-phishing-panel",[13363],{"data":13364,"marks":13365,"value":13366,"nodeType":864},{},[],"infiltrated Doko's Panel",{"data":13368,"marks":13369,"value":13370,"nodeType":864},{},[]," — a ",{"data":13372,"marks":13373,"value":13375,"nodeType":864},{},[13374],{"type":899},"real-time vishing and AiTM platform",{"data":13377,"marks":13378,"value":13379,"nodeType":864},{},[]," used by ShinyHunters and affiliated groups — the codebase was full of LLM-generated artifacts. Multiple groups were using the templated vishing panel and spinning up their own variants, but the AI-generated indicators persisted throughout. This approach to real-time vishing + browser payload has been a ",{"data":13381,"content":13382,"nodeType":883},{"uri":4082},[13383],{"data":13384,"marks":13385,"value":13387,"nodeType":864},{},[13386],{"type":1455},"mainstay of the Com affiliates like ShinyHunters this year",{"data":13389,"marks":13390,"value":1774,"nodeType":864},{},[],{"data":13392,"content":13396,"nodeType":996},{"target":13393},{"sys":13394},{"id":13395,"type":1001,"linkType":1002},"01mOiserRBXraawXwQyJNm",[],{"data":13398,"content":13399,"nodeType":860},{},[13400,13404,13408,13412,13421,13425,13434],{"data":13401,"marks":13402,"value":13403,"nodeType":864},{},[],"The broader ",{"data":13405,"marks":13406,"value":315,"nodeType":864},{},[13407],{"type":899},{"data":13409,"marks":13410,"value":13411,"nodeType":864},{},[]," family shows the same acceleration: First reported in early 2024 and adopted by four nation-state groups within a single quarter. Fast forward and ",{"data":13413,"content":13415,"nodeType":883},{"uri":13414},"https://www.crowdstrike.com/en-us/global-threat-report/",[13416],{"data":13417,"marks":13418,"value":13420,"nodeType":864},{},[13419],{"type":1455},"CrowdStrike's data",{"data":13422,"marks":13423,"value":13424,"nodeType":864},{},[]," shows a 563% increase in fake CAPTCHA incidents (one of the more common ClickFix lure types), while ",{"data":13426,"content":13428,"nodeType":883},{"uri":13427},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf",[13429],{"data":13430,"marks":13431,"value":13433,"nodeType":864},{},[13432],{"type":1455},"Microsoft reported",{"data":13435,"marks":13436,"value":13437,"nodeType":864},{},[]," it as making up 47% of observed attacks according to their Digital Defense Report.",{"data":13439,"content":13440,"nodeType":860},{},[13441,13445,13449,13453,13460,13464,13471],{"data":13442,"marks":13443,"value":13444,"nodeType":864},{},[],"And ",{"data":13446,"marks":13447,"value":11731,"nodeType":864},{},[13448],{"type":899},{"data":13450,"marks":13451,"value":13452,"nodeType":864},{},[]," — a combination of ClickFix and OAuth consent phishing techniques — suggests the next compression is already underway. Push researchers ",{"data":13454,"content":13455,"nodeType":883},{"uri":11726},[13456],{"data":13457,"marks":13458,"value":13459,"nodeType":864},{},[],"discovered the technique",{"data":13461,"marks":13462,"value":13463,"nodeType":864},{},[]," in December 2025 — a browser-native ClickFix variant hijacking OAuth consent grants via Azure CLI's localhost redirect. It was later confirmed to be tied to APT29. By January 2026, a ",{"data":13465,"content":13466,"nodeType":883},{"uri":6940},[13467],{"data":13468,"marks":13469,"value":13470,"nodeType":864},{},[],"criminal ConsentFix v3 toolkit",{"data":13472,"marks":13473,"value":13474,"nodeType":864},{},[]," had appeared on the XSS forum with Cloudflare Workers, ZoomInfo targeting, and automated exfiltration via Pipedream.",{"data":13476,"content":13480,"nodeType":996},{"target":13477},{"sys":13478},{"id":13479,"type":1001,"linkType":1002},"41FMif4T0y1maflzonWgL8",[],{"data":13482,"content":13483,"nodeType":1005},{},[],{"data":13485,"content":13486,"nodeType":1009},{},[13487],{"data":13488,"marks":13489,"value":13491,"nodeType":864},{},[13490],{"type":899},"Why technique-level detection is the only layer that holds",{"data":13493,"content":13494,"nodeType":860},{},[13495],{"data":13496,"marks":13497,"value":13498,"nodeType":864},{},[],"The middle of the Pyramid — tool signatures and artifacts — used to offer much more durable detection than infrastructure indicators. Fingerprinting a specific phishing kit by its JavaScript structure or HTML patterns provided a detection target that survived across dozens or hundreds of campaigns, even as the underlying domains rotated. Tool level detections are still better, but not by quite the same margin.",{"data":13500,"content":13504,"nodeType":996},{"target":13501},{"sys":13502},{"id":13503,"type":1001,"linkType":1002},"5pxaYdCIFiFKLPhRaPoldX",[],{"data":13506,"content":13507,"nodeType":860},{},[13508],{"data":13509,"marks":13510,"value":13511,"nodeType":864},{},[],"When the kit landscape was dominated by a handful of platforms, you could write signatures for Tycoon, Sneaky2FA, EvilProxy, and so on, and cover the lion's share of attacks. With the ecosystem now producing new variants and entirely new kits on a weekly basis, detecting by kit fingerprint starts to look uncomfortably similar to detecting by domain.",{"data":13513,"content":13514,"nodeType":860},{},[13515],{"data":13516,"marks":13517,"value":13518,"nodeType":864},{},[],"But many of these proliferating kits do share behavioral patterns at a deeper level than their code signatures. For example, every device code phishing kit implements fundamentally the same flow: present a lure, generate a device code via the OAuth Device Authorization endpoint, get the user to enter it on the legitimate authorization page, and poll for the resulting tokens. The frontends vary, the infrastructure varies, but the behavioral pattern doesn't.",{"data":13520,"content":13524,"nodeType":996},{"target":13521},{"sys":13522},{"id":13523,"type":1001,"linkType":1002},"FyyHayQtsJTwoB1kluMOl",[],{"data":13526,"content":13527,"nodeType":860},{},[13528],{"data":13529,"marks":13530,"value":13531,"nodeType":864},{},[],"Genuinely new attack techniques still require human creativity — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted. That kind of innovation hasn't been automated. But the window to discover a technique, build a detection, and then deploy it before it is adopted by criminals at scale is compressing with each generation.",{"data":13533,"content":13534,"nodeType":860},{},[13535],{"data":13536,"marks":13537,"value":13538,"nodeType":864},{},[],"Organizations that detect at the technique level and deploy before commoditization have a structural advantage that increases over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. This is the challenge we grapple with every day as we strive for the most resilient detections possible. ",{"data":13540,"content":13541,"nodeType":1116},{},[13542],{"data":13543,"content":13544,"nodeType":860},{},[13545,13549,13557,13561],{"data":13546,"marks":13547,"value":13548,"nodeType":864},{},[],"As our CPO Jacques Louw put it on ",{"data":13550,"content":13552,"nodeType":883},{"uri":13551},"https://risky.biz/RBNEWSSI128/",[13553],{"data":13554,"marks":13555,"value":13556,"nodeType":864},{},[],"Risky Business",{"data":13558,"marks":13559,"value":13560,"nodeType":864},{},[],": ",{"data":13562,"marks":13563,"value":13565,"nodeType":864},{},[13564],{"type":2246},"\"There's no list of bad domains anywhere in the product. It's a crutch — a false cheat code that stops you from doing the detection in the way that actually is resilient, because the next time you see it, it will be on a different domain.\"",{"data":13567,"content":13568,"nodeType":1005},{},[],{"data":13570,"content":13571,"nodeType":1009},{},[13572],{"data":13573,"marks":13574,"value":13576,"nodeType":864},{},[13575],{"type":899},"What it takes to detect at the top of the Pyramid",{"data":13578,"content":13579,"nodeType":860},{},[13580],{"data":13581,"marks":13582,"value":13583,"nodeType":864},{},[],"If technique-level detection is the only layer that holds, two things have to be true about your detection capability: You need the right vantage point, and you need the research velocity to stay ahead.",{"data":13585,"content":13586,"nodeType":1312},{},[13587],{"data":13588,"marks":13589,"value":13591,"nodeType":864},{},[13590],{"type":899},"You need the right vantage point",{"data":13593,"content":13594,"nodeType":860},{},[13595],{"data":13596,"marks":13597,"value":13598,"nodeType":864},{},[],"Technique-level behaviors in browser-based identity attacks — how a phishing page orchestrates credential entry, how a device code flow presents its authorization prompt, how a ClickFix variant manipulates the clipboard — are visible in the browser session and nowhere else.",{"data":13600,"content":13601,"nodeType":860},{},[13602],{"data":13603,"marks":13604,"value":13605,"nodeType":864},{},[],"Network proxies see encrypted traffic and can attempt to reconstruct page behavior from metadata, but DOM manipulation, user interaction sequences, and script execution aren't visible from that vantage point. Email gateways see the delivery mechanism (or nothing at all in the increasing number of social media and search engine based attacks) but not the payload.",{"data":13607,"content":13608,"nodeType":860},{},[13609,13613,13621],{"data":13610,"marks":13611,"value":13612,"nodeType":864},{},[],"As we disclosed in our ",{"data":13614,"content":13615,"nodeType":883},{"uri":11536},[13616],{"data":13617,"marks":13618,"value":13620,"nodeType":864},{},[13619],{"type":1455},"browser attacks report",{"data":13622,"marks":13623,"value":13624,"nodeType":864},{},[],", 95% of in-browser attacks we detect use some form of bot protection, often combined with conditional loading techniques like referrer and browser checks, reliably defeating automated analysis techniques. ",{"data":13626,"content":13627,"nodeType":860},{},[13628],{"data":13629,"marks":13630,"value":13631,"nodeType":864},{},[],"Behavioral detection at the technique level requires observing what happens on the page at the moment the user interacts with it — analyzing pages, not links. When you see the entire browsing flow — ad click, redirect chain, page render, credential prompt — an attack stands out immediately. Without that context, any detection system is forced to fill in gaps, and the gaps are where attacks hide.",{"data":13633,"content":13637,"nodeType":996},{"target":13634},{"sys":13635},{"id":13636,"type":1001,"linkType":1002},"4804g6u4POUDpL42bzP0EY",[],{"data":13639,"content":13640,"nodeType":860},{},[13641],{"data":13642,"marks":13643,"value":13644,"nodeType":864},{},[],"Push sits inside the browser session, observing this in real time. Its detections target the behavioral mechanics of techniques rather than the surface characteristics of individual kits or infrastructure.",{"data":13646,"content":13647,"nodeType":1312},{},[13648],{"data":13649,"marks":13650,"value":13652,"nodeType":864},{},[13651],{"type":899},"You need the research expertise",{"data":13654,"content":13655,"nodeType":860},{},[13656],{"data":13657,"marks":13658,"value":13659,"nodeType":864},{},[],"When the window between technique discovery and industrialized exploitation is measured in weeks rather than years, the detection pipeline needs to operate on that same compressed timescale.",{"data":13661,"content":13662,"nodeType":860},{},[13663,13667,13674],{"data":13664,"marks":13665,"value":13666,"nodeType":864},{},[],"This is where our ",{"data":13668,"content":13669,"nodeType":883},{"uri":7572},[13670],{"data":13671,"marks":13672,"value":13673,"nodeType":864},{},[],"agentic threat hunting pipeline",{"data":13675,"marks":13676,"value":13677,"nodeType":864},{},[]," fits. It's tripled our monthly detection output — not by generating bigger blocklists, but by scaling the process of discovering behavioral patterns across the telemetry generated by 3+ million browser deployments.",{"data":13679,"content":13680,"nodeType":860},{},[13681],{"data":13682,"marks":13683,"value":13684,"nodeType":864},{},[],"The detections it produces are technique-class by design, targeting how attacks work rather than the infrastructure or specific tool that implements them. The goal is curation, not accumulation — hundreds of high-fidelity behavioral detections rather than the billions of signatures and domain entries that traditional approaches require.",{"data":13686,"content":13687,"nodeType":860},{},[13688,13692,13699],{"data":13689,"marks":13690,"value":13691,"nodeType":864},{},[],"When we detected the first in-the-wild ",{"data":13693,"content":13694,"nodeType":883},{"uri":11738},[13695],{"data":13696,"marks":13697,"value":13698,"nodeType":864},{},[],"InstallFix attack",{"data":13700,"marks":13701,"value":13702,"nodeType":864},{},[]," through the pipeline — a user had searched for NotebookLM, clicked a paid Google ad, and was redirected to a fake page with a WebAssembly C2 connector — the detection shipped to all customers within minutes. It didn't depend on knowing the domain, the ad creative, or the specific kit. It depended on recognizing the technique itself.",{"data":13704,"content":13705,"nodeType":1005},{},[],{"data":13707,"content":13708,"nodeType":1009},{},[13709],{"data":13710,"marks":13711,"value":13713,"nodeType":864},{},[13712],{"type":899},"Technique-level detection is now the only option",{"data":13715,"content":13716,"nodeType":860},{},[13717],{"data":13718,"marks":13719,"value":13720,"nodeType":864},{},[],"As a framework for detection durability, the Pyramid of Pain is more relevant than ever. ",{"data":13722,"content":13723,"nodeType":860},{},[13724],{"data":13725,"marks":13726,"value":13727,"nodeType":864},{},[],"AI has made infrastructure indicators essentially disposable. The tools tier is compressing as criminal vendors vibe-code, fork, and clone tooling at machine speed. Technique-level detection is the layer that holds long-term to be able to proactively detect and block net-new attacks and the kits that power them. ",{"data":13729,"content":13730,"nodeType":860},{},[13731],{"data":13732,"marks":13733,"value":13734,"nodeType":864},{},[],"Novel attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Defending that layer requires a vantage point inside the browser session and a research pipeline fast enough to stay ahead of the accelerating path from discovery to industrialization.",{"data":13736,"content":13737,"nodeType":1005},{},[],{"data":13739,"content":13740,"nodeType":860},{},[13741],{"data":13742,"marks":13743,"value":1682,"nodeType":864},{},[],{"data":13745,"content":13746,"nodeType":860},{},[13747],{"data":13748,"marks":13749,"value":1689,"nodeType":864},{},[],{"data":13751,"content":13752,"nodeType":860},{},[13753,13756,13764],{"data":13754,"marks":13755,"value":21,"nodeType":864},{},[],{"data":13757,"content":13758,"nodeType":883},{"uri":1700},[13759],{"data":13760,"marks":13761,"value":13763,"nodeType":864},{},[13762],{"type":1455},"Book a live demo",{"data":13765,"marks":13766,"value":2719,"nodeType":864},{},[],"The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever","AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.","2026-06-01T00:00:00.000Z","the-pyramid-of-pain-in-the-ai-era",{"items":13772},[13773,13776],{"sys":13774,"name":342},{"id":13775},"4ksQNCFeBf8H4QIORqpRLw",{"sys":13777,"name":13779},{"id":13778},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":13781},[13782],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":13783},{"url":2740},{"__typename":2059,"sys":13785,"content":13787,"title":14573,"synopsis":14574,"hashTags":59,"publishedDate":14575,"slug":14576,"tagsCollection":14577,"authorsCollection":14583},{"id":13786},"Gcg7PGuICrlRcqq1QFXxH",{"json":13788},{"data":13789,"content":13790,"nodeType":856},{},[13791,13798,13805,13836,13843,13849,13855,13867,13870,13878,13894,13901,13907,13914,13921,13927,13930,13938,13945,13951,13957,13964,13971,13989,13995,13998,14006,14024,14030,14037,14040,14048,14055,14062,14068,14074,14117,14124,14127,14135,14142,14149,14192,14199,14230,14237,14280,14287,14290,14298,14317,14324,14332,14347,14354,14371,14378,14381,14387,14393,14410,14413,14421,14440,14447,14567],{"data":13792,"content":13793,"nodeType":860},{},[13794],{"data":13795,"marks":13796,"value":13797,"nodeType":864},{},[],"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",{"data":13799,"content":13800,"nodeType":860},{},[13801],{"data":13802,"marks":13803,"value":13804,"nodeType":864},{},[],"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",{"data":13806,"content":13807,"nodeType":860},{},[13808,13812,13820,13824,13832],{"data":13809,"marks":13810,"value":13811,"nodeType":864},{},[],"Several variants of this technique have been ",{"data":13813,"content":13815,"nodeType":883},{"uri":13814},"https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/",[13816],{"data":13817,"marks":13818,"value":13819,"nodeType":864},{},[],"reported over the past few months",{"data":13821,"marks":13822,"value":13823,"nodeType":864},{},[],". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",{"data":13825,"content":13827,"nodeType":883},{"uri":13826},"https://www.kaspersky.com/blog/share-chatgpt-chat-clickfix-macos-amos-infostealer/54928/",[13828],{"data":13829,"marks":13830,"value":13831,"nodeType":864},{},[],"Kaspersky documented a parallel campaign",{"data":13833,"marks":13834,"value":13835,"nodeType":864},{},[]," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",{"data":13837,"content":13838,"nodeType":860},{},[13839],{"data":13840,"marks":13841,"value":13842,"nodeType":864},{},[],"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",{"data":13844,"content":13848,"nodeType":996},{"target":13845},{"sys":13846},{"id":13847,"type":1001,"linkType":1002},"5lz9zt223pecGvdaqdvSTQ",[],{"data":13850,"content":13854,"nodeType":996},{"target":13851},{"sys":13852},{"id":13853,"type":1001,"linkType":1002},"51GomAj3VOjnbmgd1DWYu0",[],{"data":13856,"content":13857,"nodeType":860},{},[13858,13863],{"data":13859,"marks":13860,"value":13862,"nodeType":864},{},[13861],{"type":899},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",{"data":13864,"marks":13865,"value":13866,"nodeType":864},{},[],"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",{"data":13868,"content":13869,"nodeType":1005},{},[],{"data":13871,"content":13872,"nodeType":1009},{},[13873],{"data":13874,"marks":13875,"value":13877,"nodeType":864},{},[13876],{"type":899},"A fake page, not a fake conversation",{"data":13879,"content":13880,"nodeType":860},{},[13881,13885,13890],{"data":13882,"marks":13883,"value":13884,"nodeType":864},{},[],"Previously reported variants relied on shared ",{"data":13886,"marks":13887,"value":13889,"nodeType":864},{},[13888],{"type":2246},"conversations",{"data":13891,"marks":13892,"value":13893,"nodeType":864},{},[]," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",{"data":13895,"content":13896,"nodeType":860},{},[13897],{"data":13898,"marks":13899,"value":13900,"nodeType":864},{},[],"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com/s/ URL. It renders as what appears to be a ChatGPT service disruption notice:",{"data":13902,"content":13906,"nodeType":996},{"target":13903},{"sys":13904},{"id":13905,"type":1001,"linkType":1002},"1O9gyQab81SnbxhQp2aa5Z",[],{"data":13908,"content":13909,"nodeType":860},{},[13910],{"data":13911,"marks":13912,"value":13913,"nodeType":864},{},[],"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",{"data":13915,"content":13916,"nodeType":860},{},[13917],{"data":13918,"marks":13919,"value":13920,"nodeType":864},{},[],"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",{"data":13922,"content":13926,"nodeType":996},{"target":13923},{"sys":13924},{"id":13925,"type":1001,"linkType":1002},"4kQTfxB3aVH9W9BeYOuljP",[],{"data":13928,"content":13929,"nodeType":1005},{},[],{"data":13931,"content":13932,"nodeType":1009},{},[13933],{"data":13934,"marks":13935,"value":13937,"nodeType":864},{},[13936],{"type":899},"The download page",{"data":13939,"content":13940,"nodeType":860},{},[13941],{"data":13942,"marks":13943,"value":13944,"nodeType":864},{},[],"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",{"data":13946,"content":13950,"nodeType":996},{"target":13947},{"sys":13948},{"id":13949,"type":1001,"linkType":1002},"4MdFc4OB37ZihTGx506QJ6",[],{"data":13952,"content":13956,"nodeType":996},{"target":13953},{"sys":13954},{"id":13955,"type":1001,"linkType":1002},"LaPUy0zpIeY8s4PF2wkat",[],{"data":13958,"content":13959,"nodeType":860},{},[13960],{"data":13961,"marks":13962,"value":13963,"nodeType":864},{},[],"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR/VR company website with no obvious connection to ChatGPT. ",{"data":13965,"content":13966,"nodeType":860},{},[13967],{"data":13968,"marks":13969,"value":13970,"nodeType":864},{},[],"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",{"data":13972,"content":13973,"nodeType":860},{},[13974,13978,13986],{"data":13975,"marks":13976,"value":13977,"nodeType":864},{},[],"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",{"data":13979,"content":13981,"nodeType":883},{"uri":13980},"https://www.virustotal.com/gui/file/de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[13982],{"data":13983,"marks":13984,"value":13985,"nodeType":864},{},[],"flagged on VirusTotal",{"data":13987,"marks":13988,"value":2924,"nodeType":864},{},[],{"data":13990,"content":13994,"nodeType":996},{"target":13991},{"sys":13992},{"id":13993,"type":1001,"linkType":1002},"3FSbwoFJYQrcyo9uMsQIWI",[],{"data":13996,"content":13997,"nodeType":1005},{},[],{"data":13999,"content":14000,"nodeType":1009},{},[14001],{"data":14002,"marks":14003,"value":14005,"nodeType":864},{},[14004],{"type":899},"The Claude variant: same campaign, different platform",{"data":14007,"content":14008,"nodeType":860},{},[14009,14013,14020],{"data":14010,"marks":14011,"value":14012,"nodeType":864},{},[],"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",{"data":14014,"content":14015,"nodeType":883},{"uri":13814},[14016],{"data":14017,"marks":14018,"value":14019,"nodeType":864},{},[],"BleepingComputer",{"data":14021,"marks":14022,"value":14023,"nodeType":864},{},[],": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",{"data":14025,"content":14029,"nodeType":996},{"target":14026},{"sys":14027},{"id":14028,"type":1001,"linkType":1002},"5sWayuTsVdiLSLoS4sv2Vc",[],{"data":14031,"content":14032,"nodeType":860},{},[14033],{"data":14034,"marks":14035,"value":14036,"nodeType":864},{},[],"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",{"data":14038,"content":14039,"nodeType":1005},{},[],{"data":14041,"content":14042,"nodeType":1009},{},[14043],{"data":14044,"marks":14045,"value":14047,"nodeType":864},{},[14046],{"type":899},"Malvertising remains one of the top phishing delivery channels",{"data":14049,"content":14050,"nodeType":860},{},[14051],{"data":14052,"marks":14053,"value":14054,"nodeType":864},{},[],"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",{"data":14056,"content":14057,"nodeType":860},{},[14058],{"data":14059,"marks":14060,"value":14061,"nodeType":864},{},[],"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",{"data":14063,"content":14067,"nodeType":996},{"target":14064},{"sys":14065},{"id":14066,"type":1001,"linkType":1002},"1GYWOyHpZT1rdTm6IGOKu8",[],{"data":14069,"content":14073,"nodeType":996},{"target":14070},{"sys":14071},{"id":14072,"type":1001,"linkType":1002},"4HpFJRAZH2lbygaEk2xOnN",[],{"data":14075,"content":14076,"nodeType":860},{},[14077,14081,14089,14093,14101,14104,14113],{"data":14078,"marks":14079,"value":14080,"nodeType":864},{},[],"This fits a pattern Push has tracked extensively. ",{"data":14082,"content":14084,"nodeType":883},{"uri":14083},"https://pushsecurity.com/blog/verizon-dbir-2026-review/",[14085],{"data":14086,"marks":14087,"value":14088,"nodeType":864},{},[],"Search-based delivery is now the dominant channel for malware distribution",{"data":14090,"marks":14091,"value":14092,"nodeType":864},{},[]," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",{"data":14094,"content":14096,"nodeType":883},{"uri":14095},"https://pushsecurity.com/blog/analysing-a-sophisticated-google-malvertising-attack/",[14097],{"data":14098,"marks":14099,"value":14100,"nodeType":864},{},[],"malvertising campaigns impersonating brands like TradingView",{"data":14102,"marks":14103,"value":902,"nodeType":864},{},[],{"data":14105,"content":14107,"nodeType":883},{"uri":14106},"https://pushsecurity.com/blog/google-search-malvertising-campaign-continues-now-impersonating-ahrefs/",[14108],{"data":14109,"marks":14110,"value":14112,"nodeType":864},{},[14111],{"type":1455},"Ahrefs",{"data":14114,"marks":14115,"value":14116,"nodeType":864},{},[]," has demonstrated how effectively search ads can funnel victims to malicious pages. ",{"data":14118,"content":14119,"nodeType":860},{},[14120],{"data":14121,"marks":14122,"value":14123,"nodeType":864},{},[],"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",{"data":14125,"content":14126,"nodeType":1005},{},[],{"data":14128,"content":14129,"nodeType":1009},{},[14130],{"data":14131,"marks":14132,"value":14134,"nodeType":864},{},[14133],{"type":899},"Legitimate platform abuse is everywhere",{"data":14136,"content":14137,"nodeType":860},{},[14138],{"data":14139,"marks":14140,"value":14141,"nodeType":864},{},[],"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",{"data":14143,"content":14144,"nodeType":1312},{},[14145],{"data":14146,"marks":14147,"value":14148,"nodeType":864},{},[],"Legit platform abuse for delivery",{"data":14150,"content":14151,"nodeType":860},{},[14152,14156,14164,14168,14176,14180,14188],{"data":14153,"marks":14154,"value":14155,"nodeType":864},{},[],"On the delivery side, attackers have been ",{"data":14157,"content":14159,"nodeType":883},{"uri":14158},"https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/",[14160],{"data":14161,"marks":14162,"value":14163,"nodeType":864},{},[],"weaponizing stolen AWS credentials to send phishing through Amazon SES",{"data":14165,"marks":14166,"value":14167,"nodeType":864},{},[]," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",{"data":14169,"content":14171,"nodeType":883},{"uri":14170},"https://thehackernews.com/2026/05/30000-facebook-accounts-hacked-via.html",[14172],{"data":14173,"marks":14174,"value":14175,"nodeType":864},{},[],"AccountDumpling used Google AppSheet's built-in email capability",{"data":14177,"marks":14178,"value":14179,"nodeType":864},{},[]," as a phishing relay to harvest 30,000 Facebook credentials. ",{"data":14181,"content":14183,"nodeType":883},{"uri":14182},"https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/",[14184],{"data":14185,"marks":14186,"value":14187,"nodeType":864},{},[],"Scammers exploited Microsoft's own internal notification pipeline",{"data":14189,"marks":14190,"value":14191,"nodeType":864},{},[]," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",{"data":14193,"content":14194,"nodeType":1312},{},[14195],{"data":14196,"marks":14197,"value":14198,"nodeType":864},{},[],"Legit platform abuse for hosting",{"data":14200,"content":14201,"nodeType":860},{},[14202,14206,14214,14218,14226],{"data":14203,"marks":14204,"value":14205,"nodeType":864},{},[],"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",{"data":14207,"content":14209,"nodeType":883},{"uri":14208},"https://www.securityweek.com/over-500-organizations-hit-in-years-long-phishing-campaign/",[14210],{"data":14211,"marks":14212,"value":14213,"nodeType":864},{},[],"Operation HookedWing ran for four years",{"data":14215,"marks":14216,"value":14217,"nodeType":864},{},[]," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",{"data":14219,"content":14221,"nodeType":883},{"uri":14220},"https://cofense.com/blog/steal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing/",[14222],{"data":14223,"marks":14224,"value":14225,"nodeType":864},{},[],"documented the growing abuse of Vercel",{"data":14227,"marks":14228,"value":14229,"nodeType":864},{},[]," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",{"data":14231,"content":14232,"nodeType":1312},{},[14233],{"data":14234,"marks":14235,"value":14236,"nodeType":864},{},[],"Abuse of compromised websites that are otherwise legit",{"data":14238,"content":14239,"nodeType":860},{},[14240,14244,14252,14256,14264,14268,14276],{"data":14241,"marks":14242,"value":14243,"nodeType":864},{},[],"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",{"data":14245,"content":14247,"nodeType":883},{"uri":14246},"https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/",[14248],{"data":14249,"marks":14250,"value":14251,"nodeType":864},{},[],"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",{"data":14253,"marks":14254,"value":14255,"nodeType":864},{},[]," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",{"data":14257,"content":14259,"nodeType":883},{"uri":14258},"https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/",[14260],{"data":14261,"marks":14262,"value":14263,"nodeType":864},{},[],"SEO poisoning was combined with AI chatbot recommendation manipulation",{"data":14265,"marks":14266,"value":14267,"nodeType":864},{},[]," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",{"data":14269,"content":14271,"nodeType":883},{"uri":14270},"https://www.helpnetsecurity.com/2026/05/27/deno-rat-malware-fake-chatgpt-claude-installers/",[14272],{"data":14273,"marks":14274,"value":14275,"nodeType":864},{},[],"fake ChatGPT and Claude installers on GitHub and SourceForge",{"data":14277,"marks":14278,"value":14279,"nodeType":864},{},[]," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",{"data":14281,"content":14282,"nodeType":860},{},[14283],{"data":14284,"marks":14285,"value":14286,"nodeType":864},{},[],"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",{"data":14288,"content":14289,"nodeType":1005},{},[],{"data":14291,"content":14292,"nodeType":1009},{},[14293],{"data":14294,"marks":14295,"value":14297,"nodeType":864},{},[14296],{"type":899},"Impact analysis",{"data":14299,"content":14300,"nodeType":860},{},[14301,14305,14313],{"data":14302,"marks":14303,"value":14304,"nodeType":864},{},[],"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",{"data":14306,"content":14308,"nodeType":883},{"uri":14307},"https://phishing-techniques.pushsecurity.com/",[14309],{"data":14310,"marks":14311,"value":14312,"nodeType":864},{},[],"detection evasion technique",{"data":14314,"marks":14315,"value":14316,"nodeType":864},{},[],"). ",{"data":14318,"content":14319,"nodeType":860},{},[14320],{"data":14321,"marks":14322,"value":14323,"nodeType":864},{},[],"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",{"data":14325,"content":14326,"nodeType":1312},{},[14327],{"data":14328,"marks":14329,"value":14331,"nodeType":864},{},[14330],{"type":899},"How Push detected the attack",{"data":14333,"content":14334,"nodeType":860},{},[14335,14339,14343],{"data":14336,"marks":14337,"value":14338,"nodeType":864},{},[],"We've aligned our detection logic for this technique under the name ",{"data":14340,"marks":14341,"value":1555,"nodeType":864},{},[14342],{"type":899},{"data":14344,"marks":14345,"value":14346,"nodeType":864},{},[]," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",{"data":14348,"content":14349,"nodeType":860},{},[14350],{"data":14351,"marks":14352,"value":14353,"nodeType":864},{},[],"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",{"data":14355,"content":14356,"nodeType":860},{},[14357,14361,14367],{"data":14358,"marks":14359,"value":14360,"nodeType":864},{},[],"When we identified the initial instances of this campaign, we used our ",{"data":14362,"content":14363,"nodeType":883},{"uri":7572},[14364],{"data":14365,"marks":14366,"value":13673,"nodeType":864},{},[],{"data":14368,"marks":14369,"value":14370,"nodeType":864},{},[]," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",{"data":14372,"content":14373,"nodeType":860},{},[14374],{"data":14375,"marks":14376,"value":14377,"nodeType":864},{},[],"Push customers do not need to take any further action.",{"data":14379,"content":14380,"nodeType":1005},{},[],{"data":14382,"content":14383,"nodeType":860},{},[14384],{"data":14385,"marks":14386,"value":1682,"nodeType":864},{},[],{"data":14388,"content":14389,"nodeType":860},{},[14390],{"data":14391,"marks":14392,"value":1689,"nodeType":864},{},[],{"data":14394,"content":14395,"nodeType":860},{},[14396,14399,14407],{"data":14397,"marks":14398,"value":21,"nodeType":864},{},[],{"data":14400,"content":14402,"nodeType":883},{"uri":14401},"https://pushsecurity.com/demo/",[14403],{"data":14404,"marks":14405,"value":1703,"nodeType":864},{},[14406],{"type":1455},{"data":14408,"marks":14409,"value":21,"nodeType":864},{},[],{"data":14411,"content":14412,"nodeType":1005},{},[],{"data":14414,"content":14415,"nodeType":1009},{},[14416],{"data":14417,"marks":14418,"value":14420,"nodeType":864},{},[14419],{"type":899},"Indicators of compromise",{"data":14422,"content":14423,"nodeType":860},{},[14424,14428,14436],{"data":14425,"marks":14426,"value":14427,"nodeType":864},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":14429,"content":14431,"nodeType":883},{"uri":14430},"https://phishing-techniques.pushsecurity.com/techniques/domain-rotation-redirection/",[14432],{"data":14433,"marks":14434,"value":14435,"nodeType":864},{},[],"quickly spin up and rotate the sites used",{"data":14437,"marks":14438,"value":14439,"nodeType":864},{},[]," in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":14441,"content":14442,"nodeType":860},{},[14443],{"data":14444,"marks":14445,"value":14446,"nodeType":864},{},[],"At the time of writing, the indicators observed were:",{"data":14448,"content":14449,"nodeType":4845},{},[14450,14476,14499,14521,14544],{"data":14451,"content":14452,"nodeType":4581},{},[14453,14465],{"data":14454,"content":14455,"nodeType":14464},{},[14456],{"data":14457,"content":14458,"nodeType":860},{},[14459],{"data":14460,"marks":14461,"value":14463,"nodeType":864},{},[14462],{"type":899},"Indicator","table-header-cell",{"data":14466,"content":14467,"nodeType":14464},{},[14468],{"data":14469,"content":14470,"nodeType":860},{},[14471],{"data":14472,"marks":14473,"value":14475,"nodeType":864},{},[14474],{"type":899},"Type",{"data":14477,"content":14478,"nodeType":4581},{},[14479,14489],{"data":14480,"content":14481,"nodeType":4569},{},[14482],{"data":14483,"content":14484,"nodeType":860},{},[14485],{"data":14486,"marks":14487,"value":14488,"nodeType":864},{},[],"hxxps://claude[.]ai/share/8e6401b5-4849-46c4-a3cb-29e1c3c49131",{"data":14490,"content":14491,"nodeType":4569},{},[14492],{"data":14493,"content":14494,"nodeType":860},{},[14495],{"data":14496,"marks":14497,"value":14498,"nodeType":864},{},[],"URL",{"data":14500,"content":14501,"nodeType":4581},{},[14502,14512],{"data":14503,"content":14504,"nodeType":4569},{},[14505],{"data":14506,"content":14507,"nodeType":860},{},[14508],{"data":14509,"marks":14510,"value":14511,"nodeType":864},{},[],"hxxps://chatgpt[.]com/s/cb_6a0f1e6bbec88191aa7fede27163f08d",{"data":14513,"content":14514,"nodeType":4569},{},[14515],{"data":14516,"content":14517,"nodeType":860},{},[14518],{"data":14519,"marks":14520,"value":14498,"nodeType":864},{},[],{"data":14522,"content":14523,"nodeType":4581},{},[14524,14534],{"data":14525,"content":14526,"nodeType":4569},{},[14527],{"data":14528,"content":14529,"nodeType":860},{},[14530],{"data":14531,"marks":14532,"value":14533,"nodeType":864},{},[],"openew[.]app",{"data":14535,"content":14536,"nodeType":4569},{},[14537],{"data":14538,"content":14539,"nodeType":860},{},[14540],{"data":14541,"marks":14542,"value":14543,"nodeType":864},{},[],"Domain",{"data":14545,"content":14546,"nodeType":4581},{},[14547,14557],{"data":14548,"content":14549,"nodeType":4569},{},[14550],{"data":14551,"content":14552,"nodeType":860},{},[14553],{"data":14554,"marks":14555,"value":14556,"nodeType":864},{},[],"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",{"data":14558,"content":14559,"nodeType":4569},{},[14560],{"data":14561,"content":14562,"nodeType":860},{},[14563],{"data":14564,"marks":14565,"value":14566,"nodeType":864},{},[],"SHA256",{"data":14568,"content":14569,"nodeType":860},{},[14570],{"data":14571,"marks":14572,"value":21,"nodeType":864},{},[],"LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":14578},[14579,14581],{"sys":14580,"name":13779},{"id":13778},{"sys":14582,"name":342},{"id":13775},{"items":14584},[14585],{"fullName":14586,"firstName":14587,"jobTitle":14588,"profilePicture":14589},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":14590},"https://images.ctfassets.net/y1cdw1ablpvd/VCGOm62jiocjwngWTh32U/e9a30637b1c76bf988d2fec90f5b6c36/1689361049351_1.png",{"__typename":2059,"sys":14592,"content":14593,"title":2720,"synopsis":2721,"hashTags":59,"publishedDate":2722,"slug":2723,"tagsCollection":15154,"authorsCollection":15160},{"id":2061},{"json":14594},{"data":14595,"content":14596,"nodeType":856},{},[14597,14603,14609,14615,14620,14623,14630,14636,14665,14671,14695,14700,14703,14710,14716,14723,14757,14762,14768,14773,14776,14783,14789,14796,14802,14808,14821,14828,14848,14854,14859,14865,14872,14885,14907,14912,14927,14932,14939,14945,14965,14971,14977,14983,14988,14991,14998,15004,15010,15025,15032,15038,15045,15064,15074,15079,15082,15089,15095,15101,15107,15123,15126,15132,15138],{"data":14598,"content":14599,"nodeType":860},{},[14600],{"data":14601,"marks":14602,"value":2072,"nodeType":864},{},[],{"data":14604,"content":14605,"nodeType":860},{},[14606],{"data":14607,"marks":14608,"value":2079,"nodeType":864},{},[],{"data":14610,"content":14611,"nodeType":860},{},[14612],{"data":14613,"marks":14614,"value":2086,"nodeType":864},{},[],{"data":14616,"content":14619,"nodeType":996},{"target":14617},{"sys":14618},{"id":2091,"type":1001,"linkType":1002},[],{"data":14621,"content":14622,"nodeType":1005},{},[],{"data":14624,"content":14625,"nodeType":1009},{},[14626],{"data":14627,"marks":14628,"value":2103,"nodeType":864},{},[14629],{"type":899},{"data":14631,"content":14632,"nodeType":860},{},[14633],{"data":14634,"marks":14635,"value":2110,"nodeType":864},{},[],{"data":14637,"content":14638,"nodeType":941},{},[14639,14652],{"data":14640,"content":14641,"nodeType":945},{},[14642],{"data":14643,"content":14644,"nodeType":860},{},[14645,14649],{"data":14646,"marks":14647,"value":2124,"nodeType":864},{},[14648],{"type":899},{"data":14650,"marks":14651,"value":2128,"nodeType":864},{},[],{"data":14653,"content":14654,"nodeType":945},{},[14655],{"data":14656,"content":14657,"nodeType":860},{},[14658,14662],{"data":14659,"marks":14660,"value":2139,"nodeType":864},{},[14661],{"type":899},{"data":14663,"marks":14664,"value":2143,"nodeType":864},{},[],{"data":14666,"content":14667,"nodeType":860},{},[14668],{"data":14669,"marks":14670,"value":2150,"nodeType":864},{},[],{"data":14672,"content":14673,"nodeType":860},{},[14674,14677,14683,14686,14692],{"data":14675,"marks":14676,"value":2157,"nodeType":864},{},[],{"data":14678,"content":14679,"nodeType":883},{"uri":1543},[14680],{"data":14681,"marks":14682,"value":1758,"nodeType":864},{},[],{"data":14684,"marks":14685,"value":1762,"nodeType":864},{},[],{"data":14687,"content":14688,"nodeType":883},{"uri":1765},[14689],{"data":14690,"marks":14691,"value":1770,"nodeType":864},{},[],{"data":14693,"marks":14694,"value":1774,"nodeType":864},{},[],{"data":14696,"content":14699,"nodeType":996},{"target":14697},{"sys":14698},{"id":2180,"type":1001,"linkType":1002},[],{"data":14701,"content":14702,"nodeType":1005},{},[],{"data":14704,"content":14705,"nodeType":1009},{},[14706],{"data":14707,"marks":14708,"value":2192,"nodeType":864},{},[14709],{"type":899},{"data":14711,"content":14712,"nodeType":860},{},[14713],{"data":14714,"marks":14715,"value":2199,"nodeType":864},{},[],{"data":14717,"content":14718,"nodeType":860},{},[14719],{"data":14720,"marks":14721,"value":2207,"nodeType":864},{},[14722],{"type":899},{"data":14724,"content":14725,"nodeType":860},{},[14726,14729,14733,14736,14740,14743,14747,14750,14754],{"data":14727,"marks":14728,"value":2214,"nodeType":864},{},[],{"data":14730,"marks":14731,"value":2219,"nodeType":864},{},[14732],{"type":899},{"data":14734,"marks":14735,"value":2223,"nodeType":864},{},[],{"data":14737,"marks":14738,"value":2228,"nodeType":864},{},[14739],{"type":899},{"data":14741,"marks":14742,"value":2232,"nodeType":864},{},[],{"data":14744,"marks":14745,"value":2237,"nodeType":864},{},[14746],{"type":899},{"data":14748,"marks":14749,"value":2241,"nodeType":864},{},[],{"data":14751,"marks":14752,"value":2247,"nodeType":864},{},[14753],{"type":2246},{"data":14755,"marks":14756,"value":2251,"nodeType":864},{},[],{"data":14758,"content":14761,"nodeType":996},{"target":14759},{"sys":14760},{"id":2256,"type":1001,"linkType":1002},[],{"data":14763,"content":14764,"nodeType":860},{},[14765],{"data":14766,"marks":14767,"value":2264,"nodeType":864},{},[],{"data":14769,"content":14772,"nodeType":996},{"target":14770},{"sys":14771},{"id":1040,"type":1001,"linkType":1002},[],{"data":14774,"content":14775,"nodeType":1005},{},[],{"data":14777,"content":14778,"nodeType":1009},{},[14779],{"data":14780,"marks":14781,"value":2280,"nodeType":864},{},[14782],{"type":899},{"data":14784,"content":14785,"nodeType":860},{},[14786],{"data":14787,"marks":14788,"value":2287,"nodeType":864},{},[],{"data":14790,"content":14791,"nodeType":1312},{},[14792],{"data":14793,"marks":14794,"value":2295,"nodeType":864},{},[14795],{"type":899},{"data":14797,"content":14798,"nodeType":860},{},[14799],{"data":14800,"marks":14801,"value":2302,"nodeType":864},{},[],{"data":14803,"content":14804,"nodeType":860},{},[14805],{"data":14806,"marks":14807,"value":2309,"nodeType":864},{},[],{"data":14809,"content":14810,"nodeType":860},{},[14811,14814,14818],{"data":14812,"marks":14813,"value":2316,"nodeType":864},{},[],{"data":14815,"marks":14816,"value":2321,"nodeType":864},{},[14817],{"type":899},{"data":14819,"marks":14820,"value":2325,"nodeType":864},{},[],{"data":14822,"content":14823,"nodeType":1312},{},[14824],{"data":14825,"marks":14826,"value":2333,"nodeType":864},{},[14827],{"type":899},{"data":14829,"content":14830,"nodeType":860},{},[14831,14834,14838,14841,14845],{"data":14832,"marks":14833,"value":2340,"nodeType":864},{},[],{"data":14835,"marks":14836,"value":2345,"nodeType":864},{},[14837],{"type":899},{"data":14839,"marks":14840,"value":2349,"nodeType":864},{},[],{"data":14842,"marks":14843,"value":2354,"nodeType":864},{},[14844],{"type":899},{"data":14846,"marks":14847,"value":2358,"nodeType":864},{},[],{"data":14849,"content":14850,"nodeType":860},{},[14851],{"data":14852,"marks":14853,"value":2365,"nodeType":864},{},[],{"data":14855,"content":14858,"nodeType":996},{"target":14856},{"sys":14857},{"id":2370,"type":1001,"linkType":1002},[],{"data":14860,"content":14861,"nodeType":860},{},[14862],{"data":14863,"marks":14864,"value":2378,"nodeType":864},{},[],{"data":14866,"content":14867,"nodeType":1312},{},[14868],{"data":14869,"marks":14870,"value":2386,"nodeType":864},{},[14871],{"type":899},{"data":14873,"content":14874,"nodeType":860},{},[14875,14878,14882],{"data":14876,"marks":14877,"value":2393,"nodeType":864},{},[],{"data":14879,"marks":14880,"value":2228,"nodeType":864},{},[14881],{"type":899},{"data":14883,"marks":14884,"value":2401,"nodeType":864},{},[],{"data":14886,"content":14887,"nodeType":860},{},[14888,14891,14897,14900,14904],{"data":14889,"marks":14890,"value":2408,"nodeType":864},{},[],{"data":14892,"content":14893,"nodeType":883},{"uri":2411},[14894],{"data":14895,"marks":14896,"value":2416,"nodeType":864},{},[],{"data":14898,"marks":14899,"value":2420,"nodeType":864},{},[],{"data":14901,"marks":14902,"value":2425,"nodeType":864},{},[14903],{"type":899},{"data":14905,"marks":14906,"value":2429,"nodeType":864},{},[],{"data":14908,"content":14911,"nodeType":996},{"target":14909},{"sys":14910},{"id":2434,"type":1001,"linkType":1002},[],{"data":14913,"content":14914,"nodeType":860},{},[14915,14918,14924],{"data":14916,"marks":14917,"value":2442,"nodeType":864},{},[],{"data":14919,"content":14920,"nodeType":883},{"uri":2411},[14921],{"data":14922,"marks":14923,"value":2449,"nodeType":864},{},[],{"data":14925,"marks":14926,"value":2453,"nodeType":864},{},[],{"data":14928,"content":14931,"nodeType":996},{"target":14929},{"sys":14930},{"id":2458,"type":1001,"linkType":1002},[],{"data":14933,"content":14934,"nodeType":1312},{},[14935],{"data":14936,"marks":14937,"value":2467,"nodeType":864},{},[14938],{"type":899},{"data":14940,"content":14941,"nodeType":860},{},[14942],{"data":14943,"marks":14944,"value":2474,"nodeType":864},{},[],{"data":14946,"content":14947,"nodeType":860},{},[14948,14951,14955,14958,14962],{"data":14949,"marks":14950,"value":2481,"nodeType":864},{},[],{"data":14952,"marks":14953,"value":2486,"nodeType":864},{},[14954],{"type":899},{"data":14956,"marks":14957,"value":2490,"nodeType":864},{},[],{"data":14959,"marks":14960,"value":2495,"nodeType":864},{},[14961],{"type":2246},{"data":14963,"marks":14964,"value":2499,"nodeType":864},{},[],{"data":14966,"content":14967,"nodeType":860},{},[14968],{"data":14969,"marks":14970,"value":2506,"nodeType":864},{},[],{"data":14972,"content":14973,"nodeType":860},{},[14974],{"data":14975,"marks":14976,"value":2513,"nodeType":864},{},[],{"data":14978,"content":14979,"nodeType":860},{},[14980],{"data":14981,"marks":14982,"value":2520,"nodeType":864},{},[],{"data":14984,"content":14987,"nodeType":996},{"target":14985},{"sys":14986},{"id":2525,"type":1001,"linkType":1002},[],{"data":14989,"content":14990,"nodeType":1005},{},[],{"data":14992,"content":14993,"nodeType":1009},{},[14994],{"data":14995,"marks":14996,"value":2537,"nodeType":864},{},[14997],{"type":899},{"data":14999,"content":15000,"nodeType":860},{},[15001],{"data":15002,"marks":15003,"value":2544,"nodeType":864},{},[],{"data":15005,"content":15006,"nodeType":860},{},[15007],{"data":15008,"marks":15009,"value":2551,"nodeType":864},{},[],{"data":15011,"content":15012,"nodeType":860},{},[15013,15016,15022],{"data":15014,"marks":15015,"value":2558,"nodeType":864},{},[],{"data":15017,"content":15018,"nodeType":883},{"uri":2561},[15019],{"data":15020,"marks":15021,"value":2566,"nodeType":864},{},[],{"data":15023,"marks":15024,"value":2570,"nodeType":864},{},[],{"data":15026,"content":15027,"nodeType":1312},{},[15028],{"data":15029,"marks":15030,"value":2578,"nodeType":864},{},[15031],{"type":899},{"data":15033,"content":15034,"nodeType":860},{},[15035],{"data":15036,"marks":15037,"value":2585,"nodeType":864},{},[],{"data":15039,"content":15040,"nodeType":860},{},[15041],{"data":15042,"marks":15043,"value":2593,"nodeType":864},{},[15044],{"type":899},{"data":15046,"content":15047,"nodeType":860},{},[15048,15052,15055,15061],{"data":15049,"marks":15050,"value":2601,"nodeType":864},{},[15051],{"type":899},{"data":15053,"marks":15054,"value":2605,"nodeType":864},{},[],{"data":15056,"content":15057,"nodeType":883},{"uri":2411},[15058],{"data":15059,"marks":15060,"value":2612,"nodeType":864},{},[],{"data":15062,"marks":15063,"value":2616,"nodeType":864},{},[],{"data":15065,"content":15066,"nodeType":860},{},[15067,15071],{"data":15068,"marks":15069,"value":2624,"nodeType":864},{},[15070],{"type":899},{"data":15072,"marks":15073,"value":2628,"nodeType":864},{},[],{"data":15075,"content":15078,"nodeType":996},{"target":15076},{"sys":15077},{"id":2633,"type":1001,"linkType":1002},[],{"data":15080,"content":15081,"nodeType":1005},{},[],{"data":15083,"content":15084,"nodeType":1009},{},[15085],{"data":15086,"marks":15087,"value":2645,"nodeType":864},{},[15088],{"type":899},{"data":15090,"content":15091,"nodeType":860},{},[15092],{"data":15093,"marks":15094,"value":2652,"nodeType":864},{},[],{"data":15096,"content":15097,"nodeType":860},{},[15098],{"data":15099,"marks":15100,"value":2659,"nodeType":864},{},[],{"data":15102,"content":15103,"nodeType":860},{},[15104],{"data":15105,"marks":15106,"value":2666,"nodeType":864},{},[],{"data":15108,"content":15109,"nodeType":860},{},[15110,15113,15120],{"data":15111,"marks":15112,"value":2673,"nodeType":864},{},[],{"data":15114,"content":15115,"nodeType":883},{"uri":2676},[15116],{"data":15117,"marks":15118,"value":580,"nodeType":864},{},[15119],{"type":1455},{"data":15121,"marks":15122,"value":2685,"nodeType":864},{},[],{"data":15124,"content":15125,"nodeType":1005},{},[],{"data":15127,"content":15128,"nodeType":860},{},[15129],{"data":15130,"marks":15131,"value":1682,"nodeType":864},{},[],{"data":15133,"content":15134,"nodeType":860},{},[15135],{"data":15136,"marks":15137,"value":1689,"nodeType":864},{},[],{"data":15139,"content":15140,"nodeType":860},{},[15141,15144,15151],{"data":15142,"marks":15143,"value":2707,"nodeType":864},{},[],{"data":15145,"content":15146,"nodeType":883},{"uri":1700},[15147],{"data":15148,"marks":15149,"value":2715,"nodeType":864},{},[15150],{"type":1455},{"data":15152,"marks":15153,"value":2719,"nodeType":864},{},[],{"items":15155},[15156,15158],{"sys":15157,"name":2729},{"id":2728},{"sys":15159,"name":297},{"id":2732},{"items":15161},[15162],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":15163},{"url":2740},"blog/why-you-cant-control-ai-without-being-in-the-browser","AI visibility and control is a feature. Browser security is the foundation.",{"json":15167},{"data":15168,"content":15169,"nodeType":856},{},[15170],{"data":15171,"content":15172,"nodeType":860},{},[15173],{"data":15174,"marks":15175,"value":7692,"nodeType":864},{},[],{"id":6770,"publishedAt":15177},"2026-08-12T11:52:42.429Z",{"items":15179},[15180,15182],{"sys":15181,"name":297},{"id":2732},{"sys":15183,"name":2729},{"id":2728},{"items":15185},[15186,15188,15190,15192,15194,15196,15198,15200,15202,15204,15206,15208,15210,15212,15214,15216,15218,15220,15222],{"sys":15187,"name":235,"slug":236,"tier":31},{"id":232},{"sys":15189,"name":297,"slug":298,"tier":31},{"id":294},{"sys":15191,"name":279,"slug":280,"tier":31},{"id":276},{"sys":15193,"name":519,"slug":520,"tier":31},{"id":516},{"sys":15195,"name":545,"slug":546,"tier":31},{"id":542},{"sys":15197,"name":580,"slug":581,"tier":45},{"id":577},{"sys":15199,"name":252,"slug":253,"tier":45},{"id":249},{"sys":15201,"name":368,"slug":369,"tier":45},{"id":365},{"sys":15203,"name":484,"slug":485,"tier":45},{"id":481},{"sys":15205,"name":288,"slug":289,"tier":45},{"id":285},{"sys":15207,"name":315,"slug":316,"tier":45},{"id":312},{"sys":15209,"name":360,"slug":361,"tier":45},{"id":357},{"sys":15211,"name":261,"slug":262,"tier":45},{"id":258},{"sys":15213,"name":440,"slug":441,"tier":45},{"id":437},{"sys":15215,"name":475,"slug":476,"tier":45},{"id":472},{"sys":15217,"name":324,"slug":325,"tier":45},{"id":321},{"sys":15219,"name":633,"slug":634,"tier":45},{"id":630},{"sys":15221,"name":244,"slug":245,"tier":45},{"id":241},{"sys":15223,"name":607,"slug":608,"tier":45},{"id":604},"sEvs1NG13z8Guz6oaxJbRvlEv7Tcmf1seFlO6IQdBPM",{"id":15226,"title":2720,"authorsCollection":15227,"content":15233,"extension":228,"faqItemsCollection":16043,"faqTitle":16142,"featured":6,"hashTags":59,"meta":16143,"metaTitle":16144,"ogImage":59,"postType":5726,"publishedDate":2722,"relatedBlogPostsCollection":16145,"slug":2723,"stem":18715,"subtitle":59,"summary":18716,"synopsis":2721,"sys":18727,"tagsCollection":18729,"topicsCollection":18735,"__hash__":18759},"blog/blog/what-push-data-reveals-about-the-state-of-shadow-ai.json",{"items":15228},[15229],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":15230,"profilePicture":15232},[15231],"https://www.linkedin.com/in/daniel-g-/",{"url":2740},{"json":15234,"links":15794},{"data":15235,"content":15236,"nodeType":856},{},[15237,15243,15249,15255,15260,15263,15270,15276,15305,15311,15335,15340,15343,15350,15356,15363,15397,15402,15408,15413,15416,15423,15429,15436,15442,15448,15461,15468,15488,15494,15499,15505,15512,15525,15547,15552,15567,15572,15579,15585,15605,15611,15617,15623,15628,15631,15638,15644,15650,15665,15672,15678,15685,15704,15714,15719,15722,15729,15735,15741,15747,15763,15766,15772,15778],{"data":15238,"content":15239,"nodeType":860},{},[15240],{"data":15241,"marks":15242,"value":2072,"nodeType":864},{},[],{"data":15244,"content":15245,"nodeType":860},{},[15246],{"data":15247,"marks":15248,"value":2079,"nodeType":864},{},[],{"data":15250,"content":15251,"nodeType":860},{},[15252],{"data":15253,"marks":15254,"value":2086,"nodeType":864},{},[],{"data":15256,"content":15259,"nodeType":996},{"target":15257},{"sys":15258},{"id":2091,"type":1001,"linkType":1002},[],{"data":15261,"content":15262,"nodeType":1005},{},[],{"data":15264,"content":15265,"nodeType":1009},{},[15266],{"data":15267,"marks":15268,"value":2103,"nodeType":864},{},[15269],{"type":899},{"data":15271,"content":15272,"nodeType":860},{},[15273],{"data":15274,"marks":15275,"value":2110,"nodeType":864},{},[],{"data":15277,"content":15278,"nodeType":941},{},[15279,15292],{"data":15280,"content":15281,"nodeType":945},{},[15282],{"data":15283,"content":15284,"nodeType":860},{},[15285,15289],{"data":15286,"marks":15287,"value":2124,"nodeType":864},{},[15288],{"type":899},{"data":15290,"marks":15291,"value":2128,"nodeType":864},{},[],{"data":15293,"content":15294,"nodeType":945},{},[15295],{"data":15296,"content":15297,"nodeType":860},{},[15298,15302],{"data":15299,"marks":15300,"value":2139,"nodeType":864},{},[15301],{"type":899},{"data":15303,"marks":15304,"value":2143,"nodeType":864},{},[],{"data":15306,"content":15307,"nodeType":860},{},[15308],{"data":15309,"marks":15310,"value":2150,"nodeType":864},{},[],{"data":15312,"content":15313,"nodeType":860},{},[15314,15317,15323,15326,15332],{"data":15315,"marks":15316,"value":2157,"nodeType":864},{},[],{"data":15318,"content":15319,"nodeType":883},{"uri":1543},[15320],{"data":15321,"marks":15322,"value":1758,"nodeType":864},{},[],{"data":15324,"marks":15325,"value":1762,"nodeType":864},{},[],{"data":15327,"content":15328,"nodeType":883},{"uri":1765},[15329],{"data":15330,"marks":15331,"value":1770,"nodeType":864},{},[],{"data":15333,"marks":15334,"value":1774,"nodeType":864},{},[],{"data":15336,"content":15339,"nodeType":996},{"target":15337},{"sys":15338},{"id":2180,"type":1001,"linkType":1002},[],{"data":15341,"content":15342,"nodeType":1005},{},[],{"data":15344,"content":15345,"nodeType":1009},{},[15346],{"data":15347,"marks":15348,"value":2192,"nodeType":864},{},[15349],{"type":899},{"data":15351,"content":15352,"nodeType":860},{},[15353],{"data":15354,"marks":15355,"value":2199,"nodeType":864},{},[],{"data":15357,"content":15358,"nodeType":860},{},[15359],{"data":15360,"marks":15361,"value":2207,"nodeType":864},{},[15362],{"type":899},{"data":15364,"content":15365,"nodeType":860},{},[15366,15369,15373,15376,15380,15383,15387,15390,15394],{"data":15367,"marks":15368,"value":2214,"nodeType":864},{},[],{"data":15370,"marks":15371,"value":2219,"nodeType":864},{},[15372],{"type":899},{"data":15374,"marks":15375,"value":2223,"nodeType":864},{},[],{"data":15377,"marks":15378,"value":2228,"nodeType":864},{},[15379],{"type":899},{"data":15381,"marks":15382,"value":2232,"nodeType":864},{},[],{"data":15384,"marks":15385,"value":2237,"nodeType":864},{},[15386],{"type":899},{"data":15388,"marks":15389,"value":2241,"nodeType":864},{},[],{"data":15391,"marks":15392,"value":2247,"nodeType":864},{},[15393],{"type":2246},{"data":15395,"marks":15396,"value":2251,"nodeType":864},{},[],{"data":15398,"content":15401,"nodeType":996},{"target":15399},{"sys":15400},{"id":2256,"type":1001,"linkType":1002},[],{"data":15403,"content":15404,"nodeType":860},{},[15405],{"data":15406,"marks":15407,"value":2264,"nodeType":864},{},[],{"data":15409,"content":15412,"nodeType":996},{"target":15410},{"sys":15411},{"id":1040,"type":1001,"linkType":1002},[],{"data":15414,"content":15415,"nodeType":1005},{},[],{"data":15417,"content":15418,"nodeType":1009},{},[15419],{"data":15420,"marks":15421,"value":2280,"nodeType":864},{},[15422],{"type":899},{"data":15424,"content":15425,"nodeType":860},{},[15426],{"data":15427,"marks":15428,"value":2287,"nodeType":864},{},[],{"data":15430,"content":15431,"nodeType":1312},{},[15432],{"data":15433,"marks":15434,"value":2295,"nodeType":864},{},[15435],{"type":899},{"data":15437,"content":15438,"nodeType":860},{},[15439],{"data":15440,"marks":15441,"value":2302,"nodeType":864},{},[],{"data":15443,"content":15444,"nodeType":860},{},[15445],{"data":15446,"marks":15447,"value":2309,"nodeType":864},{},[],{"data":15449,"content":15450,"nodeType":860},{},[15451,15454,15458],{"data":15452,"marks":15453,"value":2316,"nodeType":864},{},[],{"data":15455,"marks":15456,"value":2321,"nodeType":864},{},[15457],{"type":899},{"data":15459,"marks":15460,"value":2325,"nodeType":864},{},[],{"data":15462,"content":15463,"nodeType":1312},{},[15464],{"data":15465,"marks":15466,"value":2333,"nodeType":864},{},[15467],{"type":899},{"data":15469,"content":15470,"nodeType":860},{},[15471,15474,15478,15481,15485],{"data":15472,"marks":15473,"value":2340,"nodeType":864},{},[],{"data":15475,"marks":15476,"value":2345,"nodeType":864},{},[15477],{"type":899},{"data":15479,"marks":15480,"value":2349,"nodeType":864},{},[],{"data":15482,"marks":15483,"value":2354,"nodeType":864},{},[15484],{"type":899},{"data":15486,"marks":15487,"value":2358,"nodeType":864},{},[],{"data":15489,"content":15490,"nodeType":860},{},[15491],{"data":15492,"marks":15493,"value":2365,"nodeType":864},{},[],{"data":15495,"content":15498,"nodeType":996},{"target":15496},{"sys":15497},{"id":2370,"type":1001,"linkType":1002},[],{"data":15500,"content":15501,"nodeType":860},{},[15502],{"data":15503,"marks":15504,"value":2378,"nodeType":864},{},[],{"data":15506,"content":15507,"nodeType":1312},{},[15508],{"data":15509,"marks":15510,"value":2386,"nodeType":864},{},[15511],{"type":899},{"data":15513,"content":15514,"nodeType":860},{},[15515,15518,15522],{"data":15516,"marks":15517,"value":2393,"nodeType":864},{},[],{"data":15519,"marks":15520,"value":2228,"nodeType":864},{},[15521],{"type":899},{"data":15523,"marks":15524,"value":2401,"nodeType":864},{},[],{"data":15526,"content":15527,"nodeType":860},{},[15528,15531,15537,15540,15544],{"data":15529,"marks":15530,"value":2408,"nodeType":864},{},[],{"data":15532,"content":15533,"nodeType":883},{"uri":2411},[15534],{"data":15535,"marks":15536,"value":2416,"nodeType":864},{},[],{"data":15538,"marks":15539,"value":2420,"nodeType":864},{},[],{"data":15541,"marks":15542,"value":2425,"nodeType":864},{},[15543],{"type":899},{"data":15545,"marks":15546,"value":2429,"nodeType":864},{},[],{"data":15548,"content":15551,"nodeType":996},{"target":15549},{"sys":15550},{"id":2434,"type":1001,"linkType":1002},[],{"data":15553,"content":15554,"nodeType":860},{},[15555,15558,15564],{"data":15556,"marks":15557,"value":2442,"nodeType":864},{},[],{"data":15559,"content":15560,"nodeType":883},{"uri":2411},[15561],{"data":15562,"marks":15563,"value":2449,"nodeType":864},{},[],{"data":15565,"marks":15566,"value":2453,"nodeType":864},{},[],{"data":15568,"content":15571,"nodeType":996},{"target":15569},{"sys":15570},{"id":2458,"type":1001,"linkType":1002},[],{"data":15573,"content":15574,"nodeType":1312},{},[15575],{"data":15576,"marks":15577,"value":2467,"nodeType":864},{},[15578],{"type":899},{"data":15580,"content":15581,"nodeType":860},{},[15582],{"data":15583,"marks":15584,"value":2474,"nodeType":864},{},[],{"data":15586,"content":15587,"nodeType":860},{},[15588,15591,15595,15598,15602],{"data":15589,"marks":15590,"value":2481,"nodeType":864},{},[],{"data":15592,"marks":15593,"value":2486,"nodeType":864},{},[15594],{"type":899},{"data":15596,"marks":15597,"value":2490,"nodeType":864},{},[],{"data":15599,"marks":15600,"value":2495,"nodeType":864},{},[15601],{"type":2246},{"data":15603,"marks":15604,"value":2499,"nodeType":864},{},[],{"data":15606,"content":15607,"nodeType":860},{},[15608],{"data":15609,"marks":15610,"value":2506,"nodeType":864},{},[],{"data":15612,"content":15613,"nodeType":860},{},[15614],{"data":15615,"marks":15616,"value":2513,"nodeType":864},{},[],{"data":15618,"content":15619,"nodeType":860},{},[15620],{"data":15621,"marks":15622,"value":2520,"nodeType":864},{},[],{"data":15624,"content":15627,"nodeType":996},{"target":15625},{"sys":15626},{"id":2525,"type":1001,"linkType":1002},[],{"data":15629,"content":15630,"nodeType":1005},{},[],{"data":15632,"content":15633,"nodeType":1009},{},[15634],{"data":15635,"marks":15636,"value":2537,"nodeType":864},{},[15637],{"type":899},{"data":15639,"content":15640,"nodeType":860},{},[15641],{"data":15642,"marks":15643,"value":2544,"nodeType":864},{},[],{"data":15645,"content":15646,"nodeType":860},{},[15647],{"data":15648,"marks":15649,"value":2551,"nodeType":864},{},[],{"data":15651,"content":15652,"nodeType":860},{},[15653,15656,15662],{"data":15654,"marks":15655,"value":2558,"nodeType":864},{},[],{"data":15657,"content":15658,"nodeType":883},{"uri":2561},[15659],{"data":15660,"marks":15661,"value":2566,"nodeType":864},{},[],{"data":15663,"marks":15664,"value":2570,"nodeType":864},{},[],{"data":15666,"content":15667,"nodeType":1312},{},[15668],{"data":15669,"marks":15670,"value":2578,"nodeType":864},{},[15671],{"type":899},{"data":15673,"content":15674,"nodeType":860},{},[15675],{"data":15676,"marks":15677,"value":2585,"nodeType":864},{},[],{"data":15679,"content":15680,"nodeType":860},{},[15681],{"data":15682,"marks":15683,"value":2593,"nodeType":864},{},[15684],{"type":899},{"data":15686,"content":15687,"nodeType":860},{},[15688,15692,15695,15701],{"data":15689,"marks":15690,"value":2601,"nodeType":864},{},[15691],{"type":899},{"data":15693,"marks":15694,"value":2605,"nodeType":864},{},[],{"data":15696,"content":15697,"nodeType":883},{"uri":2411},[15698],{"data":15699,"marks":15700,"value":2612,"nodeType":864},{},[],{"data":15702,"marks":15703,"value":2616,"nodeType":864},{},[],{"data":15705,"content":15706,"nodeType":860},{},[15707,15711],{"data":15708,"marks":15709,"value":2624,"nodeType":864},{},[15710],{"type":899},{"data":15712,"marks":15713,"value":2628,"nodeType":864},{},[],{"data":15715,"content":15718,"nodeType":996},{"target":15716},{"sys":15717},{"id":2633,"type":1001,"linkType":1002},[],{"data":15720,"content":15721,"nodeType":1005},{},[],{"data":15723,"content":15724,"nodeType":1009},{},[15725],{"data":15726,"marks":15727,"value":2645,"nodeType":864},{},[15728],{"type":899},{"data":15730,"content":15731,"nodeType":860},{},[15732],{"data":15733,"marks":15734,"value":2652,"nodeType":864},{},[],{"data":15736,"content":15737,"nodeType":860},{},[15738],{"data":15739,"marks":15740,"value":2659,"nodeType":864},{},[],{"data":15742,"content":15743,"nodeType":860},{},[15744],{"data":15745,"marks":15746,"value":2666,"nodeType":864},{},[],{"data":15748,"content":15749,"nodeType":860},{},[15750,15753,15760],{"data":15751,"marks":15752,"value":2673,"nodeType":864},{},[],{"data":15754,"content":15755,"nodeType":883},{"uri":2676},[15756],{"data":15757,"marks":15758,"value":580,"nodeType":864},{},[15759],{"type":1455},{"data":15761,"marks":15762,"value":2685,"nodeType":864},{},[],{"data":15764,"content":15765,"nodeType":1005},{},[],{"data":15767,"content":15768,"nodeType":860},{},[15769],{"data":15770,"marks":15771,"value":1682,"nodeType":864},{},[],{"data":15773,"content":15774,"nodeType":860},{},[15775],{"data":15776,"marks":15777,"value":1689,"nodeType":864},{},[],{"data":15779,"content":15780,"nodeType":860},{},[15781,15784,15791],{"data":15782,"marks":15783,"value":2707,"nodeType":864},{},[],{"data":15785,"content":15786,"nodeType":883},{"uri":1700},[15787],{"data":15788,"marks":15789,"value":2715,"nodeType":864},{},[15790],{"type":1455},{"data":15792,"marks":15793,"value":2719,"nodeType":864},{},[],{"entries":15795},{"hyperlink":15796,"inline":15797,"block":15798},[],[],[15799,15851,15865,15879,15882,15924,15975,15982,16038],{"sys":15800,"__typename":1740,"content":15801,"name":15850,"title":59},{"id":2091},{"json":15802},{"data":15803,"content":15804,"nodeType":856},{},[15805],{"data":15806,"content":15807,"nodeType":860},{},[15808,15812,15819,15823,15828,15832,15841,15845],{"data":15809,"marks":15810,"value":15811,"nodeType":864},{},[],"The industry data backs this up. The ",{"data":15813,"content":15814,"nodeType":883},{"uri":7170},[15815],{"data":15816,"marks":15817,"value":15818,"nodeType":864},{},[],"Verizon DBIR 2026",{"data":15820,"marks":15821,"value":15822,"nodeType":864},{},[]," reports that ",{"data":15824,"marks":15825,"value":15827,"nodeType":864},{},[15826],{"type":899},"45% of employees are now regular AI users on corporate devices",{"data":15829,"marks":15830,"value":15831,"nodeType":864},{},[],", up from 15% the year before. ",{"data":15833,"content":15835,"nodeType":883},{"uri":15834},"https://omdia.tech.informa.com/",[15836],{"data":15837,"marks":15838,"value":15840,"nodeType":864},{},[15839],{"type":1455},"Omdia's 2026 browser security research",{"data":15842,"marks":15843,"value":15844,"nodeType":864},{},[]," presents a stronger picture, finding that 92% allow employees to use public GenAI applications. However, given that the typical company policy sanctions a small number of approved tools, this means everything else employees are using is unsanctioned by default. ",{"data":15846,"marks":15847,"value":15849,"nodeType":864},{},[15848],{"type":899},"In other words: every organization in the survey had unsanctioned AI usage.","shadow ai insight box 1",{"sys":15852,"__typename":1740,"content":15853,"name":15864,"title":59},{"id":2180},{"json":15854},{"nodeType":856,"data":15855,"content":15856},{},[15857],{"nodeType":860,"data":15858,"content":15859},{},[15860],{"nodeType":864,"value":15861,"marks":15862,"data":15863},"An added dimension here is the role of autonomous agents. Unsupervised agents can lead to the introduction of security vulnerabilities and data exposures, while agents themselves can be targeted through new classes of attack like prompt injection. But for the majority of organizations, where most of the workforce is simply using GenAI tools in the browser, agentic security is more of a niche concern for developers. ",[],{},"Shadow AI insight box",{"sys":15866,"__typename":1740,"content":15867,"name":15878,"title":59},{"id":2256},{"json":15868},{"data":15869,"content":15870,"nodeType":856},{},[15871],{"data":15872,"content":15873,"nodeType":860},{},[15874],{"data":15875,"marks":15876,"value":15877,"nodeType":864},{},[],"These are counts of unique products observed in one week, not total installs or connections across the workforce — each unique app, extension, or integration represents a separate AI tool that at least one employee has adopted, so the actual number of individual installs and active sessions across the organization is considerably larger. When the average organization has 17 unique AI extensions deployed, for instance, and many of those are popular tools adopted independently by multiple employees, the per-user footprint adds up quickly.","Shadow ai ib1",{"sys":15880,"__typename":1724,"title":1725,"caption":1726,"layoutMode":59,"file":15881},{"id":1040},{"url":1728,"width":1729,"height":1730},{"sys":15883,"__typename":1740,"content":15884,"name":15923,"title":59},{"id":2370},{"json":15885},{"nodeType":856,"data":15886,"content":15887},{},[15888,15917],{"nodeType":860,"data":15889,"content":15890},{},[15891,15895,15899,15909,15913],{"nodeType":864,"value":15892,"marks":15893,"data":15894},"This is a perfect example of where",[],{},{"nodeType":864,"value":1171,"marks":15896,"data":15898},[15897],{"type":899},{},{"nodeType":883,"data":15900,"content":15902},{"uri":15901},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/evil-twin-integrations",[15903],{"nodeType":864,"value":15904,"marks":15905,"data":15908},"Evil Twin",[15906,15907],{"type":1455},{"type":899},{},{"nodeType":864,"value":1171,"marks":15910,"data":15912},[15911],{"type":899},{},{"nodeType":864,"value":15914,"marks":15915,"data":15916},"opportunities are likely to be abused by attackers. If you’re not familiar, this is where an attacker can effectively hide a malicious integration where an existing connection for that app is already approved, blending in with normal activity. But while historically maybe 1 out of 100 users had an automation tool like Zapier integrated already, the modern equivalent is that a much higher proportion of users already has Claude or ChatGPT integrated.",[],{},{"nodeType":860,"data":15918,"content":15919},{},[15920],{"nodeType":864,"value":21,"marks":15921,"data":15922},[],{},"Shadow ai ib4",{"sys":15925,"__typename":1740,"content":15926,"name":15974,"title":59},{"id":2434},{"json":15927},{"nodeType":856,"data":15928,"content":15929},{},[15930],{"nodeType":860,"data":15931,"content":15932},{},[15933,15937,15948,15952,15962,15965,15970],{"nodeType":864,"value":15934,"marks":15935,"data":15936},"This isn't just a Push observation —",[],{},{"nodeType":883,"data":15938,"content":15939},{"uri":2561},[15940,15943],{"nodeType":864,"value":1171,"marks":15941,"data":15942},[],{},{"nodeType":864,"value":15944,"marks":15945,"data":15947},"Omdia found that malicious browser extensions were cited by 34% of organizations",[15946],{"type":1455},{},{"nodeType":864,"value":15949,"marks":15950,"data":15951}," that experienced a browser-based attack, making them the third most common attack type after phishing and data leakage. The",[],{},{"nodeType":883,"data":15953,"content":15954},{"uri":7170},[15955,15958],{"nodeType":864,"value":1171,"marks":15956,"data":15957},[],{},{"nodeType":864,"value":15818,"marks":15959,"data":15961},[15960],{"type":1455},{},{"nodeType":864,"value":15822,"marks":15963,"data":15964},[],{},{"nodeType":864,"value":15966,"marks":15967,"data":15969},"more than 15% of corporate users had unauthorized AI browser extensions installed",[15968],{"type":899},{},{"nodeType":864,"value":15971,"marks":15972,"data":15973}," — meaning a material share of the workforce is running AI-powered code with broad permissions that no one in security approved or is monitoring. ",[],{},"Shadow ai ib2",{"sys":15976,"__typename":1724,"title":15977,"caption":15978,"layoutMode":59,"file":15979},{"id":2458},"Examples of AI imitation apps","Examples of imitation AI apps observed in active use by Push. Scammy and misleading, but not necessarily malicious (yet), but probably not something you want employees using.",{"url":15980,"width":1736,"height":15981},"https://images.ctfassets.net/y1cdw1ablpvd/73PW50LMkqoFWmsbxP7pIU/a29ed68622aeb453f618fc1eb9a1a55c/image1.png",1189,{"sys":15983,"__typename":1740,"content":15984,"name":16037,"title":59},{"id":2525},{"json":15985},{"nodeType":856,"data":15986,"content":15987},{},[15988,16006],{"nodeType":860,"data":15989,"content":15990},{},[15991,15995,16002],{"nodeType":864,"value":15992,"marks":15993,"data":15994},"The Vercel breach is a textbook illustration of integration risk. A Vercel employee had connected a consumer-grade AI app from Context.ai into their Google Workspace tenant — most likely a self-service trial that was lightly used and forgotten about. Vercel ",[],{},{"nodeType":883,"data":15996,"content":15997},{"uri":4103},[15998],{"nodeType":864,"value":15999,"marks":16000,"data":16001},"wasn't even a registered customer",[],{},{"nodeType":864,"value":16003,"marks":16004,"data":16005}," of Context.ai. When Context.ai was subsequently compromised via an infostealer infection, the attacker leveraged stored OAuth tokens to pivot into the Vercel employee's Google Workspace account, accessing internal dashboards, API keys, NPM tokens, and GitHub tokens.",[],{},{"nodeType":860,"data":16007,"content":16008},{},[16009,16013,16021,16025,16033],{"nodeType":864,"value":16010,"marks":16011,"data":16012},"Vercel is far from an isolated case. In 2025, ",[],{},{"nodeType":883,"data":16014,"content":16016},{"uri":16015},"https://pushsecurity.com/blog/scattered-lapsus-hunters/",[16017],{"nodeType":864,"value":16018,"marks":16019,"data":16020},"Scattered Lapsus$ Hunters",[],{},{"nodeType":864,"value":16022,"marks":16023,"data":16024}," launched OAuth-driven supply chain attacks against Salesforce and Google Workspace tenants after breaching Salesloft Drift and Gainsight, impacting over 1,000 organizations and stealing over 1.5 billion records. More recently, Snowflake customers were impacted after a ",[],{},{"nodeType":883,"data":16026,"content":16028},{"uri":16027},"https://www.bleepingcomputer.com/news/security/snowflake-customers-hit-in-data-theft-attacks-after-saas-integrator-breach/",[16029],{"nodeType":864,"value":16030,"marks":16031,"data":16032},"breach at data anomaly detection company Anodot",[],{},{"nodeType":864,"value":16034,"marks":16035,"data":16036},", where attackers attempted to leverage stolen authentication tokens to access downstream environments.",[],{},"Shadow ai ib3",{"sys":16039,"__typename":1717,"type":1718,"ctaText":16040,"buttonLabel":16041,"buttonColour":1721,"buttonUrl":16042},{"id":2633},"For a step-by-step walkthrough of how to implement these controls, including shadow AI discovery, graduated enforcement, and data loss prevention, see our practical guide to shadow AI visibility and control.","Read Now","pushsecurity.com/blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps",{"items":16044},[16045,16065,16097,16122],{"answer":16046,"question":16064},{"json":16047},{"nodeType":856,"data":16048,"content":16049},{},[16050,16057],{"nodeType":860,"data":16051,"content":16052},{},[16053],{"nodeType":864,"value":16054,"marks":16055,"data":16056},"Shadow IT management has a well-established playbook: discover unauthorized apps through CASB logs or network monitoring, enforce SSO to bring them under identity governance, and apply block/allow decisions at the proxy or firewall. That playbook assumes the tool is a discrete app that employees signed up for, that it's reachable through the network layer, and that the main risk is ungoverned data storage. ",[],{},{"nodeType":860,"data":16058,"content":16059},{},[16060],{"nodeType":864,"value":16061,"marks":16062,"data":16063},"Shadow AI breaks all three assumptions. AI doesn't just store data — it actively processes it, and employees submit qualitatively more sensitive material (source code, credentials, internal strategy) into AI prompts than they typically put into a project management tool or file-sharing app. AI also arrives embedded inside tools you've already approved — Salesforce, Google Workspace, Notion, Slack all ship AI features that activate without a separate procurement decision, so there's no sign-up event for a CASB to catch. And the integration surface is different: AI tools connect to other enterprise apps through OAuth grants and MCP connections that create persistent API-level access, turning each one into a potential pivot point across your SaaS estate. This level of AI integration dwarfs typical SaaS-to-SaaS interconnectivity, and what an agent can do with the data in a given app is typically much more permissive and way less predictable. ",[],{},"How is shadow AI different from regular shadow IT or shadow SaaS?",{"answer":16066,"question":16096},{"json":16067},{"nodeType":856,"data":16068,"content":16069},{},[16070,16077],{"nodeType":860,"data":16071,"content":16072},{},[16073],{"nodeType":864,"value":16074,"marks":16075,"data":16076},"When an employee uses a personal ChatGPT, Gemini, or Claude account to do work, everything they submit — prompts, file uploads, pasted code — goes to an environment your organization has no governance over. There are no data retention controls, no audit trail, no DLP policies, and no way to revoke access if that employee leaves. The Verizon DBIR found 67% of GenAI users on corporate devices use non-corporate accounts, and Push data shows 38% of file uploads to AI tools come from these shadow accounts rather than approved organizational ones. The risk isn't hypothetical usage of a banned tool — it's real work happening on the same tool you approved, just on an account you can't see or control.",[],{},{"nodeType":860,"data":16078,"content":16079},{},[16080,16084,16092],{"nodeType":864,"value":16081,"marks":16082,"data":16083},"It's even worse if that employee has been tricked into joining an external tenant (",[],{},{"nodeType":883,"data":16085,"content":16087},{"uri":16086},"https://pushsecurity.com/blog/openai-poisoned-tenant-attack",[16088],{"nodeType":864,"value":16089,"marks":16090,"data":16091},"as attackers tried to trick Push employees into doing recently",[],{},{"nodeType":864,"value":16093,"marks":16094,"data":16095},") where your data flows directly into the hands of a malicious outsider. ",[],{},"What's the risk if employees use personal AI accounts for work?",{"answer":16098,"question":16121},{"json":16099},{"nodeType":856,"data":16100,"content":16101},{},[16102],{"nodeType":860,"data":16103,"content":16104},{},[16105,16109,16117],{"nodeType":864,"value":16106,"marks":16107,"data":16108},"Yes, and this is one of the less visible risks of shadow AI. Many AI tools request OAuth permissions to connect to Google Workspace, Microsoft 365, Slack, or code repositories during setup — a \"Connect to Google Drive\" or \"Sign in with Microsoft\" flow that grants persistent API-level access to data in those systems. Unlike a browser session that expires, these tokens survive password resets and MFA changes, and they often have broader scope than users realize (shared drives, shared calendars, any collaborative resource the consenting user can reach). The ",[],{},{"nodeType":883,"data":16110,"content":16112},{"uri":16111},"https://pushsecurity.com/blog/unpacking-the-vercel-breach",[16113],{"nodeType":864,"value":16114,"marks":16115,"data":16116},"Vercel breach",[],{},{"nodeType":864,"value":16118,"marks":16119,"data":16120}," showed what happens when one of these goes wrong: a single forgotten OAuth integration from a consumer AI app gave attackers a path into internal dashboards, API keys, and source code repositories.",[],{},"Can AI tools access my other enterprise apps?",{"answer":16123,"question":16141},{"json":16124},{"nodeType":856,"data":16125,"content":16126},{},[16127,16134],{"nodeType":860,"data":16128,"content":16129},{},[16130],{"nodeType":864,"value":16131,"marks":16132,"data":16133},"MCP (Model Context Protocol) connections let AI tools interact with other applications — reading files, querying databases, triggering workflows — through a standardized interface. Approving an MCP connection grants the AI tool persistent access to whatever systems the MCP server exposes, and that access operates at the API layer rather than through the browser session you're used to controlling. ",[],{},{"nodeType":860,"data":16135,"content":16136},{},[16137],{"nodeType":864,"value":16138,"marks":16139,"data":16140},"The risk is similar to OAuth but often broader in scope: a single MCP connection to a code repository or project management tool can give the AI agent read and write access across that system, and if the AI tool or MCP server is compromised, those permissions become the attacker's permissions. Unlike a browser session, MCP tokens persist until explicitly revoked, and compromising one AI agent that's connected to multiple MCP servers yields tokens for every service it was connected to.",[],{},"What's the risk if I approve an MCP connection?","Shadow AI: Frequently asked questions",{},"Shadow AI: the numbers behind each type of shadow AI",{"items":16146},[16147,16912,17993],{"__typename":2059,"sys":16148,"content":16150,"title":16898,"synopsis":16899,"hashTags":59,"publishedDate":16900,"slug":16901,"tagsCollection":16902,"authorsCollection":16908},{"id":16149},"Lq2AFQ8VG2rMEe4h2CYuH",{"json":16151},{"data":16152,"content":16153,"nodeType":856},{},[16154,16181,16214,16221,16227,16230,16238,16245,16251,16270,16277,16285,16305,16321,16328,16335,16338,16346,16353,16360,16423,16430,16438,16450,16457,16464,16470,16478,16485,16492,16499,16506,16512,16520,16527,16611,16617,16620,16628,16635,16651,16658,16665,16671,16690,16693,16700,16707,16713,16731,16738,16745,16751,16754,16761,16768,16775,16781,16788,16794,16800,16825,16831,16843,16850,16857],{"data":16155,"content":16156,"nodeType":860},{},[16157,16161,16169,16173,16178],{"data":16158,"marks":16159,"value":16160,"nodeType":864},{},[],"This week, a user going by the name of “ShinyHunters” (though allegedly not ",{"data":16162,"content":16163,"nodeType":883},{"uri":16015},[16164],{"data":16165,"marks":16166,"value":16168,"nodeType":864},{},[16167],{"type":1455},"actual ShinyHunters",{"data":16170,"marks":16171,"value":16172,"nodeType":864},{},[],", but someone imitating them in an attempt to trade off their credibility) posted on a breach forum claiming access keys, source code, and database data stolen from cloud development platform provider ",{"data":16174,"marks":16175,"value":16177,"nodeType":864},{},[16176],{"type":899},"Vercel",{"data":16179,"marks":16180,"value":11546,"nodeType":864},{},[],{"data":16182,"content":16183,"nodeType":860},{},[16184,16188,16197,16201,16210],{"data":16185,"marks":16186,"value":16187,"nodeType":864},{},[],"This happened because a Vercel employee had connected an AI app, Context.ai, into their Google Workspace tenant. When Context.ai was compromised — ",{"data":16189,"content":16191,"nodeType":883},{"uri":16190},"https://www.infostealers.com/article/breaking-vercel-breach-linked-to-infostealer-infection-at-context-ai/",[16192],{"data":16193,"marks":16194,"value":16196,"nodeType":864},{},[16195],{"type":1455},"allegedly the result of an infostealer infection from an employee searching for Roblox cheats",{"data":16198,"marks":16199,"value":16200,"nodeType":864},{},[]," — the attacker was able to leverage OAuth tokens stored in Context.ai’s Supabase platform to access downstream customer accounts (pointing to a heavily permissioned victim, probably a developer, possibly even a ",{"data":16202,"content":16204,"nodeType":883},{"uri":16203},"https://pushsecurity.com/blog/browser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches/",[16205],{"data":16206,"marks":16207,"value":16209,"nodeType":864},{},[16208],{"type":1455},"personal device with access to corp credentials",{"data":16211,"marks":16212,"value":16213,"nodeType":864},{},[],"). ",{"data":16215,"content":16216,"nodeType":860},{},[16217],{"data":16218,"marks":16219,"value":16220,"nodeType":864},{},[],"This access included a Vercel employee’s Google Workspace account. This particular user had significant access to data and secrets in Vercel’s systems, including internal dashboards, employee records, API keys, NPM tokens, and GitHub tokens, which the attacker was able to exfiltrate, holding Vercel to ransom for $2 million. ",{"data":16222,"content":16226,"nodeType":996},{"target":16223},{"sys":16224},{"id":16225,"type":1001,"linkType":1002},"6Ft8aSnzfYVZ7j57mYeXgQ",[],{"data":16228,"content":16229,"nodeType":1005},{},[],{"data":16231,"content":16232,"nodeType":1009},{},[16233],{"data":16234,"marks":16235,"value":16237,"nodeType":864},{},[16236],{"type":899},"How did this happen, and what could have stopped it?",{"data":16239,"content":16240,"nodeType":860},{},[16241],{"data":16242,"marks":16243,"value":16244,"nodeType":864},{},[],"From Vercel’s perspective, this attack could have been avoided had their employees been blocked from adding new OAuth integrations without admin approval (a toggle in their Google admin panel, and an essential control in a well-configured environment). Or, if the integration had been flagged in a routine audit and removed. ",{"data":16246,"content":16250,"nodeType":996},{"target":16247},{"sys":16248},{"id":16249,"type":1001,"linkType":1002},"b5HFvY1m6RnuXL3a95jVt",[],{"data":16252,"content":16253,"nodeType":860},{},[16254,16258,16266],{"data":16255,"marks":16256,"value":16257,"nodeType":864},{},[],"It probably should have been removed, too. The particular OAuth app that was connected into the environment was a deprecated “AI Office Suite” product intended for consumer use. ",{"data":16259,"content":16261,"nodeType":883},{"uri":16260},"https://context.ai/security-update",[16262],{"data":16263,"marks":16264,"value":16265,"nodeType":864},{},[],"According to Context.ai",{"data":16267,"marks":16268,"value":16269,"nodeType":864},{},[],", Vercel aren’t even a registered customer — adding more evidence that this was probably the result of a self-service trial that was subsequently forgotten about. That consumer product has also since been replaced by an enterprise product. But for whatever reason, the access hadn’t been revoked (from either side). ",{"data":16271,"content":16272,"nodeType":860},{},[16273],{"data":16274,"marks":16275,"value":16276,"nodeType":864},{},[],"The elephant in the room is that Context.ai is an AI app. Most organizations are rightly nervous about employees adding unapproved AI SaaS into their environment. Having employees use shadow AI in the form of LLMs is one thing — users uploading sensitive data to unapproved apps or external tenants being the key concern. But OAuth grants are even more dangerous. Because if that app or vendor is compromised, the apps and accounts you’ve integrated it with are also at risk — which is what was exploited here. ",{"data":16278,"content":16279,"nodeType":1312},{},[16280],{"data":16281,"marks":16282,"value":16284,"nodeType":864},{},[16283],{"type":899},"Where’s the fault?",{"data":16286,"content":16287,"nodeType":860},{},[16288,16292,16301],{"data":16289,"marks":16290,"value":16291,"nodeType":864},{},[],"It’s easy to point fingers here. There are multiple control gaps and failures for both parties. Vercel should have disabled OAuth grants without admin approval, and regularly audited the connections in their environment. From a vendor's perspective, they could have also default applied a control that ",{"data":16293,"content":16295,"nodeType":883},{"uri":16294},"https://vercel.com/kb/bulletin/vercel-april-2026-security-incident",[16296],{"data":16297,"marks":16298,"value":16300,"nodeType":864},{},[16299],{"type":1455},"prevents secret environment variables from being read",{"data":16302,"marks":16303,"value":16304,"nodeType":864},{},[]," — which would have significantly reduced the impact to Vercel customers from the data breach. ",{"data":16306,"content":16307,"nodeType":860},{},[16308,16312,16317],{"data":16309,"marks":16310,"value":16311,"nodeType":864},{},[],"Context.ai comes off worse. They could and should have had better separation of accounts and privileges — and if true, their users really shouldn’t be downloading Roblox scripts on devices they use for work access. It’s important to say ",{"data":16313,"marks":16314,"value":16316,"nodeType":864},{},[16315],{"type":2246},"if true",{"data":16318,"marks":16319,"value":16320,"nodeType":864},{},[]," here, but the prospect of third parties accessing your environment from insecure devices that they use for gaming is the stuff of nightmares for enterprise security and compliance teams.",{"data":16322,"content":16323,"nodeType":860},{},[16324],{"data":16325,"marks":16326,"value":16327,"nodeType":864},{},[],"You definitely don’t want to be Context.ai in this scenario. The reputational harm could be pretty significant, and is a wake-up call for other SaaS vendors to check that their house is in order. But although Vercel have responded quickly and transparently to the incident, this could only really have happened as a result of technical and procedural control gaps on their end.",{"data":16329,"content":16330,"nodeType":860},{},[16331],{"data":16332,"marks":16333,"value":16334,"nodeType":864},{},[],"It’s worth taking a step back and looking at the bigger picture here — and how these issues might impact your organization too. ",{"data":16336,"content":16337,"nodeType":1005},{},[],{"data":16339,"content":16340,"nodeType":1009},{},[16341],{"data":16342,"marks":16343,"value":16345,"nodeType":864},{},[16344],{"type":899},"Shadow AI is still just shadow SaaS – but the AI scramble is a force multiplier",{"data":16347,"content":16348,"nodeType":860},{},[16349],{"data":16350,"marks":16351,"value":16352,"nodeType":864},{},[],"Shadow IT, and in particular shadow SaaS, is not a new problem. Most organizations run heavily (or exclusively) on SaaS, accessed in the browser, with hundreds of apps per enterprise. Unmanaged, self-adopted apps have been a thorn in the side of security teams for some time. ",{"data":16354,"content":16355,"nodeType":860},{},[16356],{"data":16357,"marks":16358,"value":16359,"nodeType":864},{},[],"There are essentially four kinds of shadow IT to be wary of in the context of AI apps:",{"data":16361,"content":16362,"nodeType":941},{},[16363,16378,16393,16408],{"data":16364,"content":16365,"nodeType":945},{},[16366],{"data":16367,"content":16368,"nodeType":860},{},[16369,16374],{"data":16370,"marks":16371,"value":16373,"nodeType":864},{},[16372],{"type":899},"Shadow apps:",{"data":16375,"marks":16376,"value":16377,"nodeType":864},{},[]," Apps that employees have signed up to and are using for business purposes without business approval. This includes apps signed up to with a corporate account or personal account. ",{"data":16379,"content":16380,"nodeType":945},{},[16381],{"data":16382,"content":16383,"nodeType":860},{},[16384,16389],{"data":16385,"marks":16386,"value":16388,"nodeType":864},{},[16387],{"type":899},"Shadow tenants:",{"data":16390,"marks":16391,"value":16392,"nodeType":864},{},[]," Apps that employees are accessing with personal accounts, essentially creating shadow tenants outside of your organization’s control — even if you’ve approved the app itself.",{"data":16394,"content":16395,"nodeType":945},{},[16396],{"data":16397,"content":16398,"nodeType":860},{},[16399,16404],{"data":16400,"marks":16401,"value":16403,"nodeType":864},{},[16402],{"type":899},"Shadow extensions:",{"data":16405,"marks":16406,"value":16407,"nodeType":864},{},[]," Many AI apps come with an extension counterpart, along with countless third-party extensions that are either untrustworthy or downright malicious. Browser extensions add another angle to the equation by presenting visibility beyond the application into browser activity. ",{"data":16409,"content":16410,"nodeType":945},{},[16411],{"data":16412,"content":16413,"nodeType":860},{},[16414,16419],{"data":16415,"marks":16416,"value":16418,"nodeType":864},{},[16417],{"type":899},"Shadow integrations:",{"data":16420,"marks":16421,"value":16422,"nodeType":864},{},[]," OAuth connections across apps that aren’t known or approved. Even if an app itself is approved, plugging that app directly into your primary enterprise apps — with all the sensitive data and functionality therein — isn't necessarily also approved.  ",{"data":16424,"content":16425,"nodeType":860},{},[16426],{"data":16427,"marks":16428,"value":16429,"nodeType":864},{},[],"In the Vercel case, we’re talking specifically about shadow integrations. But all of these present a key risk to your organization. ",{"data":16431,"content":16432,"nodeType":1312},{},[16433],{"data":16434,"marks":16435,"value":16437,"nodeType":864},{},[16436],{"type":899},"The web of OAuth sprawl spans way beyond Google and Microsoft ",{"data":16439,"content":16440,"nodeType":860},{},[16441,16446],{"data":16442,"marks":16443,"value":16445,"nodeType":864},{},[16444],{"type":899},"On average we see 17 unique AI app integrations per organization in Microsoft and Google alone",{"data":16447,"marks":16448,"value":16449,"nodeType":864},{},[],". If you consider that most organizations have probably approved 1 or 2 max for business use, and may have approved none at all for app-to-app OAuth connectivity, that’s quite a significant difference. ",{"data":16451,"content":16452,"nodeType":860},{},[16453],{"data":16454,"marks":16455,"value":16456,"nodeType":864},{},[],"The number of connections outside of these core platforms is significantly higher. Just think how the typical AI app operates. If you want it to be able to effectively automate workflows — pull data from one app, aggregate and analyze it in another, present that information in a report, dashboard, or presentation, and then distribute it — that’s a fair few integrations in just one workflow. MCP connections use OAuth to achieve this interconnectivity in the same way as any other SaaS app.",{"data":16458,"content":16459,"nodeType":860},{},[16460],{"data":16461,"marks":16462,"value":16463,"nodeType":864},{},[],"We used to talk about automation apps like Zapier as being a goldmine for attackers. Well, AI apps are on their way to being even more interconnected, more frequently used, and more flexible in terms of how attackers can abuse them. ",{"data":16465,"content":16469,"nodeType":996},{"target":16466},{"sys":16467},{"id":16468,"type":1001,"linkType":1002},"4FiWyVw7mpVBA5uBVJoOKL",[],{"data":16471,"content":16472,"nodeType":1312},{},[16473],{"data":16474,"marks":16475,"value":16477,"nodeType":864},{},[16476],{"type":899},"A note on OAuth configuration complexity",{"data":16479,"content":16480,"nodeType":860},{},[16481],{"data":16482,"marks":16483,"value":16484,"nodeType":864},{},[],"A common misconception is that when a regular user consents to an OAuth app (let's use Google Workspace as the example) the app only gets access to the things they can directly access. Technically that's true — the access is scoped to that user's permissions. But in practice, the blast radius is almost always bigger than people think.",{"data":16486,"content":16487,"nodeType":860},{},[16488],{"data":16489,"marks":16490,"value":16491,"nodeType":864},{},[],"The scope includes shared drives, shared calendars, documents shared with them, and any other collaborative resources. A single well-permissioned user (think: developer with access to secrets, dashboards, and internal tooling) is more than enough to cause serious damage through a single OAuth grant. ",{"data":16493,"content":16494,"nodeType":860},{},[16495],{"data":16496,"marks":16497,"value":16498,"nodeType":864},{},[],"The scopes themselves are often deceptively broad. An app requesting https://www.googleapis.com/auth/drive gets full read/write access to everything the user can see in Drive — not just their personal files. And the blast radius is further contingent on the data and user permission hygiene in these broader environments. ",{"data":16500,"content":16501,"nodeType":860},{},[16502],{"data":16503,"marks":16504,"value":16505,"nodeType":864},{},[],"So if your environment hasn't got cleanly separated access and permissions for different users and groups, an attacker compromising a \"normal\" user account can end up with extensive access. You don't need tenant-wide admin access when a normal user's access already spans the crown jewels.",{"data":16507,"content":16511,"nodeType":996},{"target":16508},{"sys":16509},{"id":16510,"type":1001,"linkType":1002},"2t81AnAHx2On3fBynM4vVe",[],{"data":16513,"content":16514,"nodeType":1312},{},[16515],{"data":16516,"marks":16517,"value":16519,"nodeType":864},{},[16518],{"type":899},"Unsurprisingly, OAuth breaches are stacking up",{"data":16521,"content":16522,"nodeType":860},{},[16523],{"data":16524,"marks":16525,"value":16526,"nodeType":864},{},[],"Widespread OAuth interconnectedness isn’t just an AI app problem. Attackers have been exploiting this for some time:",{"data":16528,"content":16529,"nodeType":941},{},[16530,16577],{"data":16531,"content":16532,"nodeType":945},{},[16533],{"data":16534,"content":16535,"nodeType":860},{},[16536,16540,16547,16551,16560,16564,16573],{"data":16537,"marks":16538,"value":16539,"nodeType":864},{},[],"In 2025, ",{"data":16541,"content":16542,"nodeType":883},{"uri":16015},[16543],{"data":16544,"marks":16545,"value":16018,"nodeType":864},{},[16546],{"type":1455},{"data":16548,"marks":16549,"value":16550,"nodeType":864},{},[]," launched OAuth-driven supply chain attacks against Salesforce and Google Workspace tenants after breaching Salesloft (specifically the ",{"data":16552,"content":16554,"nodeType":883},{"uri":16553},"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/",[16555],{"data":16556,"marks":16557,"value":16559,"nodeType":864},{},[16558],{"type":1455},"Salesloft Drift",{"data":16561,"marks":16562,"value":16563,"nodeType":864},{},[]," platform) and ",{"data":16565,"content":16567,"nodeType":883},{"uri":16566},"https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/",[16568],{"data":16569,"marks":16570,"value":16572,"nodeType":864},{},[16571],{"type":1455},"Gainsight",{"data":16574,"marks":16575,"value":16576,"nodeType":864},{},[],". In total, over 1000 organizations were impacted, including Google, Cloudflare, Rubrik, Elastic, Proofpoint, JFrog, Zscaler, Tenable, Palo Alto Networks, CyberArk, BeyondTrust, Qualys, and many more, with over 1.5B records stolen. ",{"data":16578,"content":16579,"nodeType":945},{},[16580],{"data":16581,"content":16582,"nodeType":860},{},[16583,16587,16594,16598,16607],{"data":16584,"marks":16585,"value":16586,"nodeType":864},{},[],"More recently, Snowflake customers were impacted after a ",{"data":16588,"content":16589,"nodeType":883},{"uri":16027},[16590],{"data":16591,"marks":16592,"value":16030,"nodeType":864},{},[16593],{"type":1455},{"data":16595,"marks":16596,"value":16597,"nodeType":864},{},[]," where the attacker attempted to leverage the stolen authentication tokens to access Salesforce data, with ",{"data":16599,"content":16601,"nodeType":883},{"uri":16600},"https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/",[16602],{"data":16603,"marks":16604,"value":16606,"nodeType":864},{},[16605],{"type":1455},"Rockstar",{"data":16608,"marks":16609,"value":16610,"nodeType":864},{},[]," a high-profile victim of the breach (again linked to Scattered Lapsus$ Hunters). ",{"data":16612,"content":16616,"nodeType":996},{"target":16613},{"sys":16614},{"id":16615,"type":1001,"linkType":1002},"3oqoL9L3fxetFcIhnfQhMQ",[],{"data":16618,"content":16619,"nodeType":1005},{},[],{"data":16621,"content":16622,"nodeType":1009},{},[16623],{"data":16624,"marks":16625,"value":16627,"nodeType":864},{},[16626],{"type":899},"Infostealers continue to drive corporate breaches",{"data":16629,"content":16630,"nodeType":860},{},[16631],{"data":16632,"marks":16633,"value":16634,"nodeType":864},{},[],"While unverified, Hudson Rock’s case for an infostealer breach being the root cause of the Context.ai breach seems believable. Infostealer infections have been one of the leading security threats for some time, fuelling breaches powered by stolen credentials and session tokens.",{"data":16636,"content":16637,"nodeType":860},{},[16638,16642,16647],{"data":16639,"marks":16640,"value":16641,"nodeType":864},{},[],"With the assumed rise in MFA coverage, it’s often surprising to security teams that stolen credentials are still a problem. ",{"data":16643,"marks":16644,"value":16646,"nodeType":864},{},[16645],{"type":899},"But of the last million logins we saw, 1 in 4 were password logins (not SSO), 2 in 5 were not protected by MFA, and 1 in 5 used a weak, breached, or reused password. ",{"data":16648,"marks":16649,"value":16650,"nodeType":864},{},[],"Plenty of scope for abuse. ",{"data":16652,"content":16653,"nodeType":860},{},[16654],{"data":16655,"marks":16656,"value":16657,"nodeType":864},{},[],"Stolen session tokens are even more valuable to attackers, enabling them to bypass authentication controls by replaying the token in their own browser. In theory, they should only be valid for a limited timeframe, but in practice this can be as many as 90 days, and sometimes indefinite. ",{"data":16659,"content":16660,"nodeType":860},{},[16661],{"data":16662,"marks":16663,"value":16664,"nodeType":864},{},[],"In this case, it seems likely that the compromised device was a developer machine (given the access to Supabase), or potentially even a personal device (given they were installing Roblox cheats…). This is relevant because these personal, developer, and BYOD machines are often less secure — developer machines are often exempt from EDR monitoring or significantly tuned-down (too noisy), while personal devices naturally lack enterprise security software.",{"data":16666,"content":16670,"nodeType":996},{"target":16667},{"sys":16668},{"id":16669,"type":1001,"linkType":1002},"139oaGgwRKZbwJzyex9LA5",[],{"data":16672,"content":16673,"nodeType":860},{},[16674,16678,16686],{"data":16675,"marks":16676,"value":16677,"nodeType":864},{},[],"We’ve also seen an uptick in developer-oriented phishing and malvertising campaigns. The ",{"data":16679,"content":16680,"nodeType":883},{"uri":11738},[16681],{"data":16682,"marks":16683,"value":16685,"nodeType":864},{},[16684],{"type":1455},"InstallFix campaign",{"data":16687,"marks":16688,"value":16689,"nodeType":864},{},[]," we identified, intercepting users as they attempt to install AI tools like Claude Code and NotebookLM, is an example of this — and also another way that attackers are capitalizing on AI hype. ",{"data":16691,"content":16692,"nodeType":1005},{},[],{"data":16694,"content":16695,"nodeType":1009},{},[16696],{"data":16697,"marks":16698,"value":2578,"nodeType":864},{},[16699],{"type":899},{"data":16701,"content":16702,"nodeType":860},{},[16703],{"data":16704,"marks":16705,"value":16706,"nodeType":864},{},[],"There are some immediate next steps that we’ll quickly summarize here, as they've already been covered in wider reporting. If you’re a Vercel customer, you should urgently rotate every credential stored as a non-sensitive variable that could have been exposed, enable the sensitive variable feature toggle, and monitor your account for anomalous activity. And if you’re using the specific Context.ai integration, you need to revoke it ASAP and begin a full audit of the connected accounts, both inside Workspace and broader connected apps (this isn’t that easy, as we’ll highlight in a moment). ",{"data":16708,"content":16712,"nodeType":996},{"target":16709},{"sys":16710},{"id":16711,"type":1001,"linkType":1002},"76HViirkH2R4QAzWg605sv",[],{"data":16714,"content":16715,"nodeType":860},{},[16716,16720,16728],{"data":16717,"marks":16718,"value":16719,"nodeType":864},{},[],"Taking a step back, organizations really need to get their arms around OAuth integrations in their environment. A default-deny approach to allowing users to consent to new integrations, and routinely auditing the ones already in your environment to ensure they’re still definitely required, is essential. Each integration expands your attack surface and could potentially grant an attacker extensive access to your environment. This default-deny approach isn't exactly a new concept for security teams and is the same in principle as what we recently advised for ",{"data":16721,"content":16722,"nodeType":883},{"uri":11825},[16723],{"data":16724,"marks":16725,"value":16727,"nodeType":864},{},[16726],{"type":1455},"browser extension management",{"data":16729,"marks":16730,"value":11546,"nodeType":864},{},[],{"data":16732,"content":16733,"nodeType":860},{},[16734],{"data":16735,"marks":16736,"value":16737,"nodeType":864},{},[],"This is fairly straightforward in your main enterprise cloud environment (think M365 or Google Workspace). But doing it across every SaaS app that allows some level of OAuth integration with another (i.e. every SaaS app) is somewhat harder. Not only do you need to have a comprehensive and up-to-date inventory, you need to be an app admin for every app (not always the case for self-adopted apps) and the particular app needs to give you the control to restrict and remove OAuth grants on behalf of users in your tenant. ",{"data":16739,"content":16740,"nodeType":860},{},[16741],{"data":16742,"marks":16743,"value":16744,"nodeType":864},{},[],"Again, this is not exclusively a Shadow AI problem, even if AI adoption is contributing significantly to the sprawl. ",{"data":16746,"content":16750,"nodeType":996},{"target":16747},{"sys":16748},{"id":16749,"type":1001,"linkType":1002},"XKKHUiz56G82uwYhbv2Qv",[],{"data":16752,"content":16753,"nodeType":1005},{},[],{"data":16755,"content":16756,"nodeType":1009},{},[16757],{"data":16758,"marks":16759,"value":7533,"nodeType":864},{},[16760],{"type":899},{"data":16762,"content":16763,"nodeType":860},{},[16764],{"data":16765,"marks":16766,"value":16767,"nodeType":864},{},[],"As we’ve established, there are quite a few pieces to this puzzle. Push can help with all of them. ",{"data":16769,"content":16770,"nodeType":860},{},[16771],{"data":16772,"marks":16773,"value":16774,"nodeType":864},{},[],"Push observes every app login your employees make in their browser, building a comprehensive picture of SaaS and AI use across your organization. This includes how they’re logging in and how secure the login is: did it have MFA, what kind of MFA, was it using a weak or compromised password, did they use SSO, and so on. ",{"data":16776,"content":16780,"nodeType":996},{"target":16777},{"sys":16778},{"id":16779,"type":1001,"linkType":1002},"2B205bUaLm6vG8mIQ0rJvA",[],{"data":16782,"content":16783,"nodeType":860},{},[16784],{"data":16785,"marks":16786,"value":16787,"nodeType":864},{},[],"Push also tracks OAuth integrations in your environment and gives you the ability to manage and remove them in core environments like M365 and Google Workspace, providing a single platform for you to view, manage, and secure app use across your organization. ",{"data":16789,"content":16793,"nodeType":996},{"target":16790},{"sys":16791},{"id":16792,"type":1001,"linkType":1002},"eEbdBUfyzZsdIOjFOXHpM",[],{"data":16795,"content":16799,"nodeType":996},{"target":16796},{"sys":16797},{"id":16798,"type":1001,"linkType":1002},"1MTFxfROuGKxnkHQwWHe8K",[],{"data":16801,"content":16802,"nodeType":860},{},[16803,16807,16812,16816,16821],{"data":16804,"marks":16805,"value":16806,"nodeType":864},{},[],"This makes it easy to surface both vulnerabilities and possible control gaps, and do something about them. But where Push really excels is in the ability to observe and block OAuth connection requests ",{"data":16808,"marks":16809,"value":16811,"nodeType":864},{},[16810],{"type":899},"even outside of your primary enterprise apps.",{"data":16813,"marks":16814,"value":16815,"nodeType":864},{},[]," Using Push, you can detect and block OAuth integration requests as they traverse the browser. This ",{"data":16817,"marks":16818,"value":16820,"nodeType":864},{},[16819],{"type":899},"app-agnostic",{"data":16822,"marks":16823,"value":16824,"nodeType":864},{},[]," level of control is absolutely critical to halting OAuth integration sprawl. ",{"data":16826,"content":16830,"nodeType":996},{"target":16827},{"sys":16828},{"id":16829,"type":1001,"linkType":1002},"2VZ4uw6MXslXME2ueydGuT",[],{"data":16832,"content":16833,"nodeType":1312},{},[16834,16838],{"data":16835,"marks":16836,"value":16837,"nodeType":864},{},[],"And t",{"data":16839,"marks":16840,"value":16842,"nodeType":864},{},[16841],{"type":899},"hat’s not all …",{"data":16844,"content":16845,"nodeType":860},{},[16846],{"data":16847,"marks":16848,"value":16849,"nodeType":864},{},[],"Push’s browser-based security platform also detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, device code phishing, ClickFix, and session hijacking in real time. This includes the most prominent infostealer delivery vectors in terms of malvertising and *Fix-style attacks. Push analyzes every web page in every browser session and tab for threats, in real time, with no latency. ",{"data":16851,"content":16852,"nodeType":860},{},[16853],{"data":16854,"marks":16855,"value":16856,"nodeType":864},{},[],"But as we've established, you don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your attack surface.",{"data":16858,"content":16859,"nodeType":860},{},[16860,16864,16872,16875,16884,16888,16895],{"data":16861,"marks":16862,"value":16863,"nodeType":864},{},[],"To learn more about Push, ",{"data":16865,"content":16867,"nodeType":883},{"uri":16866},"https://pushsecurity.com/resources/product-brochure",[16868],{"data":16869,"marks":16870,"value":16871,"nodeType":864},{},[],"check out our latest product overview",{"data":16873,"marks":16874,"value":3731,"nodeType":864},{},[],{"data":16876,"content":16878,"nodeType":883},{"uri":16877},"https://pushsecurity.com/product-demo/",[16879],{"data":16880,"marks":16881,"value":16883,"nodeType":864},{},[16882],{"type":1455},"view our demo library",{"data":16885,"marks":16886,"value":16887,"nodeType":864},{},[],", or ",{"data":16889,"content":16890,"nodeType":883},{"uri":1700},[16891],{"data":16892,"marks":16893,"value":16894,"nodeType":864},{},[],"book some time with one of our team for a live demo",{"data":16896,"marks":16897,"value":2924,"nodeType":864},{},[],"Unpacking the Vercel breach: A cautionary tale for Shadow AI and OAuth sprawl","In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider.","2026-04-23T00:00:00.000Z","unpacking-the-vercel-breach",{"items":16903},[16904,16906],{"sys":16905,"name":13779},{"id":13778},{"sys":16907,"name":342},{"id":13775},{"items":16909},[16910],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":16911},{"url":2740},{"__typename":2059,"sys":16913,"content":16914,"title":4865,"synopsis":4866,"hashTags":59,"publishedDate":4867,"slug":4868,"tagsCollection":17983,"authorsCollection":17989},{"id":3628},{"json":16915},{"data":16916,"content":16917,"nodeType":856},{},[16918,16931,16936,16942,16948,16953,16956,16963,16970,16985,17023,17028,17041,17044,17051,17058,17080,17112,17118,17121,17128,17135,17141,17146,17152,17155,17162,17169,17203,17233,17239,17242,17249,17256,17276,17282,17321,17327,17330,17337,17344,17380,17386,17391,17394,17401,17408,17434,17440,17445,17451,17454,17461,17468,17491,17497,17503,17509,17512,17519,17526,17532,17537,17543,17564,17587,17590,17597,17604,17610,17616,17619,17626,17681,17684,17691,17697,17965,17968],{"data":16919,"content":16920,"nodeType":860},{},[16921,16924,16928],{"data":16922,"marks":16923,"value":3639,"nodeType":864},{},[],{"data":16925,"marks":16926,"value":3644,"nodeType":864},{},[16927],{"type":899},{"data":16929,"marks":16930,"value":3648,"nodeType":864},{},[],{"data":16932,"content":16935,"nodeType":996},{"target":16933},{"sys":16934},{"id":3653,"type":1001,"linkType":1002},[],{"data":16937,"content":16938,"nodeType":860},{},[16939],{"data":16940,"marks":16941,"value":3661,"nodeType":864},{},[],{"data":16943,"content":16944,"nodeType":860},{},[16945],{"data":16946,"marks":16947,"value":3668,"nodeType":864},{},[],{"data":16949,"content":16952,"nodeType":996},{"target":16950},{"sys":16951},{"id":3673,"type":1001,"linkType":1002},[],{"data":16954,"content":16955,"nodeType":1005},{},[],{"data":16957,"content":16958,"nodeType":1009},{},[16959],{"data":16960,"marks":16961,"value":3685,"nodeType":864},{},[16962],{"type":899},{"data":16964,"content":16965,"nodeType":860},{},[16966],{"data":16967,"marks":16968,"value":3693,"nodeType":864},{},[16969],{"type":899},{"data":16971,"content":16972,"nodeType":860},{},[16973,16976,16982],{"data":16974,"marks":16975,"value":3700,"nodeType":864},{},[],{"data":16977,"content":16978,"nodeType":883},{"uri":3703},[16979],{"data":16980,"marks":16981,"value":3708,"nodeType":864},{},[],{"data":16983,"marks":16984,"value":3712,"nodeType":864},{},[],{"data":16986,"content":16987,"nodeType":860},{},[16988,16991,16997,17000,17004,17007,17011,17014,17020],{"data":16989,"marks":16990,"value":3719,"nodeType":864},{},[],{"data":16992,"content":16993,"nodeType":883},{"uri":3722},[16994],{"data":16995,"marks":16996,"value":3727,"nodeType":864},{},[],{"data":16998,"marks":16999,"value":3731,"nodeType":864},{},[],{"data":17001,"marks":17002,"value":3736,"nodeType":864},{},[17003],{"type":899},{"data":17005,"marks":17006,"value":2232,"nodeType":864},{},[],{"data":17008,"marks":17009,"value":3744,"nodeType":864},{},[17010],{"type":899},{"data":17012,"marks":17013,"value":3748,"nodeType":864},{},[],{"data":17015,"content":17016,"nodeType":883},{"uri":3751},[17017],{"data":17018,"marks":17019,"value":3756,"nodeType":864},{},[],{"data":17021,"marks":17022,"value":3760,"nodeType":864},{},[],{"data":17024,"content":17027,"nodeType":996},{"target":17025},{"sys":17026},{"id":3765,"type":1001,"linkType":1002},[],{"data":17029,"content":17030,"nodeType":860},{},[17031,17034,17038],{"data":17032,"marks":17033,"value":3773,"nodeType":864},{},[],{"data":17035,"marks":17036,"value":3778,"nodeType":864},{},[17037],{"type":899},{"data":17039,"marks":17040,"value":2924,"nodeType":864},{},[],{"data":17042,"content":17043,"nodeType":1005},{},[],{"data":17045,"content":17046,"nodeType":1009},{},[17047],{"data":17048,"marks":17049,"value":3792,"nodeType":864},{},[17050],{"type":899},{"data":17052,"content":17053,"nodeType":860},{},[17054],{"data":17055,"marks":17056,"value":3693,"nodeType":864},{},[17057],{"type":899},{"data":17059,"content":17060,"nodeType":860},{},[17061,17064,17070,17073,17077],{"data":17062,"marks":17063,"value":3806,"nodeType":864},{},[],{"data":17065,"content":17066,"nodeType":883},{"uri":3809},[17067],{"data":17068,"marks":17069,"value":3814,"nodeType":864},{},[],{"data":17071,"marks":17072,"value":3818,"nodeType":864},{},[],{"data":17074,"marks":17075,"value":3823,"nodeType":864},{},[17076],{"type":899},{"data":17078,"marks":17079,"value":3827,"nodeType":864},{},[],{"data":17081,"content":17082,"nodeType":860},{},[17083,17086,17092,17095,17099,17102,17109],{"data":17084,"marks":17085,"value":3834,"nodeType":864},{},[],{"data":17087,"content":17088,"nodeType":883},{"uri":3837},[17089],{"data":17090,"marks":17091,"value":3842,"nodeType":864},{},[],{"data":17093,"marks":17094,"value":3846,"nodeType":864},{},[],{"data":17096,"marks":17097,"value":3851,"nodeType":864},{},[17098],{"type":899},{"data":17100,"marks":17101,"value":3855,"nodeType":864},{},[],{"data":17103,"content":17104,"nodeType":883},{"uri":3858},[17105],{"data":17106,"marks":17107,"value":3864,"nodeType":864},{},[17108],{"type":899},{"data":17110,"marks":17111,"value":3868,"nodeType":864},{},[],{"data":17113,"content":17114,"nodeType":860},{},[17115],{"data":17116,"marks":17117,"value":3875,"nodeType":864},{},[],{"data":17119,"content":17120,"nodeType":1005},{},[],{"data":17122,"content":17123,"nodeType":1009},{},[17124],{"data":17125,"marks":17126,"value":3886,"nodeType":864},{},[17127],{"type":899},{"data":17129,"content":17130,"nodeType":860},{},[17131],{"data":17132,"marks":17133,"value":3894,"nodeType":864},{},[17134],{"type":899},{"data":17136,"content":17137,"nodeType":860},{},[17138],{"data":17139,"marks":17140,"value":3901,"nodeType":864},{},[],{"data":17142,"content":17145,"nodeType":996},{"target":17143},{"sys":17144},{"id":3906,"type":1001,"linkType":1002},[],{"data":17147,"content":17148,"nodeType":860},{},[17149],{"data":17150,"marks":17151,"value":3914,"nodeType":864},{},[],{"data":17153,"content":17154,"nodeType":1005},{},[],{"data":17156,"content":17157,"nodeType":1009},{},[17158],{"data":17159,"marks":17160,"value":3925,"nodeType":864},{},[17161],{"type":899},{"data":17163,"content":17164,"nodeType":860},{},[17165],{"data":17166,"marks":17167,"value":3894,"nodeType":864},{},[17168],{"type":899},{"data":17170,"content":17171,"nodeType":860},{},[17172,17175,17182,17185,17191,17194,17200],{"data":17173,"marks":17174,"value":3939,"nodeType":864},{},[],{"data":17176,"content":17177,"nodeType":883},{"uri":3942},[17178],{"data":17179,"marks":17180,"value":3948,"nodeType":864},{},[17181],{"type":1455},{"data":17183,"marks":17184,"value":3731,"nodeType":864},{},[],{"data":17186,"content":17187,"nodeType":883},{"uri":3954},[17188],{"data":17189,"marks":17190,"value":3959,"nodeType":864},{},[],{"data":17192,"marks":17193,"value":3731,"nodeType":864},{},[],{"data":17195,"content":17196,"nodeType":883},{"uri":3965},[17197],{"data":17198,"marks":17199,"value":3970,"nodeType":864},{},[],{"data":17201,"marks":17202,"value":3974,"nodeType":864},{},[],{"data":17204,"content":17205,"nodeType":860},{},[17206,17209,17216,17219,17223,17226,17230],{"data":17207,"marks":17208,"value":21,"nodeType":864},{},[],{"data":17210,"content":17211,"nodeType":883},{"uri":2411},[17212],{"data":17213,"marks":17214,"value":3988,"nodeType":864},{},[17215],{"type":1455},{"data":17217,"marks":17218,"value":3992,"nodeType":864},{},[],{"data":17220,"marks":17221,"value":3997,"nodeType":864},{},[17222],{"type":899},{"data":17224,"marks":17225,"value":4001,"nodeType":864},{},[],{"data":17227,"marks":17228,"value":4006,"nodeType":864},{},[17229],{"type":2246},{"data":17231,"marks":17232,"value":4010,"nodeType":864},{},[],{"data":17234,"content":17235,"nodeType":860},{},[17236],{"data":17237,"marks":17238,"value":4017,"nodeType":864},{},[],{"data":17240,"content":17241,"nodeType":1005},{},[],{"data":17243,"content":17244,"nodeType":1009},{},[17245],{"data":17246,"marks":17247,"value":4028,"nodeType":864},{},[17248],{"type":899},{"data":17250,"content":17251,"nodeType":860},{},[17252],{"data":17253,"marks":17254,"value":3894,"nodeType":864},{},[17255],{"type":899},{"data":17257,"content":17258,"nodeType":860},{},[17259,17262,17266,17269,17273],{"data":17260,"marks":17261,"value":4042,"nodeType":864},{},[],{"data":17263,"marks":17264,"value":4047,"nodeType":864},{},[17265],{"type":2246},{"data":17267,"marks":17268,"value":4051,"nodeType":864},{},[],{"data":17270,"marks":17271,"value":4056,"nodeType":864},{},[17272],{"type":2246},{"data":17274,"marks":17275,"value":4060,"nodeType":864},{},[],{"data":17277,"content":17278,"nodeType":860},{},[17279],{"data":17280,"marks":17281,"value":4067,"nodeType":864},{},[],{"data":17283,"content":17284,"nodeType":941},{},[17285,17303],{"data":17286,"content":17287,"nodeType":945},{},[17288],{"data":17289,"content":17290,"nodeType":860},{},[17291,17294,17300],{"data":17292,"marks":17293,"value":2761,"nodeType":864},{},[],{"data":17295,"content":17296,"nodeType":883},{"uri":4082},[17297],{"data":17298,"marks":17299,"value":4087,"nodeType":864},{},[],{"data":17301,"marks":17302,"value":4091,"nodeType":864},{},[],{"data":17304,"content":17305,"nodeType":945},{},[17306],{"data":17307,"content":17308,"nodeType":860},{},[17309,17312,17318],{"data":17310,"marks":17311,"value":2761,"nodeType":864},{},[],{"data":17313,"content":17314,"nodeType":883},{"uri":4103},[17315],{"data":17316,"marks":17317,"value":4108,"nodeType":864},{},[],{"data":17319,"marks":17320,"value":4112,"nodeType":864},{},[],{"data":17322,"content":17323,"nodeType":860},{},[17324],{"data":17325,"marks":17326,"value":4119,"nodeType":864},{},[],{"data":17328,"content":17329,"nodeType":1005},{},[],{"data":17331,"content":17332,"nodeType":1009},{},[17333],{"data":17334,"marks":17335,"value":4130,"nodeType":864},{},[17336],{"type":899},{"data":17338,"content":17339,"nodeType":860},{},[17340],{"data":17341,"marks":17342,"value":4138,"nodeType":864},{},[17343],{"type":899},{"data":17345,"content":17346,"nodeType":860},{},[17347,17350,17354,17357,17363,17366,17370,17373,17377],{"data":17348,"marks":17349,"value":4145,"nodeType":864},{},[],{"data":17351,"marks":17352,"value":4150,"nodeType":864},{},[17353],{"type":899},{"data":17355,"marks":17356,"value":4154,"nodeType":864},{},[],{"data":17358,"content":17359,"nodeType":883},{"uri":3237},[17360],{"data":17361,"marks":17362,"value":4161,"nodeType":864},{},[],{"data":17364,"marks":17365,"value":4165,"nodeType":864},{},[],{"data":17367,"marks":17368,"value":4170,"nodeType":864},{},[17369],{"type":899},{"data":17371,"marks":17372,"value":4174,"nodeType":864},{},[],{"data":17374,"marks":17375,"value":4179,"nodeType":864},{},[17376],{"type":899},{"data":17378,"marks":17379,"value":4183,"nodeType":864},{},[],{"data":17381,"content":17382,"nodeType":860},{},[17383],{"data":17384,"marks":17385,"value":4190,"nodeType":864},{},[],{"data":17387,"content":17390,"nodeType":996},{"target":17388},{"sys":17389},{"id":4195,"type":1001,"linkType":1002},[],{"data":17392,"content":17393,"nodeType":1005},{},[],{"data":17395,"content":17396,"nodeType":1009},{},[17397],{"data":17398,"marks":17399,"value":4207,"nodeType":864},{},[17400],{"type":899},{"data":17402,"content":17403,"nodeType":860},{},[17404],{"data":17405,"marks":17406,"value":4215,"nodeType":864},{},[17407],{"type":899},{"data":17409,"content":17410,"nodeType":860},{},[17411,17414,17421,17424,17431],{"data":17412,"marks":17413,"value":4222,"nodeType":864},{},[],{"data":17415,"content":17416,"nodeType":883},{"uri":2561},[17417],{"data":17418,"marks":17419,"value":4230,"nodeType":864},{},[17420],{"type":899},{"data":17422,"marks":17423,"value":4234,"nodeType":864},{},[],{"data":17425,"content":17426,"nodeType":883},{"uri":4237},[17427],{"data":17428,"marks":17429,"value":4243,"nodeType":864},{},[17430],{"type":899},{"data":17432,"marks":17433,"value":4247,"nodeType":864},{},[],{"data":17435,"content":17436,"nodeType":860},{},[17437],{"data":17438,"marks":17439,"value":4254,"nodeType":864},{},[],{"data":17441,"content":17444,"nodeType":996},{"target":17442},{"sys":17443},{"id":4259,"type":1001,"linkType":1002},[],{"data":17446,"content":17447,"nodeType":860},{},[17448],{"data":17449,"marks":17450,"value":4267,"nodeType":864},{},[],{"data":17452,"content":17453,"nodeType":1005},{},[],{"data":17455,"content":17456,"nodeType":1009},{},[17457],{"data":17458,"marks":17459,"value":4278,"nodeType":864},{},[17460],{"type":899},{"data":17462,"content":17463,"nodeType":860},{},[17464],{"data":17465,"marks":17466,"value":4286,"nodeType":864},{},[17467],{"type":899},{"data":17469,"content":17470,"nodeType":860},{},[17471,17474,17478,17481,17488],{"data":17472,"marks":17473,"value":4293,"nodeType":864},{},[],{"data":17475,"marks":17476,"value":4298,"nodeType":864},{},[17477],{"type":2246},{"data":17479,"marks":17480,"value":4302,"nodeType":864},{},[],{"data":17482,"content":17483,"nodeType":883},{"uri":4305},[17484],{"data":17485,"marks":17486,"value":4311,"nodeType":864},{},[17487],{"type":899},{"data":17489,"marks":17490,"value":4315,"nodeType":864},{},[],{"data":17492,"content":17493,"nodeType":860},{},[17494],{"data":17495,"marks":17496,"value":4322,"nodeType":864},{},[],{"data":17498,"content":17499,"nodeType":860},{},[17500],{"data":17501,"marks":17502,"value":4329,"nodeType":864},{},[],{"data":17504,"content":17505,"nodeType":860},{},[17506],{"data":17507,"marks":17508,"value":4336,"nodeType":864},{},[],{"data":17510,"content":17511,"nodeType":1005},{},[],{"data":17513,"content":17514,"nodeType":1009},{},[17515],{"data":17516,"marks":17517,"value":4347,"nodeType":864},{},[17518],{"type":899},{"data":17520,"content":17521,"nodeType":860},{},[17522],{"data":17523,"marks":17524,"value":4355,"nodeType":864},{},[17525],{"type":899},{"data":17527,"content":17528,"nodeType":860},{},[17529],{"data":17530,"marks":17531,"value":4362,"nodeType":864},{},[],{"data":17533,"content":17536,"nodeType":996},{"target":17534},{"sys":17535},{"id":4367,"type":1001,"linkType":1002},[],{"data":17538,"content":17539,"nodeType":860},{},[17540],{"data":17541,"marks":17542,"value":4375,"nodeType":864},{},[],{"data":17544,"content":17545,"nodeType":941},{},[17546,17555],{"data":17547,"content":17548,"nodeType":945},{},[17549],{"data":17550,"content":17551,"nodeType":860},{},[17552],{"data":17553,"marks":17554,"value":4388,"nodeType":864},{},[],{"data":17556,"content":17557,"nodeType":945},{},[17558],{"data":17559,"content":17560,"nodeType":860},{},[17561],{"data":17562,"marks":17563,"value":4398,"nodeType":864},{},[],{"data":17565,"content":17566,"nodeType":860},{},[17567,17570,17577,17580,17584],{"data":17568,"marks":17569,"value":4405,"nodeType":864},{},[],{"data":17571,"content":17572,"nodeType":883},{"uri":4408},[17573],{"data":17574,"marks":17575,"value":4414,"nodeType":864},{},[17576],{"type":899},{"data":17578,"marks":17579,"value":4418,"nodeType":864},{},[],{"data":17581,"marks":17582,"value":4423,"nodeType":864},{},[17583],{"type":2246},{"data":17585,"marks":17586,"value":4427,"nodeType":864},{},[],{"data":17588,"content":17589,"nodeType":1005},{},[],{"data":17591,"content":17592,"nodeType":1009},{},[17593],{"data":17594,"marks":17595,"value":4438,"nodeType":864},{},[17596],{"type":899},{"data":17598,"content":17599,"nodeType":860},{},[17600],{"data":17601,"marks":17602,"value":4446,"nodeType":864},{},[17603],{"type":899},{"data":17605,"content":17606,"nodeType":860},{},[17607],{"data":17608,"marks":17609,"value":4453,"nodeType":864},{},[],{"data":17611,"content":17612,"nodeType":860},{},[17613],{"data":17614,"marks":17615,"value":4460,"nodeType":864},{},[],{"data":17617,"content":17618,"nodeType":1005},{},[],{"data":17620,"content":17621,"nodeType":1009},{},[17622],{"data":17623,"marks":17624,"value":4471,"nodeType":864},{},[17625],{"type":899},{"data":17627,"content":17628,"nodeType":941},{},[17629,17642,17655,17668],{"data":17630,"content":17631,"nodeType":945},{},[17632],{"data":17633,"content":17634,"nodeType":860},{},[17635,17639],{"data":17636,"marks":17637,"value":4485,"nodeType":864},{},[17638],{"type":899},{"data":17640,"marks":17641,"value":4489,"nodeType":864},{},[],{"data":17643,"content":17644,"nodeType":945},{},[17645],{"data":17646,"content":17647,"nodeType":860},{},[17648,17652],{"data":17649,"marks":17650,"value":4500,"nodeType":864},{},[17651],{"type":899},{"data":17653,"marks":17654,"value":4504,"nodeType":864},{},[],{"data":17656,"content":17657,"nodeType":945},{},[17658],{"data":17659,"content":17660,"nodeType":860},{},[17661,17665],{"data":17662,"marks":17663,"value":4515,"nodeType":864},{},[17664],{"type":899},{"data":17666,"marks":17667,"value":4519,"nodeType":864},{},[],{"data":17669,"content":17670,"nodeType":945},{},[17671],{"data":17672,"content":17673,"nodeType":860},{},[17674,17678],{"data":17675,"marks":17676,"value":781,"nodeType":864},{},[17677],{"type":899},{"data":17679,"marks":17680,"value":4533,"nodeType":864},{},[],{"data":17682,"content":17683,"nodeType":1005},{},[],{"data":17685,"content":17686,"nodeType":1009},{},[17687],{"data":17688,"marks":17689,"value":4544,"nodeType":864},{},[17690],{"type":899},{"data":17692,"content":17693,"nodeType":860},{},[17694],{"data":17695,"marks":17696,"value":4551,"nodeType":864},{},[],{"data":17698,"content":17699,"nodeType":4845},{},[17700,17723,17745,17767,17789,17811,17833,17855,17877,17899,17921,17943],{"data":17701,"content":17702,"nodeType":4581},{},[17703,17713],{"data":17704,"content":17705,"nodeType":4569},{},[17706],{"data":17707,"content":17708,"nodeType":860},{},[17709],{"data":17710,"marks":17711,"value":4568,"nodeType":864},{},[17712],{"type":899},{"data":17714,"content":17715,"nodeType":4569},{},[17716],{"data":17717,"content":17718,"nodeType":860},{},[17719],{"data":17720,"marks":17721,"value":4580,"nodeType":864},{},[17722],{"type":899},{"data":17724,"content":17725,"nodeType":4581},{},[17726,17736],{"data":17727,"content":17728,"nodeType":4569},{},[17729],{"data":17730,"content":17731,"nodeType":860},{},[17732],{"data":17733,"marks":17734,"value":4595,"nodeType":864},{},[17735],{"type":899},{"data":17737,"content":17738,"nodeType":4569},{},[17739],{"data":17740,"content":17741,"nodeType":860},{},[17742],{"data":17743,"marks":17744,"value":4605,"nodeType":864},{},[],{"data":17746,"content":17747,"nodeType":4581},{},[17748,17758],{"data":17749,"content":17750,"nodeType":4569},{},[17751],{"data":17752,"content":17753,"nodeType":860},{},[17754],{"data":17755,"marks":17756,"value":4619,"nodeType":864},{},[17757],{"type":899},{"data":17759,"content":17760,"nodeType":4569},{},[17761],{"data":17762,"content":17763,"nodeType":860},{},[17764],{"data":17765,"marks":17766,"value":4629,"nodeType":864},{},[],{"data":17768,"content":17769,"nodeType":4581},{},[17770,17780],{"data":17771,"content":17772,"nodeType":4569},{},[17773],{"data":17774,"content":17775,"nodeType":860},{},[17776],{"data":17777,"marks":17778,"value":4643,"nodeType":864},{},[17779],{"type":899},{"data":17781,"content":17782,"nodeType":4569},{},[17783],{"data":17784,"content":17785,"nodeType":860},{},[17786],{"data":17787,"marks":17788,"value":4653,"nodeType":864},{},[],{"data":17790,"content":17791,"nodeType":4581},{},[17792,17802],{"data":17793,"content":17794,"nodeType":4569},{},[17795],{"data":17796,"content":17797,"nodeType":860},{},[17798],{"data":17799,"marks":17800,"value":4667,"nodeType":864},{},[17801],{"type":899},{"data":17803,"content":17804,"nodeType":4569},{},[17805],{"data":17806,"content":17807,"nodeType":860},{},[17808],{"data":17809,"marks":17810,"value":4677,"nodeType":864},{},[],{"data":17812,"content":17813,"nodeType":4581},{},[17814,17824],{"data":17815,"content":17816,"nodeType":4569},{},[17817],{"data":17818,"content":17819,"nodeType":860},{},[17820],{"data":17821,"marks":17822,"value":4691,"nodeType":864},{},[17823],{"type":899},{"data":17825,"content":17826,"nodeType":4569},{},[17827],{"data":17828,"content":17829,"nodeType":860},{},[17830],{"data":17831,"marks":17832,"value":4701,"nodeType":864},{},[],{"data":17834,"content":17835,"nodeType":4581},{},[17836,17846],{"data":17837,"content":17838,"nodeType":4569},{},[17839],{"data":17840,"content":17841,"nodeType":860},{},[17842],{"data":17843,"marks":17844,"value":4715,"nodeType":864},{},[17845],{"type":899},{"data":17847,"content":17848,"nodeType":4569},{},[17849],{"data":17850,"content":17851,"nodeType":860},{},[17852],{"data":17853,"marks":17854,"value":4725,"nodeType":864},{},[],{"data":17856,"content":17857,"nodeType":4581},{},[17858,17868],{"data":17859,"content":17860,"nodeType":4569},{},[17861],{"data":17862,"content":17863,"nodeType":860},{},[17864],{"data":17865,"marks":17866,"value":4739,"nodeType":864},{},[17867],{"type":899},{"data":17869,"content":17870,"nodeType":4569},{},[17871],{"data":17872,"content":17873,"nodeType":860},{},[17874],{"data":17875,"marks":17876,"value":4749,"nodeType":864},{},[],{"data":17878,"content":17879,"nodeType":4581},{},[17880,17890],{"data":17881,"content":17882,"nodeType":4569},{},[17883],{"data":17884,"content":17885,"nodeType":860},{},[17886],{"data":17887,"marks":17888,"value":4763,"nodeType":864},{},[17889],{"type":899},{"data":17891,"content":17892,"nodeType":4569},{},[17893],{"data":17894,"content":17895,"nodeType":860},{},[17896],{"data":17897,"marks":17898,"value":4773,"nodeType":864},{},[],{"data":17900,"content":17901,"nodeType":4581},{},[17902,17912],{"data":17903,"content":17904,"nodeType":4569},{},[17905],{"data":17906,"content":17907,"nodeType":860},{},[17908],{"data":17909,"marks":17910,"value":4787,"nodeType":864},{},[17911],{"type":899},{"data":17913,"content":17914,"nodeType":4569},{},[17915],{"data":17916,"content":17917,"nodeType":860},{},[17918],{"data":17919,"marks":17920,"value":4797,"nodeType":864},{},[],{"data":17922,"content":17923,"nodeType":4581},{},[17924,17934],{"data":17925,"content":17926,"nodeType":4569},{},[17927],{"data":17928,"content":17929,"nodeType":860},{},[17930],{"data":17931,"marks":17932,"value":4811,"nodeType":864},{},[17933],{"type":899},{"data":17935,"content":17936,"nodeType":4569},{},[17937],{"data":17938,"content":17939,"nodeType":860},{},[17940],{"data":17941,"marks":17942,"value":4821,"nodeType":864},{},[],{"data":17944,"content":17945,"nodeType":4581},{},[17946,17956],{"data":17947,"content":17948,"nodeType":4569},{},[17949],{"data":17950,"content":17951,"nodeType":860},{},[17952],{"data":17953,"marks":17954,"value":4500,"nodeType":864},{},[17955],{"type":899},{"data":17957,"content":17958,"nodeType":4569},{},[17959],{"data":17960,"content":17961,"nodeType":860},{},[17962],{"data":17963,"marks":17964,"value":4844,"nodeType":864},{},[],{"data":17966,"content":17967,"nodeType":1005},{},[],{"data":17969,"content":17970,"nodeType":860},{},[17971,17974,17980],{"data":17972,"marks":17973,"value":4855,"nodeType":864},{},[],{"data":17975,"content":17976,"nodeType":883},{"uri":1700},[17977],{"data":17978,"marks":17979,"value":1703,"nodeType":864},{},[],{"data":17981,"marks":17982,"value":21,"nodeType":864},{},[],{"items":17984},[17985,17987],{"sys":17986,"name":297},{"id":2732},{"sys":17988,"name":2729},{"id":2728},{"items":17990},[17991],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":17992},{"url":4881},{"__typename":2059,"sys":17994,"content":17995,"title":845,"synopsis":4895,"hashTags":59,"publishedDate":2055,"slug":4882,"tagsCollection":18705,"authorsCollection":18711},{"id":4897},{"json":17996},{"nodeType":856,"data":17997,"content":17998},{},[17999,18005,18011,18049,18055,18061,18109,18114,18117,18124,18130,18140,18145,18155,18160,18170,18175,18178,18185,18191,18206,18215,18221,18227,18230,18237,18243,18263,18268,18274,18287,18300,18305,18318,18331,18337,18343,18349,18354,18357,18364,18370,18376,18382,18395,18401,18421,18426,18432,18437,18447,18453,18458,18463,18466,18473,18479,18495,18501,18508,18514,18524,18537,18542,18552,18579,18585,18598,18603,18616,18622,18628,18631,18638,18644,18650,18656,18662,18668,18674,18677,18683,18689],{"nodeType":860,"data":18000,"content":18001},{},[18002],{"nodeType":864,"value":865,"marks":18003,"data":18004},[],{},{"nodeType":860,"data":18006,"content":18007},{},[18008],{"nodeType":864,"value":872,"marks":18009,"data":18010},[],{},{"nodeType":860,"data":18012,"content":18013},{},[18014,18017,18023,18026,18030,18033,18037,18040,18046],{"nodeType":864,"value":879,"marks":18015,"data":18016},[],{},{"nodeType":883,"data":18018,"content":18019},{"uri":885},[18020],{"nodeType":864,"value":888,"marks":18021,"data":18022},[],{},{"nodeType":864,"value":892,"marks":18024,"data":18025},[],{},{"nodeType":864,"value":896,"marks":18027,"data":18029},[18028],{"type":899},{},{"nodeType":864,"value":902,"marks":18031,"data":18032},[],{},{"nodeType":864,"value":906,"marks":18034,"data":18036},[18035],{"type":899},{},{"nodeType":864,"value":911,"marks":18038,"data":18039},[],{},{"nodeType":883,"data":18041,"content":18042},{"uri":916},[18043],{"nodeType":864,"value":919,"marks":18044,"data":18045},[],{},{"nodeType":864,"value":923,"marks":18047,"data":18048},[],{},{"nodeType":860,"data":18050,"content":18051},{},[18052],{"nodeType":864,"value":930,"marks":18053,"data":18054},[],{},{"nodeType":860,"data":18056,"content":18057},{},[18058],{"nodeType":864,"value":937,"marks":18059,"data":18060},[],{},{"nodeType":941,"data":18062,"content":18063},{},[18064,18073,18082,18091,18100],{"nodeType":945,"data":18065,"content":18066},{},[18067],{"nodeType":860,"data":18068,"content":18069},{},[18070],{"nodeType":864,"value":952,"marks":18071,"data":18072},[],{},{"nodeType":945,"data":18074,"content":18075},{},[18076],{"nodeType":860,"data":18077,"content":18078},{},[18079],{"nodeType":864,"value":962,"marks":18080,"data":18081},[],{},{"nodeType":945,"data":18083,"content":18084},{},[18085],{"nodeType":860,"data":18086,"content":18087},{},[18088],{"nodeType":864,"value":972,"marks":18089,"data":18090},[],{},{"nodeType":945,"data":18092,"content":18093},{},[18094],{"nodeType":860,"data":18095,"content":18096},{},[18097],{"nodeType":864,"value":982,"marks":18098,"data":18099},[],{},{"nodeType":945,"data":18101,"content":18102},{},[18103],{"nodeType":860,"data":18104,"content":18105},{},[18106],{"nodeType":864,"value":992,"marks":18107,"data":18108},[],{},{"nodeType":996,"data":18110,"content":18113},{"target":18111},{"sys":18112},{"id":1000,"type":1001,"linkType":1002},[],{"nodeType":1005,"data":18115,"content":18116},{},[],{"nodeType":1009,"data":18118,"content":18119},{},[18120],{"nodeType":864,"value":1013,"marks":18121,"data":18123},[18122],{"type":899},{},{"nodeType":860,"data":18125,"content":18126},{},[18127],{"nodeType":864,"value":1021,"marks":18128,"data":18129},[],{},{"nodeType":860,"data":18131,"content":18132},{},[18133,18137],{"nodeType":864,"value":1028,"marks":18134,"data":18136},[18135],{"type":899},{},{"nodeType":864,"value":1033,"marks":18138,"data":18139},[],{},{"nodeType":996,"data":18141,"content":18144},{"target":18142},{"sys":18143},{"id":1040,"type":1001,"linkType":1002},[],{"nodeType":860,"data":18146,"content":18147},{},[18148,18152],{"nodeType":864,"value":1046,"marks":18149,"data":18151},[18150],{"type":899},{},{"nodeType":864,"value":1051,"marks":18153,"data":18154},[],{},{"nodeType":996,"data":18156,"content":18159},{"target":18157},{"sys":18158},{"id":1058,"type":1001,"linkType":1002},[],{"nodeType":860,"data":18161,"content":18162},{},[18163,18167],{"nodeType":864,"value":1064,"marks":18164,"data":18166},[18165],{"type":899},{},{"nodeType":864,"value":1069,"marks":18168,"data":18169},[],{},{"nodeType":996,"data":18171,"content":18174},{"target":18172},{"sys":18173},{"id":1076,"type":1001,"linkType":1002},[],{"nodeType":1005,"data":18176,"content":18177},{},[],{"nodeType":1009,"data":18179,"content":18180},{},[18181],{"nodeType":864,"value":1085,"marks":18182,"data":18184},[18183],{"type":899},{},{"nodeType":860,"data":18186,"content":18187},{},[18188],{"nodeType":864,"value":1093,"marks":18189,"data":18190},[],{},{"nodeType":860,"data":18192,"content":18193},{},[18194,18197,18203],{"nodeType":864,"value":1100,"marks":18195,"data":18196},[],{},{"nodeType":883,"data":18198,"content":18199},{"uri":1105},[18200],{"nodeType":864,"value":1108,"marks":18201,"data":18202},[],{},{"nodeType":864,"value":1112,"marks":18204,"data":18205},[],{},{"nodeType":1116,"data":18207,"content":18208},{},[18209],{"nodeType":860,"data":18210,"content":18211},{},[18212],{"nodeType":864,"value":1123,"marks":18213,"data":18214},[],{},{"nodeType":860,"data":18216,"content":18217},{},[18218],{"nodeType":864,"value":1130,"marks":18219,"data":18220},[],{},{"nodeType":860,"data":18222,"content":18223},{},[18224],{"nodeType":864,"value":1137,"marks":18225,"data":18226},[],{},{"nodeType":1005,"data":18228,"content":18229},{},[],{"nodeType":1009,"data":18231,"content":18232},{},[18233],{"nodeType":864,"value":1147,"marks":18234,"data":18236},[18235],{"type":899},{},{"nodeType":860,"data":18238,"content":18239},{},[18240],{"nodeType":864,"value":1155,"marks":18241,"data":18242},[],{},{"nodeType":860,"data":18244,"content":18245},{},[18246,18249,18253,18256,18260],{"nodeType":864,"value":1162,"marks":18247,"data":18248},[],{},{"nodeType":864,"value":1166,"marks":18250,"data":18252},[18251],{"type":899},{},{"nodeType":864,"value":1171,"marks":18254,"data":18255},[],{},{"nodeType":864,"value":1175,"marks":18257,"data":18259},[18258],{"type":899},{},{"nodeType":864,"value":1180,"marks":18261,"data":18262},[],{},{"nodeType":996,"data":18264,"content":18267},{"target":18265},{"sys":18266},{"id":1187,"type":1001,"linkType":1002},[],{"nodeType":860,"data":18269,"content":18270},{},[18271],{"nodeType":864,"value":1193,"marks":18272,"data":18273},[],{},{"nodeType":860,"data":18275,"content":18276},{},[18277,18280,18284],{"nodeType":864,"value":1200,"marks":18278,"data":18279},[],{},{"nodeType":864,"value":1204,"marks":18281,"data":18283},[18282],{"type":899},{},{"nodeType":864,"value":1209,"marks":18285,"data":18286},[],{},{"nodeType":860,"data":18288,"content":18289},{},[18290,18293,18297],{"nodeType":864,"value":1216,"marks":18291,"data":18292},[],{},{"nodeType":864,"value":1220,"marks":18294,"data":18296},[18295],{"type":899},{},{"nodeType":864,"value":1225,"marks":18298,"data":18299},[],{},{"nodeType":996,"data":18301,"content":18304},{"target":18302},{"sys":18303},{"id":1232,"type":1001,"linkType":1002},[],{"nodeType":860,"data":18306,"content":18307},{},[18308,18311,18315],{"nodeType":864,"value":1238,"marks":18309,"data":18310},[],{},{"nodeType":864,"value":1242,"marks":18312,"data":18314},[18313],{"type":899},{},{"nodeType":864,"value":1247,"marks":18316,"data":18317},[],{},{"nodeType":860,"data":18319,"content":18320},{},[18321,18324,18328],{"nodeType":864,"value":1254,"marks":18322,"data":18323},[],{},{"nodeType":864,"value":1258,"marks":18325,"data":18327},[18326],{"type":899},{},{"nodeType":864,"value":1263,"marks":18329,"data":18330},[],{},{"nodeType":860,"data":18332,"content":18333},{},[18334],{"nodeType":864,"value":1270,"marks":18335,"data":18336},[],{},{"nodeType":860,"data":18338,"content":18339},{},[18340],{"nodeType":864,"value":1277,"marks":18341,"data":18342},[],{},{"nodeType":860,"data":18344,"content":18345},{},[18346],{"nodeType":864,"value":1284,"marks":18347,"data":18348},[],{},{"nodeType":996,"data":18350,"content":18353},{"target":18351},{"sys":18352},{"id":1291,"type":1001,"linkType":1002},[],{"nodeType":1005,"data":18355,"content":18356},{},[],{"nodeType":1009,"data":18358,"content":18359},{},[18360],{"nodeType":864,"value":1300,"marks":18361,"data":18363},[18362],{"type":899},{},{"nodeType":860,"data":18365,"content":18366},{},[18367],{"nodeType":864,"value":1308,"marks":18368,"data":18369},[],{},{"nodeType":1312,"data":18371,"content":18372},{},[18373],{"nodeType":864,"value":1316,"marks":18374,"data":18375},[],{},{"nodeType":860,"data":18377,"content":18378},{},[18379],{"nodeType":864,"value":1323,"marks":18380,"data":18381},[],{},{"nodeType":860,"data":18383,"content":18384},{},[18385,18388,18392],{"nodeType":864,"value":1330,"marks":18386,"data":18387},[],{},{"nodeType":864,"value":1334,"marks":18389,"data":18391},[18390],{"type":899},{},{"nodeType":864,"value":1339,"marks":18393,"data":18394},[],{},{"nodeType":860,"data":18396,"content":18397},{},[18398],{"nodeType":864,"value":1346,"marks":18399,"data":18400},[],{},{"nodeType":860,"data":18402,"content":18403},{},[18404,18407,18411,18414,18418],{"nodeType":864,"value":1353,"marks":18405,"data":18406},[],{},{"nodeType":864,"value":1357,"marks":18408,"data":18410},[18409],{"type":899},{},{"nodeType":864,"value":1362,"marks":18412,"data":18413},[],{},{"nodeType":864,"value":1366,"marks":18415,"data":18417},[18416],{"type":899},{},{"nodeType":864,"value":1371,"marks":18419,"data":18420},[],{},{"nodeType":996,"data":18422,"content":18425},{"target":18423},{"sys":18424},{"id":1378,"type":1001,"linkType":1002},[],{"nodeType":860,"data":18427,"content":18428},{},[18429],{"nodeType":864,"value":1384,"marks":18430,"data":18431},[],{},{"nodeType":996,"data":18433,"content":18436},{"target":18434},{"sys":18435},{"id":1391,"type":1001,"linkType":1002},[],{"nodeType":860,"data":18438,"content":18439},{},[18440,18444],{"nodeType":864,"value":1397,"marks":18441,"data":18443},[18442],{"type":899},{},{"nodeType":864,"value":1402,"marks":18445,"data":18446},[],{},{"nodeType":860,"data":18448,"content":18449},{},[18450],{"nodeType":864,"value":1409,"marks":18451,"data":18452},[],{},{"nodeType":996,"data":18454,"content":18457},{"target":18455},{"sys":18456},{"id":1416,"type":1001,"linkType":1002},[],{"nodeType":996,"data":18459,"content":18462},{"target":18460},{"sys":18461},{"id":1422,"type":1001,"linkType":1002},[],{"nodeType":1005,"data":18464,"content":18465},{},[],{"nodeType":1009,"data":18467,"content":18468},{},[18469],{"nodeType":864,"value":1431,"marks":18470,"data":18472},[18471],{"type":899},{},{"nodeType":860,"data":18474,"content":18475},{},[18476],{"nodeType":864,"value":1439,"marks":18477,"data":18478},[],{},{"nodeType":860,"data":18480,"content":18481},{},[18482,18485,18492],{"nodeType":864,"value":21,"marks":18483,"data":18484},[],{},{"nodeType":883,"data":18486,"content":18487},{"uri":916},[18488],{"nodeType":864,"value":1452,"marks":18489,"data":18491},[18490],{"type":1455},{},{"nodeType":864,"value":1458,"marks":18493,"data":18494},[],{},{"nodeType":860,"data":18496,"content":18497},{},[18498],{"nodeType":864,"value":1465,"marks":18499,"data":18500},[],{},{"nodeType":1312,"data":18502,"content":18503},{},[18504],{"nodeType":864,"value":1472,"marks":18505,"data":18507},[18506],{"type":899},{},{"nodeType":860,"data":18509,"content":18510},{},[18511],{"nodeType":864,"value":1480,"marks":18512,"data":18513},[],{},{"nodeType":860,"data":18515,"content":18516},{},[18517,18521],{"nodeType":864,"value":1487,"marks":18518,"data":18520},[18519],{"type":899},{},{"nodeType":864,"value":1492,"marks":18522,"data":18523},[],{},{"nodeType":860,"data":18525,"content":18526},{},[18527,18530,18534],{"nodeType":864,"value":1499,"marks":18528,"data":18529},[],{},{"nodeType":864,"value":1503,"marks":18531,"data":18533},[18532],{"type":899},{},{"nodeType":864,"value":1508,"marks":18535,"data":18536},[],{},{"nodeType":996,"data":18538,"content":18541},{"target":18539},{"sys":18540},{"id":1515,"type":1001,"linkType":1002},[],{"nodeType":860,"data":18543,"content":18544},{},[18545,18549],{"nodeType":864,"value":1521,"marks":18546,"data":18548},[18547],{"type":899},{},{"nodeType":864,"value":1526,"marks":18550,"data":18551},[],{},{"nodeType":860,"data":18553,"content":18554},{},[18555,18559,18562,18569,18572,18576],{"nodeType":864,"value":1533,"marks":18556,"data":18558},[18557],{"type":899},{},{"nodeType":864,"value":1538,"marks":18560,"data":18561},[],{},{"nodeType":883,"data":18563,"content":18564},{"uri":1543},[18565],{"nodeType":864,"value":1546,"marks":18566,"data":18568},[18567],{"type":1455},{},{"nodeType":864,"value":1551,"marks":18570,"data":18571},[],{},{"nodeType":864,"value":1555,"marks":18573,"data":18575},[18574],{"type":899},{},{"nodeType":864,"value":1560,"marks":18577,"data":18578},[],{},{"nodeType":860,"data":18580,"content":18581},{},[18582],{"nodeType":864,"value":1567,"marks":18583,"data":18584},[],{},{"nodeType":860,"data":18586,"content":18587},{},[18588,18591,18595],{"nodeType":864,"value":1574,"marks":18589,"data":18590},[],{},{"nodeType":864,"value":1578,"marks":18592,"data":18594},[18593],{"type":899},{},{"nodeType":864,"value":1583,"marks":18596,"data":18597},[],{},{"nodeType":996,"data":18599,"content":18602},{"target":18600},{"sys":18601},{"id":1590,"type":1001,"linkType":1002},[],{"nodeType":860,"data":18604,"content":18605},{},[18606,18609,18613],{"nodeType":864,"value":1596,"marks":18607,"data":18608},[],{},{"nodeType":864,"value":1600,"marks":18610,"data":18612},[18611],{"type":899},{},{"nodeType":864,"value":1605,"marks":18614,"data":18615},[],{},{"nodeType":860,"data":18617,"content":18618},{},[18619],{"nodeType":864,"value":1612,"marks":18620,"data":18621},[],{},{"nodeType":860,"data":18623,"content":18624},{},[18625],{"nodeType":864,"value":1619,"marks":18626,"data":18627},[],{},{"nodeType":1005,"data":18629,"content":18630},{},[],{"nodeType":1312,"data":18632,"content":18633},{},[18634],{"nodeType":864,"value":1629,"marks":18635,"data":18637},[18636],{"type":899},{},{"nodeType":860,"data":18639,"content":18640},{},[18641],{"nodeType":864,"value":1637,"marks":18642,"data":18643},[],{},{"nodeType":860,"data":18645,"content":18646},{},[18647],{"nodeType":864,"value":1644,"marks":18648,"data":18649},[],{},{"nodeType":860,"data":18651,"content":18652},{},[18653],{"nodeType":864,"value":1651,"marks":18654,"data":18655},[],{},{"nodeType":860,"data":18657,"content":18658},{},[18659],{"nodeType":864,"value":1658,"marks":18660,"data":18661},[],{},{"nodeType":860,"data":18663,"content":18664},{},[18665],{"nodeType":864,"value":1665,"marks":18666,"data":18667},[],{},{"nodeType":860,"data":18669,"content":18670},{},[18671],{"nodeType":864,"value":1672,"marks":18672,"data":18673},[],{},{"nodeType":1005,"data":18675,"content":18676},{},[],{"nodeType":860,"data":18678,"content":18679},{},[18680],{"nodeType":864,"value":1682,"marks":18681,"data":18682},[],{},{"nodeType":860,"data":18684,"content":18685},{},[18686],{"nodeType":864,"value":1689,"marks":18687,"data":18688},[],{},{"nodeType":860,"data":18690,"content":18691},{},[18692,18695,18702],{"nodeType":864,"value":21,"marks":18693,"data":18694},[],{},{"nodeType":883,"data":18696,"content":18697},{"uri":1700},[18698],{"nodeType":864,"value":1703,"marks":18699,"data":18701},[18700],{"type":1455},{},{"nodeType":864,"value":21,"marks":18703,"data":18704},[],{},{"items":18706},[18707,18709],{"sys":18708,"name":4904},{"id":4903},{"sys":18710,"name":545},{"id":4907},{"items":18712},[18713],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":18714},{"url":853},"blog/what-push-data-reveals-about-the-state-of-shadow-ai",{"json":18717},{"data":18718,"content":18719,"nodeType":856},{},[18720],{"data":18721,"content":18722,"nodeType":860},{},[18723],{"data":18724,"marks":18725,"value":18726,"nodeType":864},{},[],"Push telemetry shows that the average organization has 16 unique AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in active use — most of them unapproved. Shadow AI is arguably shadow SaaS with better marketing. But AI adoption has been a genuine force multiplier for the problem.",{"id":2061,"publishedAt":18728},"2026-08-13T11:44:25.332Z",{"items":18730},[18731,18733],{"sys":18732,"name":2729},{"id":2728},{"sys":18734,"name":297},{"id":2732},{"items":18736},[18737,18739,18741,18743,18745,18747,18749,18751,18753,18755,18757],{"sys":18738,"name":235,"slug":236,"tier":31},{"id":232},{"sys":18740,"name":545,"slug":546,"tier":31},{"id":542},{"sys":18742,"name":297,"slug":298,"tier":31},{"id":294},{"sys":18744,"name":413,"slug":414,"tier":31},{"id":410},{"sys":18746,"name":580,"slug":581,"tier":45},{"id":577},{"sys":18748,"name":589,"slug":590,"tier":45},{"id":586},{"sys":18750,"name":484,"slug":485,"tier":45},{"id":481},{"sys":18752,"name":288,"slug":289,"tier":45},{"id":285},{"sys":18754,"name":368,"slug":369,"tier":45},{"id":365},{"sys":18756,"name":633,"slug":634,"tier":45},{"id":630},{"sys":18758,"name":252,"slug":253,"tier":45},{"id":249},"Fve3K-AKY2ZaHd8DzKxQ7Gji-9e6fXsHOZB-s2X214A",{"id":18761,"title":18762,"authorsCollection":18763,"content":18771,"extension":228,"faqItemsCollection":19300,"faqTitle":59,"featured":6,"hashTags":59,"meta":19302,"metaTitle":19303,"ogImage":59,"postType":5726,"publishedDate":11982,"relatedBlogPostsCollection":19304,"slug":24237,"stem":24238,"subtitle":59,"summary":24239,"synopsis":24261,"sys":24262,"tagsCollection":24265,"topicsCollection":24271,"__hash__":24309},"blog/blog/7-things-we-learned-from-matt-johansen.json","What we learned from 'Security Theater vs. Security That Works' with Matt Johansen",{"items":18764},[18765],{"fullName":18766,"firstName":18767,"jobTitle":18768,"socialLinks":59,"profilePicture":18769},"Daniel Park","Daniel","Technical Content",{"url":18770},"https://images.ctfassets.net/y1cdw1ablpvd/6Cwg1xVeCdzUvxBIMfnDO5/6b18ed126b53611e7b521da34f900d29/254-0-2.jpg",{"json":18772,"links":19284},{"data":18773,"content":18774,"nodeType":856},{},[18775,18783,18790,18818,18825,18832,18835,18843,18850,18868,18875,18893,18896,18904,18911,18930,18949,18967,18970,18976,18982,18985,18993,19000,19016,19023,19026,19034,19073,19080,19087,19094,19102,19121,19139,19146,19153,19160,19178,19181,19189,19196,19214,19221,19228,19231,19253,19256,19262,19268],{"data":18776,"content":18777,"nodeType":1009},{},[18778],{"data":18779,"marks":18780,"value":18782,"nodeType":864},{},[18781],{"type":899},"1. Hackers don't hack in, they log in",{"data":18784,"content":18785,"nodeType":860},{},[18786],{"data":18787,"marks":18788,"value":18789,"nodeType":864},{},[],"Matt made the point early on that \"the modern web frameworks that have come out have done more to shift application security than any security vendor ever did.\" It's measurably harder to write exploitable code in 2026 than it was even five years ago, and the data reflects that — as Matt put it, \"most hacks that we read about these days are actually logins, not actually hacks in terms of vulnerabilities.\" Attackers aren't breaking in — they're logging in.",{"data":18791,"content":18792,"nodeType":860},{},[18793,18797,18802,18806,18814],{"data":18794,"marks":18795,"value":18796,"nodeType":864},{},[],"The data backs this up across the board. CrowdStrike's 2026 Global Threat Report found that ",{"data":18798,"marks":18799,"value":18801,"nodeType":864},{},[18800],{"type":899},"82% of attack detections are now malware-free",{"data":18803,"marks":18804,"value":18805,"nodeType":864},{},[]," — no exploit, no payload, just access and legitimate functionality being abused. ",{"data":18807,"content":18809,"nodeType":883},{"uri":18808},"https://services.google.com/fh/files/misc/cloud_threat_horizons_report_h12026.pdf",[18810],{"data":18811,"marks":18812,"value":18813,"nodeType":864},{},[],"Google/Mandiant",{"data":18815,"marks":18816,"value":18817,"nodeType":864},{},[]," recently reported that identity issues were the initial access vector in 83% of cloud-related incidents.",{"data":18819,"content":18820,"nodeType":860},{},[18821],{"data":18822,"marks":18823,"value":18824,"nodeType":864},{},[],"And when you look at the economics, the shift makes obvious sense: a browser RCE goes for around $250,000, while a PhaaS kit rental runs about $1,000 per year and a bulk stolen credential list costs $15. For a rational attacker, identity abuse isn't just easier — it's orders of magnitude cheaper.",{"data":18826,"content":18827,"nodeType":860},{},[18828],{"data":18829,"marks":18830,"value":18831,"nodeType":864},{},[],"This isn't a new observation, but it's one that still hasn't fully landed in how most organizations allocate their security budgets. The bulk of enterprise security spending is still pointed at the endpoint and the network — tooling built for an era when the primary threat was malware and exploitation. The threat model has moved, and for a lot of organizations, the stack hasn't moved with it.",{"data":18833,"content":18834,"nodeType":1005},{},[],{"data":18836,"content":18837,"nodeType":1009},{},[18838],{"data":18839,"marks":18840,"value":18842,"nodeType":864},{},[18841],{"type":899},"2. AI is a force multiplier, but it isn't a super hacker",{"data":18844,"content":18845,"nodeType":860},{},[18846],{"data":18847,"marks":18848,"value":18849,"nodeType":864},{},[],"The Mythos discourse has been hard to escape. As Matt put it, the view that \"the AI super hacker has escaped the lab\" is \"not actually what's going on.\" What's actually happening is that AI models trained to understand code are turning out to be very good at finding specific types of vulnerabilities in predominantly legacy codebases — but defenders stand to gain a lot too.",{"data":18851,"content":18852,"nodeType":860},{},[18853,18857,18865],{"data":18854,"marks":18855,"value":18856,"nodeType":864},{},[],"As Matt referenced, Google's CISO Heather Adkins said on stage at the Unprompted conference that Google's stated goal is \"to eliminate all software vulnerabilities, period.\" And browser zero-days already hit a ",{"data":18858,"content":18860,"nodeType":883},{"uri":18859},"https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review",[18861],{"data":18862,"marks":18863,"value":18864,"nodeType":864},{},[],"historic low at just 9% of all zero-days reported to Google in 2025",{"data":18866,"marks":18867,"value":2924,"nodeType":864},{},[],{"data":18869,"content":18870,"nodeType":860},{},[18871],{"data":18872,"marks":18873,"value":18874,"nodeType":864},{},[],"But won't AI-assisted vulnerability discovery eventually make browser exploits cheaper for attackers too? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":18876,"content":18877,"nodeType":860},{},[18878,18882,18889],{"data":18879,"marks":18880,"value":18881,"nodeType":864},{},[],"As Matt noted, \"they didn't train these models to be good at cybersecurity — they just trained them to get better and better at code,\" and big tech vendors like Google have the resources to really invest in these tools. The rational play for attackers is the same one it's been for years: skip the exploit development entirely and ",{"data":18883,"content":18884,"nodeType":883},{"uri":7549},[18885],{"data":18886,"marks":18887,"value":18888,"nodeType":864},{},[],"steal identities and sessions in the browser",{"data":18890,"marks":18891,"value":18892,"nodeType":864},{},[]," instead.",{"data":18894,"content":18895,"nodeType":1005},{},[],{"data":18897,"content":18898,"nodeType":1009},{},[18899],{"data":18900,"marks":18901,"value":18903,"nodeType":864},{},[18902],{"type":899},"3. MFA is essential — but it isn't a silver bullet",{"data":18905,"content":18906,"nodeType":860},{},[18907],{"data":18908,"marks":18909,"value":18910,"nodeType":864},{},[],"Nobody's arguing against MFA. It's one of the most important security controls any organization can deploy, and both Matt and Mark were clear about that. But the conversation surfaced something that doesn't get enough attention: there are always gaps in coverage, and attackers have consistently found ways under, over, or through it.",{"data":18912,"content":18913,"nodeType":860},{},[18914,18918,18926],{"data":18915,"marks":18916,"value":18917,"nodeType":864},{},[],"Mark observed that every organization he talks to says they're in the process of \"rolling out\" MFA. It's always in progress, never complete — there's always an app that doesn't support it, a legacy system that can't handle it, a user population that hasn't been migrated, or a SaaS vendor charging extra for the privilege (the ",{"data":18919,"content":18921,"nodeType":883},{"uri":18920},"https://pushsecurity.com/blog/minimum-viable-identity-security/",[18922],{"data":18923,"marks":18924,"value":18925,"nodeType":864},{},[],"security tax",{"data":18927,"marks":18928,"value":18929,"nodeType":864},{},[],"). Coverage gaps are the norm, not the exception.",{"data":18931,"content":18932,"nodeType":860},{},[18933,18937,18945],{"data":18934,"marks":18935,"value":18936,"nodeType":864},{},[],"Then there's the bypass evolution. Matt walked through the history — SMS and SIM swapping, push notifications and push fatigue, and now ",{"data":18938,"content":18940,"nodeType":883},{"uri":18939},"https://pushsecurity.com/blog/2025-top-phishing-trends/",[18941],{"data":18942,"marks":18943,"value":18944,"nodeType":864},{},[],"AiTM kits ",{"data":18946,"marks":18947,"value":18948,"nodeType":864},{},[],"that proxy the entire authentication flow, capturing both the password and the MFA token in a single attack. Every step up the MFA ladder, attackers have found a way around. Phishing-resistant methods like hardware tokens and passkeys are a meaningful improvement, but rollout is slow and uneven.",{"data":18950,"content":18951,"nodeType":860},{},[18952,18956,18963],{"data":18953,"marks":18954,"value":18955,"nodeType":864},{},[],"And then there's the class of attacks that sidestep authentication entirely. Consent phishing, ",{"data":18957,"content":18958,"nodeType":883},{"uri":3259},[18959],{"data":18960,"marks":18961,"value":18962,"nodeType":864},{},[],"device code phishing",{"data":18964,"marks":18965,"value":18966,"nodeType":864},{},[],", session hijacking — these are all post-authentication attacks. The user has already authenticated successfully, the MFA did its job, and the attacker is going after what comes after: OAuth tokens, session cookies, consent grants. Matt compared these to zero days for identity — they bypass the entire front end of your defensive stack. MFA is absolutely something you should be rolling out and strengthening, but it's one layer in what needs to be a deeper defense.",{"data":18968,"content":18969,"nodeType":1005},{},[],{"data":18971,"content":18975,"nodeType":996},{"target":18972},{"sys":18973},{"id":18974,"type":1001,"linkType":1002},"7upGHPt7eVNji6v22h124t",[],{"data":18977,"content":18981,"nodeType":996},{"target":18978},{"sys":18979},{"id":18980,"type":1001,"linkType":1002},"53U3LHhhHFYnEpShdLmDqs",[],{"data":18983,"content":18984,"nodeType":1005},{},[],{"data":18986,"content":18987,"nodeType":1009},{},[18988],{"data":18989,"marks":18990,"value":18992,"nodeType":864},{},[18991],{"type":899},"4. User training is not enough: better technical controls are required",{"data":18994,"content":18995,"nodeType":860},{},[18996],{"data":18997,"marks":18998,"value":18999,"nodeType":864},{},[],"Matt was blunt on this one: \"If those tips worked, cybersecurity as a profession would be out of business.\" 20+ years of user awareness training, and phishing is arguably more effective than ever. The standard advice — hover over links, check the sender, look for typos — assumes a level of sustained vigilance that no human can maintain across every interaction, every day.",{"data":19001,"content":19002,"nodeType":860},{},[19003,19007,19012],{"data":19004,"marks":19005,"value":19006,"nodeType":864},{},[],"What made his point land was the contrast between the comment sections on his ClickFix content — \"Who the hell would fall for this?\" — and the reality that ",{"data":19008,"marks":19009,"value":19011,"nodeType":864},{},[19010],{"type":899},"every incident response professional he knows is currently working a ClickFix case. ",{"data":19013,"marks":19014,"value":19015,"nodeType":864},{},[],"The people saying nobody would fall for it are not the people cleaning up after it.",{"data":19017,"content":19018,"nodeType":860},{},[19019],{"data":19020,"marks":19021,"value":19022,"nodeType":864},{},[],"Matt also brought the recent Lazarus group fake job scams: threat actors spending six months building trust with a target — meeting in person at conferences, multiple times — before eventually getting them to install a malicious browser extension during a Zoom call. All of the social engineering that precedes the actual compromise is just trust-building, and the sophistication of that trust-building is increasing faster than any training program can keep up with. You need defensive layers that don't depend on the user making the right call every single time.",{"data":19024,"content":19025,"nodeType":1005},{},[],{"data":19027,"content":19028,"nodeType":1009},{},[19029],{"data":19030,"marks":19031,"value":19033,"nodeType":864},{},[19032],{"type":899},"5. Every IR pro you know is working a ClickFix case",{"data":19035,"content":19036,"nodeType":860},{},[19037,19041,19048,19052,19060,19063,19069],{"data":19038,"marks":19039,"value":19040,"nodeType":864},{},[],"ClickFix came up repeatedly, and for good reason — it's one of the ",{"data":19042,"content":19043,"nodeType":883},{"uri":7549},[19044],{"data":19045,"marks":19046,"value":19047,"nodeType":864},{},[],"most common initial access vectors",{"data":19049,"marks":19050,"value":19051,"nodeType":864},{},[]," being reported right now. Matt said he doesn't know a single IR professional in his network who \"isn't actively working a ClickFix-related case.\" The technique, which tricks users into copying and pasting malicious commands, has spawned an entire family of variants (",{"data":19053,"content":19054,"nodeType":883},{"uri":11738},[19055],{"data":19056,"marks":19057,"value":19059,"nodeType":864},{},[19058],{"type":1455},"InstallFix",{"data":19061,"marks":19062,"value":3731,"nodeType":864},{},[],{"data":19064,"content":19065,"nodeType":883},{"uri":11726},[19066],{"data":19067,"marks":19068,"value":11731,"nodeType":864},{},[],{"data":19070,"marks":19071,"value":19072,"nodeType":864},{},[],", and others), and they're evolving fast.",{"data":19074,"content":19075,"nodeType":860},{},[19076],{"data":19077,"marks":19078,"value":19079,"nodeType":864},{},[],"Matt shared a particularly good example of why the \"just don't fall for it\" advice falls apart. Attackers were paying for ads promoting ChatGPT chat history links on technical search queries — things like \"how to clean up disk space on Mac.\" The top result was a legitimate-looking ChatGPT interface with what appeared to be helpful terminal commands.",{"data":19081,"content":19082,"nodeType":860},{},[19083],{"data":19084,"marks":19085,"value":19086,"nodeType":864},{},[],"The user was already looking for commands to copy and paste into their terminal. The attack didn't need to trick them into doing something unusual — it just showed up in the exact context where copy-pasting commands was the expected behavior.",{"data":19088,"content":19089,"nodeType":860},{},[19090],{"data":19091,"marks":19092,"value":19093,"nodeType":864},{},[],"The new variants keep appearing because the underlying technique is modular — the trust-building wrapper changes (fake CAPTCHAs, fake error messages, fake install instructions, fake AI chat interfaces), but the core mechanic is the same. What makes it dangerous is that each new wrapper goes quasi-viral among attackers when it proves successful, which means the window between a new variant appearing and widespread adoption is very short.",{"data":19095,"content":19096,"nodeType":1009},{},[19097],{"data":19098,"marks":19099,"value":19101,"nodeType":864},{},[19100],{"type":899},"6. Browser extensions are the threat that never went away (and it's a bigger problem than ever)",{"data":19103,"content":19104,"nodeType":860},{},[19105,19109,19117],{"data":19106,"marks":19107,"value":19108,"nodeType":864},{},[],"Browser extensions are a topic we've ",{"data":19110,"content":19112,"nodeType":883},{"uri":19111},"https://pushsecurity.com/resources/browser-extensions-webinar",[19113],{"data":19114,"marks":19115,"value":19116,"nodeType":864},{},[],"covered in depth before",{"data":19118,"marks":19119,"value":19120,"nodeType":864},{},[],", and Matt's perspective reinforced why. His first conference talk — Black Hat and DEF CON in 2011 — was about Chrome extension security. As he put it: \"I could give that talk right now with very few changes to the slides and it would still be extremely relevant.\"",{"data":19122,"content":19123,"nodeType":860},{},[19124,19128,19135],{"data":19125,"marks":19126,"value":19127,"nodeType":864},{},[],"The core problem hasn't moved: ",{"data":19129,"content":19130,"nodeType":883},{"uri":2411},[19131],{"data":19132,"marks":19133,"value":19134,"nodeType":864},{},[],"extensions need broad permissions to function",{"data":19136,"marks":19137,"value":19138,"nodeType":864},{},[],", even for completely legitimate use cases. A password manager needs to read login forms on every website. A dark mode extension needs to modify the DOM on every page. An RSS reader needs access to arbitrary sites. These aren't excessive permissions — they're the minimum required for the extension to do what it advertises.",{"data":19140,"content":19141,"nodeType":860},{},[19142],{"data":19143,"marks":19144,"value":19145,"nodeType":864},{},[],"What's making it worse is the AI adoption wave. Many AI tools ship with browser extension counterparts, and employees are installing them alongside the apps themselves — often without approval. The broader rush to adopt AI tooling is acting as a force multiplier for the shadow SaaS problem that security teams have been struggling with for years, and extensions are a big part of that.",{"data":19147,"content":19148,"nodeType":860},{},[19149],{"data":19150,"marks":19151,"value":19152,"nodeType":864},{},[],"The ways extensions get compromised vary. Users still get tricked into installing something malicious from the start, but legitimate extensions also turn malicious after the fact. Matt outlined several mechanisms: developer accounts getting compromised and attackers pushing malicious updates to the existing user base; extension developers accepting monetization deals that turn out to be data-harvesting operations; and threat actors outright purchasing extensions with established user bases and then pushing malware to them.",{"data":19154,"content":19155,"nodeType":860},{},[19156],{"data":19157,"marks":19158,"value":19159,"nodeType":864},{},[],"The Chrome Web Store doesn't solve this. Matt noted that he uploaded a proof-of-concept extension literally called \"Malicious Extension\" and it made it onto the store. There's some review process, but it's not real-time, it's not continuous, and it doesn't cover updates after initial submission.",{"data":19161,"content":19162,"nodeType":860},{},[19163,19167,19174],{"data":19164,"marks":19165,"value":19166,"nodeType":864},{},[],"Even organizations with a formal extension approval process typically only look at the extension once — at install time. Nobody's reviewing every update to every approved extension. And the risk assessment? \"It's mostly based on vibes. There's very little science here.\" Even at organizations with mature security programs, Matt hasn't seen many that have ",{"data":19168,"content":19169,"nodeType":883},{"uri":11825},[19170],{"data":19171,"marks":19172,"value":19173,"nodeType":864},{},[],"real-time, ongoing visibility",{"data":19175,"marks":19176,"value":19177,"nodeType":864},{},[]," into what's happening inside their employees' browser extensions.",{"data":19179,"content":19180,"nodeType":1005},{},[],{"data":19182,"content":19183,"nodeType":1009},{},[19184],{"data":19185,"marks":19186,"value":19188,"nodeType":864},{},[19187],{"type":899},"7. You have 30 minutes to respond to a cloud intrusion — and revoking the token isn't enough",{"data":19190,"content":19191,"nodeType":860},{},[19192],{"data":19193,"marks":19194,"value":19195,"nodeType":864},{},[],"Matt was direct about the speed benchmark practitioners should be targeting: meaningful containment and eradication within about 30 minutes, because attackers are partially achieving their objectives in 20 to 40 minutes and significantly past the point of no return within an hour.",{"data":19197,"content":19198,"nodeType":860},{},[19199,19203,19210],{"data":19200,"marks":19201,"value":19202,"nodeType":864},{},[],"The data supports this picture. CrowdStrike reports that the average e-crime \"breakout time\" (moving from initial access to high-value assets) is now just 29 minutes, while Google reports that the median time between initial access and hand-off to a secondary group has collapsed from ",{"data":19204,"content":19205,"nodeType":883},{"uri":3837},[19206],{"data":19207,"marks":19208,"value":19209,"nodeType":864},{},[],"over 8 hours in 2022 to just 22 seconds in 2025",{"data":19211,"marks":19212,"value":19213,"nodeType":864},{},[]," — pointing to a highly automated, interconnected, and professionalized threat actor ecosystem.",{"data":19215,"content":19216,"nodeType":860},{},[19217],{"data":19218,"marks":19219,"value":19220,"nodeType":864},{},[],"But speed alone isn't the problem Matt emphasized — it's that the containment actions practitioners think they have don't actually work the way they expect. His anecdote about revoking an IdP OAuth token and assuming the session was killed, only to discover that the 200 downstream SaaS session tokens were still live, will resonate with anyone who has worked an identity-based incident.",{"data":19222,"content":19223,"nodeType":860},{},[19224],{"data":19225,"marks":19226,"value":19227,"nodeType":864},{},[],"You can't move that fast if you're figuring out what your tools can and can't do during the incident. The teams that handle these situations well are the ones that have taken stock of their actual capabilities beforehand — what their IdP revokes, what it doesn't, which SaaS apps have independent session management, where the gaps are. The teams that don't are the ones at \"1 AM with a pager in hand going, 'What the hell do I do now?'\" as Matt described it. \"Ask me how I know.\"",{"data":19229,"content":19230,"nodeType":1005},{},[],{"data":19232,"content":19233,"nodeType":1116},{},[19234],{"data":19235,"content":19236,"nodeType":860},{},[19237,19241,19249],{"data":19238,"marks":19239,"value":19240,"nodeType":864},{},[],"This post is a recap of ",{"data":19242,"content":19244,"nodeType":883},{"uri":19243},"https://pushsecurity.com/resources/security-theatre-vs-security-works",[19245],{"data":19246,"marks":19247,"value":19248,"nodeType":864},{},[],"Security theatre vs. security that works",{"data":19250,"marks":19251,"value":19252,"nodeType":864},{},[],", the third episode in Push Security's webcast series on the state of browser attacks. Watch the full recording for the complete conversation, including live Q&A with Mark and Matt.",{"data":19254,"content":19255,"nodeType":1005},{},[],{"data":19257,"content":19258,"nodeType":860},{},[19259],{"data":19260,"marks":19261,"value":1682,"nodeType":864},{},[],{"data":19263,"content":19264,"nodeType":860},{},[19265],{"data":19266,"marks":19267,"value":1689,"nodeType":864},{},[],{"data":19269,"content":19270,"nodeType":860},{},[19271,19274,19281],{"data":19272,"marks":19273,"value":21,"nodeType":864},{},[],{"data":19275,"content":19276,"nodeType":883},{"uri":1700},[19277],{"data":19278,"marks":19279,"value":13763,"nodeType":864},{},[19280],{"type":1455},{"data":19282,"marks":19283,"value":2719,"nodeType":864},{},[],{"entries":19285},{"hyperlink":19286,"inline":19287,"block":19288},[],[],[19289,19293],{"sys":19290,"__typename":1717,"type":1718,"ctaText":19291,"buttonLabel":19292,"buttonColour":1721,"buttonUrl":11562},{"id":18974},"Check out our browser and identity attacks matrix for a comprehensive overview of attack techniques using a MITRE-inspired mapping.","Check it out",{"sys":19294,"__typename":1724,"title":11754,"caption":19295,"layoutMode":59,"file":19296},{"id":18980},"Browser and identity-based techniques have exploded since we first launched our attack matrix",{"url":19297,"width":19298,"height":19299},"https://images.ctfassets.net/y1cdw1ablpvd/L0Yc77y9vzrKVD72BQGX2/4ffe0bf61bd62f025262b8efd74394b7/Browser___Identity_Attacks_Matrix__1_.png",6160,4432,{"items":19301},[],{},"7 things we learned from our conversation with Matt Johansen",{"items":19305},[19306,22314,23395],{"__typename":2059,"sys":19307,"content":19309,"title":22297,"synopsis":22298,"hashTags":59,"publishedDate":22299,"slug":361,"tagsCollection":22300,"authorsCollection":22306},{"id":19308},"5DmCqTU2Tg4adYScA5vT2x",{"json":19310},{"data":19311,"content":19312,"nodeType":856},{},[19313,19319,19339,19357,19364,19370,19377,19384,19387,19395,19401,19485,19505,19511,19518,19633,19639,19642,19650,19657,19663,19666,19674,19715,19721,19728,19735,19742,19749,19768,19774,19780,19786,19792,19798,19804,19810,19816,20079,20082,20090,20225,20231,20234,20242,20282,20416,20422,20425,20433,20580,20586,20589,20597,20603,20743,20749,20755,20758,20766,20913,20919,20922,20930,21076,21082,21085,21093,21188,21194,21197,21205,21299,21305,21308,21316,21322,21455,21461,21464,21472,21521,21527,21530,21538,21677,21682,21685,21693,21825,21831,21834,21842,21854,21861,21867,21873,21880,21901,21917,21923,21926,21934,21942,21963,21984,21989,21996,22003,22011,22018,22025,22032,22040,22047,22098,22104,22107,22115,22122,22129,22176,22182,22189,22192,22200,22207,22214,22234,22240,22247,22254,22261],{"data":19314,"content":19318,"nodeType":996},{"target":19315},{"sys":19316},{"id":19317,"type":1001,"linkType":1002},"XOFOeNqmRHeiRbkPOJrP1",[],{"data":19320,"content":19321,"nodeType":860},{},[19322,19326,19335],{"data":19323,"marks":19324,"value":19325,"nodeType":864},{},[],"The OAuth 2.0 ",{"data":19327,"content":19329,"nodeType":883},{"uri":19328},"https://www.rfc-editor.org/rfc/rfc8628",[19330],{"data":19331,"marks":19332,"value":19334,"nodeType":864},{},[19333],{"type":1455},"device authorization grant",{"data":19336,"marks":19337,"value":19338,"nodeType":864},{},[]," was designed to enable input-constrained devices to sign-in to apps by asking the user to complete the login on a separate device by entering a code. But today, it’s mainly used when accessing CLI tools, meaning that many users encounter the device code flow daily. ",{"data":19340,"content":19341,"nodeType":860},{},[19342,19345,19353],{"data":19343,"marks":19344,"value":21,"nodeType":864},{},[],{"data":19346,"content":19348,"nodeType":883},{"uri":19347},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_code_phishing/description.md",[19349],{"data":19350,"marks":19351,"value":360,"nodeType":864},{},[19352],{"type":1455},{"data":19354,"marks":19355,"value":19356,"nodeType":864},{},[]," attacks designed to exploit this authorization flow are not new — it was among the first techniques that we added to the SaaS attacks matrix back in 2023. But it’s taken until now for it to really enter mainstream adoption. ",{"data":19358,"content":19359,"nodeType":860},{},[19360],{"data":19361,"marks":19362,"value":19363,"nodeType":864},{},[],"The technique tricks a user into issuing access tokens for an attacker-controlled application (not a device, confusingly). Any app that supports device code logins can be a target. Popular examples include Microsoft, Google, Salesforce, GitHub, and AWS. That said, Microsoft is, as always, much more heavily targeted at scale now than any other app.",{"data":19365,"content":19369,"nodeType":996},{"target":19366},{"sys":19367},{"id":19368,"type":1001,"linkType":1002},"Al0pGH8vmOYiufDFiAbt0",[],{"data":19371,"content":19372,"nodeType":860},{},[19373],{"data":19374,"marks":19375,"value":19376,"nodeType":864},{},[],"We’ve always been surprised that attackers haven’t commonly used device code phishing in their standard toolkit, preferring session-stealing AITM phishing and other social engineering attacks like ClickFix. But it’s pretty clear from the recent data that the shift to mainstream adoption has now happened. ",{"data":19378,"content":19379,"nodeType":860},{},[19380],{"data":19381,"marks":19382,"value":19383,"nodeType":864},{},[],"In this blog post, we’ll explore the history of device code phishing, what’s changed for it to enter mainstream adoption, how it works under the hood (with recent examples), and what security teams can do about it. ",{"data":19385,"content":19386,"nodeType":1005},{},[],{"data":19388,"content":19389,"nodeType":1009},{},[19390],{"data":19391,"marks":19392,"value":19394,"nodeType":864},{},[19393],{"type":899},"A brief history of device code phishing",{"data":19396,"content":19400,"nodeType":996},{"target":19397},{"sys":19398},{"id":19399,"type":1001,"linkType":1002},"6u3DgvSGChtTJu7l9I7PG1",[],{"data":19402,"content":19403,"nodeType":860},{},[19404,19408,19417,19421,19430,19434,19443,19447,19456,19460,19469,19472,19481],{"data":19405,"marks":19406,"value":19407,"nodeType":864},{},[],"The technique was first documented in 2020, before Secureworks released the first tooling framework ",{"data":19409,"content":19411,"nodeType":883},{"uri":19410},"https://github.com/secureworks/PhishInSuits",[19412],{"data":19413,"marks":19414,"value":19416,"nodeType":864},{},[19415],{"type":1455},"PhishInSuits",{"data":19418,"marks":19419,"value":19420,"nodeType":864},{},[]," a year later. A host of research followed, including ",{"data":19422,"content":19424,"nodeType":883},{"uri":19423},"https://github.com/secureworks/squarephish",[19425],{"data":19426,"marks":19427,"value":19429,"nodeType":864},{},[19428],{"type":1455},"SquarePhish",{"data":19431,"marks":19432,"value":19433,"nodeType":864},{},[]," v1 (using QR codes to trigger the 15 minute code expiration window), Dirk-Jan Mollema’s ",{"data":19435,"content":19437,"nodeType":883},{"uri":19436},"https://dirkjanm.io/phishing-for-microsoft-entra-primary-refresh-tokens/",[19438],{"data":19439,"marks":19440,"value":19442,"nodeType":864},{},[19441],{"type":1455},"key research",{"data":19444,"marks":19445,"value":19446,"nodeType":864},{},[]," (chaining device code phishing via Microsoft apps into Primary Refresh Token (PRT) acquisition to gain full browser-level access) and Dennis Kniep’s ",{"data":19448,"content":19450,"nodeType":883},{"uri":19449},"https://github.com/denniskniep/DeviceCodePhishing",[19451],{"data":19452,"marks":19453,"value":19455,"nodeType":864},{},[19454],{"type":1455},"DeviceCodePhishing tool",{"data":19457,"marks":19458,"value":19459,"nodeType":864},{},[]," which automates the entire flow with a headless browser. (Other recent noteworthy tools include ",{"data":19461,"content":19463,"nodeType":883},{"uri":19462},"https://github.com/nromsdahl/squarephish2",[19464],{"data":19465,"marks":19466,"value":19468,"nodeType":864},{},[19467],{"type":1455},"SquarePhish2",{"data":19470,"marks":19471,"value":902,"nodeType":864},{},[],{"data":19473,"content":19475,"nodeType":883},{"uri":19474},"https://github.com/praetorian-inc/GitPhish",[19476],{"data":19477,"marks":19478,"value":19480,"nodeType":864},{},[19479],{"type":1455},"GitPhish",{"data":19482,"marks":19483,"value":19484,"nodeType":864},{},[],", so shout out to those too). ",{"data":19486,"content":19487,"nodeType":860},{},[19488,19492,19501],{"data":19489,"marks":19490,"value":19491,"nodeType":864},{},[],"It wasn’t until August 2024 that in-the-wild exploitation was first identified, with Russia-linked campaigns then continuing into 2025 before entering mainstream criminal adoption. This trend has continued to gather momentum in 2026 with ",{"data":19493,"content":19495,"nodeType":883},{"uri":19494},"https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html",[19496],{"data":19497,"marks":19498,"value":19500,"nodeType":864},{},[19499],{"type":1455},"EvilTokens",{"data":19502,"marks":19503,"value":19504,"nodeType":864},{},[],", the first reported criminal PhaaS kit for device code phishing, already powering massive campaigns after launching in February. ",{"data":19506,"content":19510,"nodeType":996},{"target":19507},{"sys":19508},{"id":19509,"type":1001,"linkType":1002},"6xsfmbYEzpW7CdDiNzO6cu",[],{"data":19512,"content":19513,"nodeType":860},{},[19514],{"data":19515,"marks":19516,"value":19517,"nodeType":864},{},[],"Some of the noteworthy in-the-wild campaigns include:",{"data":19519,"content":19520,"nodeType":941},{},[19521,19554,19574],{"data":19522,"content":19523,"nodeType":945},{},[19524],{"data":19525,"content":19526,"nodeType":860},{},[19527,19531,19539,19542,19550],{"data":19528,"marks":19529,"value":19530,"nodeType":864},{},[],"Storm-2372, tracked by ",{"data":19532,"content":19534,"nodeType":883},{"uri":19533},"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/",[19535],{"data":19536,"marks":19537,"value":19538,"nodeType":864},{},[],"Microsoft",{"data":19540,"marks":19541,"value":902,"nodeType":864},{},[],{"data":19543,"content":19545,"nodeType":883},{"uri":19544},"https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/",[19546],{"data":19547,"marks":19548,"value":19549,"nodeType":864},{},[],"Volexity",{"data":19551,"marks":19552,"value":19553,"nodeType":864},{},[],", linked to multiple Russia-aligned clusters, combining spear-phishing and social engineering with device code phishing payloads against strategic intelligence targets.",{"data":19555,"content":19556,"nodeType":945},{},[19557],{"data":19558,"content":19559,"nodeType":860},{},[19560,19564,19570],{"data":19561,"marks":19562,"value":19563,"nodeType":864},{},[],"The massive Salesforce campaign operated by ",{"data":19565,"content":19566,"nodeType":883},{"uri":16015},[19567],{"data":19568,"marks":19569,"value":16018,"nodeType":864},{},[],{"data":19571,"marks":19572,"value":19573,"nodeType":864},{},[]," (SLH) combined vishing with a device code phishing payload targeting Salesforce. The attacks morphed into a broader supply chain campaign using stolen credentials, ultimately resulting in 1000+ organizations being compromised and over 1.5 billion stolen records claimed. ",{"data":19575,"content":19576,"nodeType":945},{},[19577],{"data":19578,"content":19579,"nodeType":860},{},[19580,19584,19592,19596,19605,19608,19617,19621,19629],{"data":19581,"marks":19582,"value":19583,"nodeType":864},{},[],"A massive spike in activity in late 2025 and 2026. This includes ",{"data":19585,"content":19587,"nodeType":883},{"uri":19586},"https://www.proofpoint.com/us/blog/threat-insight/access-granted-phishing-device-code-authorization-account-takeover",[19588],{"data":19589,"marks":19590,"value":19591,"nodeType":864},{},[],"multiple threat clusters",{"data":19593,"marks":19594,"value":19595,"nodeType":864},{},[]," tracked using device code phishing techniques, more ",{"data":19597,"content":19599,"nodeType":883},{"uri":19598},"https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/",[19600],{"data":19601,"marks":19602,"value":19604,"nodeType":864},{},[19603],{"type":1455},"criminal operations linked to SLH",{"data":19606,"marks":19607,"value":2232,"nodeType":864},{},[],{"data":19609,"content":19611,"nodeType":883},{"uri":19610},"https://newtonpaul.com/blog/device-code-phish-update/",[19612],{"data":19613,"marks":19614,"value":19616,"nodeType":864},{},[19615],{"type":1455},"hundreds of organizations being targeted via PhaaS architecture,",{"data":19618,"marks":19619,"value":19620,"nodeType":864},{},[]," which looks to be the same campaign as the recently uncovered EvilTokens PhaaS reported by ",{"data":19622,"content":19623,"nodeType":883},{"uri":7018},[19624],{"data":19625,"marks":19626,"value":19628,"nodeType":864},{},[19627],{"type":1455},"Huntress",{"data":19630,"marks":19631,"value":19632,"nodeType":864},{},[]," (featuring abuse of the Railway PaaS platform). ",{"data":19634,"content":19638,"nodeType":996},{"target":19635},{"sys":19636},{"id":19637,"type":1001,"linkType":1002},"3WLt6qLCK8CSwr0QZxZiMv",[],{"data":19640,"content":19641,"nodeType":1005},{},[],{"data":19643,"content":19644,"nodeType":1009},{},[19645],{"data":19646,"marks":19647,"value":19649,"nodeType":864},{},[19648],{"type":899},"What we’re seeing in the wild",{"data":19651,"content":19652,"nodeType":860},{},[19653],{"data":19654,"marks":19655,"value":19656,"nodeType":864},{},[],"As mentioned, we’ve also seen a huge spike in device code phishing activity this year, with multiple kits, page designs, and lure types. We’ve now identified 14+ distinct kits in circulation in the wild, with EvilTokens being the most prevalent. It’s clear that attackers are both spinning up their own kits and creative derivatives of others — we’ve seen kits that are visually similar to EvilTokens (close enough to be clones or forks) but with very different backends, for example AWS, Digital Ocean, 2cloud, and more. ",{"data":19658,"content":19662,"nodeType":996},{"target":19659},{"sys":19660},{"id":19661,"type":1001,"linkType":1002},"nJCbTw85GKXdqrlIkzZwi",[],{"data":19664,"content":19665,"nodeType":1005},{},[],{"data":19667,"content":19668,"nodeType":1312},{},[19669],{"data":19670,"marks":19671,"value":19673,"nodeType":864},{},[19672],{"type":899},"“ANTIBOT” (EvilTokens)",{"data":19675,"content":19676,"nodeType":860},{},[19677,19680,19687,19690,19699,19703,19711],{"data":19678,"marks":19679,"value":21,"nodeType":864},{},[],{"data":19681,"content":19682,"nodeType":883},{"uri":7018},[19683],{"data":19684,"marks":19685,"value":19628,"nodeType":864},{},[19686],{"type":1455},{"data":19688,"marks":19689,"value":3731,"nodeType":864},{},[],{"data":19691,"content":19693,"nodeType":883},{"uri":19692},"https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/",[19694],{"data":19695,"marks":19696,"value":19698,"nodeType":864},{},[19697],{"type":1455},"Sekoia",{"data":19700,"marks":19701,"value":19702,"nodeType":864},{},[],", and researcher ",{"data":19704,"content":19705,"nodeType":883},{"uri":19610},[19706],{"data":19707,"marks":19708,"value":19710,"nodeType":864},{},[19709],{"type":1455},"Paul Newton",{"data":19712,"marks":19713,"value":19714,"nodeType":864},{},[]," have already done a great job of providing IOCs for the recent EvilTokens activity spike, including multiple backend Railway IPs in authentication events. ",{"data":19716,"content":19720,"nodeType":996},{"target":19717},{"sys":19718},{"id":19719,"type":1001,"linkType":1002},"1XNviq5OvMf5TEAc59F6g5",[],{"data":19722,"content":19723,"nodeType":860},{},[19724],{"data":19725,"marks":19726,"value":19727,"nodeType":864},{},[],"Beyond the most widely observed implementation featuring a Cloudflare Workers frontend and Railway backend for authentication, we’ve also tracked additional versions of EvilTokens in circulation since January 2026 (many of which remain live along with the current “production” version of the kit). ",{"data":19729,"content":19730,"nodeType":860},{},[19731],{"data":19732,"marks":19733,"value":19734,"nodeType":864},{},[],"You can see an evolution of the kit in the videos and screenshots below, from early precursors seen in mid-January, the first mentions of ANTIBOT in the page code in late-January, the parallel development of a “Courts Access” fork that lacks the ANTIBOT references, and finally production EvilTokens in February. One of the key threads between the versions is the presence of a generateFallbackCode() JS function and use of a /generate-codes API call. ",{"data":19736,"content":19737,"nodeType":860},{},[19738],{"data":19739,"marks":19740,"value":19741,"nodeType":864},{},[],"Early implementations were quite different, for example using ScrapingBee to generate the displayed code, and varied hosting on vercel, fastly, edgeone, and others. ",{"data":19743,"content":19744,"nodeType":860},{},[19745],{"data":19746,"marks":19747,"value":19748,"nodeType":864},{},[],"After initially appearing on custom domains, the production version is now predominantly hosted on Cloudflare Workers, as per the broader tracking of the campaign. The descriptive HTML comments around ANTIBOT functions have also been removed in later versions. ",{"data":19750,"content":19751,"nodeType":860},{},[19752,19756,19764],{"data":19753,"marks":19754,"value":19755,"nodeType":864},{},[],"The production version of EvilTokens showcases common ",{"data":19757,"content":19758,"nodeType":883},{"uri":14307},[19759],{"data":19760,"marks":19761,"value":19763,"nodeType":864},{},[19762],{"type":1455},"detection evasion techniques",{"data":19765,"marks":19766,"value":19767,"nodeType":864},{},[]," we've come to associate with PhaaS kits in the AiTM space — using multiple redirects through trusted sites before serving the malicious page, using bot protection to block security tools from analyzing the page, and so on. It also uses a pop-up window for the device code entry rather than a redirect, reducing the friction for the victim (it looks pretty convincing, too).",{"data":19769,"content":19773,"nodeType":996},{"target":19770},{"sys":19771},{"id":19772,"type":1001,"linkType":1002},"73rNOIEDPfP5IJwpFaxVc2",[],{"data":19775,"content":19779,"nodeType":996},{"target":19776},{"sys":19777},{"id":19778,"type":1001,"linkType":1002},"5BJSvOQUW9UpsQtoDNtgTC",[],{"data":19781,"content":19785,"nodeType":996},{"target":19782},{"sys":19783},{"id":19784,"type":1001,"linkType":1002},"3dbePPxVb4h4SauGg3glIL",[],{"data":19787,"content":19791,"nodeType":996},{"target":19788},{"sys":19789},{"id":19790,"type":1001,"linkType":1002},"1UOLcmNQvOsL5tdLSVuviq",[],{"data":19793,"content":19797,"nodeType":996},{"target":19794},{"sys":19795},{"id":19796,"type":1001,"linkType":1002},"55XRqLSwUUi2D4ZVpJboml",[],{"data":19799,"content":19803,"nodeType":996},{"target":19800},{"sys":19801},{"id":19802,"type":1001,"linkType":1002},"5wg5yr2Lo8t3f72ZV815c",[],{"data":19805,"content":19809,"nodeType":996},{"target":19806},{"sys":19807},{"id":19808,"type":1001,"linkType":1002},"35cowlL6i3rkGXOGmSxlI1",[],{"data":19811,"content":19812,"nodeType":860},{},[19813],{"data":19814,"marks":19815,"value":21,"nodeType":864},{},[],{"data":19817,"content":19818,"nodeType":4845},{},[19819,19843,19926,19978,20002],{"data":19820,"content":19821,"nodeType":4581},{},[19822,19833],{"data":19823,"content":19824,"nodeType":4569},{},[19825],{"data":19826,"content":19827,"nodeType":860},{},[19828],{"data":19829,"marks":19830,"value":19832,"nodeType":864},{},[19831],{"type":899},"Frontend infrastructure",{"data":19834,"content":19835,"nodeType":4569},{},[19836],{"data":19837,"content":19838,"nodeType":860},{},[19839],{"data":19840,"marks":19841,"value":19842,"nodeType":864},{},[],"Workers.dev, vercel.app, github.io, fastly.net, edgeone.dev",{"data":19844,"content":19845,"nodeType":4581},{},[19846,19857],{"data":19847,"content":19848,"nodeType":4569},{},[19849],{"data":19850,"content":19851,"nodeType":860},{},[19852],{"data":19853,"marks":19854,"value":19856,"nodeType":864},{},[19855],{"type":899},"Backend infrastructure",{"data":19858,"content":19859,"nodeType":4569},{},[19860,19890],{"data":19861,"content":19862,"nodeType":860},{},[19863,19868,19872,19877,19881,19886],{"data":19864,"marks":19865,"value":19867,"nodeType":864},{},[19866],{"type":899},"Example IP: (V3) ",{"data":19869,"marks":19870,"value":19871,"nodeType":864},{},[],"162.220.232.71 (Railway AS400940) ",{"data":19873,"marks":19874,"value":19876,"nodeType":864},{},[19875],{"type":899},"(V2)",{"data":19878,"marks":19879,"value":19880,"nodeType":864},{},[]," 71.11.42.193 ",{"data":19882,"marks":19883,"value":19885,"nodeType":864},{},[19884],{"type":899},"(V1) ",{"data":19887,"marks":19888,"value":19889,"nodeType":864},{},[],"72.218.25.107",{"data":19891,"content":19892,"nodeType":860},{},[19893,19898,19901,19906,19910,19914,19918,19922],{"data":19894,"marks":19895,"value":19897,"nodeType":864},{},[19896],{"type":899},"Backend User Agent:",{"data":19899,"marks":19900,"value":1171,"nodeType":864},{},[],{"data":19902,"marks":19903,"value":19905,"nodeType":864},{},[19904],{"type":899},"(V3) ",{"data":19907,"marks":19908,"value":19909,"nodeType":864},{},[],"node, ",{"data":19911,"marks":19912,"value":19876,"nodeType":864},{},[19913],{"type":899},{"data":19915,"marks":19916,"value":19917,"nodeType":864},{},[],", Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683 Safari/537.36 OPR/57.0.3098.91 ",{"data":19919,"marks":19920,"value":19885,"nodeType":864},{},[19921],{"type":899},{"data":19923,"marks":19924,"value":19925,"nodeType":864},{},[],"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36 OPR/56.0.3051.52 ",{"data":19927,"content":19928,"nodeType":4581},{},[19929,19940],{"data":19930,"content":19931,"nodeType":4569},{},[19932],{"data":19933,"content":19934,"nodeType":860},{},[19935],{"data":19936,"marks":19937,"value":19939,"nodeType":864},{},[19938],{"type":899},"Network paths",{"data":19941,"content":19942,"nodeType":4569},{},[19943,19950,19957,19964,19971],{"data":19944,"content":19945,"nodeType":860},{},[19946],{"data":19947,"marks":19948,"value":19949,"nodeType":864},{},[],"/api/rate-limit ",{"data":19951,"content":19952,"nodeType":860},{},[19953],{"data":19954,"marks":19955,"value":19956,"nodeType":864},{},[],"/api/fingerprint ",{"data":19958,"content":19959,"nodeType":860},{},[19960],{"data":19961,"marks":19962,"value":19963,"nodeType":864},{},[],"/api/captcha-verify ",{"data":19965,"content":19966,"nodeType":860},{},[19967],{"data":19968,"marks":19969,"value":19970,"nodeType":864},{},[],"/api/init /api/generate-code ",{"data":19972,"content":19973,"nodeType":860},{},[19974],{"data":19975,"marks":19976,"value":19977,"nodeType":864},{},[],"/api/check-auth",{"data":19979,"content":19980,"nodeType":4581},{},[19981,19992],{"data":19982,"content":19983,"nodeType":4569},{},[19984],{"data":19985,"content":19986,"nodeType":860},{},[19987],{"data":19988,"marks":19989,"value":19991,"nodeType":864},{},[19990],{"type":899},"Lure themes",{"data":19993,"content":19994,"nodeType":4569},{},[19995],{"data":19996,"content":19997,"nodeType":860},{},[19998],{"data":19999,"marks":20000,"value":20001,"nodeType":864},{},[],"Various MS lures (e.g. Outlook, SharePoint, Teams) DocuSign, Adobe",{"data":20003,"content":20004,"nodeType":4581},{},[20005,20016],{"data":20006,"content":20007,"nodeType":4569},{},[20008],{"data":20009,"content":20010,"nodeType":860},{},[20011],{"data":20012,"marks":20013,"value":20015,"nodeType":864},{},[20014],{"type":899},"Example Domain",{"data":20017,"content":20018,"nodeType":4569},{},[20019,20031,20043,20055,20067],{"data":20020,"content":20021,"nodeType":860},{},[20022,20027],{"data":20023,"marks":20024,"value":20026,"nodeType":864},{},[20025],{"type":899},"Precursor A:",{"data":20028,"marks":20029,"value":20030,"nodeType":864},{},[]," teams-zpfvwnpxuc[.]edgeone.dev",{"data":20032,"content":20033,"nodeType":860},{},[20034,20039],{"data":20035,"marks":20036,"value":20038,"nodeType":864},{},[20037],{"type":899},"Precursor B: ",{"data":20040,"marks":20041,"value":20042,"nodeType":864},{},[],"authenticate-m365-accountsecurity-m-pi[.]vercel.app",{"data":20044,"content":20045,"nodeType":860},{},[20046,20051],{"data":20047,"marks":20048,"value":20050,"nodeType":864},{},[20049],{"type":899},"Courts Access: ",{"data":20052,"marks":20053,"value":20054,"nodeType":864},{},[],"secure-systems-validations-courts[.]vercel.app",{"data":20056,"content":20057,"nodeType":860},{},[20058,20063],{"data":20059,"marks":20060,"value":20062,"nodeType":864},{},[20061],{"type":899},"Early ANTIBOT:",{"data":20064,"marks":20065,"value":20066,"nodeType":864},{},[]," interface-auth-en-useast[.]global.ssl.fastly.net",{"data":20068,"content":20069,"nodeType":860},{},[20070,20075],{"data":20071,"marks":20072,"value":20074,"nodeType":864},{},[20073],{"type":899},"Production ANTIBOT: ",{"data":20076,"marks":20077,"value":20078,"nodeType":864},{},[],"index-z059-document-pending-reviewsign-xlss7994824[.]awalizer[.]workers.dev",{"data":20080,"content":20081,"nodeType":1005},{},[],{"data":20083,"content":20084,"nodeType":1312},{},[20085],{"data":20086,"marks":20087,"value":20089,"nodeType":864},{},[20088],{"type":899},"“SHAREFILE”",{"data":20091,"content":20092,"nodeType":4845},{},[20093,20116,20155,20178,20201],{"data":20094,"content":20095,"nodeType":4581},{},[20096,20106],{"data":20097,"content":20098,"nodeType":4569},{},[20099],{"data":20100,"content":20101,"nodeType":860},{},[20102],{"data":20103,"marks":20104,"value":19832,"nodeType":864},{},[20105],{"type":899},{"data":20107,"content":20108,"nodeType":4569},{},[20109],{"data":20110,"content":20111,"nodeType":860},{},[20112],{"data":20113,"marks":20114,"value":20115,"nodeType":864},{},[],"No hosting markers visible.",{"data":20117,"content":20118,"nodeType":4581},{},[20119,20129],{"data":20120,"content":20121,"nodeType":4569},{},[20122],{"data":20123,"content":20124,"nodeType":860},{},[20125],{"data":20126,"marks":20127,"value":19856,"nodeType":864},{},[20128],{"type":899},{"data":20130,"content":20131,"nodeType":4569},{},[20132,20144],{"data":20133,"content":20134,"nodeType":860},{},[20135,20140],{"data":20136,"marks":20137,"value":20139,"nodeType":864},{},[20138],{"type":899},"Example IP:",{"data":20141,"marks":20142,"value":20143,"nodeType":864},{},[]," 147.45.60.47 (Global Connectivity Solutions LLP AS215540)",{"data":20145,"content":20146,"nodeType":860},{},[20147,20151],{"data":20148,"marks":20149,"value":19897,"nodeType":864},{},[20150],{"type":899},{"data":20152,"marks":20153,"value":20154,"nodeType":864},{},[]," node",{"data":20156,"content":20157,"nodeType":4581},{},[20158,20168],{"data":20159,"content":20160,"nodeType":4569},{},[20161],{"data":20162,"content":20163,"nodeType":860},{},[20164],{"data":20165,"marks":20166,"value":19939,"nodeType":864},{},[20167],{"type":899},{"data":20169,"content":20170,"nodeType":4569},{},[20171],{"data":20172,"content":20173,"nodeType":860},{},[20174],{"data":20175,"marks":20176,"value":20177,"nodeType":864},{},[],"POST /api/device/start  POST /api/device/poll",{"data":20179,"content":20180,"nodeType":4581},{},[20181,20191],{"data":20182,"content":20183,"nodeType":4569},{},[20184],{"data":20185,"content":20186,"nodeType":860},{},[20187],{"data":20188,"marks":20189,"value":19991,"nodeType":864},{},[20190],{"type":899},{"data":20192,"content":20193,"nodeType":4569},{},[20194],{"data":20195,"content":20196,"nodeType":860},{},[20197],{"data":20198,"marks":20199,"value":20200,"nodeType":864},{},[],"Citrix ShareFile document transfer — file card with sender info, expiry warning, download/preview buttons",{"data":20202,"content":20203,"nodeType":4581},{},[20204,20215],{"data":20205,"content":20206,"nodeType":4569},{},[20207],{"data":20208,"content":20209,"nodeType":860},{},[20210],{"data":20211,"marks":20212,"value":20214,"nodeType":864},{},[20213],{"type":899},"Example domain",{"data":20216,"content":20217,"nodeType":4569},{},[20218],{"data":20219,"content":20220,"nodeType":860},{},[20221],{"data":20222,"marks":20223,"value":20224,"nodeType":864},{},[],"cghdfg[.]vbchkioi[.]su",{"data":20226,"content":20230,"nodeType":996},{"target":20227},{"sys":20228},{"id":20229,"type":1001,"linkType":1002},"1TtZ6VsMSTlPvy7W996w9E",[],{"data":20232,"content":20233,"nodeType":1005},{},[],{"data":20235,"content":20236,"nodeType":1312},{},[20237],{"data":20238,"marks":20239,"value":20241,"nodeType":864},{},[20240],{"type":899},"Kali365 (internal name “CLURE”)",{"data":20243,"content":20244,"nodeType":860},{},[20245,20249,20254,20258,20266,20270,20278],{"data":20246,"marks":20247,"value":20248,"nodeType":864},{},[],"Clure was recently linked to the ",{"data":20250,"marks":20251,"value":20253,"nodeType":864},{},[20252],{"type":899},"Kali365",{"data":20255,"marks":20256,"value":20257,"nodeType":864},{},[]," PhaaS platform based on an ",{"data":20259,"content":20261,"nodeType":883},{"uri":20260},"https://www.ic3.gov/PSA/2026/PSA260521",[20262],{"data":20263,"marks":20264,"value":20265,"nodeType":864},{},[],"FBI advisory",{"data":20267,"marks":20268,"value":20269,"nodeType":864},{},[]," and additional research from ",{"data":20271,"content":20273,"nodeType":883},{"uri":20272},"https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/",[20274],{"data":20275,"marks":20276,"value":20277,"nodeType":864},{},[],"Arctic Wolf",{"data":20279,"marks":20280,"value":20281,"nodeType":864},{},[],". This is yet another example of Device Code Phishing and AiTM phishing capabilities being integrated into unified phishing platforms. ",{"data":20283,"content":20284,"nodeType":4845},{},[20285,20308,20347,20370,20393],{"data":20286,"content":20287,"nodeType":4581},{},[20288,20298],{"data":20289,"content":20290,"nodeType":4569},{},[20291],{"data":20292,"content":20293,"nodeType":860},{},[20294],{"data":20295,"marks":20296,"value":19832,"nodeType":864},{},[20297],{"type":899},{"data":20299,"content":20300,"nodeType":4569},{},[20301],{"data":20302,"content":20303,"nodeType":860},{},[20304],{"data":20305,"marks":20306,"value":20307,"nodeType":864},{},[],"API on api.duemineral.uk:8443 and api.loadingdocuments.uk:8443 (rotates). ",{"data":20309,"content":20310,"nodeType":4581},{},[20311,20321],{"data":20312,"content":20313,"nodeType":4569},{},[20314],{"data":20315,"content":20316,"nodeType":860},{},[20317],{"data":20318,"marks":20319,"value":19856,"nodeType":864},{},[20320],{"type":899},{"data":20322,"content":20323,"nodeType":4569},{},[20324,20336],{"data":20325,"content":20326,"nodeType":860},{},[20327,20332],{"data":20328,"marks":20329,"value":20331,"nodeType":864},{},[20330],{"type":899},"Example IP: ",{"data":20333,"marks":20334,"value":20335,"nodeType":864},{},[],"162.243.166.119 (DigitalOcean AS14061)",{"data":20337,"content":20338,"nodeType":860},{},[20339,20343],{"data":20340,"marks":20341,"value":19897,"nodeType":864},{},[20342],{"type":899},{"data":20344,"marks":20345,"value":20346,"nodeType":864},{},[]," python-requests/2.32.5",{"data":20348,"content":20349,"nodeType":4581},{},[20350,20360],{"data":20351,"content":20352,"nodeType":4569},{},[20353],{"data":20354,"content":20355,"nodeType":860},{},[20356],{"data":20357,"marks":20358,"value":19939,"nodeType":864},{},[20359],{"type":899},{"data":20361,"content":20362,"nodeType":4569},{},[20363],{"data":20364,"content":20365,"nodeType":860},{},[20366],{"data":20367,"marks":20368,"value":20369,"nodeType":864},{},[],"GET /api/status/{numeric_SID} (port :8443)",{"data":20371,"content":20372,"nodeType":4581},{},[20373,20383],{"data":20374,"content":20375,"nodeType":4569},{},[20376],{"data":20377,"content":20378,"nodeType":860},{},[20379],{"data":20380,"marks":20381,"value":19991,"nodeType":864},{},[20382],{"type":899},{"data":20384,"content":20385,"nodeType":4569},{},[20386],{"data":20387,"content":20388,"nodeType":860},{},[20389],{"data":20390,"marks":20391,"value":20392,"nodeType":864},{},[],"SharePoint \"Team Site\" doc library, SharePoint \"Shared Document\" individual share",{"data":20394,"content":20395,"nodeType":4581},{},[20396,20406],{"data":20397,"content":20398,"nodeType":4569},{},[20399],{"data":20400,"content":20401,"nodeType":860},{},[20402],{"data":20403,"marks":20404,"value":20214,"nodeType":864},{},[20405],{"type":899},{"data":20407,"content":20408,"nodeType":4569},{},[20409],{"data":20410,"content":20411,"nodeType":860},{},[20412],{"data":20413,"marks":20414,"value":20415,"nodeType":864},{},[],"auth[.]duemineral[.]uk",{"data":20417,"content":20421,"nodeType":996},{"target":20418},{"sys":20419},{"id":20420,"type":1001,"linkType":1002},"Y1AiT3dJRTXz64pb68kca",[],{"data":20423,"content":20424,"nodeType":1005},{},[],{"data":20426,"content":20427,"nodeType":1312},{},[20428],{"data":20429,"marks":20430,"value":20432,"nodeType":864},{},[20431],{"type":899},"“LINKID”",{"data":20434,"content":20435,"nodeType":4845},{},[20436,20459,20504,20534,20557],{"data":20437,"content":20438,"nodeType":4581},{},[20439,20449],{"data":20440,"content":20441,"nodeType":4569},{},[20442],{"data":20443,"content":20444,"nodeType":860},{},[20445],{"data":20446,"marks":20447,"value":19832,"nodeType":864},{},[20448],{"type":899},{"data":20450,"content":20451,"nodeType":4569},{},[20452],{"data":20453,"content":20454,"nodeType":860},{},[20455],{"data":20456,"marks":20457,"value":20458,"nodeType":864},{},[],"Adobe variant has Cloudflare challenge-platform iframe (CF-protected origin). Relative API paths — self-hosted.",{"data":20460,"content":20461,"nodeType":4581},{},[20462,20472],{"data":20463,"content":20464,"nodeType":4569},{},[20465],{"data":20466,"content":20467,"nodeType":860},{},[20468],{"data":20469,"marks":20470,"value":19856,"nodeType":864},{},[20471],{"type":899},{"data":20473,"content":20474,"nodeType":4569},{},[20475,20486,20493],{"data":20476,"content":20477,"nodeType":860},{},[20478,20482],{"data":20479,"marks":20480,"value":20331,"nodeType":864},{},[20481],{"type":899},{"data":20483,"marks":20484,"value":20485,"nodeType":864},{},[],"185.176.220.22 (2cloud.eu AS39845)",{"data":20487,"content":20488,"nodeType":860},{},[20489],{"data":20490,"marks":20491,"value":20492,"nodeType":864},{},[],"2600:1f10:470d:9a00:1437:ec30:be61:3494 (AWS AS16509)",{"data":20494,"content":20495,"nodeType":860},{},[20496,20500],{"data":20497,"marks":20498,"value":19897,"nodeType":864},{},[20499],{"type":899},{"data":20501,"marks":20502,"value":20503,"nodeType":864},{},[]," axios/1.10.0 , axios/1.13.6",{"data":20505,"content":20506,"nodeType":4581},{},[20507,20517],{"data":20508,"content":20509,"nodeType":4569},{},[20510],{"data":20511,"content":20512,"nodeType":860},{},[20513],{"data":20514,"marks":20515,"value":19939,"nodeType":864},{},[20516],{"type":899},{"data":20518,"content":20519,"nodeType":4569},{},[20520,20527],{"data":20521,"content":20522,"nodeType":860},{},[20523],{"data":20524,"marks":20525,"value":20526,"nodeType":864},{},[],"POST /api/device/start",{"data":20528,"content":20529,"nodeType":860},{},[20530],{"data":20531,"marks":20532,"value":20533,"nodeType":864},{},[],"GET /api/device/status/{sessionId}",{"data":20535,"content":20536,"nodeType":4581},{},[20537,20547],{"data":20538,"content":20539,"nodeType":4569},{},[20540],{"data":20541,"content":20542,"nodeType":860},{},[20543],{"data":20544,"marks":20545,"value":19991,"nodeType":864},{},[20546],{"type":899},{"data":20548,"content":20549,"nodeType":4569},{},[20550],{"data":20551,"content":20552,"nodeType":860},{},[20553],{"data":20554,"marks":20555,"value":20556,"nodeType":864},{},[],"MS Teams meeting invitation (with interactive date/time picker), Adobe Acrobat Sign document review",{"data":20558,"content":20559,"nodeType":4581},{},[20560,20570],{"data":20561,"content":20562,"nodeType":4569},{},[20563],{"data":20564,"content":20565,"nodeType":860},{},[20566],{"data":20567,"marks":20568,"value":20214,"nodeType":864},{},[20569],{"type":899},{"data":20571,"content":20572,"nodeType":4569},{},[20573],{"data":20574,"content":20575,"nodeType":860},{},[20576],{"data":20577,"marks":20578,"value":20579,"nodeType":864},{},[],"sdtr-site[.]cfd",{"data":20581,"content":20585,"nodeType":996},{"target":20582},{"sys":20583},{"id":20584,"type":1001,"linkType":1002},"22hsIzlkptC2JTIUtbOuUn",[],{"data":20587,"content":20588,"nodeType":1005},{},[],{"data":20590,"content":20591,"nodeType":1312},{},[20592],{"data":20593,"marks":20594,"value":20596,"nodeType":864},{},[20595],{"type":899},"Device Code Lab (formerly codename \"AUTHOV”)",{"data":20598,"content":20602,"nodeType":996},{"target":20599},{"sys":20600},{"id":20601,"type":1001,"linkType":1002},"5vllVaa0Ry0wKs46ssrZLC",[],{"data":20604,"content":20605,"nodeType":4845},{},[20606,20629,20674,20697,20720],{"data":20607,"content":20608,"nodeType":4581},{},[20609,20619],{"data":20610,"content":20611,"nodeType":4569},{},[20612],{"data":20613,"content":20614,"nodeType":860},{},[20615],{"data":20616,"marks":20617,"value":19832,"nodeType":864},{},[20618],{"type":899},{"data":20620,"content":20621,"nodeType":4569},{},[20622],{"data":20623,"content":20624,"nodeType":860},{},[20625],{"data":20626,"marks":20627,"value":20628,"nodeType":864},{},[],"workers.dev",{"data":20630,"content":20631,"nodeType":4581},{},[20632,20642],{"data":20633,"content":20634,"nodeType":4569},{},[20635],{"data":20636,"content":20637,"nodeType":860},{},[20638],{"data":20639,"marks":20640,"value":19856,"nodeType":864},{},[20641],{"type":899},{"data":20643,"content":20644,"nodeType":4569},{},[20645,20656],{"data":20646,"content":20647,"nodeType":860},{},[20648,20652],{"data":20649,"marks":20650,"value":20331,"nodeType":864},{},[20651],{"type":899},{"data":20653,"marks":20654,"value":20655,"nodeType":864},{},[],"192.3.225.100 (HostPapa / ColoCrossing AS36352)",{"data":20657,"content":20658,"nodeType":860},{},[20659,20663,20666,20670],{"data":20660,"marks":20661,"value":19897,"nodeType":864},{},[20662],{"type":899},{"data":20664,"marks":20665,"value":1171,"nodeType":864},{},[],{"data":20667,"marks":20668,"value":7160,"nodeType":864},{},[20669],{"type":899},{"data":20671,"marks":20672,"value":20673,"nodeType":864},{},[],"python-httpx/0.28.1",{"data":20675,"content":20676,"nodeType":4581},{},[20677,20687],{"data":20678,"content":20679,"nodeType":4569},{},[20680],{"data":20681,"content":20682,"nodeType":860},{},[20683],{"data":20684,"marks":20685,"value":19939,"nodeType":864},{},[20686],{"type":899},{"data":20688,"content":20689,"nodeType":4569},{},[20690],{"data":20691,"content":20692,"nodeType":860},{},[20693],{"data":20694,"marks":20695,"value":20696,"nodeType":864},{},[],"GET /landing/api/session-status?session_id=&token=",{"data":20698,"content":20699,"nodeType":4581},{},[20700,20710],{"data":20701,"content":20702,"nodeType":4569},{},[20703],{"data":20704,"content":20705,"nodeType":860},{},[20706],{"data":20707,"marks":20708,"value":19991,"nodeType":864},{},[20709],{"type":899},{"data":20711,"content":20712,"nodeType":4569},{},[20713],{"data":20714,"content":20715,"nodeType":860},{},[20716],{"data":20717,"marks":20718,"value":20719,"nodeType":864},{},[],"Adobe Acrobat document sharing (PDF preview, sender avatar)",{"data":20721,"content":20722,"nodeType":4581},{},[20723,20733],{"data":20724,"content":20725,"nodeType":4569},{},[20726],{"data":20727,"content":20728,"nodeType":860},{},[20729],{"data":20730,"marks":20731,"value":20214,"nodeType":864},{},[20732],{"type":899},{"data":20734,"content":20735,"nodeType":4569},{},[20736],{"data":20737,"content":20738,"nodeType":860},{},[20739],{"data":20740,"marks":20741,"value":20742,"nodeType":864},{},[],"milosh-solibella-0dcio[.]sgttommy.workers.dev",{"data":20744,"content":20748,"nodeType":996},{"target":20745},{"sys":20746},{"id":20747,"type":1001,"linkType":1002},"6szO6IKJ32usyxIKX1efZy",[],{"data":20750,"content":20754,"nodeType":996},{"target":20751},{"sys":20752},{"id":20753,"type":1001,"linkType":1002},"lEqV3RTMIY8y011lnhX7P",[],{"data":20756,"content":20757,"nodeType":1005},{},[],{"data":20759,"content":20760,"nodeType":1312},{},[20761],{"data":20762,"marks":20763,"value":20765,"nodeType":864},{},[20764],{"type":899},"“DOCUPOLL”",{"data":20767,"content":20768,"nodeType":4845},{},[20769,20792,20830,20867,20890],{"data":20770,"content":20771,"nodeType":4581},{},[20772,20782],{"data":20773,"content":20774,"nodeType":4569},{},[20775],{"data":20776,"content":20777,"nodeType":860},{},[20778],{"data":20779,"marks":20780,"value":19832,"nodeType":864},{},[20781],{"type":899},{"data":20783,"content":20784,"nodeType":4569},{},[20785],{"data":20786,"content":20787,"nodeType":860},{},[20788],{"data":20789,"marks":20790,"value":20791,"nodeType":864},{},[],"Github.io and workers.dev hosting",{"data":20793,"content":20794,"nodeType":4581},{},[20795,20805],{"data":20796,"content":20797,"nodeType":4569},{},[20798],{"data":20799,"content":20800,"nodeType":860},{},[20801],{"data":20802,"marks":20803,"value":19856,"nodeType":864},{},[20804],{"type":899},{"data":20806,"content":20807,"nodeType":4569},{},[20808,20819],{"data":20809,"content":20810,"nodeType":860},{},[20811,20815],{"data":20812,"marks":20813,"value":20331,"nodeType":864},{},[20814],{"type":899},{"data":20816,"marks":20817,"value":20818,"nodeType":864},{},[],"144.172.103.240 (FranTech Solutions / RouterHosting / Cloudzy AS14956)",{"data":20820,"content":20821,"nodeType":860},{},[20822,20826],{"data":20823,"marks":20824,"value":19897,"nodeType":864},{},[20825],{"type":899},{"data":20827,"marks":20828,"value":20829,"nodeType":864},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19042",{"data":20831,"content":20832,"nodeType":4581},{},[20833,20843],{"data":20834,"content":20835,"nodeType":4569},{},[20836],{"data":20837,"content":20838,"nodeType":860},{},[20839],{"data":20840,"marks":20841,"value":19939,"nodeType":864},{},[20842],{"type":899},{"data":20844,"content":20845,"nodeType":4569},{},[20846,20853,20860],{"data":20847,"content":20848,"nodeType":860},{},[20849],{"data":20850,"marks":20851,"value":20852,"nodeType":864},{},[],"POST /api/v1/landing-pages/public/{slug}/init",{"data":20854,"content":20855,"nodeType":860},{},[20856],{"data":20857,"marks":20858,"value":20859,"nodeType":864},{},[],"POST .../poll",{"data":20861,"content":20862,"nodeType":860},{},[20863],{"data":20864,"marks":20865,"value":20866,"nodeType":864},{},[],"POST .../track",{"data":20868,"content":20869,"nodeType":4581},{},[20870,20880],{"data":20871,"content":20872,"nodeType":4569},{},[20873],{"data":20874,"content":20875,"nodeType":860},{},[20876],{"data":20877,"marks":20878,"value":19991,"nodeType":864},{},[20879],{"type":899},{"data":20881,"content":20882,"nodeType":4569},{},[20883],{"data":20884,"content":20885,"nodeType":860},{},[20886],{"data":20887,"marks":20888,"value":20889,"nodeType":864},{},[],"DocuSign document signing. One sample is a full scrape of real docusign.com (free-account page) with kit injected.",{"data":20891,"content":20892,"nodeType":4581},{},[20893,20903],{"data":20894,"content":20895,"nodeType":4569},{},[20896],{"data":20897,"content":20898,"nodeType":860},{},[20899],{"data":20900,"marks":20901,"value":20214,"nodeType":864},{},[20902],{"type":899},{"data":20904,"content":20905,"nodeType":4569},{},[20906],{"data":20907,"content":20908,"nodeType":860},{},[20909],{"data":20910,"marks":20911,"value":20912,"nodeType":864},{},[],"docufirmar[.]github.io",{"data":20914,"content":20918,"nodeType":996},{"target":20915},{"sys":20916},{"id":20917,"type":1001,"linkType":1002},"6Y1XABHnQD82R3MW80HnQZ",[],{"data":20920,"content":20921,"nodeType":1005},{},[],{"data":20923,"content":20924,"nodeType":1312},{},[20925],{"data":20926,"marks":20927,"value":20929,"nodeType":864},{},[20928],{"type":899},"“FLOW_TOKEN”",{"data":20931,"content":20932,"nodeType":4845},{},[20933,20955,21000,21030,21053],{"data":20934,"content":20935,"nodeType":4581},{},[20936,20946],{"data":20937,"content":20938,"nodeType":4569},{},[20939],{"data":20940,"content":20941,"nodeType":860},{},[20942],{"data":20943,"marks":20944,"value":19832,"nodeType":864},{},[20945],{"type":899},{"data":20947,"content":20948,"nodeType":4569},{},[20949],{"data":20950,"content":20951,"nodeType":860},{},[20952],{"data":20953,"marks":20954,"value":20628,"nodeType":864},{},[],{"data":20956,"content":20957,"nodeType":4581},{},[20958,20968],{"data":20959,"content":20960,"nodeType":4569},{},[20961],{"data":20962,"content":20963,"nodeType":860},{},[20964],{"data":20965,"marks":20966,"value":19856,"nodeType":864},{},[20967],{"type":899},{"data":20969,"content":20970,"nodeType":4569},{},[20971,20982],{"data":20972,"content":20973,"nodeType":860},{},[20974,20978],{"data":20975,"marks":20976,"value":20331,"nodeType":864},{},[20977],{"type":899},{"data":20979,"marks":20980,"value":20981,"nodeType":864},{},[],"43.166.163.163 (Tencent Cloud AS132203)",{"data":20983,"content":20984,"nodeType":860},{},[20985,20989,20992,20996],{"data":20986,"marks":20987,"value":19897,"nodeType":864},{},[20988],{"type":899},{"data":20990,"marks":20991,"value":1171,"nodeType":864},{},[],{"data":20993,"marks":20994,"value":7160,"nodeType":864},{},[20995],{"type":899},{"data":20997,"marks":20998,"value":20999,"nodeType":864},{},[],"(null)",{"data":21001,"content":21002,"nodeType":4581},{},[21003,21013],{"data":21004,"content":21005,"nodeType":4569},{},[21006],{"data":21007,"content":21008,"nodeType":860},{},[21009],{"data":21010,"marks":21011,"value":19939,"nodeType":864},{},[21012],{"type":899},{"data":21014,"content":21015,"nodeType":4569},{},[21016,21023],{"data":21017,"content":21018,"nodeType":860},{},[21019],{"data":21020,"marks":21021,"value":21022,"nodeType":864},{},[],"POST /api/handler.php ",{"data":21024,"content":21025,"nodeType":860},{},[21026],{"data":21027,"marks":21028,"value":21029,"nodeType":864},{},[],"(actions: device_code_generate, device_code_poll_public)",{"data":21031,"content":21032,"nodeType":4581},{},[21033,21043],{"data":21034,"content":21035,"nodeType":4569},{},[21036],{"data":21037,"content":21038,"nodeType":860},{},[21039],{"data":21040,"marks":21041,"value":19991,"nodeType":864},{},[21042],{"type":899},{"data":21044,"content":21045,"nodeType":4569},{},[21046],{"data":21047,"content":21048,"nodeType":860},{},[21049],{"data":21050,"marks":21051,"value":21052,"nodeType":864},{},[],"DocuSign \"Salary Adjustment Document — 2026\", Microsoft banner · HR Department sender",{"data":21054,"content":21055,"nodeType":4581},{},[21056,21066],{"data":21057,"content":21058,"nodeType":4569},{},[21059],{"data":21060,"content":21061,"nodeType":860},{},[21062],{"data":21063,"marks":21064,"value":20214,"nodeType":864},{},[21065],{"type":899},{"data":21067,"content":21068,"nodeType":4569},{},[21069],{"data":21070,"content":21071,"nodeType":860},{},[21072],{"data":21073,"marks":21074,"value":21075,"nodeType":864},{},[],"salaryadjustment-2afb52.pmb6fefc52b3f9aa5c2dbf[.]workers.dev",{"data":21077,"content":21081,"nodeType":996},{"target":21078},{"sys":21079},{"id":21080,"type":1001,"linkType":1002},"6xiTDHStbiJh7LMhjAZcPd",[],{"data":21083,"content":21084,"nodeType":1005},{},[],{"data":21086,"content":21087,"nodeType":1312},{},[21088],{"data":21089,"marks":21090,"value":21092,"nodeType":864},{},[21091],{"type":899},"“PAPRIKA”",{"data":21094,"content":21095,"nodeType":4845},{},[21096,21119,21142,21165],{"data":21097,"content":21098,"nodeType":4581},{},[21099,21109],{"data":21100,"content":21101,"nodeType":4569},{},[21102],{"data":21103,"content":21104,"nodeType":860},{},[21105],{"data":21106,"marks":21107,"value":19832,"nodeType":864},{},[21108],{"type":899},{"data":21110,"content":21111,"nodeType":4569},{},[21112],{"data":21113,"content":21114,"nodeType":860},{},[21115],{"data":21116,"marks":21117,"value":21118,"nodeType":864},{},[],"AWS S3 hosting",{"data":21120,"content":21121,"nodeType":4581},{},[21122,21132],{"data":21123,"content":21124,"nodeType":4569},{},[21125],{"data":21126,"content":21127,"nodeType":860},{},[21128],{"data":21129,"marks":21130,"value":19939,"nodeType":864},{},[21131],{"type":899},{"data":21133,"content":21134,"nodeType":4569},{},[21135],{"data":21136,"content":21137,"nodeType":860},{},[21138],{"data":21139,"marks":21140,"value":21141,"nodeType":864},{},[],"POST /api/v1/loader",{"data":21143,"content":21144,"nodeType":4581},{},[21145,21155],{"data":21146,"content":21147,"nodeType":4569},{},[21148],{"data":21149,"content":21150,"nodeType":860},{},[21151],{"data":21152,"marks":21153,"value":19991,"nodeType":864},{},[21154],{"type":899},{"data":21156,"content":21157,"nodeType":4569},{},[21158],{"data":21159,"content":21160,"nodeType":860},{},[21161],{"data":21162,"marks":21163,"value":21164,"nodeType":864},{},[],"MS login clone (\"Sign in to your account\"), \"Office 365\" branding, fake \"Powered by Okta\" footer",{"data":21166,"content":21167,"nodeType":4581},{},[21168,21178],{"data":21169,"content":21170,"nodeType":4569},{},[21171],{"data":21172,"content":21173,"nodeType":860},{},[21174],{"data":21175,"marks":21176,"value":20214,"nodeType":864},{},[21177],{"type":899},{"data":21179,"content":21180,"nodeType":4569},{},[21181],{"data":21182,"content":21183,"nodeType":860},{},[21184],{"data":21185,"marks":21186,"value":21187,"nodeType":864},{},[],"redirect-523346-d95027ec[.]s3.amazonaws.com",{"data":21189,"content":21193,"nodeType":996},{"target":21190},{"sys":21191},{"id":21192,"type":1001,"linkType":1002},"6WFXqUDzcJHKWSwVIcDZAf",[],{"data":21195,"content":21196,"nodeType":1005},{},[],{"data":21198,"content":21199,"nodeType":1312},{},[21200],{"data":21201,"marks":21202,"value":21204,"nodeType":864},{},[21203],{"type":899},"“DCSTATUS”",{"data":21206,"content":21207,"nodeType":4845},{},[21208,21230,21253,21276],{"data":21209,"content":21210,"nodeType":4581},{},[21211,21221],{"data":21212,"content":21213,"nodeType":4569},{},[21214],{"data":21215,"content":21216,"nodeType":860},{},[21217],{"data":21218,"marks":21219,"value":19832,"nodeType":864},{},[21220],{"type":899},{"data":21222,"content":21223,"nodeType":4569},{},[21224],{"data":21225,"content":21226,"nodeType":860},{},[21227],{"data":21228,"marks":21229,"value":20115,"nodeType":864},{},[],{"data":21231,"content":21232,"nodeType":4581},{},[21233,21243],{"data":21234,"content":21235,"nodeType":4569},{},[21236],{"data":21237,"content":21238,"nodeType":860},{},[21239],{"data":21240,"marks":21241,"value":19939,"nodeType":864},{},[21242],{"type":899},{"data":21244,"content":21245,"nodeType":4569},{},[21246],{"data":21247,"content":21248,"nodeType":860},{},[21249],{"data":21250,"marks":21251,"value":21252,"nodeType":864},{},[],"GET /dc/status/{base64url_sid}",{"data":21254,"content":21255,"nodeType":4581},{},[21256,21266],{"data":21257,"content":21258,"nodeType":4569},{},[21259],{"data":21260,"content":21261,"nodeType":860},{},[21262],{"data":21263,"marks":21264,"value":19991,"nodeType":864},{},[21265],{"type":899},{"data":21267,"content":21268,"nodeType":4569},{},[21269],{"data":21270,"content":21271,"nodeType":860},{},[21272],{"data":21273,"marks":21274,"value":21275,"nodeType":864},{},[],"Generic \"Microsoft 365 - Secure Access\" verification page",{"data":21277,"content":21278,"nodeType":4581},{},[21279,21289],{"data":21280,"content":21281,"nodeType":4569},{},[21282],{"data":21283,"content":21284,"nodeType":860},{},[21285],{"data":21286,"marks":21287,"value":20214,"nodeType":864},{},[21288],{"type":899},{"data":21290,"content":21291,"nodeType":4569},{},[21292],{"data":21293,"content":21294,"nodeType":860},{},[21295],{"data":21296,"marks":21297,"value":21298,"nodeType":864},{},[],"owa[.]apmmacleans[.]ca",{"data":21300,"content":21304,"nodeType":996},{"target":21301},{"sys":21302},{"id":21303,"type":1001,"linkType":1002},"ugYhHeXY1lQdKooALmrIs",[],{"data":21306,"content":21307,"nodeType":1005},{},[],{"data":21309,"content":21310,"nodeType":1312},{},[21311],{"data":21312,"marks":21313,"value":21315,"nodeType":864},{},[21314],{"type":899},"“DOLCE”",{"data":21317,"content":21321,"nodeType":996},{"target":21318},{"sys":21319},{"id":21320,"type":1001,"linkType":1002},"7TzU6kk01Un45NB0buEz2",[],{"data":21323,"content":21324,"nodeType":4845},{},[21325,21348,21386,21409,21432],{"data":21326,"content":21327,"nodeType":4581},{},[21328,21338],{"data":21329,"content":21330,"nodeType":4569},{},[21331],{"data":21332,"content":21333,"nodeType":860},{},[21334],{"data":21335,"marks":21336,"value":19832,"nodeType":864},{},[21337],{"type":899},{"data":21339,"content":21340,"nodeType":4569},{},[21341],{"data":21342,"content":21343,"nodeType":860},{},[21344],{"data":21345,"marks":21346,"value":21347,"nodeType":864},{},[],"Microsoft PowerApps hosting",{"data":21349,"content":21350,"nodeType":4581},{},[21351,21361],{"data":21352,"content":21353,"nodeType":4569},{},[21354],{"data":21355,"content":21356,"nodeType":860},{},[21357],{"data":21358,"marks":21359,"value":19856,"nodeType":864},{},[21360],{"type":899},{"data":21362,"content":21363,"nodeType":4569},{},[21364,21375],{"data":21365,"content":21366,"nodeType":860},{},[21367,21371],{"data":21368,"marks":21369,"value":20331,"nodeType":864},{},[21370],{"type":899},{"data":21372,"marks":21373,"value":21374,"nodeType":864},{},[],"34.53.159.84 (Google Cloud AS396982)",{"data":21376,"content":21377,"nodeType":860},{},[21378,21382],{"data":21379,"marks":21380,"value":19897,"nodeType":864},{},[21381],{"type":899},{"data":21383,"marks":21384,"value":21385,"nodeType":864},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36",{"data":21387,"content":21388,"nodeType":4581},{},[21389,21399],{"data":21390,"content":21391,"nodeType":4569},{},[21392],{"data":21393,"content":21394,"nodeType":860},{},[21395],{"data":21396,"marks":21397,"value":19939,"nodeType":864},{},[21398],{"type":899},{"data":21400,"content":21401,"nodeType":4569},{},[21402],{"data":21403,"content":21404,"nodeType":860},{},[21405],{"data":21406,"marks":21407,"value":21408,"nodeType":864},{},[],"GET /api/generatecode (CloudFront)",{"data":21410,"content":21411,"nodeType":4581},{},[21412,21422],{"data":21413,"content":21414,"nodeType":4569},{},[21415],{"data":21416,"content":21417,"nodeType":860},{},[21418],{"data":21419,"marks":21420,"value":19991,"nodeType":864},{},[21421],{"type":899},{"data":21423,"content":21424,"nodeType":4569},{},[21425],{"data":21426,"content":21427,"nodeType":860},{},[21428],{"data":21429,"marks":21430,"value":21431,"nodeType":864},{},[],"Dolce & Gabbana branded, Italian language, MS account verification",{"data":21433,"content":21434,"nodeType":4581},{},[21435,21445],{"data":21436,"content":21437,"nodeType":4569},{},[21438],{"data":21439,"content":21440,"nodeType":860},{},[21441],{"data":21442,"marks":21443,"value":20214,"nodeType":864},{},[21444],{"type":899},{"data":21446,"content":21447,"nodeType":4569},{},[21448],{"data":21449,"content":21450,"nodeType":860},{},[21451],{"data":21452,"marks":21453,"value":21454,"nodeType":864},{},[],"data-migration-dolcegabbana[.]powerappsportals.com",{"data":21456,"content":21460,"nodeType":996},{"target":21457},{"sys":21458},{"id":21459,"type":1001,"linkType":1002},"4ayQDvpf5NNOBrj9wZZRiO",[],{"data":21462,"content":21463,"nodeType":1005},{},[],{"data":21465,"content":21466,"nodeType":1312},{},[21467],{"data":21468,"marks":21469,"value":21471,"nodeType":864},{},[21470],{"type":899},"Venom",{"data":21473,"content":21474,"nodeType":4845},{},[21475,21498],{"data":21476,"content":21477,"nodeType":4581},{},[21478,21488],{"data":21479,"content":21480,"nodeType":4569},{},[21481],{"data":21482,"content":21483,"nodeType":860},{},[21484],{"data":21485,"marks":21486,"value":19939,"nodeType":864},{},[21487],{"type":899},{"data":21489,"content":21490,"nodeType":4569},{},[21491],{"data":21492,"content":21493,"nodeType":860},{},[21494],{"data":21495,"marks":21496,"value":21497,"nodeType":864},{},[],"POST /token/api/device/start\nGET /token/api/device/status/{sessionId}",{"data":21499,"content":21500,"nodeType":4581},{},[21501,21511],{"data":21502,"content":21503,"nodeType":4569},{},[21504],{"data":21505,"content":21506,"nodeType":860},{},[21507],{"data":21508,"marks":21509,"value":19991,"nodeType":864},{},[21510],{"type":899},{"data":21512,"content":21513,"nodeType":4569},{},[21514],{"data":21515,"content":21516,"nodeType":860},{},[21517],{"data":21518,"marks":21519,"value":21520,"nodeType":864},{},[],"Various: examples include DocuSign \"Verification\" (Microsoft sign-in pretext); DHL \"Delivery Checkpoint\" package shipment pretext",{"data":21522,"content":21526,"nodeType":996},{"target":21523},{"sys":21524},{"id":21525,"type":1001,"linkType":1002},"79C3fces0hgTdf3G68cIrf",[],{"data":21528,"content":21529,"nodeType":1005},{},[],{"data":21531,"content":21532,"nodeType":1312},{},[21533],{"data":21534,"marks":21535,"value":21537,"nodeType":864},{},[21536],{"type":899},"Tycoon2FA",{"data":21539,"content":21540,"nodeType":4845},{},[21541,21571,21608,21631,21654],{"data":21542,"content":21543,"nodeType":4581},{},[21544,21554],{"data":21545,"content":21546,"nodeType":4569},{},[21547],{"data":21548,"content":21549,"nodeType":860},{},[21550],{"data":21551,"marks":21552,"value":19832,"nodeType":864},{},[21553],{"type":899},{"data":21555,"content":21556,"nodeType":4569},{},[21557,21564],{"data":21558,"content":21559,"nodeType":860},{},[21560],{"data":21561,"marks":21562,"value":21563,"nodeType":864},{},[],"Github.io and Cloudflare Workers (workers.dev) hosting",{"data":21565,"content":21566,"nodeType":860},{},[21567],{"data":21568,"marks":21569,"value":21570,"nodeType":864},{},[],"Compromised-site landing pages and CF Workers (*.workers.dev) used as frontends; victim email passed in URL as last path segment ($base64) or ?acct/?encoded query",{"data":21572,"content":21573,"nodeType":4581},{},[21574,21584],{"data":21575,"content":21576,"nodeType":4569},{},[21577],{"data":21578,"content":21579,"nodeType":860},{},[21580],{"data":21581,"marks":21582,"value":19856,"nodeType":864},{},[21583],{"type":899},{"data":21585,"content":21586,"nodeType":4569},{},[21587,21598],{"data":21588,"content":21589,"nodeType":860},{},[21590,21594],{"data":21591,"marks":21592,"value":20331,"nodeType":864},{},[21593],{"type":899},{"data":21595,"marks":21596,"value":21597,"nodeType":864},{},[],"47.253.5.88 (Alibaba Cloud)",{"data":21599,"content":21600,"nodeType":860},{},[21601,21605],{"data":21602,"marks":21603,"value":19897,"nodeType":864},{},[21604],{"type":899},{"data":21606,"marks":21607,"value":20154,"nodeType":864},{},[],{"data":21609,"content":21610,"nodeType":4581},{},[21611,21621],{"data":21612,"content":21613,"nodeType":4569},{},[21614],{"data":21615,"content":21616,"nodeType":860},{},[21617],{"data":21618,"marks":21619,"value":19939,"nodeType":864},{},[21620],{"type":899},{"data":21622,"content":21623,"nodeType":4569},{},[21624],{"data":21625,"content":21626,"nodeType":860},{},[21627],{"data":21628,"marks":21629,"value":21630,"nodeType":864},{},[],"GET /api/session/{UUIDv4} polled with header X-API-Key: \u003Cprefix>_\u003C64-hex> (key materialised at runtime via atob(window.__cyb3r.k)) \nPOST /api/device-code with body {\"prt_foci_session_id\": \"\u003CUUID>\"} (second-stage code retrieval after initial session error)",{"data":21632,"content":21633,"nodeType":4581},{},[21634,21644],{"data":21635,"content":21636,"nodeType":4569},{},[21637],{"data":21638,"content":21639,"nodeType":860},{},[21640],{"data":21641,"marks":21642,"value":19991,"nodeType":864},{},[21643],{"type":899},{"data":21645,"content":21646,"nodeType":4569},{},[21647],{"data":21648,"content":21649,"nodeType":860},{},[21650],{"data":21651,"marks":21652,"value":21653,"nodeType":864},{},[],"Various: SharePoint \"Remittance Advice\"; Microsoft 365 generic sign-in; Microsoft 365 Voicemail (.mp3 attachment); OneDrive \"Shared file\"; German \"Sicheres Dokumentenportal\" PDF lure",{"data":21655,"content":21656,"nodeType":4581},{},[21657,21667],{"data":21658,"content":21659,"nodeType":4569},{},[21660],{"data":21661,"content":21662,"nodeType":860},{},[21663],{"data":21664,"marks":21665,"value":20214,"nodeType":864},{},[21666],{"type":899},{"data":21668,"content":21669,"nodeType":4569},{},[21670],{"data":21671,"content":21672,"nodeType":860},{},[21673],{"data":21674,"marks":21675,"value":21676,"nodeType":864},{},[],"afriqbeauglobal[.]com/homepage/index[.]html",{"data":21678,"content":21681,"nodeType":996},{"target":21679},{"sys":21680},{"id":13317,"type":1001,"linkType":1002},[],{"data":21683,"content":21684,"nodeType":1005},{},[],{"data":21686,"content":21687,"nodeType":1312},{},[21688],{"data":21689,"marks":21690,"value":21692,"nodeType":864},{},[21691],{"type":899},"\"CYB3R\"",{"data":21694,"content":21695,"nodeType":4845},{},[21696,21719,21757,21779,21802],{"data":21697,"content":21698,"nodeType":4581},{},[21699,21709],{"data":21700,"content":21701,"nodeType":4569},{},[21702],{"data":21703,"content":21704,"nodeType":860},{},[21705],{"data":21706,"marks":21707,"value":19832,"nodeType":864},{},[21708],{"type":899},{"data":21710,"content":21711,"nodeType":4569},{},[21712],{"data":21713,"content":21714,"nodeType":860},{},[21715],{"data":21716,"marks":21717,"value":21718,"nodeType":864},{},[],"Cloudflare Workers (workers.dev) hosting",{"data":21720,"content":21721,"nodeType":4581},{},[21722,21732],{"data":21723,"content":21724,"nodeType":4569},{},[21725],{"data":21726,"content":21727,"nodeType":860},{},[21728],{"data":21729,"marks":21730,"value":19856,"nodeType":864},{},[21731],{"type":899},{"data":21733,"content":21734,"nodeType":4569},{},[21735,21746],{"data":21736,"content":21737,"nodeType":860},{},[21738,21742],{"data":21739,"marks":21740,"value":20331,"nodeType":864},{},[21741],{"type":899},{"data":21743,"marks":21744,"value":21745,"nodeType":864},{},[],"2400:8d60:2::1:c116:843e (Evoxt VPS)",{"data":21747,"content":21748,"nodeType":860},{},[21749,21753],{"data":21750,"marks":21751,"value":19897,"nodeType":864},{},[21752],{"type":899},{"data":21754,"marks":21755,"value":21756,"nodeType":864},{},[]," axios/1.13.6",{"data":21758,"content":21759,"nodeType":4581},{},[21760,21770],{"data":21761,"content":21762,"nodeType":4569},{},[21763],{"data":21764,"content":21765,"nodeType":860},{},[21766],{"data":21767,"marks":21768,"value":19939,"nodeType":864},{},[21769],{"type":899},{"data":21771,"content":21772,"nodeType":4569},{},[21773],{"data":21774,"content":21775,"nodeType":860},{},[21776],{"data":21777,"marks":21778,"value":21630,"nodeType":864},{},[],{"data":21780,"content":21781,"nodeType":4581},{},[21782,21792],{"data":21783,"content":21784,"nodeType":4569},{},[21785],{"data":21786,"content":21787,"nodeType":860},{},[21788],{"data":21789,"marks":21790,"value":19991,"nodeType":864},{},[21791],{"type":899},{"data":21793,"content":21794,"nodeType":4569},{},[21795],{"data":21796,"content":21797,"nodeType":860},{},[21798],{"data":21799,"marks":21800,"value":21801,"nodeType":864},{},[],"DocuSign in Spanish (\"Documento Firmar — COTIZACIÓN/ESTIMACIÓN.pdf\", \"Complete su firma\", \"Verifique su identidad\", \"Continuar a Microsoft\").",{"data":21803,"content":21804,"nodeType":4581},{},[21805,21815],{"data":21806,"content":21807,"nodeType":4569},{},[21808],{"data":21809,"content":21810,"nodeType":860},{},[21811],{"data":21812,"marks":21813,"value":20214,"nodeType":864},{},[21814],{"type":899},{"data":21816,"content":21817,"nodeType":4569},{},[21818],{"data":21819,"content":21820,"nodeType":860},{},[21821],{"data":21822,"marks":21823,"value":21824,"nodeType":864},{},[],"muzagestion[.]secure-share[.]workers.dev",{"data":21826,"content":21830,"nodeType":996},{"target":21827},{"sys":21828},{"id":21829,"type":1001,"linkType":1002},"5EU0QNteiQcYybKG1W1cS3",[],{"data":21832,"content":21833,"nodeType":1005},{},[],{"data":21835,"content":21836,"nodeType":1009},{},[21837],{"data":21838,"marks":21839,"value":21841,"nodeType":864},{},[21840],{"type":899},"Device code phishing under the hood",{"data":21843,"content":21844,"nodeType":860},{},[21845,21849],{"data":21846,"marks":21847,"value":21848,"nodeType":864},{},[],"The attacker POSTs to the authorization server's device authorization endpoint with its client_id (i.e. an application ID) and requested scopes or resources. The server responds with a device_code (used for polling), a user_code, a verification_uri, an expires_in value, and a polling interval. The user visits the URL, enters the code and approves the request. Meanwhile, the device polls the token endpoint. Once approved, the server returns an access token, a refresh token (if offline_access was requested), and an ID token (if openid was included). ",{"data":21850,"marks":21851,"value":21853,"nodeType":864},{},[21852],{"type":899},"The attacker now has API access to the victim's account. ",{"data":21855,"content":21856,"nodeType":860},{},[21857],{"data":21858,"marks":21859,"value":21860,"nodeType":864},{},[],"Broadly, this gives the attacker a comparable level of control to a “normal” phishing attack (with conditions based on the scopes granted and specific app being targeted) while API access grants additional capabilities beyond standard browser sessions. When combined with other techniques, this access can be exchanged to open normal browser app sessions and access SSO connected apps.",{"data":21862,"content":21866,"nodeType":996},{"target":21863},{"sys":21864},{"id":21865,"type":1001,"linkType":1002},"4WtQR2xsE236yoyhSXj58Z",[],{"data":21868,"content":21872,"nodeType":996},{"target":21869},{"sys":21870},{"id":21871,"type":1001,"linkType":1002},"1x7Lip7JdY2xlHKKurT7qJ",[],{"data":21874,"content":21875,"nodeType":860},{},[21876],{"data":21877,"marks":21878,"value":21879,"nodeType":864},{},[],"At this point, you can achieve a number of objectives both inside the app ecosystem and across SSO connected apps — e.g. data theft, disruption, and ultimately extortion.",{"data":21881,"content":21882,"nodeType":860},{},[21883,21887,21892,21896],{"data":21884,"marks":21885,"value":21886,"nodeType":864},{},[],"Critically, the initial request to generate a device code is typically ",{"data":21888,"marks":21889,"value":21891,"nodeType":864},{},[21890],{"type":899},"unauthenticated",{"data":21893,"marks":21894,"value":21895,"nodeType":864},{},[]," across all providers — ",{"data":21897,"marks":21898,"value":21900,"nodeType":864},{},[21899],{"type":899},"anyone can generate one, from any machine, without proving any relationship to the target organization.",{"data":21902,"content":21903,"nodeType":860},{},[21904,21908,21913],{"data":21905,"marks":21906,"value":21907,"nodeType":864},{},[],"So, the attacker has to deliver a set of instructions via a phishing channel (e.g. email, social media DM, corp IM platform, and so on) with a device code that they have generated. The victim then enters this code on the ",{"data":21909,"marks":21910,"value":21912,"nodeType":864},{},[21911],{"type":899},"legitimate device code login page",{"data":21914,"marks":21915,"value":21916,"nodeType":864},{},[]," for that app and issues the tokens to the attacker.",{"data":21918,"content":21922,"nodeType":996},{"target":21919},{"sys":21920},{"id":21921,"type":1001,"linkType":1002},"1txUYuQjH9FlbDGTo8AbZB",[],{"data":21924,"content":21925,"nodeType":1005},{},[],{"data":21927,"content":21928,"nodeType":1009},{},[21929],{"data":21930,"marks":21931,"value":21933,"nodeType":864},{},[21932],{"type":899},"Why device code phishing is so dangerous",{"data":21935,"content":21936,"nodeType":1312},{},[21937],{"data":21938,"marks":21939,"value":21941,"nodeType":864},{},[21940],{"type":899},"Device code phishing bypasses authentication controls (including passkeys)",{"data":21943,"content":21944,"nodeType":860},{},[21945,21949,21954,21958],{"data":21946,"marks":21947,"value":21948,"nodeType":864},{},[],"A device code phishing attack ",{"data":21950,"marks":21951,"value":21953,"nodeType":864},{},[21952],{"type":899},"cannot be prevented with authentication controls",{"data":21955,"marks":21956,"value":21957,"nodeType":864},{},[],". This includes all forms of MFA and ",{"data":21959,"marks":21960,"value":21962,"nodeType":864},{},[21961],{"type":899},"even “phishing-resistant” authentication methods such as passkeys. ",{"data":21964,"content":21965,"nodeType":860},{},[21966,21971,21975,21980],{"data":21967,"marks":21968,"value":21970,"nodeType":864},{},[21969],{"type":899},"The device code authorization is effectively performed post-authentication. ",{"data":21972,"marks":21973,"value":21974,"nodeType":864},{},[],"If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. ",{"data":21976,"marks":21977,"value":21979,"nodeType":864},{},[21978],{"type":899},"No password or MFA required. ",{"data":21981,"marks":21982,"value":21983,"nodeType":864},{},[],"You can see an example in the video below.",{"data":21985,"content":21988,"nodeType":996},{"target":21986},{"sys":21987},{"id":20917,"type":1001,"linkType":1002},[],{"data":21990,"content":21991,"nodeType":860},{},[21992],{"data":21993,"marks":21994,"value":21995,"nodeType":864},{},[],"Even if you do have to sign in again (because you're not already signed in for some reason), the attack still works because it isn't targeting the login — it's targeting the authorization layer instead.",{"data":21997,"content":21998,"nodeType":860},{},[21999],{"data":22000,"marks":22001,"value":22002,"nodeType":864},{},[],"This is what makes device code phishing different to other standard phishing methods like AiTM phishing (and arguably even more effective in environments with strict identity control enforcement). ",{"data":22004,"content":22005,"nodeType":1312},{},[22006],{"data":22007,"marks":22008,"value":22010,"nodeType":864},{},[22009],{"type":899},"Device code logins are a feature, not a vulnerability, making attacks difficult to block",{"data":22012,"content":22013,"nodeType":860},{},[22014],{"data":22015,"marks":22016,"value":22017,"nodeType":864},{},[],"Device code authorization is a legitimate mechanism regularly used in enterprise environments, particularly for CLI logins. Tools like Azure CLI, GitHub CLI, and AWS CLI all use (or have used) the device code flow as a primary or fallback authentication method. This creates a dual problem for defenders. ",{"data":22019,"content":22020,"nodeType":860},{},[22021],{"data":22022,"marks":22023,"value":22024,"nodeType":864},{},[],"First, the phishing attack happens entirely on a legitimate site — there's no fake login page, no malicious payload to scan for, and the URL in the browser is genuine. Since there's no traditional phishing content being delivered, these attacks are more resistant to detection by email and network security tools.",{"data":22026,"content":22027,"nodeType":860},{},[22028],{"data":22029,"marks":22030,"value":22031,"nodeType":864},{},[],"Second, the widespread legitimate use of device code flow — particularly among developers and technical users — normalizes the experience of entering device codes. A phishing lure asking them to do the same thing is indistinguishable from a legitimate IT request. And for non-technical users, this experience isn't much different to, for example, entering a code sent via email or authenticator app. ",{"data":22033,"content":22034,"nodeType":1312},{},[22035],{"data":22036,"marks":22037,"value":22039,"nodeType":864},{},[22038],{"type":899},"Multiple apps are vulnerable, with different risk profiles",{"data":22041,"content":22042,"nodeType":860},{},[22043],{"data":22044,"marks":22045,"value":22046,"nodeType":864},{},[],"Various apps implement the device code flow, each with different levels of control and default security, but the risk is not uniform across platforms. ",{"data":22048,"content":22049,"nodeType":941},{},[22050,22065,22079],{"data":22051,"content":22052,"nodeType":945},{},[22053],{"data":22054,"content":22055,"nodeType":860},{},[22056,22061],{"data":22057,"marks":22058,"value":22060,"nodeType":864},{},[22059],{"type":899},"Google Workspace ",{"data":22062,"marks":22063,"value":22064,"nodeType":864},{},[],"is a significantly lower-risk target because Google explicitly limits which scopes are available to the device code flow — Gmail, Calendar, and most Workspace APIs are simply unavailable through this mechanism. ",{"data":22066,"content":22067,"nodeType":945},{},[22068],{"data":22069,"content":22070,"nodeType":860},{},[22071,22075],{"data":22072,"marks":22073,"value":19538,"nodeType":864},{},[22074],{"type":899},{"data":22076,"marks":22077,"value":22078,"nodeType":864},{},[]," offers the broadest attack surface due to unrestricted scopes, reusable first-party client IDs, and the FOCI/PRT escalation paths. ",{"data":22080,"content":22081,"nodeType":945},{},[22082],{"data":22083,"content":22084,"nodeType":860},{},[22085,22089,22094],{"data":22086,"marks":22087,"value":22088,"nodeType":864},{},[],"Apps like ",{"data":22090,"marks":22091,"value":22093,"nodeType":864},{},[22092],{"type":899},"GitHub",{"data":22095,"marks":22096,"value":22097,"nodeType":864},{},[]," sit in between — broad scopes are available (including full repository access), but the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",{"data":22099,"content":22103,"nodeType":996},{"target":22100},{"sys":22101},{"id":22102,"type":1001,"linkType":1002},"ejNSC76jge1p1zzz9wwiG",[],{"data":22105,"content":22106,"nodeType":1005},{},[],{"data":22108,"content":22109,"nodeType":1009},{},[22110],{"data":22111,"marks":22112,"value":22114,"nodeType":864},{},[22113],{"type":899},"Security recommendations",{"data":22116,"content":22117,"nodeType":860},{},[22118],{"data":22119,"marks":22120,"value":22121,"nodeType":864},{},[],"Security teams need to consider the risk posed by device code phishing across multiple apps where device code authorization grants are common, particularly for developers and technical users. ",{"data":22123,"content":22124,"nodeType":860},{},[22125],{"data":22126,"marks":22127,"value":22128,"nodeType":864},{},[],"In an ideal world, you would simply block device code logins. But this can’t be done without causing serious disruption in some environments, while some apps simply don’t provide the tools required to do so. For example, device code is the default CLI sign-in method for GitHub. Developer-heavy organizations are likely to encounter higher levels of legitimate use.",{"data":22130,"content":22131,"nodeType":860},{},[22132,22136,22145,22149,22154,22158,22163,22167,22172],{"data":22133,"marks":22134,"value":22135,"nodeType":864},{},[],"Microsoft arguably offers the strongest control options (other than Google, who negate it right out of the gate), though they do require a fair amount of work. ",{"data":22137,"content":22139,"nodeType":883},{"uri":22138},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-microsoft-managed-policies-to-raise-your-identity-security-posture/4286758",[22140],{"data":22141,"marks":22142,"value":22144,"nodeType":864},{},[22143],{"type":1455},"Microsoft now explicitly recommends",{"data":22146,"marks":22147,"value":22148,"nodeType":864},{},[]," blocking device code flow for tenants that haven't used it in the past 25 days. Their guidance is to create a custom CA policy: target relevant users, set the ",{"data":22150,"marks":22151,"value":22153,"nodeType":864},{},[22152],{"type":899},"Authentication Flows",{"data":22155,"marks":22156,"value":22157,"nodeType":864},{},[]," condition to block ",{"data":22159,"marks":22160,"value":22162,"nodeType":864},{},[22161],{"type":899},"Device Code Flow",{"data":22164,"marks":22165,"value":22166,"nodeType":864},{},[],", and set the grant control to ",{"data":22168,"marks":22169,"value":22171,"nodeType":864},{},[22170],{"type":899},"Block Access",{"data":22173,"marks":22174,"value":22175,"nodeType":864},{},[],". Deploy in report-only mode first to identify any legitimate device code usage, then enforce with narrow exceptions.",{"data":22177,"content":22181,"nodeType":996},{"target":22178},{"sys":22179},{"id":22180,"type":1001,"linkType":1002},"mQIj2o9xRzkZYKNmanB25",[],{"data":22183,"content":22184,"nodeType":860},{},[22185],{"data":22186,"marks":22187,"value":22188,"nodeType":864},{},[],"For other apps, you’re mainly limited to monitoring and response. Ensuring you’re getting authentication logs for these apps is vital, and searching for unusual access patterns (e.g. unusual login protocols, having different IPs for the authorization grant and subsequent account activity). ",{"data":22190,"content":22191,"nodeType":1005},{},[],{"data":22193,"content":22194,"nodeType":1009},{},[22195],{"data":22196,"marks":22197,"value":22199,"nodeType":864},{},[22198],{"type":899},"How Push Security can help",{"data":22201,"content":22202,"nodeType":860},{},[22203],{"data":22204,"marks":22205,"value":22206,"nodeType":864},{},[],"Push customers can use our browser-based capabilities to overcome the limitations of app-level controls and detect, intercept, and shut down attacks in real time. ",{"data":22208,"content":22209,"nodeType":860},{},[22210],{"data":22211,"marks":22212,"value":22213,"nodeType":864},{},[],"Our research team is already tracking multiple device code phishing campaigns and toolkits, including the EvilTokens kit. Blocking controls are already in place to prevent customers from interacting with malicious pages that match our detections for these new toolkits, ensuring that these pages can be identified and blocked in real time regardless of the infrastructure. ",{"data":22215,"content":22216,"nodeType":860},{},[22217,22221,22230],{"data":22218,"marks":22219,"value":22220,"nodeType":864},{},[],"Using Push you can also ",{"data":22222,"content":22224,"nodeType":883},{"uri":22223},"https://pushsecurity.com/help/can-i-use-push-to-help-protect-against-device-code-phishing-scenarios/",[22225],{"data":22226,"marks":22227,"value":22229,"nodeType":864},{},[22228],{"type":1455},"configure in-browser warnings",{"data":22231,"marks":22232,"value":22233,"nodeType":864},{},[]," whenever a user accesses a URL used for device code logins. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":22235,"content":22239,"nodeType":996},{"target":22236},{"sys":22237},{"id":22238,"type":1001,"linkType":1002},"3JsbGaOKSS3INzBUJpoh1W",[],{"data":22241,"content":22242,"nodeType":860},{},[22243],{"data":22244,"marks":22245,"value":22246,"nodeType":864},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing device login pages if you’re confident that disruption won’t be caused. ",{"data":22248,"content":22249,"nodeType":1312},{},[22250],{"data":22251,"marks":22252,"value":3578,"nodeType":864},{},[22253],{"type":899},{"data":22255,"content":22256,"nodeType":860},{},[22257],{"data":22258,"marks":22259,"value":22260,"nodeType":864},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":22262,"content":22263,"nodeType":860},{},[22264,22267,22274,22277,22284,22287,22294],{"data":22265,"marks":22266,"value":16863,"nodeType":864},{},[],{"data":22268,"content":22269,"nodeType":883},{"uri":16866},[22270],{"data":22271,"marks":22272,"value":16871,"nodeType":864},{},[22273],{"type":1455},{"data":22275,"marks":22276,"value":3731,"nodeType":864},{},[],{"data":22278,"content":22279,"nodeType":883},{"uri":16877},[22280],{"data":22281,"marks":22282,"value":16883,"nodeType":864},{},[22283],{"type":1455},{"data":22285,"marks":22286,"value":16887,"nodeType":864},{},[],{"data":22288,"content":22289,"nodeType":883},{"uri":1700},[22290],{"data":22291,"marks":22292,"value":16894,"nodeType":864},{},[22293],{"type":1455},{"data":22295,"marks":22296,"value":2924,"nodeType":864},{},[],"Device code phishing attacks have skyrocketed: here’s what you need to know","Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.","2026-04-04T00:00:00.000Z",{"items":22301},[22302,22304],{"sys":22303,"name":13779},{"id":13778},{"sys":22305,"name":342},{"id":13775},{"items":22307},[22308],{"fullName":22309,"firstName":22310,"jobTitle":22311,"profilePicture":22312},"Luke Jennings","Luke","Vice President, R&D",{"url":22313},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":2059,"sys":22315,"content":22316,"title":4865,"synopsis":4866,"hashTags":59,"publishedDate":4867,"slug":4868,"tagsCollection":23385,"authorsCollection":23391},{"id":3628},{"json":22317},{"data":22318,"content":22319,"nodeType":856},{},[22320,22333,22338,22344,22350,22355,22358,22365,22372,22387,22425,22430,22443,22446,22453,22460,22482,22514,22520,22523,22530,22537,22543,22548,22554,22557,22564,22571,22605,22635,22641,22644,22651,22658,22678,22684,22723,22729,22732,22739,22746,22782,22788,22793,22796,22803,22810,22836,22842,22847,22853,22856,22863,22870,22893,22899,22905,22911,22914,22921,22928,22934,22939,22945,22966,22989,22992,22999,23006,23012,23018,23021,23028,23083,23086,23093,23099,23367,23370],{"data":22321,"content":22322,"nodeType":860},{},[22323,22326,22330],{"data":22324,"marks":22325,"value":3639,"nodeType":864},{},[],{"data":22327,"marks":22328,"value":3644,"nodeType":864},{},[22329],{"type":899},{"data":22331,"marks":22332,"value":3648,"nodeType":864},{},[],{"data":22334,"content":22337,"nodeType":996},{"target":22335},{"sys":22336},{"id":3653,"type":1001,"linkType":1002},[],{"data":22339,"content":22340,"nodeType":860},{},[22341],{"data":22342,"marks":22343,"value":3661,"nodeType":864},{},[],{"data":22345,"content":22346,"nodeType":860},{},[22347],{"data":22348,"marks":22349,"value":3668,"nodeType":864},{},[],{"data":22351,"content":22354,"nodeType":996},{"target":22352},{"sys":22353},{"id":3673,"type":1001,"linkType":1002},[],{"data":22356,"content":22357,"nodeType":1005},{},[],{"data":22359,"content":22360,"nodeType":1009},{},[22361],{"data":22362,"marks":22363,"value":3685,"nodeType":864},{},[22364],{"type":899},{"data":22366,"content":22367,"nodeType":860},{},[22368],{"data":22369,"marks":22370,"value":3693,"nodeType":864},{},[22371],{"type":899},{"data":22373,"content":22374,"nodeType":860},{},[22375,22378,22384],{"data":22376,"marks":22377,"value":3700,"nodeType":864},{},[],{"data":22379,"content":22380,"nodeType":883},{"uri":3703},[22381],{"data":22382,"marks":22383,"value":3708,"nodeType":864},{},[],{"data":22385,"marks":22386,"value":3712,"nodeType":864},{},[],{"data":22388,"content":22389,"nodeType":860},{},[22390,22393,22399,22402,22406,22409,22413,22416,22422],{"data":22391,"marks":22392,"value":3719,"nodeType":864},{},[],{"data":22394,"content":22395,"nodeType":883},{"uri":3722},[22396],{"data":22397,"marks":22398,"value":3727,"nodeType":864},{},[],{"data":22400,"marks":22401,"value":3731,"nodeType":864},{},[],{"data":22403,"marks":22404,"value":3736,"nodeType":864},{},[22405],{"type":899},{"data":22407,"marks":22408,"value":2232,"nodeType":864},{},[],{"data":22410,"marks":22411,"value":3744,"nodeType":864},{},[22412],{"type":899},{"data":22414,"marks":22415,"value":3748,"nodeType":864},{},[],{"data":22417,"content":22418,"nodeType":883},{"uri":3751},[22419],{"data":22420,"marks":22421,"value":3756,"nodeType":864},{},[],{"data":22423,"marks":22424,"value":3760,"nodeType":864},{},[],{"data":22426,"content":22429,"nodeType":996},{"target":22427},{"sys":22428},{"id":3765,"type":1001,"linkType":1002},[],{"data":22431,"content":22432,"nodeType":860},{},[22433,22436,22440],{"data":22434,"marks":22435,"value":3773,"nodeType":864},{},[],{"data":22437,"marks":22438,"value":3778,"nodeType":864},{},[22439],{"type":899},{"data":22441,"marks":22442,"value":2924,"nodeType":864},{},[],{"data":22444,"content":22445,"nodeType":1005},{},[],{"data":22447,"content":22448,"nodeType":1009},{},[22449],{"data":22450,"marks":22451,"value":3792,"nodeType":864},{},[22452],{"type":899},{"data":22454,"content":22455,"nodeType":860},{},[22456],{"data":22457,"marks":22458,"value":3693,"nodeType":864},{},[22459],{"type":899},{"data":22461,"content":22462,"nodeType":860},{},[22463,22466,22472,22475,22479],{"data":22464,"marks":22465,"value":3806,"nodeType":864},{},[],{"data":22467,"content":22468,"nodeType":883},{"uri":3809},[22469],{"data":22470,"marks":22471,"value":3814,"nodeType":864},{},[],{"data":22473,"marks":22474,"value":3818,"nodeType":864},{},[],{"data":22476,"marks":22477,"value":3823,"nodeType":864},{},[22478],{"type":899},{"data":22480,"marks":22481,"value":3827,"nodeType":864},{},[],{"data":22483,"content":22484,"nodeType":860},{},[22485,22488,22494,22497,22501,22504,22511],{"data":22486,"marks":22487,"value":3834,"nodeType":864},{},[],{"data":22489,"content":22490,"nodeType":883},{"uri":3837},[22491],{"data":22492,"marks":22493,"value":3842,"nodeType":864},{},[],{"data":22495,"marks":22496,"value":3846,"nodeType":864},{},[],{"data":22498,"marks":22499,"value":3851,"nodeType":864},{},[22500],{"type":899},{"data":22502,"marks":22503,"value":3855,"nodeType":864},{},[],{"data":22505,"content":22506,"nodeType":883},{"uri":3858},[22507],{"data":22508,"marks":22509,"value":3864,"nodeType":864},{},[22510],{"type":899},{"data":22512,"marks":22513,"value":3868,"nodeType":864},{},[],{"data":22515,"content":22516,"nodeType":860},{},[22517],{"data":22518,"marks":22519,"value":3875,"nodeType":864},{},[],{"data":22521,"content":22522,"nodeType":1005},{},[],{"data":22524,"content":22525,"nodeType":1009},{},[22526],{"data":22527,"marks":22528,"value":3886,"nodeType":864},{},[22529],{"type":899},{"data":22531,"content":22532,"nodeType":860},{},[22533],{"data":22534,"marks":22535,"value":3894,"nodeType":864},{},[22536],{"type":899},{"data":22538,"content":22539,"nodeType":860},{},[22540],{"data":22541,"marks":22542,"value":3901,"nodeType":864},{},[],{"data":22544,"content":22547,"nodeType":996},{"target":22545},{"sys":22546},{"id":3906,"type":1001,"linkType":1002},[],{"data":22549,"content":22550,"nodeType":860},{},[22551],{"data":22552,"marks":22553,"value":3914,"nodeType":864},{},[],{"data":22555,"content":22556,"nodeType":1005},{},[],{"data":22558,"content":22559,"nodeType":1009},{},[22560],{"data":22561,"marks":22562,"value":3925,"nodeType":864},{},[22563],{"type":899},{"data":22565,"content":22566,"nodeType":860},{},[22567],{"data":22568,"marks":22569,"value":3894,"nodeType":864},{},[22570],{"type":899},{"data":22572,"content":22573,"nodeType":860},{},[22574,22577,22584,22587,22593,22596,22602],{"data":22575,"marks":22576,"value":3939,"nodeType":864},{},[],{"data":22578,"content":22579,"nodeType":883},{"uri":3942},[22580],{"data":22581,"marks":22582,"value":3948,"nodeType":864},{},[22583],{"type":1455},{"data":22585,"marks":22586,"value":3731,"nodeType":864},{},[],{"data":22588,"content":22589,"nodeType":883},{"uri":3954},[22590],{"data":22591,"marks":22592,"value":3959,"nodeType":864},{},[],{"data":22594,"marks":22595,"value":3731,"nodeType":864},{},[],{"data":22597,"content":22598,"nodeType":883},{"uri":3965},[22599],{"data":22600,"marks":22601,"value":3970,"nodeType":864},{},[],{"data":22603,"marks":22604,"value":3974,"nodeType":864},{},[],{"data":22606,"content":22607,"nodeType":860},{},[22608,22611,22618,22621,22625,22628,22632],{"data":22609,"marks":22610,"value":21,"nodeType":864},{},[],{"data":22612,"content":22613,"nodeType":883},{"uri":2411},[22614],{"data":22615,"marks":22616,"value":3988,"nodeType":864},{},[22617],{"type":1455},{"data":22619,"marks":22620,"value":3992,"nodeType":864},{},[],{"data":22622,"marks":22623,"value":3997,"nodeType":864},{},[22624],{"type":899},{"data":22626,"marks":22627,"value":4001,"nodeType":864},{},[],{"data":22629,"marks":22630,"value":4006,"nodeType":864},{},[22631],{"type":2246},{"data":22633,"marks":22634,"value":4010,"nodeType":864},{},[],{"data":22636,"content":22637,"nodeType":860},{},[22638],{"data":22639,"marks":22640,"value":4017,"nodeType":864},{},[],{"data":22642,"content":22643,"nodeType":1005},{},[],{"data":22645,"content":22646,"nodeType":1009},{},[22647],{"data":22648,"marks":22649,"value":4028,"nodeType":864},{},[22650],{"type":899},{"data":22652,"content":22653,"nodeType":860},{},[22654],{"data":22655,"marks":22656,"value":3894,"nodeType":864},{},[22657],{"type":899},{"data":22659,"content":22660,"nodeType":860},{},[22661,22664,22668,22671,22675],{"data":22662,"marks":22663,"value":4042,"nodeType":864},{},[],{"data":22665,"marks":22666,"value":4047,"nodeType":864},{},[22667],{"type":2246},{"data":22669,"marks":22670,"value":4051,"nodeType":864},{},[],{"data":22672,"marks":22673,"value":4056,"nodeType":864},{},[22674],{"type":2246},{"data":22676,"marks":22677,"value":4060,"nodeType":864},{},[],{"data":22679,"content":22680,"nodeType":860},{},[22681],{"data":22682,"marks":22683,"value":4067,"nodeType":864},{},[],{"data":22685,"content":22686,"nodeType":941},{},[22687,22705],{"data":22688,"content":22689,"nodeType":945},{},[22690],{"data":22691,"content":22692,"nodeType":860},{},[22693,22696,22702],{"data":22694,"marks":22695,"value":2761,"nodeType":864},{},[],{"data":22697,"content":22698,"nodeType":883},{"uri":4082},[22699],{"data":22700,"marks":22701,"value":4087,"nodeType":864},{},[],{"data":22703,"marks":22704,"value":4091,"nodeType":864},{},[],{"data":22706,"content":22707,"nodeType":945},{},[22708],{"data":22709,"content":22710,"nodeType":860},{},[22711,22714,22720],{"data":22712,"marks":22713,"value":2761,"nodeType":864},{},[],{"data":22715,"content":22716,"nodeType":883},{"uri":4103},[22717],{"data":22718,"marks":22719,"value":4108,"nodeType":864},{},[],{"data":22721,"marks":22722,"value":4112,"nodeType":864},{},[],{"data":22724,"content":22725,"nodeType":860},{},[22726],{"data":22727,"marks":22728,"value":4119,"nodeType":864},{},[],{"data":22730,"content":22731,"nodeType":1005},{},[],{"data":22733,"content":22734,"nodeType":1009},{},[22735],{"data":22736,"marks":22737,"value":4130,"nodeType":864},{},[22738],{"type":899},{"data":22740,"content":22741,"nodeType":860},{},[22742],{"data":22743,"marks":22744,"value":4138,"nodeType":864},{},[22745],{"type":899},{"data":22747,"content":22748,"nodeType":860},{},[22749,22752,22756,22759,22765,22768,22772,22775,22779],{"data":22750,"marks":22751,"value":4145,"nodeType":864},{},[],{"data":22753,"marks":22754,"value":4150,"nodeType":864},{},[22755],{"type":899},{"data":22757,"marks":22758,"value":4154,"nodeType":864},{},[],{"data":22760,"content":22761,"nodeType":883},{"uri":3237},[22762],{"data":22763,"marks":22764,"value":4161,"nodeType":864},{},[],{"data":22766,"marks":22767,"value":4165,"nodeType":864},{},[],{"data":22769,"marks":22770,"value":4170,"nodeType":864},{},[22771],{"type":899},{"data":22773,"marks":22774,"value":4174,"nodeType":864},{},[],{"data":22776,"marks":22777,"value":4179,"nodeType":864},{},[22778],{"type":899},{"data":22780,"marks":22781,"value":4183,"nodeType":864},{},[],{"data":22783,"content":22784,"nodeType":860},{},[22785],{"data":22786,"marks":22787,"value":4190,"nodeType":864},{},[],{"data":22789,"content":22792,"nodeType":996},{"target":22790},{"sys":22791},{"id":4195,"type":1001,"linkType":1002},[],{"data":22794,"content":22795,"nodeType":1005},{},[],{"data":22797,"content":22798,"nodeType":1009},{},[22799],{"data":22800,"marks":22801,"value":4207,"nodeType":864},{},[22802],{"type":899},{"data":22804,"content":22805,"nodeType":860},{},[22806],{"data":22807,"marks":22808,"value":4215,"nodeType":864},{},[22809],{"type":899},{"data":22811,"content":22812,"nodeType":860},{},[22813,22816,22823,22826,22833],{"data":22814,"marks":22815,"value":4222,"nodeType":864},{},[],{"data":22817,"content":22818,"nodeType":883},{"uri":2561},[22819],{"data":22820,"marks":22821,"value":4230,"nodeType":864},{},[22822],{"type":899},{"data":22824,"marks":22825,"value":4234,"nodeType":864},{},[],{"data":22827,"content":22828,"nodeType":883},{"uri":4237},[22829],{"data":22830,"marks":22831,"value":4243,"nodeType":864},{},[22832],{"type":899},{"data":22834,"marks":22835,"value":4247,"nodeType":864},{},[],{"data":22837,"content":22838,"nodeType":860},{},[22839],{"data":22840,"marks":22841,"value":4254,"nodeType":864},{},[],{"data":22843,"content":22846,"nodeType":996},{"target":22844},{"sys":22845},{"id":4259,"type":1001,"linkType":1002},[],{"data":22848,"content":22849,"nodeType":860},{},[22850],{"data":22851,"marks":22852,"value":4267,"nodeType":864},{},[],{"data":22854,"content":22855,"nodeType":1005},{},[],{"data":22857,"content":22858,"nodeType":1009},{},[22859],{"data":22860,"marks":22861,"value":4278,"nodeType":864},{},[22862],{"type":899},{"data":22864,"content":22865,"nodeType":860},{},[22866],{"data":22867,"marks":22868,"value":4286,"nodeType":864},{},[22869],{"type":899},{"data":22871,"content":22872,"nodeType":860},{},[22873,22876,22880,22883,22890],{"data":22874,"marks":22875,"value":4293,"nodeType":864},{},[],{"data":22877,"marks":22878,"value":4298,"nodeType":864},{},[22879],{"type":2246},{"data":22881,"marks":22882,"value":4302,"nodeType":864},{},[],{"data":22884,"content":22885,"nodeType":883},{"uri":4305},[22886],{"data":22887,"marks":22888,"value":4311,"nodeType":864},{},[22889],{"type":899},{"data":22891,"marks":22892,"value":4315,"nodeType":864},{},[],{"data":22894,"content":22895,"nodeType":860},{},[22896],{"data":22897,"marks":22898,"value":4322,"nodeType":864},{},[],{"data":22900,"content":22901,"nodeType":860},{},[22902],{"data":22903,"marks":22904,"value":4329,"nodeType":864},{},[],{"data":22906,"content":22907,"nodeType":860},{},[22908],{"data":22909,"marks":22910,"value":4336,"nodeType":864},{},[],{"data":22912,"content":22913,"nodeType":1005},{},[],{"data":22915,"content":22916,"nodeType":1009},{},[22917],{"data":22918,"marks":22919,"value":4347,"nodeType":864},{},[22920],{"type":899},{"data":22922,"content":22923,"nodeType":860},{},[22924],{"data":22925,"marks":22926,"value":4355,"nodeType":864},{},[22927],{"type":899},{"data":22929,"content":22930,"nodeType":860},{},[22931],{"data":22932,"marks":22933,"value":4362,"nodeType":864},{},[],{"data":22935,"content":22938,"nodeType":996},{"target":22936},{"sys":22937},{"id":4367,"type":1001,"linkType":1002},[],{"data":22940,"content":22941,"nodeType":860},{},[22942],{"data":22943,"marks":22944,"value":4375,"nodeType":864},{},[],{"data":22946,"content":22947,"nodeType":941},{},[22948,22957],{"data":22949,"content":22950,"nodeType":945},{},[22951],{"data":22952,"content":22953,"nodeType":860},{},[22954],{"data":22955,"marks":22956,"value":4388,"nodeType":864},{},[],{"data":22958,"content":22959,"nodeType":945},{},[22960],{"data":22961,"content":22962,"nodeType":860},{},[22963],{"data":22964,"marks":22965,"value":4398,"nodeType":864},{},[],{"data":22967,"content":22968,"nodeType":860},{},[22969,22972,22979,22982,22986],{"data":22970,"marks":22971,"value":4405,"nodeType":864},{},[],{"data":22973,"content":22974,"nodeType":883},{"uri":4408},[22975],{"data":22976,"marks":22977,"value":4414,"nodeType":864},{},[22978],{"type":899},{"data":22980,"marks":22981,"value":4418,"nodeType":864},{},[],{"data":22983,"marks":22984,"value":4423,"nodeType":864},{},[22985],{"type":2246},{"data":22987,"marks":22988,"value":4427,"nodeType":864},{},[],{"data":22990,"content":22991,"nodeType":1005},{},[],{"data":22993,"content":22994,"nodeType":1009},{},[22995],{"data":22996,"marks":22997,"value":4438,"nodeType":864},{},[22998],{"type":899},{"data":23000,"content":23001,"nodeType":860},{},[23002],{"data":23003,"marks":23004,"value":4446,"nodeType":864},{},[23005],{"type":899},{"data":23007,"content":23008,"nodeType":860},{},[23009],{"data":23010,"marks":23011,"value":4453,"nodeType":864},{},[],{"data":23013,"content":23014,"nodeType":860},{},[23015],{"data":23016,"marks":23017,"value":4460,"nodeType":864},{},[],{"data":23019,"content":23020,"nodeType":1005},{},[],{"data":23022,"content":23023,"nodeType":1009},{},[23024],{"data":23025,"marks":23026,"value":4471,"nodeType":864},{},[23027],{"type":899},{"data":23029,"content":23030,"nodeType":941},{},[23031,23044,23057,23070],{"data":23032,"content":23033,"nodeType":945},{},[23034],{"data":23035,"content":23036,"nodeType":860},{},[23037,23041],{"data":23038,"marks":23039,"value":4485,"nodeType":864},{},[23040],{"type":899},{"data":23042,"marks":23043,"value":4489,"nodeType":864},{},[],{"data":23045,"content":23046,"nodeType":945},{},[23047],{"data":23048,"content":23049,"nodeType":860},{},[23050,23054],{"data":23051,"marks":23052,"value":4500,"nodeType":864},{},[23053],{"type":899},{"data":23055,"marks":23056,"value":4504,"nodeType":864},{},[],{"data":23058,"content":23059,"nodeType":945},{},[23060],{"data":23061,"content":23062,"nodeType":860},{},[23063,23067],{"data":23064,"marks":23065,"value":4515,"nodeType":864},{},[23066],{"type":899},{"data":23068,"marks":23069,"value":4519,"nodeType":864},{},[],{"data":23071,"content":23072,"nodeType":945},{},[23073],{"data":23074,"content":23075,"nodeType":860},{},[23076,23080],{"data":23077,"marks":23078,"value":781,"nodeType":864},{},[23079],{"type":899},{"data":23081,"marks":23082,"value":4533,"nodeType":864},{},[],{"data":23084,"content":23085,"nodeType":1005},{},[],{"data":23087,"content":23088,"nodeType":1009},{},[23089],{"data":23090,"marks":23091,"value":4544,"nodeType":864},{},[23092],{"type":899},{"data":23094,"content":23095,"nodeType":860},{},[23096],{"data":23097,"marks":23098,"value":4551,"nodeType":864},{},[],{"data":23100,"content":23101,"nodeType":4845},{},[23102,23125,23147,23169,23191,23213,23235,23257,23279,23301,23323,23345],{"data":23103,"content":23104,"nodeType":4581},{},[23105,23115],{"data":23106,"content":23107,"nodeType":4569},{},[23108],{"data":23109,"content":23110,"nodeType":860},{},[23111],{"data":23112,"marks":23113,"value":4568,"nodeType":864},{},[23114],{"type":899},{"data":23116,"content":23117,"nodeType":4569},{},[23118],{"data":23119,"content":23120,"nodeType":860},{},[23121],{"data":23122,"marks":23123,"value":4580,"nodeType":864},{},[23124],{"type":899},{"data":23126,"content":23127,"nodeType":4581},{},[23128,23138],{"data":23129,"content":23130,"nodeType":4569},{},[23131],{"data":23132,"content":23133,"nodeType":860},{},[23134],{"data":23135,"marks":23136,"value":4595,"nodeType":864},{},[23137],{"type":899},{"data":23139,"content":23140,"nodeType":4569},{},[23141],{"data":23142,"content":23143,"nodeType":860},{},[23144],{"data":23145,"marks":23146,"value":4605,"nodeType":864},{},[],{"data":23148,"content":23149,"nodeType":4581},{},[23150,23160],{"data":23151,"content":23152,"nodeType":4569},{},[23153],{"data":23154,"content":23155,"nodeType":860},{},[23156],{"data":23157,"marks":23158,"value":4619,"nodeType":864},{},[23159],{"type":899},{"data":23161,"content":23162,"nodeType":4569},{},[23163],{"data":23164,"content":23165,"nodeType":860},{},[23166],{"data":23167,"marks":23168,"value":4629,"nodeType":864},{},[],{"data":23170,"content":23171,"nodeType":4581},{},[23172,23182],{"data":23173,"content":23174,"nodeType":4569},{},[23175],{"data":23176,"content":23177,"nodeType":860},{},[23178],{"data":23179,"marks":23180,"value":4643,"nodeType":864},{},[23181],{"type":899},{"data":23183,"content":23184,"nodeType":4569},{},[23185],{"data":23186,"content":23187,"nodeType":860},{},[23188],{"data":23189,"marks":23190,"value":4653,"nodeType":864},{},[],{"data":23192,"content":23193,"nodeType":4581},{},[23194,23204],{"data":23195,"content":23196,"nodeType":4569},{},[23197],{"data":23198,"content":23199,"nodeType":860},{},[23200],{"data":23201,"marks":23202,"value":4667,"nodeType":864},{},[23203],{"type":899},{"data":23205,"content":23206,"nodeType":4569},{},[23207],{"data":23208,"content":23209,"nodeType":860},{},[23210],{"data":23211,"marks":23212,"value":4677,"nodeType":864},{},[],{"data":23214,"content":23215,"nodeType":4581},{},[23216,23226],{"data":23217,"content":23218,"nodeType":4569},{},[23219],{"data":23220,"content":23221,"nodeType":860},{},[23222],{"data":23223,"marks":23224,"value":4691,"nodeType":864},{},[23225],{"type":899},{"data":23227,"content":23228,"nodeType":4569},{},[23229],{"data":23230,"content":23231,"nodeType":860},{},[23232],{"data":23233,"marks":23234,"value":4701,"nodeType":864},{},[],{"data":23236,"content":23237,"nodeType":4581},{},[23238,23248],{"data":23239,"content":23240,"nodeType":4569},{},[23241],{"data":23242,"content":23243,"nodeType":860},{},[23244],{"data":23245,"marks":23246,"value":4715,"nodeType":864},{},[23247],{"type":899},{"data":23249,"content":23250,"nodeType":4569},{},[23251],{"data":23252,"content":23253,"nodeType":860},{},[23254],{"data":23255,"marks":23256,"value":4725,"nodeType":864},{},[],{"data":23258,"content":23259,"nodeType":4581},{},[23260,23270],{"data":23261,"content":23262,"nodeType":4569},{},[23263],{"data":23264,"content":23265,"nodeType":860},{},[23266],{"data":23267,"marks":23268,"value":4739,"nodeType":864},{},[23269],{"type":899},{"data":23271,"content":23272,"nodeType":4569},{},[23273],{"data":23274,"content":23275,"nodeType":860},{},[23276],{"data":23277,"marks":23278,"value":4749,"nodeType":864},{},[],{"data":23280,"content":23281,"nodeType":4581},{},[23282,23292],{"data":23283,"content":23284,"nodeType":4569},{},[23285],{"data":23286,"content":23287,"nodeType":860},{},[23288],{"data":23289,"marks":23290,"value":4763,"nodeType":864},{},[23291],{"type":899},{"data":23293,"content":23294,"nodeType":4569},{},[23295],{"data":23296,"content":23297,"nodeType":860},{},[23298],{"data":23299,"marks":23300,"value":4773,"nodeType":864},{},[],{"data":23302,"content":23303,"nodeType":4581},{},[23304,23314],{"data":23305,"content":23306,"nodeType":4569},{},[23307],{"data":23308,"content":23309,"nodeType":860},{},[23310],{"data":23311,"marks":23312,"value":4787,"nodeType":864},{},[23313],{"type":899},{"data":23315,"content":23316,"nodeType":4569},{},[23317],{"data":23318,"content":23319,"nodeType":860},{},[23320],{"data":23321,"marks":23322,"value":4797,"nodeType":864},{},[],{"data":23324,"content":23325,"nodeType":4581},{},[23326,23336],{"data":23327,"content":23328,"nodeType":4569},{},[23329],{"data":23330,"content":23331,"nodeType":860},{},[23332],{"data":23333,"marks":23334,"value":4811,"nodeType":864},{},[23335],{"type":899},{"data":23337,"content":23338,"nodeType":4569},{},[23339],{"data":23340,"content":23341,"nodeType":860},{},[23342],{"data":23343,"marks":23344,"value":4821,"nodeType":864},{},[],{"data":23346,"content":23347,"nodeType":4581},{},[23348,23358],{"data":23349,"content":23350,"nodeType":4569},{},[23351],{"data":23352,"content":23353,"nodeType":860},{},[23354],{"data":23355,"marks":23356,"value":4500,"nodeType":864},{},[23357],{"type":899},{"data":23359,"content":23360,"nodeType":4569},{},[23361],{"data":23362,"content":23363,"nodeType":860},{},[23364],{"data":23365,"marks":23366,"value":4844,"nodeType":864},{},[],{"data":23368,"content":23369,"nodeType":1005},{},[],{"data":23371,"content":23372,"nodeType":860},{},[23373,23376,23382],{"data":23374,"marks":23375,"value":4855,"nodeType":864},{},[],{"data":23377,"content":23378,"nodeType":883},{"uri":1700},[23379],{"data":23380,"marks":23381,"value":1703,"nodeType":864},{},[],{"data":23383,"marks":23384,"value":21,"nodeType":864},{},[],{"items":23386},[23387,23389],{"sys":23388,"name":297},{"id":2732},{"sys":23390,"name":2729},{"id":2728},{"items":23392},[23393],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":23394},{"url":4881},{"__typename":2059,"sys":23396,"content":23398,"title":24223,"synopsis":24224,"hashTags":59,"publishedDate":24225,"slug":24226,"tagsCollection":24227,"authorsCollection":24233},{"id":23397},"211Dd0EIrXPOFpvRgs0fEE",{"json":23399},{"data":23400,"content":23401,"nodeType":856},{},[23402,23421,23440,23457,23463,23466,23474,23481,23488,23495,23502,23510,23513,23521,23528,23535,23542,23548,23556,23574,23581,23588,23604,23612,23641,23657,23664,23691,23699,23729,23736,23744,23762,23769,23776,23782,23789,23797,23815,23822,23841,23848,23851,23859,23866,23951,23958,23974,23977,24007,24025,24032,24039,24042,24050,24068,24075,24082,24099,24102,24110,24117,24150,24157,24174,24192,24198,24201,24208],{"data":23403,"content":23404,"nodeType":860},{},[23405,23409,23417],{"data":23406,"marks":23407,"value":23408,"nodeType":864},{},[],"When we released the ",{"data":23410,"content":23412,"nodeType":883},{"uri":23411},"https://pushsecurity.com/blog/saas-attack-techniques/",[23413],{"data":23414,"marks":23415,"value":23416,"nodeType":864},{},[],"SaaS attack matrix",{"data":23418,"marks":23419,"value":23420,"nodeType":864},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":23422,"content":23423,"nodeType":860},{},[23424,23428,23436],{"data":23425,"marks":23426,"value":23427,"nodeType":864},{},[],"A year later, we ",{"data":23429,"content":23431,"nodeType":883},{"uri":23430},"https://pushsecurity.com/blog/the-saas-attack-matrix-one-year-on/",[23432],{"data":23433,"marks":23434,"value":23435,"nodeType":864},{},[],"reviewed what had changed",{"data":23437,"marks":23438,"value":23439,"nodeType":864},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":23441,"content":23442,"nodeType":860},{},[23443,23447,23453],{"data":23444,"marks":23445,"value":23446,"nodeType":864},{},[],"Today, we're re-releasing the matrix as the ",{"data":23448,"content":23449,"nodeType":883},{"uri":11562},[23450],{"data":23451,"marks":23452,"value":11754,"nodeType":864},{},[],{"data":23454,"marks":23455,"value":23456,"nodeType":864},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":23458,"content":23462,"nodeType":996},{"target":23459},{"sys":23460},{"id":23461,"type":1001,"linkType":1002},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":23464,"content":23465,"nodeType":1005},{},[],{"data":23467,"content":23468,"nodeType":1009},{},[23469],{"data":23470,"marks":23471,"value":23473,"nodeType":864},{},[23472],{"type":899},"Why the scope needed to change",{"data":23475,"content":23476,"nodeType":860},{},[23477],{"data":23478,"marks":23479,"value":23480,"nodeType":864},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":23482,"content":23483,"nodeType":860},{},[23484],{"data":23485,"marks":23486,"value":23487,"nodeType":864},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":23489,"content":23490,"nodeType":860},{},[23491],{"data":23492,"marks":23493,"value":23494,"nodeType":864},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":23496,"content":23497,"nodeType":860},{},[23498],{"data":23499,"marks":23500,"value":23501,"nodeType":864},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":23503,"content":23504,"nodeType":860},{},[23505],{"data":23506,"marks":23507,"value":23509,"nodeType":864},{},[23508],{"type":899},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":23511,"content":23512,"nodeType":1005},{},[],{"data":23514,"content":23515,"nodeType":1009},{},[23516],{"data":23517,"marks":23518,"value":23520,"nodeType":864},{},[23519],{"type":899},"The technique landscape has transformed",{"data":23522,"content":23523,"nodeType":860},{},[23524],{"data":23525,"marks":23526,"value":23527,"nodeType":864},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":23529,"content":23530,"nodeType":860},{},[23531],{"data":23532,"marks":23533,"value":23534,"nodeType":864},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":23536,"content":23537,"nodeType":860},{},[23538],{"data":23539,"marks":23540,"value":23541,"nodeType":864},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":23543,"content":23547,"nodeType":996},{"target":23544},{"sys":23545},{"id":23546,"type":1001,"linkType":1002},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":23549,"content":23550,"nodeType":1312},{},[23551],{"data":23552,"marks":23553,"value":23555,"nodeType":864},{},[23554],{"type":899},"AiTM phishing has become the default phishing method",{"data":23557,"content":23558,"nodeType":860},{},[23559,23563,23570],{"data":23560,"marks":23561,"value":23562,"nodeType":864},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":23564,"content":23565,"nodeType":883},{"uri":18939},[23566],{"data":23567,"marks":23568,"value":23569,"nodeType":864},{},[],"62% of phishing detected by Microsoft",{"data":23571,"marks":23572,"value":23573,"nodeType":864},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":23575,"content":23576,"nodeType":860},{},[23577],{"data":23578,"marks":23579,"value":23580,"nodeType":864},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":23582,"content":23583,"nodeType":860},{},[23584],{"data":23585,"marks":23586,"value":23587,"nodeType":864},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":23589,"content":23590,"nodeType":860},{},[23591,23595,23600],{"data":23592,"marks":23593,"value":23594,"nodeType":864},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":23596,"marks":23597,"value":23599,"nodeType":864},{},[23598],{"type":899},"442% year-over-year increase",{"data":23601,"marks":23602,"value":23603,"nodeType":864},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":23605,"content":23606,"nodeType":1312},{},[23607],{"data":23608,"marks":23609,"value":23611,"nodeType":864},{},[23610],{"type":899},"ClickFix is the top reported initial access vector",{"data":23613,"content":23614,"nodeType":860},{},[23615,23619,23626,23630,23637],{"data":23616,"marks":23617,"value":23618,"nodeType":864},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":23620,"content":23621,"nodeType":883},{"uri":13427},[23622],{"data":23623,"marks":23624,"value":23625,"nodeType":864},{},[],"most common initial access vector in 2025",{"data":23627,"marks":23628,"value":23629,"nodeType":864},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":23631,"content":23632,"nodeType":883},{"uri":3237},[23633],{"data":23634,"marks":23635,"value":23636,"nodeType":864},{},[],"563% increase",{"data":23638,"marks":23639,"value":23640,"nodeType":864},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":23642,"content":23643,"nodeType":860},{},[23644,23648,23653],{"data":23645,"marks":23646,"value":23647,"nodeType":864},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":23649,"marks":23650,"value":23652,"nodeType":864},{},[23651],{"type":899},"4 in 5 ClickFix payloads",{"data":23654,"marks":23655,"value":23656,"nodeType":864},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":23658,"content":23659,"nodeType":860},{},[23660],{"data":23661,"marks":23662,"value":23663,"nodeType":864},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":23665,"content":23666,"nodeType":860},{},[23667,23671,23677,23681,23687],{"data":23668,"marks":23669,"value":23670,"nodeType":864},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":23672,"content":23673,"nodeType":883},{"uri":11738},[23674],{"data":23675,"marks":23676,"value":19059,"nodeType":864},{},[],{"data":23678,"marks":23679,"value":23680,"nodeType":864},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":23682,"content":23683,"nodeType":883},{"uri":11726},[23684],{"data":23685,"marks":23686,"value":11731,"nodeType":864},{},[],{"data":23688,"marks":23689,"value":23690,"nodeType":864},{},[]," was a genuinely novel development.",{"data":23692,"content":23693,"nodeType":1312},{},[23694],{"data":23695,"marks":23696,"value":23698,"nodeType":864},{},[23697],{"type":899},"Browser-native ClickFix: ConsentFix",{"data":23700,"content":23701,"nodeType":860},{},[23702,23706,23714,23718,23725],{"data":23703,"marks":23704,"value":23705,"nodeType":864},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":23707,"content":23709,"nodeType":883},{"uri":23708},"https://pushsecurity.com/blog/consentfix-debrief/",[23710],{"data":23711,"marks":23712,"value":23713,"nodeType":864},{},[],"traced to APT29",{"data":23715,"marks":23716,"value":23717,"nodeType":864},{},[]," and has since been ",{"data":23719,"content":23720,"nodeType":883},{"uri":6940},[23721],{"data":23722,"marks":23723,"value":23724,"nodeType":864},{},[],"commercialized on criminal forums",{"data":23726,"marks":23727,"value":23728,"nodeType":864},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":23730,"content":23731,"nodeType":860},{},[23732],{"data":23733,"marks":23734,"value":23735,"nodeType":864},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":23737,"content":23738,"nodeType":1312},{},[23739],{"data":23740,"marks":23741,"value":23743,"nodeType":864},{},[23742],{"type":899},"Attackers have pivoted to authorization attacks to get around login controls",{"data":23745,"content":23746,"nodeType":860},{},[23747,23751,23758],{"data":23748,"marks":23749,"value":23750,"nodeType":864},{},[],"Authorization attacks like device code phishing have seen a ",{"data":23752,"content":23753,"nodeType":883},{"uri":3259},[23754],{"data":23755,"marks":23756,"value":23757,"nodeType":864},{},[],"37.5x increase",{"data":23759,"marks":23760,"value":23761,"nodeType":864},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":23763,"content":23764,"nodeType":860},{},[23765],{"data":23766,"marks":23767,"value":23768,"nodeType":864},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":23770,"content":23771,"nodeType":860},{},[23772],{"data":23773,"marks":23774,"value":23775,"nodeType":864},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":23777,"content":23781,"nodeType":996},{"target":23778},{"sys":23779},{"id":23780,"type":1001,"linkType":1002},"2WPb41lNRajdpt5pogQg8M",[],{"data":23783,"content":23784,"nodeType":860},{},[23785],{"data":23786,"marks":23787,"value":23788,"nodeType":864},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":23790,"content":23791,"nodeType":1312},{},[23792],{"data":23793,"marks":23794,"value":23796,"nodeType":864},{},[23795],{"type":899},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":23798,"content":23799,"nodeType":860},{},[23800,23804,23811],{"data":23801,"marks":23802,"value":23803,"nodeType":864},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":23805,"content":23806,"nodeType":883},{"uri":2411},[23807],{"data":23808,"marks":23809,"value":23810,"nodeType":864},{},[],"Cyberhaven compromise",{"data":23812,"marks":23813,"value":23814,"nodeType":864},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":23816,"content":23817,"nodeType":860},{},[23818],{"data":23819,"marks":23820,"value":23821,"nodeType":864},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":23823,"content":23824,"nodeType":860},{},[23825,23829,23837],{"data":23826,"marks":23827,"value":23828,"nodeType":864},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":23830,"content":23831,"nodeType":883},{"uri":2411},[23832],{"data":23833,"marks":23834,"value":23836,"nodeType":864},{},[23835],{"type":1455},"most malicious extensions didn't start out malicious",{"data":23838,"marks":23839,"value":23840,"nodeType":864},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":23842,"content":23843,"nodeType":860},{},[23844],{"data":23845,"marks":23846,"value":23847,"nodeType":864},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":23849,"content":23850,"nodeType":1005},{},[],{"data":23852,"content":23853,"nodeType":1009},{},[23854],{"data":23855,"marks":23856,"value":23858,"nodeType":864},{},[23857],{"type":899},"The evolution is playing out in public breaches",{"data":23860,"content":23861,"nodeType":860},{},[23862],{"data":23863,"marks":23864,"value":23865,"nodeType":864},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":23867,"content":23868,"nodeType":941},{},[23869,23889,23911,23931],{"data":23870,"content":23871,"nodeType":945},{},[23872],{"data":23873,"content":23874,"nodeType":860},{},[23875,23879,23885],{"data":23876,"marks":23877,"value":23878,"nodeType":864},{},[],"When ",{"data":23880,"content":23881,"nodeType":883},{"uri":16015},[23882],{"data":23883,"marks":23884,"value":16018,"nodeType":864},{},[],{"data":23886,"marks":23887,"value":23888,"nodeType":864},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.",{"data":23890,"content":23891,"nodeType":945},{},[23892],{"data":23893,"content":23894,"nodeType":860},{},[23895,23899,23907],{"data":23896,"marks":23897,"value":23898,"nodeType":864},{},[],"When the same collective launched ",{"data":23900,"content":23902,"nodeType":883},{"uri":23901},"https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign/",[23903],{"data":23904,"marks":23905,"value":23906,"nodeType":864},{},[],"AiTM phishing campaigns",{"data":23908,"marks":23909,"value":23910,"nodeType":864},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":23912,"content":23913,"nodeType":945},{},[23914],{"data":23915,"content":23916,"nodeType":860},{},[23917,23920,23927],{"data":23918,"marks":23919,"value":23878,"nodeType":864},{},[],{"data":23921,"content":23922,"nodeType":883},{"uri":11726},[23923],{"data":23924,"marks":23925,"value":23926,"nodeType":864},{},[],"APT29 deployed ConsentFix",{"data":23928,"marks":23929,"value":23930,"nodeType":864},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":23932,"content":23933,"nodeType":945},{},[23934],{"data":23935,"content":23936,"nodeType":860},{},[23937,23940,23947],{"data":23938,"marks":23939,"value":2761,"nodeType":864},{},[],{"data":23941,"content":23943,"nodeType":883},{"uri":23942},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[23944],{"data":23945,"marks":23946,"value":3756,"nodeType":864},{},[],{"data":23948,"marks":23949,"value":23950,"nodeType":864},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.",{"data":23952,"content":23953,"nodeType":860},{},[23954],{"data":23955,"marks":23956,"value":23957,"nodeType":864},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":23959,"content":23960,"nodeType":860},{},[23961,23965,23970],{"data":23962,"marks":23963,"value":23964,"nodeType":864},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":23966,"marks":23967,"value":23969,"nodeType":864},{},[23968],{"type":899},"29 minutes",{"data":23971,"marks":23972,"value":23973,"nodeType":864},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":23975,"content":23976,"nodeType":1005},{},[],{"data":23978,"content":23979,"nodeType":1009},{},[23980,23985,23991,23996,24002],{"data":23981,"marks":23982,"value":23984,"nodeType":864},{},[23983],{"type":899},"Sidenote: why we're looking at attacks ",{"data":23986,"marks":23987,"value":23990,"nodeType":864},{},[23988,23989],{"type":2246},{"type":899},"in",{"data":23992,"marks":23993,"value":23995,"nodeType":864},{},[23994],{"type":899}," the browser, not ",{"data":23997,"marks":23998,"value":24001,"nodeType":864},{},[23999,24000],{"type":2246},{"type":899},"on",{"data":24003,"marks":24004,"value":24006,"nodeType":864},{},[24005],{"type":899}," the browser",{"data":24008,"content":24009,"nodeType":860},{},[24010,24014,24021],{"data":24011,"marks":24012,"value":24013,"nodeType":864},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":24015,"content":24016,"nodeType":883},{"uri":18859},[24017],{"data":24018,"marks":24019,"value":24020,"nodeType":864},{},[],"historic low of 9%",{"data":24022,"marks":24023,"value":24024,"nodeType":864},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":24026,"content":24027,"nodeType":860},{},[24028],{"data":24029,"marks":24030,"value":24031,"nodeType":864},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":24033,"content":24034,"nodeType":860},{},[24035],{"data":24036,"marks":24037,"value":24038,"nodeType":864},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":24040,"content":24041,"nodeType":1005},{},[],{"data":24043,"content":24044,"nodeType":1009},{},[24045],{"data":24046,"marks":24047,"value":24049,"nodeType":864},{},[24048],{"type":899},"What hasn't changed",{"data":24051,"content":24052,"nodeType":860},{},[24053,24057,24064],{"data":24054,"marks":24055,"value":24056,"nodeType":864},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":24058,"content":24060,"nodeType":883},{"uri":24059},"https://github.com/pushsecurity/saas-attacks",[24061],{"data":24062,"marks":24063,"value":22093,"nodeType":864},{},[],{"data":24065,"marks":24066,"value":24067,"nodeType":864},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":24069,"content":24070,"nodeType":860},{},[24071],{"data":24072,"marks":24073,"value":24074,"nodeType":864},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":24076,"content":24077,"nodeType":860},{},[24078],{"data":24079,"marks":24080,"value":24081,"nodeType":864},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":24083,"content":24084,"nodeType":860},{},[24085,24089,24096],{"data":24086,"marks":24087,"value":24088,"nodeType":864},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":24090,"content":24092,"nodeType":883},{"uri":24091},"https://github.com/pushsecurity/browser-identity-attacks-matrix",[24093],{"data":24094,"marks":24095,"value":22093,"nodeType":864},{},[],{"data":24097,"marks":24098,"value":2924,"nodeType":864},{},[],{"data":24100,"content":24101,"nodeType":1005},{},[],{"data":24103,"content":24104,"nodeType":1009},{},[24105],{"data":24106,"marks":24107,"value":24109,"nodeType":864},{},[24108],{"type":899},"Looking ahead",{"data":24111,"content":24112,"nodeType":860},{},[24113],{"data":24114,"marks":24115,"value":24116,"nodeType":864},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":24118,"content":24119,"nodeType":941},{},[24120,24130,24140],{"data":24121,"content":24122,"nodeType":945},{},[24123],{"data":24124,"content":24125,"nodeType":860},{},[24126],{"data":24127,"marks":24128,"value":24129,"nodeType":864},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":24131,"content":24132,"nodeType":945},{},[24133],{"data":24134,"content":24135,"nodeType":860},{},[24136],{"data":24137,"marks":24138,"value":24139,"nodeType":864},{},[],"ClickFix has spawned fully browser-native variants.",{"data":24141,"content":24142,"nodeType":945},{},[24143],{"data":24144,"content":24145,"nodeType":860},{},[24146],{"data":24147,"marks":24148,"value":24149,"nodeType":864},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":24151,"content":24152,"nodeType":860},{},[24153],{"data":24154,"marks":24155,"value":24156,"nodeType":864},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":24158,"content":24159,"nodeType":860},{},[24160,24164,24171],{"data":24161,"marks":24162,"value":24163,"nodeType":864},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":24165,"content":24166,"nodeType":883},{"uri":11562},[24167],{"data":24168,"marks":24169,"value":24170,"nodeType":864},{},[],"explore the matrix here",{"data":24172,"marks":24173,"value":2924,"nodeType":864},{},[],{"data":24175,"content":24176,"nodeType":860},{},[24177,24181,24188],{"data":24178,"marks":24179,"value":24180,"nodeType":864},{},[],"You can also read our recent ",{"data":24182,"content":24183,"nodeType":883},{"uri":11536},[24184],{"data":24185,"marks":24186,"value":24187,"nodeType":864},{},[],"browser attack techniques report",{"data":24189,"marks":24190,"value":24191,"nodeType":864},{},[]," for more information.",{"data":24193,"content":24197,"nodeType":996},{"target":24194},{"sys":24195},{"id":24196,"type":1001,"linkType":1002},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":24199,"content":24200,"nodeType":1005},{},[],{"data":24202,"content":24203,"nodeType":860},{},[24204],{"data":24205,"marks":24206,"value":24207,"nodeType":864},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":24209,"content":24210,"nodeType":860},{},[24211,24214,24220],{"data":24212,"marks":24213,"value":2707,"nodeType":864},{},[],{"data":24215,"content":24216,"nodeType":883},{"uri":1700},[24217],{"data":24218,"marks":24219,"value":2715,"nodeType":864},{},[],{"data":24221,"marks":24222,"value":2719,"nodeType":864},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":24228},[24229,24231],{"sys":24230,"name":13779},{"id":13778},{"sys":24232,"name":342},{"id":13775},{"items":24234},[24235],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":24236},{"url":2740},"7-things-we-learned-from-matt-johansen","blog/7-things-we-learned-from-matt-johansen",{"json":24240},{"data":24241,"content":24242,"nodeType":856},{},[24243],{"data":24244,"content":24245,"nodeType":860},{},[24246,24250,24257],{"data":24247,"marks":24248,"value":24249,"nodeType":864},{},[],"In the final installment of our ",{"data":24251,"content":24252,"nodeType":883},{"uri":19243},[24253],{"data":24254,"marks":24255,"value":24256,"nodeType":864},{},[],"State of Browser Attacks series",{"data":24258,"marks":24259,"value":24260,"nodeType":864},{},[],", Push Field CTO Mark Orlando sat down with Matt Johansen, security veteran, former Reddit security lead, and founder of the Vulnerable U newsletter, to talk about what's actually working in security and what's just theater. Here are seven takeaways from the conversation.","What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works. ",{"id":24263,"publishedAt":24264},"3EM39T0mqy5DscsNSact3Z","2026-08-12T12:00:52.913Z",{"items":24266},[24267,24269],{"sys":24268,"name":297},{"id":2732},{"sys":24270,"name":2729},{"id":2728},{"items":24272},[24273,24275,24277,24279,24281,24283,24285,24287,24289,24291,24293,24295,24297,24299,24301,24303,24305,24307],{"sys":24274,"name":279,"slug":280,"tier":31},{"id":276},{"sys":24276,"name":413,"slug":414,"tier":31},{"id":410},{"sys":24278,"name":297,"slug":298,"tier":31},{"id":294},{"sys":24280,"name":519,"slug":520,"tier":31},{"id":516},{"sys":24282,"name":261,"slug":262,"tier":45},{"id":258},{"sys":24284,"name":315,"slug":316,"tier":45},{"id":312},{"sys":24286,"name":466,"slug":467,"tier":45},{"id":463},{"sys":24288,"name":511,"slug":512,"tier":45},{"id":508},{"sys":24290,"name":571,"slug":572,"tier":45},{"id":568},{"sys":24292,"name":360,"slug":361,"tier":45},{"id":357},{"sys":24294,"name":288,"slug":289,"tier":45},{"id":285},{"sys":24296,"name":607,"slug":608,"tier":45},{"id":604},{"sys":24298,"name":554,"slug":555,"tier":45},{"id":551},{"sys":24300,"name":457,"slug":458,"tier":45},{"id":454},{"sys":24302,"name":484,"slug":485,"tier":45},{"id":481},{"sys":24304,"name":333,"slug":334,"tier":45},{"id":330},{"sys":24306,"name":422,"slug":423,"tier":45},{"id":419},{"sys":24308,"name":244,"slug":245,"tier":45},{"id":241},"AunB53ENgDXpGtfck0wVIWIMH2JNgreFpn5xEkZdVmo",{"id":24311,"title":11980,"authorsCollection":24312,"content":24318,"extension":228,"faqItemsCollection":24935,"faqTitle":59,"featured":6,"hashTags":59,"meta":24937,"metaTitle":24938,"ogImage":59,"postType":5726,"publishedDate":11982,"relatedBlogPostsCollection":24939,"slug":11983,"stem":27386,"subtitle":59,"summary":27387,"synopsis":11981,"sys":27398,"tagsCollection":27400,"topicsCollection":27406,"__hash__":27432},"blog/blog/enterprise-browser-vs-browser-extension-which-should-your-security-team-choose.json",{"items":24313},[24314],{"fullName":4878,"firstName":4879,"jobTitle":851,"socialLinks":24315,"profilePicture":24317},[24316],"https://www.linkedin.com/in/alexhenshall/",{"url":4881},{"json":24319,"links":24906},{"data":24320,"content":24321,"nodeType":856},{},[24322,24328,24334,24353,24359,24365,24371,24374,24381,24387,24403,24409,24415,24457,24463,24470,24476,24482,24488,24491,24498,24504,24514,24520,24527,24543,24548,24581,24586,24592,24602,24607,24613,24628,24635,24641,24657,24662,24669,24675,24806,24809,24816,24822,24828,24831,24838,24844,24854,24864,24874,24884,24890],{"data":24323,"content":24324,"nodeType":860},{},[24325],{"data":24326,"marks":24327,"value":11297,"nodeType":864},{},[],{"data":24329,"content":24330,"nodeType":860},{},[24331],{"data":24332,"marks":24333,"value":11304,"nodeType":864},{},[],{"data":24335,"content":24336,"nodeType":1116},{},[24337],{"data":24338,"content":24339,"nodeType":860},{},[24340,24343,24350],{"data":24341,"marks":24342,"value":11314,"nodeType":864},{},[],{"data":24344,"content":24345,"nodeType":883},{"uri":2561},[24346],{"data":24347,"marks":24348,"value":11322,"nodeType":864},{},[24349],{"type":1455},{"data":24351,"marks":24352,"value":11326,"nodeType":864},{},[],{"data":24354,"content":24355,"nodeType":860},{},[24356],{"data":24357,"marks":24358,"value":11333,"nodeType":864},{},[],{"data":24360,"content":24361,"nodeType":860},{},[24362],{"data":24363,"marks":24364,"value":11340,"nodeType":864},{},[],{"data":24366,"content":24367,"nodeType":860},{},[24368],{"data":24369,"marks":24370,"value":11347,"nodeType":864},{},[],{"data":24372,"content":24373,"nodeType":1005},{},[],{"data":24375,"content":24376,"nodeType":1009},{},[24377],{"data":24378,"marks":24379,"value":11358,"nodeType":864},{},[24380],{"type":899},{"data":24382,"content":24383,"nodeType":860},{},[24384],{"data":24385,"marks":24386,"value":11365,"nodeType":864},{},[],{"data":24388,"content":24389,"nodeType":1116},{},[24390],{"data":24391,"content":24392,"nodeType":860},{},[24393,24396,24400],{"data":24394,"marks":24395,"value":11375,"nodeType":864},{},[],{"data":24397,"marks":24398,"value":11380,"nodeType":864},{},[24399],{"type":2246},{"data":24401,"marks":24402,"value":7160,"nodeType":864},{},[],{"data":24404,"content":24405,"nodeType":860},{},[24406],{"data":24407,"marks":24408,"value":11390,"nodeType":864},{},[],{"data":24410,"content":24411,"nodeType":860},{},[24412],{"data":24413,"marks":24414,"value":11397,"nodeType":864},{},[],{"data":24416,"content":24417,"nodeType":941},{},[24418,24431,24444],{"data":24419,"content":24420,"nodeType":945},{},[24421],{"data":24422,"content":24423,"nodeType":860},{},[24424,24428],{"data":24425,"marks":24426,"value":11411,"nodeType":864},{},[24427],{"type":899},{"data":24429,"marks":24430,"value":11415,"nodeType":864},{},[],{"data":24432,"content":24433,"nodeType":945},{},[24434],{"data":24435,"content":24436,"nodeType":860},{},[24437,24441],{"data":24438,"marks":24439,"value":11426,"nodeType":864},{},[24440],{"type":899},{"data":24442,"marks":24443,"value":11430,"nodeType":864},{},[],{"data":24445,"content":24446,"nodeType":945},{},[24447],{"data":24448,"content":24449,"nodeType":860},{},[24450,24454],{"data":24451,"marks":24452,"value":11441,"nodeType":864},{},[24453],{"type":899},{"data":24455,"marks":24456,"value":11445,"nodeType":864},{},[],{"data":24458,"content":24459,"nodeType":860},{},[24460],{"data":24461,"marks":24462,"value":11452,"nodeType":864},{},[],{"data":24464,"content":24465,"nodeType":1312},{},[24466],{"data":24467,"marks":24468,"value":11460,"nodeType":864},{},[24469],{"type":899},{"data":24471,"content":24472,"nodeType":860},{},[24473],{"data":24474,"marks":24475,"value":11467,"nodeType":864},{},[],{"data":24477,"content":24478,"nodeType":860},{},[24479],{"data":24480,"marks":24481,"value":11474,"nodeType":864},{},[],{"data":24483,"content":24484,"nodeType":860},{},[24485],{"data":24486,"marks":24487,"value":11481,"nodeType":864},{},[],{"data":24489,"content":24490,"nodeType":1005},{},[],{"data":24492,"content":24493,"nodeType":1009},{},[24494],{"data":24495,"marks":24496,"value":11492,"nodeType":864},{},[24497],{"type":899},{"data":24499,"content":24500,"nodeType":860},{},[24501],{"data":24502,"marks":24503,"value":11499,"nodeType":864},{},[],{"data":24505,"content":24506,"nodeType":860},{},[24507,24510],{"data":24508,"marks":24509,"value":11506,"nodeType":864},{},[],{"data":24511,"marks":24512,"value":11511,"nodeType":864},{},[24513],{"type":2246},{"data":24515,"content":24516,"nodeType":860},{},[24517],{"data":24518,"marks":24519,"value":11518,"nodeType":864},{},[],{"data":24521,"content":24522,"nodeType":1312},{},[24523],{"data":24524,"marks":24525,"value":11526,"nodeType":864},{},[24526],{"type":899},{"data":24528,"content":24529,"nodeType":860},{},[24530,24533,24540],{"data":24531,"marks":24532,"value":11533,"nodeType":864},{},[],{"data":24534,"content":24535,"nodeType":883},{"uri":11536},[24536],{"data":24537,"marks":24538,"value":11542,"nodeType":864},{},[24539],{"type":1455},{"data":24541,"marks":24542,"value":11546,"nodeType":864},{},[],{"data":24544,"content":24547,"nodeType":996},{"target":24545},{"sys":24546},{"id":11551,"type":1001,"linkType":1002},[],{"data":24549,"content":24550,"nodeType":860},{},[24551,24554,24561,24564,24568,24571,24578],{"data":24552,"marks":24553,"value":11559,"nodeType":864},{},[],{"data":24555,"content":24556,"nodeType":883},{"uri":11562},[24557],{"data":24558,"marks":24559,"value":11568,"nodeType":864},{},[24560],{"type":1455},{"data":24562,"marks":24563,"value":11572,"nodeType":864},{},[],{"data":24565,"marks":24566,"value":11577,"nodeType":864},{},[24567],{"type":899},{"data":24569,"marks":24570,"value":11581,"nodeType":864},{},[],{"data":24572,"content":24573,"nodeType":883},{"uri":11584},[24574],{"data":24575,"marks":24576,"value":11590,"nodeType":864},{},[24577],{"type":1455},{"data":24579,"marks":24580,"value":11546,"nodeType":864},{},[],{"data":24582,"content":24585,"nodeType":996},{"target":24583},{"sys":24584},{"id":11598,"type":1001,"linkType":1002},[],{"data":24587,"content":24588,"nodeType":860},{},[24589],{"data":24590,"marks":24591,"value":11606,"nodeType":864},{},[],{"data":24593,"content":24594,"nodeType":860},{},[24595,24598],{"data":24596,"marks":24597,"value":11613,"nodeType":864},{},[],{"data":24599,"marks":24600,"value":11618,"nodeType":864},{},[24601],{"type":899},{"data":24603,"content":24606,"nodeType":996},{"target":24604},{"sys":24605},{"id":11623,"type":1001,"linkType":1002},[],{"data":24608,"content":24609,"nodeType":860},{},[24610],{"data":24611,"marks":24612,"value":11631,"nodeType":864},{},[],{"data":24614,"content":24615,"nodeType":860},{},[24616,24619,24625],{"data":24617,"marks":24618,"value":2761,"nodeType":864},{},[],{"data":24620,"content":24621,"nodeType":883},{"uri":11640},[24622],{"data":24623,"marks":24624,"value":11645,"nodeType":864},{},[],{"data":24626,"marks":24627,"value":11649,"nodeType":864},{},[],{"data":24629,"content":24630,"nodeType":1312},{},[24631],{"data":24632,"marks":24633,"value":11657,"nodeType":864},{},[24634],{"type":899},{"data":24636,"content":24637,"nodeType":860},{},[24638],{"data":24639,"marks":24640,"value":11664,"nodeType":864},{},[],{"data":24642,"content":24643,"nodeType":860},{},[24644,24647,24654],{"data":24645,"marks":24646,"value":11671,"nodeType":864},{},[],{"data":24648,"content":24649,"nodeType":883},{"uri":11674},[24650],{"data":24651,"marks":24652,"value":11680,"nodeType":864},{},[24653],{"type":1455},{"data":24655,"marks":24656,"value":11684,"nodeType":864},{},[],{"data":24658,"content":24661,"nodeType":996},{"target":24659},{"sys":24660},{"id":11689,"type":1001,"linkType":1002},[],{"data":24663,"content":24664,"nodeType":1312},{},[24665],{"data":24666,"marks":24667,"value":11698,"nodeType":864},{},[24668],{"type":899},{"data":24670,"content":24671,"nodeType":860},{},[24672],{"data":24673,"marks":24674,"value":11705,"nodeType":864},{},[],{"data":24676,"content":24677,"nodeType":941},{},[24678,24718,24749,24780,24793],{"data":24679,"content":24680,"nodeType":945},{},[24681],{"data":24682,"content":24683,"nodeType":860},{},[24684,24688,24691,24697,24700,24706,24709,24715],{"data":24685,"marks":24686,"value":11719,"nodeType":864},{},[24687],{"type":899},{"data":24689,"marks":24690,"value":11723,"nodeType":864},{},[],{"data":24692,"content":24693,"nodeType":883},{"uri":11726},[24694],{"data":24695,"marks":24696,"value":11731,"nodeType":864},{},[],{"data":24698,"marks":24699,"value":11735,"nodeType":864},{},[],{"data":24701,"content":24702,"nodeType":883},{"uri":11738},[24703],{"data":24704,"marks":24705,"value":11743,"nodeType":864},{},[],{"data":24707,"marks":24708,"value":11747,"nodeType":864},{},[],{"data":24710,"content":24711,"nodeType":883},{"uri":7549},[24712],{"data":24713,"marks":24714,"value":11754,"nodeType":864},{},[],{"data":24716,"marks":24717,"value":11758,"nodeType":864},{},[],{"data":24719,"content":24720,"nodeType":945},{},[24721],{"data":24722,"content":24723,"nodeType":860},{},[24724,24728,24731,24737,24740,24746],{"data":24725,"marks":24726,"value":11769,"nodeType":864},{},[24727],{"type":899},{"data":24729,"marks":24730,"value":11773,"nodeType":864},{},[],{"data":24732,"content":24733,"nodeType":883},{"uri":7572},[24734],{"data":24735,"marks":24736,"value":7578,"nodeType":864},{},[],{"data":24738,"marks":24739,"value":11783,"nodeType":864},{},[],{"data":24741,"content":24742,"nodeType":883},{"uri":11786},[24743],{"data":24744,"marks":24745,"value":11791,"nodeType":864},{},[],{"data":24747,"marks":24748,"value":11795,"nodeType":864},{},[],{"data":24750,"content":24751,"nodeType":945},{},[24752],{"data":24753,"content":24754,"nodeType":860},{},[24755,24759,24762,24768,24771,24777],{"data":24756,"marks":24757,"value":11806,"nodeType":864},{},[24758],{"type":899},{"data":24760,"marks":24761,"value":11810,"nodeType":864},{},[],{"data":24763,"content":24764,"nodeType":883},{"uri":11813},[24765],{"data":24766,"marks":24767,"value":11818,"nodeType":864},{},[],{"data":24769,"marks":24770,"value":11822,"nodeType":864},{},[],{"data":24772,"content":24773,"nodeType":883},{"uri":11825},[24774],{"data":24775,"marks":24776,"value":11830,"nodeType":864},{},[],{"data":24778,"marks":24779,"value":11834,"nodeType":864},{},[],{"data":24781,"content":24782,"nodeType":945},{},[24783],{"data":24784,"content":24785,"nodeType":860},{},[24786,24790],{"data":24787,"marks":24788,"value":11845,"nodeType":864},{},[24789],{"type":899},{"data":24791,"marks":24792,"value":11849,"nodeType":864},{},[],{"data":24794,"content":24795,"nodeType":945},{},[24796],{"data":24797,"content":24798,"nodeType":860},{},[24799,24803],{"data":24800,"marks":24801,"value":11860,"nodeType":864},{},[24802],{"type":899},{"data":24804,"marks":24805,"value":11864,"nodeType":864},{},[],{"data":24807,"content":24808,"nodeType":1005},{},[],{"data":24810,"content":24811,"nodeType":1009},{},[24812],{"data":24813,"marks":24814,"value":11875,"nodeType":864},{},[24815],{"type":899},{"data":24817,"content":24818,"nodeType":860},{},[24819],{"data":24820,"marks":24821,"value":11882,"nodeType":864},{},[],{"data":24823,"content":24824,"nodeType":860},{},[24825],{"data":24826,"marks":24827,"value":11889,"nodeType":864},{},[],{"data":24829,"content":24830,"nodeType":1005},{},[],{"data":24832,"content":24833,"nodeType":1009},{},[24834],{"data":24835,"marks":24836,"value":11900,"nodeType":864},{},[24837],{"type":899},{"data":24839,"content":24840,"nodeType":860},{},[24841],{"data":24842,"marks":24843,"value":11907,"nodeType":864},{},[],{"data":24845,"content":24846,"nodeType":860},{},[24847,24851],{"data":24848,"marks":24849,"value":11915,"nodeType":864},{},[24850],{"type":899},{"data":24852,"marks":24853,"value":11919,"nodeType":864},{},[],{"data":24855,"content":24856,"nodeType":860},{},[24857,24861],{"data":24858,"marks":24859,"value":11927,"nodeType":864},{},[24860],{"type":899},{"data":24862,"marks":24863,"value":11931,"nodeType":864},{},[],{"data":24865,"content":24866,"nodeType":860},{},[24867,24871],{"data":24868,"marks":24869,"value":11939,"nodeType":864},{},[24870],{"type":899},{"data":24872,"marks":24873,"value":11943,"nodeType":864},{},[],{"data":24875,"content":24876,"nodeType":860},{},[24877,24881],{"data":24878,"marks":24879,"value":11951,"nodeType":864},{},[24880],{"type":899},{"data":24882,"marks":24883,"value":11955,"nodeType":864},{},[],{"data":24885,"content":24886,"nodeType":860},{},[24887],{"data":24888,"marks":24889,"value":11962,"nodeType":864},{},[],{"data":24891,"content":24892,"nodeType":860},{},[24893,24896,24903],{"data":24894,"marks":24895,"value":21,"nodeType":864},{},[],{"data":24897,"content":24898,"nodeType":883},{"uri":1700},[24899],{"data":24900,"marks":24901,"value":11976,"nodeType":864},{},[24902],{"type":1455},{"data":24904,"marks":24905,"value":2924,"nodeType":864},{},[],{"entries":24907},{"hyperlink":24908,"inline":24909,"block":24910},[],[],[24911,24914,24922,24927],{"sys":24912,"__typename":1717,"type":1718,"ctaText":24913,"buttonLabel":151,"buttonColour":1721,"buttonUrl":11536},{"id":11551},"Read our report on the browser attack techniques security teams need to contend with in 2026 (no gates!)",{"sys":24915,"__typename":1724,"title":24916,"caption":24917,"layoutMode":59,"file":24918},{"id":11598},"Comparing ease of deployment x security value for browser security solutions","Comparing ease of deployment x security value for browser security solutions.",{"url":24919,"width":24920,"height":24921},"https://images.ctfassets.net/y1cdw1ablpvd/4z1RAFROesqaBF4H3qR8yu/1e21a68602402773bfa843fd0208d4ca/Screenshot_2026-07-27_at_10.36.43.png",1408,952,{"sys":24923,"__typename":1717,"type":1718,"ctaText":24924,"buttonLabel":24925,"buttonColour":1721,"buttonUrl":24926},{"id":11623},"Read our blog for a step-by-step guide to how Push protects against browser-based attacks. ","Read the blog","https://pushsecurity.com/blog/guide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks/",{"sys":24928,"__typename":1724,"title":24929,"caption":24930,"layoutMode":59,"file":24931},{"id":11689},"SEB Blog Quote Callout","What security leaders have to say about Push.",{"url":24932,"width":24933,"height":24934},"https://images.ctfassets.net/y1cdw1ablpvd/3puINxgWMVBvsieKSMxbcA/d68e403607ea8786de911f7c0bbdd1d3/Frame_628075.png",1390,930,{"items":24936},[],{},"Enterprise browser vs. browser extension solution analysis",{"items":24940},[24941,25525,26305],{"__typename":2059,"sys":24942,"content":24944,"title":25511,"synopsis":25512,"hashTags":59,"publishedDate":25513,"slug":25514,"tagsCollection":25515,"authorsCollection":25521},{"id":24943},"LlTjdYp5ALHM3YIvsCibZ",{"json":24945},{"data":24946,"content":24947,"nodeType":856},{},[24948,24955,24982,24989,24992,25000,25007,25014,25021,25029,25083,25090,25098,25105,25112,25120,25127,25134,25153,25184,25191,25194,25202,25210,25228,25236,25255,25263,25270,25278,25285,25293,25300,25303,25311,25318,25329,25348,25356,25363,25369,25377,25413,25419,25427,25444,25452,25470,25473,25481,25488,25495],{"data":24949,"content":24950,"nodeType":860},{},[24951],{"data":24952,"marks":24953,"value":24954,"nodeType":864},{},[],"Three browser security companies have been acquired by major security platforms in five months. CrowdStrike acquired Seraphic Security in January 2026. Zscaler absorbed SquareX in February. In May, Akamai announced the acquisition of LayerX. Add Palo Alto Networks' earlier acquisition of Talon, and the browser security market has consolidated faster than almost any adjacent security category before it.",{"data":24956,"content":24957,"nodeType":860},{},[24958,24962,24969,24972,24979],{"data":24959,"marks":24960,"value":24961,"nodeType":864},{},[],"These acquisitions recognize that the browser is now where employees work, where AI runs, and where the most damaging attacks on organizations originate. It’s telling that browser security already accounts for ",{"data":24963,"content":24964,"nodeType":883},{"uri":2561},[24965],{"data":24966,"marks":24967,"value":24968,"nodeType":864},{},[],"12.6% of the average security budget",{"data":24970,"marks":24971,"value":2232,"nodeType":864},{},[],{"data":24973,"content":24974,"nodeType":883},{"uri":2561},[24975],{"data":24976,"marks":24977,"value":24978,"nodeType":864},{},[],"85% of organizations expect to increase that spend over the next 12-24 months",{"data":24980,"marks":24981,"value":2924,"nodeType":864},{},[],{"data":24983,"content":24984,"nodeType":860},{},[24985],{"data":24986,"marks":24987,"value":24988,"nodeType":864},{},[],"But for security buyers, consolidation creates a risk as much as an opportunity. The question isn't whether your existing platform vendor now offers browser security — it's whether what they're offering can actually protect you as the threat landscape evolves.",{"data":24990,"content":24991,"nodeType":1005},{},[],{"data":24993,"content":24994,"nodeType":1009},{},[24995],{"data":24996,"marks":24997,"value":24999,"nodeType":864},{},[24998],{"type":899},"Why \"good enough\" isn't good enough in the browser",{"data":25001,"content":25002,"nodeType":860},{},[25003],{"data":25004,"marks":25005,"value":25006,"nodeType":864},{},[],"The consolidation pitch is tempting. If you're already a CrowdStrike, Zscaler, or Palo Alto customer, adding browser security through an existing relationship means fewer vendors, fewer contracts, and a coherent narrative about platform consolidation that plays well internally. ",{"data":25008,"content":25009,"nodeType":860},{},[25010],{"data":25011,"marks":25012,"value":25013,"nodeType":864},{},[],"Security teams make these kinds of tradeoffs all the time — accepting that your SASE vendor's threat intelligence feed may not match a dedicated provider, or that your EDR vendor's vulnerability management module may not match a dedicated scanner — are reasonable decisions where the operational benefit of consolidation outweighs the capability difference.",{"data":25015,"content":25016,"nodeType":860},{},[25017],{"data":25018,"marks":25019,"value":25020,"nodeType":864},{},[],"But browser security is a category where the stakes are too high to accept a \"good enough\" solution. The majority of all reported breaches now originate in the browser and attacker tradecraft in this space is advancing at an unprecedented rate thanks to AI. These risks warrant the strongest form of defense. Here are three reasons that “good enough” solutions don't give you that:",{"data":25022,"content":25023,"nodeType":1312},{},[25024],{"data":25025,"marks":25026,"value":25028,"nodeType":864},{},[25027],{"type":899},"1. Most platform browser solutions were built for the wrong problems",{"data":25030,"content":25031,"nodeType":860},{},[25032,25035,25044,25048,25056,25060,25068,25072,25079],{"data":25033,"marks":25034,"value":21,"nodeType":864},{},[],{"data":25036,"content":25038,"nodeType":883},{"uri":25037},"https://www.crowdstrike.com/en-us/resources/infographics/identity-security-risk-review/",[25039],{"data":25040,"marks":25041,"value":25043,"nodeType":864},{},[25042],{"type":1455},"CrowdStrike's own research",{"data":25045,"marks":25046,"value":25047,"nodeType":864},{},[]," puts identity involvement in 80% of all modern breaches. Identity weaknesses played a material role in ",{"data":25049,"content":25051,"nodeType":883},{"uri":25050},"https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report",[25052],{"data":25053,"marks":25054,"value":25055,"nodeType":864},{},[],"almost 90% of Unit 42 incident response investigations",{"data":25057,"marks":25058,"value":25059,"nodeType":864},{},[],". The breaches making headlines — 2024's ",{"data":25061,"content":25063,"nodeType":883},{"uri":25062},"https://pushsecurity.com/blog/snowflake-retro",[25064],{"data":25065,"marks":25066,"value":25067,"nodeType":864},{},[],"mass Snowflake account compromises",{"data":25069,"marks":25070,"value":25071,"nodeType":864},{},[],", 2025's wave of Salesforce-targeted attacks, and 2026's ",{"data":25073,"content":25074,"nodeType":883},{"uri":4082},[25075],{"data":25076,"marks":25077,"value":25078,"nodeType":864},{},[],"continued spree of data theft and extortion",{"data":25080,"marks":25081,"value":25082,"nodeType":864},{},[]," — all trace back to identity weaknesses exploited through the browser: credentials stuffed into login pages that lacked MFA, session tokens hijacked via AiTM phishing, OAuth consent abused to grant persistent access, and device code flows manipulated to bypass authentication entirely. ",{"data":25084,"content":25085,"nodeType":860},{},[25086],{"data":25087,"marks":25088,"value":25089,"nodeType":864},{},[],"Yet Seraphic was built for browser runtime exploit prevention, SquareX for file-based malware sandboxing, LayerX for access governance and AI usage policy. These are real use cases, but they're not the use cases behind headline breaches. If your browser security solution checks a box for \"phishing protection\" but can't detect the identity attack techniques that are actually being industrialized and deployed at scale, you have a gap — and the danger is that you don't know it's there.",{"data":25091,"content":25092,"nodeType":1312},{},[25093],{"data":25094,"marks":25095,"value":25097,"nodeType":864},{},[25096],{"type":899},"2. Even solutions claiming the right capabilities often deliver them superficially",{"data":25099,"content":25100,"nodeType":860},{},[25101],{"data":25102,"marks":25103,"value":25104,"nodeType":864},{},[],"Every browser security vendor claims phishing detection, ClickFix protection, and session security. What varies enormously is whether those capabilities work against real, live, never-before-seen attacker infrastructure — or only against known-bad indicators that attackers rotate in minutes. 95% of in-browser attacks detected by Push used bot protection to evade blocklists; 89% of phishing domains are active for fewer than two days. ",{"data":25106,"content":25107,"nodeType":860},{},[25108],{"data":25109,"marks":25110,"value":25111,"nodeType":864},{},[],"A solution that appears comprehensive in a demo or PoV may leave significant gaps when tested against adversaries who understand exactly how security tools work and actively engineer around them. ",{"data":25113,"content":25114,"nodeType":1312},{},[25115],{"data":25116,"marks":25117,"value":25119,"nodeType":864},{},[25118],{"type":899},"3. AI is only going to widen the gap between \"good enough\" and what you need",{"data":25121,"content":25122,"nodeType":860},{},[25123],{"data":25124,"marks":25125,"value":25126,"nodeType":864},{},[],"When a browser security product is acquired, engineering effort turns inwards towards integration with the parent platform, not advancing detection capability. ",{"data":25128,"content":25129,"nodeType":860},{},[25130],{"data":25131,"marks":25132,"value":25133,"nodeType":864},{},[],"That dynamic plays out differently for each acquisition, but in Seraphic's case it is expected to be particularly heightened. Seraphic works by injecting an agent into the browser's JavaScript runtime. This is the same approach antivirus vendors have used for years, with well-documented stability consequences. Stability is now a top priority for CrowdStrike, which means the Seraphic integration will proceed cautiously. For buyers, that translates directly into slower capability advancement, not faster.",{"data":25135,"content":25136,"nodeType":860},{},[25137,25141,25149],{"data":25138,"marks":25139,"value":25140,"nodeType":864},{},[],"But this is no time for engineering efforts to turn inward, as the threat landscape continues to evolve at an unprecedented rate. You only need to look at the rise of techniques like device code phishing, which have gone from ",{"data":25142,"content":25143,"nodeType":883},{"uri":3259},[25144],{"data":25145,"marks":25146,"value":25148,"nodeType":864},{},[25147],{"type":1455},"research curiosity to industrialized exploitation",{"data":25150,"marks":25151,"value":25152,"nodeType":864},{},[]," in a matter of months — in large part enabled by AI-powered tools and AI-assisted development. Similarly, AI has compressed the time to generate a convincing phishing campaign from hours to minutes. ",{"data":25154,"content":25155,"nodeType":860},{},[25156,25160,25167,25171,25180],{"data":25157,"marks":25158,"value":25159,"nodeType":864},{},[],"But it's not only external threats: ",{"data":25161,"content":25162,"nodeType":883},{"uri":2561},[25163],{"data":25164,"marks":25165,"value":25166,"nodeType":864},{},[],"92% of organizations allow employees to use public GenAI applications",{"data":25168,"marks":25169,"value":25170,"nodeType":864},{},[]," — every one of them with unsanctioned AI use occurring by design — employees are routinely entering sensitive data into unapproved AI tools, and ",{"data":25172,"content":25174,"nodeType":883},{"uri":25173},"https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025",[25175],{"data":25176,"marks":25177,"value":25179,"nodeType":864},{},[25178],{"type":1455},"Gartner predicts",{"data":25181,"marks":25182,"value":25183,"nodeType":864},{},[]," 40% of enterprise applications will feature AI agents by end of 2026, up from under 5% in 2025. ",{"data":25185,"content":25186,"nodeType":860},{},[25187],{"data":25188,"marks":25189,"value":25190,"nodeType":864},{},[],"The gap between an acquired product focused on integration and vendors whose single-minded focus is on stopping these emerging threats will continue to widen over time.",{"data":25192,"content":25193,"nodeType":1005},{},[],{"data":25195,"content":25196,"nodeType":1009},{},[25197],{"data":25198,"marks":25199,"value":25201,"nodeType":864},{},[25200],{"type":899},"How to identify a genuinely best-of-breed solution",{"data":25203,"content":25204,"nodeType":1312},{},[25205],{"data":25206,"marks":25207,"value":25209,"nodeType":864},{},[25208],{"type":899},"Start from your own requirements",{"data":25211,"content":25212,"nodeType":860},{},[25213,25217,25224],{"data":25214,"marks":25215,"value":25216,"nodeType":864},{},[],"Define the outcomes you need before speaking to any vendor. The ",{"data":25218,"content":25219,"nodeType":883},{"uri":11640},[25220],{"data":25221,"marks":25222,"value":25223,"nodeType":864},{},[],"highest-value browser security use cases",{"data":25225,"marks":25226,"value":25227,"nodeType":864},{},[]," are account takeover prevention, advanced phishing detection, identity posture hardening, browser extension security, and shadow SaaS and OAuth governance.",{"data":25229,"content":25230,"nodeType":1312},{},[25231],{"data":25232,"marks":25233,"value":25235,"nodeType":864},{},[25234],{"type":899},"Understand how it detects, not just what it claims",{"data":25237,"content":25238,"nodeType":860},{},[25239,25243,25251],{"data":25240,"marks":25241,"value":25242,"nodeType":864},{},[],"Most solutions rely on IoCs — matching known-bad domains, URLs, and IPs against feeds that attackers rotate in minutes.  There’s a major shortcoming with this approach, though: attackers rotate infrastructure faster than any blocklist updates and use bot protection to stay off threat intelligence feeds, making every attack feel ",{"data":25244,"content":25245,"nodeType":883},{"uri":13094},[25246],{"data":25247,"marks":25248,"value":25250,"nodeType":864},{},[25249],{"type":1455},"like a zero-day",{"data":25252,"marks":25253,"value":25254,"nodeType":864},{},[],". The only approach that reliably works is TTP-based behavioral detection. Ask every vendor: are you detecting a known-bad indicator or a behavioral technique?",{"data":25256,"content":25257,"nodeType":1312},{},[25258],{"data":25259,"marks":25260,"value":25262,"nodeType":864},{},[25261],{"type":899},"Test against real attacker behavior",{"data":25264,"content":25265,"nodeType":860},{},[25266],{"data":25267,"marks":25268,"value":25269,"nodeType":864},{},[],"Don't evaluate phishing detection with old phishing URLs. By the time you’re running these tests their IoCs will already be on block-lists (see point above). Instead, deploy realistic testing scenarios and look for demonstrable evidence of stopping real-world phishing kits — Evilginx, Tycoon2FA, Sneaky2FA, and so on. ",{"data":25271,"content":25272,"nodeType":1312},{},[25273],{"data":25274,"marks":25275,"value":25277,"nodeType":864},{},[25276],{"type":899},"Assess innovation velocity",{"data":25279,"content":25280,"nodeType":860},{},[25281],{"data":25282,"marks":25283,"value":25284,"nodeType":864},{},[],"Ask every vendor about their research output and feature release history over the past six months — are they discovering and publishing novel attack techniques, or covering what others already documented? Are new detections shipping continuously, or in quarterly cycles? For acquired products specifically, also ask how the roadmap has changed since acquisition. ",{"data":25286,"content":25287,"nodeType":1312},{},[25288],{"data":25289,"marks":25290,"value":25292,"nodeType":864},{},[25291],{"type":899},"Consider operationalization, vendor focus, and lock-in",{"data":25294,"content":25295,"nodeType":860},{},[25296],{"data":25297,"marks":25298,"value":25299,"nodeType":864},{},[],"Many solutions demo well but create significant overhead at scale. Consider whether you want another agent on endpoints, and whether you have the resources to tune granular policies without drowning in false positives. Your requirements might not carry the same weight with a platform vendor with tens of thousands of customers across multiple product lines, versus a dedicated vendor whose entire roadmap exists to solve your problem. And factor in lock-in: every capability consolidated into an existing platform vendor reduces your ability to change direction later.",{"data":25301,"content":25302,"nodeType":1005},{},[],{"data":25304,"content":25305,"nodeType":1009},{},[25306],{"data":25307,"marks":25308,"value":25310,"nodeType":864},{},[25309],{"type":899},"Why Push is the best-of-breed browser security solution",{"data":25312,"content":25313,"nodeType":860},{},[25314],{"data":25315,"marks":25316,"value":25317,"nodeType":864},{},[],"Think of Push as EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Here’s why customers choose Push as a best-of-breed solution:",{"data":25319,"content":25320,"nodeType":1312},{},[25321,25326],{"data":25322,"marks":25323,"value":25325,"nodeType":864},{},[25324],{"type":899},"Push is built for the security problems that actually cause breaches",{"data":25327,"marks":25328,"value":1171,"nodeType":864},{},[],{"data":25330,"content":25331,"nodeType":860},{},[25332,25336,25344],{"data":25333,"marks":25334,"value":25335,"nodeType":864},{},[],"The highest-value browser security problems — account takeover prevention, advanced phishing detection, identity posture hardening, browser extension security, shadow SaaS and OAuth governance — all require visibility inside the browser session. Push was built from the ground up for exactly that. The same foundational capability that detects AiTM phishing and ClickFix attacks also surfaces the exposure most security teams don't know they have: ",{"data":25337,"content":25339,"nodeType":883},{"uri":25338},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[25340],{"data":25341,"marks":25342,"value":25343,"nodeType":864},{},[],"across Push's customer base",{"data":25345,"marks":25346,"value":25347,"nodeType":864},{},[],", 1 in 4 logins use passwords rather than SSO, 2 in 5 are unprotected by MFA, and 46.76% of browser extensions carry permissions sufficient to perform account takeover — none of it visible from the endpoint, network, or email layer.",{"data":25349,"content":25350,"nodeType":1312},{},[25351],{"data":25352,"marks":25353,"value":25355,"nodeType":864},{},[25354],{"type":899},"Push detects high-fidelity attacker TTPs, not low-level IoCs",{"data":25357,"content":25358,"nodeType":860},{},[25359],{"data":25360,"marks":25361,"value":25362,"nodeType":864},{},[],"Push's browser extension operates as a flight recorder inside the session, capturing every page load, credential submission, OAuth consent flow, and user action in real time. That telemetry surfaces attacker behavior — the page structure and script signatures of AiTM kits, the clipboard mechanics of ClickFix, the OAuth flow characteristics of ConsentFix — rather than infrastructure indicators that attackers rotate in minutes. This is how Push intercepts “zero-day” phishing using fresh infrastructure and domains every time, while most solutions are stuck playing known-bad whac-a-mole. ",{"data":25364,"content":25368,"nodeType":996},{"target":25365},{"sys":25366},{"id":25367,"type":1001,"linkType":1002},"4ho5gOHl1loo9Jtv9nPoq1",[],{"data":25370,"content":25371,"nodeType":1312},{},[25372],{"data":25373,"marks":25374,"value":25376,"nodeType":864},{},[25375],{"type":899},"Push’s research and agentic threat hunting keeps you ahead of attacker innovation",{"data":25378,"content":25379,"nodeType":860},{},[25380,25384,25390,25393,25399,25403,25409],{"data":25381,"marks":25382,"value":25383,"nodeType":864},{},[],"Push named ",{"data":25385,"content":25386,"nodeType":883},{"uri":11726},[25387],{"data":25388,"marks":25389,"value":11731,"nodeType":864},{},[],{"data":25391,"marks":25392,"value":902,"nodeType":864},{},[],{"data":25394,"content":25395,"nodeType":883},{"uri":11738},[25396],{"data":25397,"marks":25398,"value":19059,"nodeType":864},{},[],{"data":25400,"marks":25401,"value":25402,"nodeType":864},{},[]," before any other vendor detected either in production. That research feeds an ",{"data":25404,"content":25405,"nodeType":883},{"uri":7572},[25406],{"data":25407,"marks":25408,"value":7578,"nodeType":864},{},[],{"data":25410,"marks":25411,"value":25412,"nodeType":864},{},[]," built on two learning loops — an inner loop for real-time detection of known techniques, and an outer loop where autonomous agents continuously hunt across 3 million deployed browsers for emerging threats, writing new detections and deploying them to customer environments in minutes. ",{"data":25414,"content":25418,"nodeType":996},{"target":25415},{"sys":25416},{"id":25417,"type":1001,"linkType":1002},"17y3jchoPysKQTf2ra59Bv",[],{"data":25420,"content":25421,"nodeType":1312},{},[25422],{"data":25423,"marks":25424,"value":25426,"nodeType":864},{},[25425],{"type":899},"Push solves more use cases than just stopping advanced attacks",{"data":25428,"content":25429,"nodeType":860},{},[25430,25434,25441],{"data":25431,"marks":25432,"value":25433,"nodeType":864},{},[],"Push uses the same browser-layer visibility to surface every AI tool, agentic browser, extension, and OAuth integration in use across the organization — and enforce policy on what employees can do inside them in real time, including unsanctioned tools no other layer sees. The same technical capabilities provided by Push also harden the identity attack surface, prevent data loss, accelerate insider investigations, and let security teams write custom detections and policies for organization-specific risks. One extension, one deployment, ",{"data":25435,"content":25436,"nodeType":883},{"uri":11640},[25437],{"data":25438,"marks":25439,"value":25440,"nodeType":864},{},[],"multiple high-value use cases",{"data":25442,"marks":25443,"value":2924,"nodeType":864},{},[],{"data":25445,"content":25446,"nodeType":1312},{},[25447],{"data":25448,"marks":25449,"value":25451,"nodeType":864},{},[25450],{"type":899},"Push is built to be operationalized at scale, not just demoed",{"data":25453,"content":25454,"nodeType":860},{},[25455,25459,25466],{"data":25456,"marks":25457,"value":25458,"nodeType":864},{},[],"Push deploys to ",{"data":25460,"content":25461,"nodeType":883},{"uri":11674},[25462],{"data":25463,"marks":25464,"value":25465,"nodeType":864},{},[],"100,000 users in under one hour on a normal workday",{"data":25467,"marks":25468,"value":25469,"nodeType":864},{},[]," — no migration overhead or performance impact. The false positive rate is negligible, meaning no alert noise and no policy tuning overhead. And because Push is independent, it integrates into open ecosystems — feeding browser-layer telemetry into your SIEM, XDR, SOAR, and identity tools alongside the rest of your stack, without adding to your platform lock-in.",{"data":25471,"content":25472,"nodeType":1005},{},[],{"data":25474,"content":25475,"nodeType":1009},{},[25476],{"data":25477,"marks":25478,"value":25480,"nodeType":864},{},[25479],{"type":899},"Final thoughts",{"data":25482,"content":25483,"nodeType":860},{},[25484],{"data":25485,"marks":25486,"value":25487,"nodeType":864},{},[],"Three acquisitions in five months is a strong market signal, but a strong market signal about vendor interest in a category is not the same thing as a strong signal about capability. The attacker techniques and tooling behind breaches in 2026 are evolving faster than any acquired product with split engineering priorities can reasonably track. ",{"data":25489,"content":25490,"nodeType":860},{},[25491],{"data":25492,"marks":25493,"value":25494,"nodeType":864},{},[],"Security buyers who accept a bundled browser solution because it is included in an existing contract are making a procurement decision, not a security decision. The threats in the browser are serious and sophisticated enough to justify the investment in a tool built to stop them. If you agree, Push is worth a serious look.",{"data":25496,"content":25497,"nodeType":860},{},[25498,25501,25508],{"data":25499,"marks":25500,"value":21,"nodeType":864},{},[],{"data":25502,"content":25503,"nodeType":883},{"uri":1700},[25504],{"data":25505,"marks":25506,"value":1703,"nodeType":864},{},[25507],{"type":1455},{"data":25509,"marks":25510,"value":21,"nodeType":864},{},[],"Why \"good enough\" isn’t enough: the case for best-of-breed browser security","Why \"good enough\" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.","2026-05-19T00:00:00.000Z","the-case-for-best-of-breed-browser-security",{"items":25516},[25517,25519],{"sys":25518,"name":297},{"id":2732},{"sys":25520,"name":13779},{"id":13778},{"items":25522},[25523],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":25524},{"url":4881},{"__typename":2059,"sys":25526,"content":25528,"title":26291,"synopsis":26292,"hashTags":59,"publishedDate":26293,"slug":26294,"tagsCollection":26295,"authorsCollection":26301},{"id":25527},"2V130uMePtxAaefYQAKInb",{"json":25529},{"data":25530,"content":25531,"nodeType":856},{},[25532,25538,25545,25552,25559,25562,25570,25577,25589,25601,25606,25613,25616,25624,25631,25637,25644,25651,25758,25765,25768,25776,25783,25846,25862,25868,25875,25878,25886,25893,25901,25908,25915,25945,25952,25960,25967,25974,25981,25989,25996,26003,26010,26013,26021,26033,26040,26047,26055,26062,26069,26077,26084,26147,26163,26181,26189,26196,26204,26211,26218,26225,26231,26239,26246,26253,26258,26265,26272,26279,26285],{"data":25533,"content":25537,"nodeType":996},{"target":25534},{"sys":25535},{"id":25536,"type":1001,"linkType":1002},"5CPZ96xixlhgh6oqQ2rfmO",[],{"data":25539,"content":25540,"nodeType":860},{},[25541],{"data":25542,"marks":25543,"value":25544,"nodeType":864},{},[],"When a security team evaluates browser security solutions, they're usually asking the right question: “How do we protect our users as they work in the browser?”",{"data":25546,"content":25547,"nodeType":860},{},[25548],{"data":25549,"marks":25550,"value":25551,"nodeType":864},{},[],"But the answer they get from many vendors is shaped by a fundamentally different threat model — one that treats the browser as a piece of software to be hardened against exploitation, rather than as the arena where your users’ identities get stolen.",{"data":25553,"content":25554,"nodeType":860},{},[25555],{"data":25556,"marks":25557,"value":25558,"nodeType":864},{},[],"This distinction has enormous consequences for your security posture and the return you can expect from your investment in a new solution.",{"data":25560,"content":25561,"nodeType":1005},{},[],{"data":25563,"content":25564,"nodeType":1009},{},[25565],{"data":25566,"marks":25567,"value":25569,"nodeType":864},{},[25568],{"type":899},"Two different problems, dressed the same",{"data":25571,"content":25572,"nodeType":860},{},[25573],{"data":25574,"marks":25575,"value":25576,"nodeType":864},{},[],"When it comes to protecting users as they work in the browser, security tools typically fall into one of two camps:",{"data":25578,"content":25579,"nodeType":860},{},[25580,25585],{"data":25581,"marks":25582,"value":25584,"nodeType":864},{},[25583],{"type":899},"The first camp:",{"data":25586,"marks":25587,"value":25588,"nodeType":864},{},[]," represented by solutions like Seraphic (now CrowdStrike) — is built around the threat of attacking the browser itself. The architecture is designed to scramble the browser’s JavaScript runtime and prevent exploits from detonating and breaking out of the browser sandbox. This is browser hardening: defending the browser as software against exploitation by attackers who want to compromise the underlying device.",{"data":25590,"content":25591,"nodeType":860},{},[25592,25597],{"data":25593,"marks":25594,"value":25596,"nodeType":864},{},[25595],{"type":899},"The second camp:",{"data":25598,"marks":25599,"value":25600,"nodeType":864},{},[]," and the one Push Security occupies uniquely, focuses on what happens inside the browser when a user is working normally. Phishing pages harvesting credentials. Session tokens being stolen. Malicious OAuth applications being granted access through social engineering. Adversary-in-the-middle proxies intercepting authentication flows. These attacks don't exploit the browser. They exploit the human — and now agents — using it via the browser's legitimate capabilities (think of it as LOTL, browser edition).",{"data":25602,"content":25605,"nodeType":996},{"target":25603},{"sys":25604},{"id":23546,"type":1001,"linkType":1002},[],{"data":25607,"content":25608,"nodeType":860},{},[25609],{"data":25610,"marks":25611,"value":25612,"nodeType":864},{},[],"The question for any security team evaluating this space: which of these threat models presents the greatest risks to my organization?",{"data":25614,"content":25615,"nodeType":1005},{},[],{"data":25617,"content":25618,"nodeType":1009},{},[25619],{"data":25620,"marks":25621,"value":25623,"nodeType":864},{},[25622],{"type":899},"How organizations are actually being breached",{"data":25625,"content":25626,"nodeType":860},{},[25627],{"data":25628,"marks":25629,"value":25630,"nodeType":864},{},[],"Let's look at the major breach campaigns of the last three years without the marketing filter and a pattern emerges immediately. Scattered Spider and its successors breached MGM Resorts, Caesars, M&S, JLR, and Salesforce customers — not through browser exploits, but through social engineering, phishing and Adversary-in-the-Middle attacks that stole session tokens and SSO credentials. ",{"data":25632,"content":25636,"nodeType":996},{"target":25633},{"sys":25634},{"id":25635,"type":1001,"linkType":1002},"2qIMTiyyIsQFAyGJ9Ikyej",[],{"data":25638,"content":25639,"nodeType":860},{},[25640],{"data":25641,"marks":25642,"value":25643,"nodeType":864},{},[],"In every case, the attack happened in the browser — using stolen identities to log into legitimate cloud services — not on the browser through exploitation of the browser engine itself.",{"data":25645,"content":25646,"nodeType":860},{},[25647],{"data":25648,"marks":25649,"value":25650,"nodeType":864},{},[],"The data from major threat intelligence sources is unambiguous:",{"data":25652,"content":25653,"nodeType":941},{},[25654,25672,25691,25710,25729,25743],{"data":25655,"content":25656,"nodeType":945},{},[25657],{"data":25658,"content":25659,"nodeType":860},{},[25660,25664,25668],{"data":25661,"marks":25662,"value":25663,"nodeType":864},{},[],"Identity weaknesses played a material role in ",{"data":25665,"marks":25666,"value":25055,"nodeType":864},{},[25667],{"type":899},{"data":25669,"marks":25670,"value":25671,"nodeType":864},{},[]," (Palo Alto Networks Unit 42 IR Report)",{"data":25673,"content":25674,"nodeType":945},{},[25675],{"data":25676,"content":25677,"nodeType":860},{},[25678,25682,25687],{"data":25679,"marks":25680,"value":25681,"nodeType":864},{},[],"Credential abuse and phishing combined accounted for ",{"data":25683,"marks":25684,"value":25686,"nodeType":864},{},[25685],{"type":899},"38% of all breaches",{"data":25688,"marks":25689,"value":25690,"nodeType":864},{},[],", making identity the single largest breach vector (Verizon DBIR 2025)",{"data":25692,"content":25693,"nodeType":945},{},[25694],{"data":25695,"content":25696,"nodeType":860},{},[25697,25701,25706],{"data":25698,"marks":25699,"value":25700,"nodeType":864},{},[],"Cloud-conscious intrusions — attackers using stolen identities to access cloud services — rose ",{"data":25702,"marks":25703,"value":25705,"nodeType":864},{},[25704],{"type":899},"37% in 2025",{"data":25707,"marks":25708,"value":25709,"nodeType":864},{},[],", up 266% among state-nexus actors (CrowdStrike 2026 Global Threat Report)",{"data":25711,"content":25712,"nodeType":945},{},[25713],{"data":25714,"content":25715,"nodeType":860},{},[25716,25720,25725],{"data":25717,"marks":25718,"value":25719,"nodeType":864},{},[],"In cloud-related incidents, identity issues drove initial access in ",{"data":25721,"marks":25722,"value":25724,"nodeType":864},{},[25723],{"type":899},"83% of cases",{"data":25726,"marks":25727,"value":25728,"nodeType":864},{},[]," (Mandiant / Google Cloud Threat Horizons H1 2026)",{"data":25730,"content":25731,"nodeType":945},{},[25732],{"data":25733,"content":25734,"nodeType":860},{},[25735,25739],{"data":25736,"marks":25737,"value":18801,"nodeType":864},{},[25738],{"type":899},{"data":25740,"marks":25741,"value":25742,"nodeType":864},{},[]," — they don't touch the endpoint and abuse legitimate access and functionality (CrowdStrike 2026 Global Threat Report)",{"data":25744,"content":25745,"nodeType":945},{},[25746],{"data":25747,"content":25748,"nodeType":860},{},[25749,25754],{"data":25750,"marks":25751,"value":25753,"nodeType":864},{},[25752],{"type":899},"49% of organizations",{"data":25755,"marks":25756,"value":25757,"nodeType":864},{},[]," suffered a successful browser-based attack in the last 12 months (Omdia 2026)",{"data":25759,"content":25760,"nodeType":860},{},[25761],{"data":25762,"marks":25763,"value":25764,"nodeType":864},{},[],"These aren't edge cases. This is now the primary attack playbook.",{"data":25766,"content":25767,"nodeType":1005},{},[],{"data":25769,"content":25770,"nodeType":1312},{},[25771],{"data":25772,"marks":25773,"value":25775,"nodeType":864},{},[25774],{"type":899},"The economics of attack choice",{"data":25777,"content":25778,"nodeType":860},{},[25779],{"data":25780,"marks":25781,"value":25782,"nodeType":864},{},[],"Attackers are rational actors. They pick the cheapest, most reliable path to their objective. The economics of browser exploitation versus identity theft tell the whole story:",{"data":25784,"content":25785,"nodeType":941},{},[25786,25801,25816,25831],{"data":25787,"content":25788,"nodeType":945},{},[25789],{"data":25790,"content":25791,"nodeType":860},{},[25792,25796],{"data":25793,"marks":25794,"value":25795,"nodeType":864},{},[],"Chrome sandbox RCE exploit (bug bounty value): ",{"data":25797,"marks":25798,"value":25800,"nodeType":864},{},[25799],{"type":899},"$250,000",{"data":25802,"content":25803,"nodeType":945},{},[25804],{"data":25805,"content":25806,"nodeType":860},{},[25807,25811],{"data":25808,"marks":25809,"value":25810,"nodeType":864},{},[],"IAB-provided IdP admin account: ",{"data":25812,"marks":25813,"value":25815,"nodeType":864},{},[25814],{"type":899},"~$3,000",{"data":25817,"content":25818,"nodeType":945},{},[25819],{"data":25820,"content":25821,"nodeType":860},{},[25822,25826],{"data":25823,"marks":25824,"value":25825,"nodeType":864},{},[],"1-year phishing kit rental (PhaaS): ",{"data":25827,"marks":25828,"value":25830,"nodeType":864},{},[25829],{"type":899},"~$1,000",{"data":25832,"content":25833,"nodeType":945},{},[25834],{"data":25835,"content":25836,"nodeType":860},{},[25837,25841],{"data":25838,"marks":25839,"value":25840,"nodeType":864},{},[],"Bulk stolen credential list: ",{"data":25842,"marks":25843,"value":25845,"nodeType":864},{},[25844],{"type":899},"~$15",{"data":25847,"content":25848,"nodeType":860},{},[25849,25853,25858],{"data":25850,"marks":25851,"value":25852,"nodeType":864},{},[],"Browser zero-days accounted for just ",{"data":25854,"marks":25855,"value":25857,"nodeType":864},{},[25856],{"type":899},"9% of all zero-days reported to Google in 2025",{"data":25859,"marks":25860,"value":25861,"nodeType":864},{},[]," — described by Google's own researchers as a \"historic low.\" Chrome's sandbox architecture, site isolation, and hardware-backed security features are the result of years of sustained hardening investment. When a browser vulnerability is discovered, Google typically deploys a patch within days.",{"data":25863,"content":25867,"nodeType":996},{"target":25864},{"sys":25865},{"id":25866,"type":1001,"linkType":1002},"5XWKHTT5J06yWcgZIOL95t",[],{"data":25869,"content":25870,"nodeType":860},{},[25871],{"data":25872,"marks":25873,"value":25874,"nodeType":864},{},[],"The bottom line: browser exploits are extraordinarily expensive to develop, increasingly difficult to execute reliably against a hardened modern browser, and patched rapidly when discovered. In sharp contrast, identity attacks are cheap to run, highly scalable, and have a low technical barrier to adoption — that’s why they’re responsible for the overwhelming majority of enterprise breaches. Attackers have voted with their resources.",{"data":25876,"content":25877,"nodeType":1005},{},[],{"data":25879,"content":25880,"nodeType":1009},{},[25881],{"data":25882,"marks":25883,"value":25885,"nodeType":864},{},[25884],{"type":899},"What you're actually buying with each vendor",{"data":25887,"content":25888,"nodeType":860},{},[25889],{"data":25890,"marks":25891,"value":25892,"nodeType":864},{},[],"Understanding the core architectural choice each vendor has made helps decode what their solution can and cannot protect you from.",{"data":25894,"content":25895,"nodeType":1312},{},[25896],{"data":25897,"marks":25898,"value":25900,"nodeType":864},{},[25899],{"type":899},"Seraphic (CrowdStrike)",{"data":25902,"content":25903,"nodeType":860},{},[25904],{"data":25905,"marks":25906,"value":25907,"nodeType":864},{},[],"Seraphic's architecture is built to inject into the browser's JavaScript runtime at the OS layer, scrambling browser internals to prevent exploits from executing. This is a technically sophisticated approach to a technically interesting problem that is, by every threat intelligence measure, not the problem causing enterprise breaches at scale.",{"data":25909,"content":25910,"nodeType":860},{},[25911],{"data":25912,"marks":25913,"value":25914,"nodeType":864},{},[],"Beyond the threat model mismatch, there are structural concerns with the approach itself. Injecting an agent into the browser's JS runtime is a technique with well-documented stability consequences. This is the same approach antivirus vendors have used for years, often at the cost of system stability. Seraphic now runs alongside the CrowdStrike Falcon sensor on managed devices, combining two heavyweight agents on the same machine. For any organization with CrowdStrike already deployed, the question isn't theoretical: how has that combination been validated in production environments?",{"data":25916,"content":25917,"nodeType":860},{},[25918,25922,25929,25933,25941],{"data":25919,"marks":25920,"value":25921,"nodeType":864},{},[],"There's also the managed-device limitation. Seraphic requires a kernel-level agent, which means it loses meaningful capability on unmanaged devices, BYOD machines, and contractor endpoints. This is not a niche concern: according to ",{"data":25923,"content":25924,"nodeType":883},{"uri":2561},[25925],{"data":25926,"marks":25927,"value":25928,"nodeType":864},{},[],"Omdia's 2026 browser security survey",{"data":25930,"marks":25931,"value":25932,"nodeType":864},{},[],", 32% of users access corporate applications from unmanaged devices at least occasionally. Agent-based solutions are blind to nearly a third of your actual attack surface by design. The Okta breach began on a support engineer's personal device, where ",{"data":25934,"content":25935,"nodeType":883},{"uri":16203},[25936],{"data":25937,"marks":25938,"value":25940,"nodeType":864},{},[25939],{"type":1455},"corporate credentials had synced",{"data":25942,"marks":25943,"value":25944,"nodeType":864},{},[]," via Chrome's built-in profile sync. No agent, no visibility.",{"data":25946,"content":25947,"nodeType":860},{},[25948],{"data":25949,"marks":25950,"value":25951,"nodeType":864},{},[],"Teams evaluating Seraphic today are also buying into an integration roadmap, not a shipped capability. The acquisition by CrowdStrike closed in early 2026. The work of wiring browser telemetry into Falcon Fusion and correlating it with endpoint signals is currently a promise, not a production feature.",{"data":25953,"content":25954,"nodeType":1312},{},[25955],{"data":25956,"marks":25957,"value":25959,"nodeType":864},{},[25958],{"type":899},"SquareX (Zscaler)",{"data":25961,"content":25962,"nodeType":860},{},[25963],{"data":25964,"marks":25965,"value":25966,"nodeType":864},{},[],"SquareX's core capability is sandboxing suspicious file downloads inside disposable browser containers before they reach the endpoint. This is a legitimate approach to a real but declining problem. 82% of attack detections are now malware-free (CrowdStrike 2026 Global Threat Report) — attacks don't arrive as files to be sandboxed, they arrive as authenticated sessions. And the delivery channel shift makes the picture even starker: across Push's customer base, 1 in 3 phishing payloads are now delivered outside of email entirely — via social media, ads, and messaging platforms — and 4 in 5 ClickFix payloads arrive through search engines, not email. The threat that SquareX was architecturally designed to address is a shrinking share of the actual attack surface, and it's shrinking fast.",{"data":25968,"content":25969,"nodeType":860},{},[25970],{"data":25971,"marks":25972,"value":25973,"nodeType":864},{},[],"Zscaler already has sandboxing built into ZIA. For an existing Zscaler customer evaluating SquareX, the honest question is: what does this add beyond some extension analysis capability and what you already have? The AiTM phishing campaign that stole your user's credentials and accessed your cloud applications generates no malicious file, triggers no sandbox, and produces no network signal for Zscaler's traffic inspection to catch — because it happened entirely inside a browser session using legitimate authentication flows.",{"data":25975,"content":25976,"nodeType":860},{},[25977],{"data":25978,"marks":25979,"value":25980,"nodeType":864},{},[],"The acquisition also raises product focus questions. Being absorbed into a network-centric platform means SquareX is now optimized for Zscaler's priorities, not for standalone browser detection and response. Teams that care about investigation, threat hunting, and incident response should ask specifically what SquareX adds in those workflows under Zscaler ownership.",{"data":25982,"content":25983,"nodeType":1312},{},[25984],{"data":25985,"marks":25986,"value":25988,"nodeType":864},{},[25987],{"type":899},"LayerX",{"data":25990,"content":25991,"nodeType":860},{},[25992],{"data":25993,"marks":25994,"value":25995,"nodeType":864},{},[],"LayerX is primarily a policy enforcement and risk scoring platform focused on internal governance — controlling which applications employees access, what data moves through the browser, and whether behavior complies with internal rules.",{"data":25997,"content":25998,"nodeType":860},{},[25999],{"data":26000,"marks":26001,"value":26002,"nodeType":864},{},[],"Push Security covers that ground too. Push provides full visibility over AI tool usage, shadow SaaS, unmanaged identities, and data loss vectors — including sensitive data submitted through AI prompts, file uploads to personal cloud destinations, and OAuth grants to third-party applications. The same browser telemetry that detects external attacks also surfaces insider risks and powers DLP controls and compliance audit evidence, all from a single extension.",{"data":26004,"content":26005,"nodeType":860},{},[26006],{"data":26007,"marks":26008,"value":26009,"nodeType":864},{},[],"The critical difference is that Push goes significantly further. Where LayerX scores risk and enforces policy, Push detects active external attack techniques in real time: AiTM phishing kits as they execute, session tokens being stolen, ClickFix lures through behavioral analysis of page structure. These are the attacks causing the most damaging breaches today, and they don't surface on a risk score until after the damage is done. Push addresses both the governance problem and the external threat problem from the same platform. LayerX addresses only the first.",{"data":26011,"content":26012,"nodeType":1005},{},[],{"data":26014,"content":26015,"nodeType":1009},{},[26016],{"data":26017,"marks":26018,"value":26020,"nodeType":864},{},[26019],{"type":899},"Securing the organization via the browser: Push Security",{"data":26022,"content":26023,"nodeType":860},{},[26024,26029],{"data":26025,"marks":26026,"value":26028,"nodeType":864},{},[26027],{"type":899},"Push Security is built on a different architectural premise:",{"data":26030,"marks":26031,"value":26032,"nodeType":864},{},[]," the browser is not primarily a piece of software to harden against exploitation. It is the primary workplace, the primary SaaS access point, and the arena where the majority of modern identity attacks play out. The goal is to secure the organization via the browser — not just to secure the browser itself.",{"data":26034,"content":26035,"nodeType":860},{},[26036],{"data":26037,"marks":26038,"value":26039,"nodeType":864},{},[],"This means Push's detection surface is built around the attacks that are actually causing breaches: adversary-in-the-middle phishing, ClickFix and its many variants, credential stuffing against shadow identities, session token theft and replay, OAuth consent abuse, and the full spectrum of identity-based initial access techniques that dominate the modern threat landscape.",{"data":26041,"content":26042,"nodeType":860},{},[26043],{"data":26044,"marks":26045,"value":26046,"nodeType":864},{},[],"The deployment model reflects the threat model. Push deploys as a lightweight browser extension — no kernel-level agent, no device dependency, no migration to a new browser. It works on managed and unmanaged devices, across every traditional, enterprise and AI browser where employees are doing work and attackers are targeting them. The operational overhead is minimal by design: Push has been deployed to 100,000 users in under one hour during normal business hours.",{"data":26048,"content":26049,"nodeType":1312},{},[26050],{"data":26051,"marks":26052,"value":26054,"nodeType":864},{},[26053],{"type":899},"Detection philosophy: targeting what attackers can't change",{"data":26056,"content":26057,"nodeType":860},{},[26058],{"data":26059,"marks":26060,"value":26061,"nodeType":864},{},[],"Push's detection approach targets attacker TTPs rather than indicators of compromise that attackers can rotate in minutes. 95% of attacks detected by Push used some form of bot protection service — meaning the specific domain and IP were deliberately obscured. If your primary detection relies on blocklists, recent reports tell us that 89% of phishing domains will evade you: because they're active for less than two days, they can be spun up, down, and replaced faster than blocklists can keep up.",{"data":26063,"content":26064,"nodeType":860},{},[26065],{"data":26066,"marks":26067,"value":26068,"nodeType":864},{},[],"Behavioral detection of the attack technique — the AiTM relay structure, the credential entry on a cloned login page, the anomalous session context — remains valid regardless of what domain the attack is hosted on or which PhaaS kit was used to build it.",{"data":26070,"content":26071,"nodeType":1312},{},[26072],{"data":26073,"marks":26074,"value":26076,"nodeType":864},{},[26075],{"type":899},"Measuring the identity attack surface (it's bigger than you realize)",{"data":26078,"content":26079,"nodeType":860},{},[26080],{"data":26081,"marks":26082,"value":26083,"nodeType":864},{},[],"Because Push has visibility into actual login behavior across thousands of organizations, it can quantify the attack surface that identity-based attacks exploit. Of the last million logins observed by Push:",{"data":26085,"content":26086,"nodeType":941},{},[26087,26102,26117,26132],{"data":26088,"content":26089,"nodeType":945},{},[26090],{"data":26091,"content":26092,"nodeType":860},{},[26093,26098],{"data":26094,"marks":26095,"value":26097,"nodeType":864},{},[26096],{"type":899},"15 corporate identities were identified per employee",{"data":26099,"marks":26100,"value":26101,"nodeType":864},{},[]," used to access cloud apps",{"data":26103,"content":26104,"nodeType":945},{},[26105],{"data":26106,"content":26107,"nodeType":860},{},[26108,26113],{"data":26109,"marks":26110,"value":26112,"nodeType":864},{},[26111],{"type":899},"1 in 4",{"data":26114,"marks":26115,"value":26116,"nodeType":864},{},[]," were password logins, not SSO",{"data":26118,"content":26119,"nodeType":945},{},[26120],{"data":26121,"content":26122,"nodeType":860},{},[26123,26128],{"data":26124,"marks":26125,"value":26127,"nodeType":864},{},[26126],{"type":899},"2 in 5",{"data":26129,"marks":26130,"value":26131,"nodeType":864},{},[]," were not protected by MFA",{"data":26133,"content":26134,"nodeType":945},{},[26135],{"data":26136,"content":26137,"nodeType":860},{},[26138,26143],{"data":26139,"marks":26140,"value":26142,"nodeType":864},{},[26141],{"type":899},"1 in 5",{"data":26144,"marks":26145,"value":26146,"nodeType":864},{},[]," used a weak, breached, or reused password",{"data":26148,"content":26149,"nodeType":860},{},[26150,26154,26159],{"data":26151,"marks":26152,"value":26153,"nodeType":864},{},[],"And it's not just login hygiene. Across Push's customer base, ",{"data":26155,"marks":26156,"value":26158,"nodeType":864},{},[26157],{"type":899},"46%+ of browser extensions in corporate environments have the permission combinations required for direct account takeover via session theft if they are malicious or compromised by an attacker",{"data":26160,"marks":26161,"value":26162,"nodeType":864},{},[],". Most organizations have no inventory of what's running in their employees' browsers, let alone visibility into what those extensions can access.",{"data":26164,"content":26165,"nodeType":860},{},[26166,26170,26177],{"data":26167,"marks":26168,"value":26169,"nodeType":864},{},[],"These aren't theoretical vulnerabilities. They're the specific weaknesses that browser-native identity attacks are designed to exploit. ",{"data":26171,"content":26172,"nodeType":883},{"uri":3210},[26173],{"data":26174,"marks":26175,"value":26176,"nodeType":864},{},[],"This visibility turns browser security from a reactive posture into a proactive one",{"data":26178,"marks":26179,"value":26180,"nodeType":864},{},[]," — you can see and remediate the identity weaknesses before an attacker exploits them, not just detect the attack while it's in progress.",{"data":26182,"content":26183,"nodeType":1312},{},[26184],{"data":26185,"marks":26186,"value":26188,"nodeType":864},{},[26187],{"type":899},"The ROI case",{"data":26190,"content":26191,"nodeType":860},{},[26192],{"data":26193,"marks":26194,"value":26195,"nodeType":864},{},[],"The ROI question for any security investment is: what quantum of real risk does this tool address, at what cost in money and operational friction?",{"data":26197,"content":26198,"nodeType":860},{},[26199],{"data":26200,"marks":26201,"value":26203,"nodeType":864},{},[26202],{"type":899},"That calculation looks very different depending on your threat model.",{"data":26205,"content":26206,"nodeType":860},{},[26207],{"data":26208,"marks":26209,"value":26210,"nodeType":864},{},[],"A solution focused on browser engine exploits and sandbox escapes is defending against an attack category that represents a tiny fraction of actual enterprise breaches, requires extraordinary attacker resources to execute, and is increasingly mitigated by browser vendors themselves through hardening and rapid patching. Chrome's automatic update cycle means that even when a browser vulnerability is discovered and disclosed, it is typically in front of users as a patch within days. The defenders here are Google, Mozilla, and Microsoft — with multi-billion dollar security teams and full access to the browser internals.",{"data":26212,"content":26213,"nodeType":860},{},[26214],{"data":26215,"marks":26216,"value":26217,"nodeType":864},{},[],"A solution focused on identity attacks via the browser — phishing, credential theft, session hijacking, OAuth abuse, malicious browser extensions — is defending against the primary cause of enterprise breaches, one that is accelerating (cloud-conscious intrusions up 37% in 2025, browser-based attacks increasing at 68% of organizations over the past two years per Omdia) and increasingly automated through PhaaS infrastructure that gives low-skill attackers enterprise-grade capability for $1,000 a year.",{"data":26219,"content":26220,"nodeType":860},{},[26221],{"data":26222,"marks":26223,"value":26224,"nodeType":864},{},[],"There's also a forward-looking dimension. The threat landscape isn't moving toward more browser exploitation. It's moving further into identity abuse. AI-powered phishing lowers the social engineering barrier. Agentic browsers will automate credential stuffing and account takeover at a scale that wasn't previously possible. And attackers are already adapting to authentication improvements: device code phishing has increased 37x since the start of 2026, a technique specifically designed to circumvent passkeys by bypassing the authentication flow entirely — the attacker never encounters a login page. The investment in identity-centric browser detection compounds over time as the attack surface evolves in the same direction.",{"data":26226,"content":26230,"nodeType":996},{"target":26227},{"sys":26228},{"id":26229,"type":1001,"linkType":1002},"cQ6WPV2NMYvDMZXifqzK1",[],{"data":26232,"content":26233,"nodeType":1312},{},[26234],{"data":26235,"marks":26236,"value":26238,"nodeType":864},{},[26237],{"type":899},"The verdict",{"data":26240,"content":26241,"nodeType":860},{},[26242],{"data":26243,"marks":26244,"value":26245,"nodeType":864},{},[],"Browser security is a real and growing priority — according to Omdia Research, it is now a top-five priority for 88% of security leaders and the top priority for 26% of them. 85% expect their browser security spending to increase over the next 12–24 months. The question isn't whether to invest. It's what to invest in.",{"data":26247,"content":26248,"nodeType":860},{},[26249],{"data":26250,"marks":26251,"value":26252,"nodeType":864},{},[],"The browser is where your users work, where attackers target them, and where the identity attacks causing the majority of enterprise breaches play out. But not all browser security investments address the same problem.",{"data":26254,"content":26257,"nodeType":996},{"target":26255},{"sys":26256},{"id":11598,"type":1001,"linkType":1002},[],{"data":26259,"content":26260,"nodeType":860},{},[26261],{"data":26262,"marks":26263,"value":26264,"nodeType":864},{},[],"Solutions like Seraphic are built to defend against a browser being exploited by an attacker trying to break out of the sandbox — an attack that represents a historic low as a share of enterprise incidents, and one that Google's own hardening and rapid patching increasingly mitigates automatically. SquareX is built around malware sandboxing — a legitimate but declining share of the initial access landscape, and a capability Zscaler's existing customers already partially have. LayerX focuses on internal governance rather than external threats.",{"data":26266,"content":26267,"nodeType":860},{},[26268],{"data":26269,"marks":26270,"value":26271,"nodeType":864},{},[],"Push Security is built to defend against the attacks that are behind the major breaches hitting the headlines: identity theft, credential abuse, session hijacking, and the full identity attack kill chain that plays out inside the browser every time an attacker logs in as your user. Every major threat intelligence report points to these as the primary breach vectors. The economics of attack choice guarantee they'll remain so.",{"data":26273,"content":26274,"nodeType":860},{},[26275],{"data":26276,"marks":26277,"value":26278,"nodeType":864},{},[],"The security team that deploys Push gets the greatest coverage of the highest-impact threats, on managed and unmanaged devices, with the lightest operational footprint. That is the browser security investment that moves the needle on real organizational risk — not the browser security investment that defends the software nobody's actually attacking.",{"data":26280,"content":26284,"nodeType":996},{"target":26281},{"sys":26282},{"id":26283,"type":1001,"linkType":1002},"3a2sEWgWKZulGLCFfODwk0",[],{"data":26286,"content":26287,"nodeType":860},{},[26288],{"data":26289,"marks":26290,"value":21,"nodeType":864},{},[],"How to avoid the browser security buyer's trap","Securing the browser vs. securing the organization via the browser — what's the difference?","2026-05-13T00:00:00.000Z","how-to-avoid-the-browser-security-buyers-trap",{"items":26296},[26297,26299],{"sys":26298,"name":297},{"id":2732},{"sys":26300,"name":2729},{"id":2728},{"items":26302},[26303],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":26304},{"url":4881},{"__typename":2059,"sys":26306,"content":26307,"title":4865,"synopsis":4866,"hashTags":59,"publishedDate":4867,"slug":4868,"tagsCollection":27376,"authorsCollection":27382},{"id":3628},{"json":26308},{"data":26309,"content":26310,"nodeType":856},{},[26311,26324,26329,26335,26341,26346,26349,26356,26363,26378,26416,26421,26434,26437,26444,26451,26473,26505,26511,26514,26521,26528,26534,26539,26545,26548,26555,26562,26596,26626,26632,26635,26642,26649,26669,26675,26714,26720,26723,26730,26737,26773,26779,26784,26787,26794,26801,26827,26833,26838,26844,26847,26854,26861,26884,26890,26896,26902,26905,26912,26919,26925,26930,26936,26957,26980,26983,26990,26997,27003,27009,27012,27019,27074,27077,27084,27090,27358,27361],{"data":26312,"content":26313,"nodeType":860},{},[26314,26317,26321],{"data":26315,"marks":26316,"value":3639,"nodeType":864},{},[],{"data":26318,"marks":26319,"value":3644,"nodeType":864},{},[26320],{"type":899},{"data":26322,"marks":26323,"value":3648,"nodeType":864},{},[],{"data":26325,"content":26328,"nodeType":996},{"target":26326},{"sys":26327},{"id":3653,"type":1001,"linkType":1002},[],{"data":26330,"content":26331,"nodeType":860},{},[26332],{"data":26333,"marks":26334,"value":3661,"nodeType":864},{},[],{"data":26336,"content":26337,"nodeType":860},{},[26338],{"data":26339,"marks":26340,"value":3668,"nodeType":864},{},[],{"data":26342,"content":26345,"nodeType":996},{"target":26343},{"sys":26344},{"id":3673,"type":1001,"linkType":1002},[],{"data":26347,"content":26348,"nodeType":1005},{},[],{"data":26350,"content":26351,"nodeType":1009},{},[26352],{"data":26353,"marks":26354,"value":3685,"nodeType":864},{},[26355],{"type":899},{"data":26357,"content":26358,"nodeType":860},{},[26359],{"data":26360,"marks":26361,"value":3693,"nodeType":864},{},[26362],{"type":899},{"data":26364,"content":26365,"nodeType":860},{},[26366,26369,26375],{"data":26367,"marks":26368,"value":3700,"nodeType":864},{},[],{"data":26370,"content":26371,"nodeType":883},{"uri":3703},[26372],{"data":26373,"marks":26374,"value":3708,"nodeType":864},{},[],{"data":26376,"marks":26377,"value":3712,"nodeType":864},{},[],{"data":26379,"content":26380,"nodeType":860},{},[26381,26384,26390,26393,26397,26400,26404,26407,26413],{"data":26382,"marks":26383,"value":3719,"nodeType":864},{},[],{"data":26385,"content":26386,"nodeType":883},{"uri":3722},[26387],{"data":26388,"marks":26389,"value":3727,"nodeType":864},{},[],{"data":26391,"marks":26392,"value":3731,"nodeType":864},{},[],{"data":26394,"marks":26395,"value":3736,"nodeType":864},{},[26396],{"type":899},{"data":26398,"marks":26399,"value":2232,"nodeType":864},{},[],{"data":26401,"marks":26402,"value":3744,"nodeType":864},{},[26403],{"type":899},{"data":26405,"marks":26406,"value":3748,"nodeType":864},{},[],{"data":26408,"content":26409,"nodeType":883},{"uri":3751},[26410],{"data":26411,"marks":26412,"value":3756,"nodeType":864},{},[],{"data":26414,"marks":26415,"value":3760,"nodeType":864},{},[],{"data":26417,"content":26420,"nodeType":996},{"target":26418},{"sys":26419},{"id":3765,"type":1001,"linkType":1002},[],{"data":26422,"content":26423,"nodeType":860},{},[26424,26427,26431],{"data":26425,"marks":26426,"value":3773,"nodeType":864},{},[],{"data":26428,"marks":26429,"value":3778,"nodeType":864},{},[26430],{"type":899},{"data":26432,"marks":26433,"value":2924,"nodeType":864},{},[],{"data":26435,"content":26436,"nodeType":1005},{},[],{"data":26438,"content":26439,"nodeType":1009},{},[26440],{"data":26441,"marks":26442,"value":3792,"nodeType":864},{},[26443],{"type":899},{"data":26445,"content":26446,"nodeType":860},{},[26447],{"data":26448,"marks":26449,"value":3693,"nodeType":864},{},[26450],{"type":899},{"data":26452,"content":26453,"nodeType":860},{},[26454,26457,26463,26466,26470],{"data":26455,"marks":26456,"value":3806,"nodeType":864},{},[],{"data":26458,"content":26459,"nodeType":883},{"uri":3809},[26460],{"data":26461,"marks":26462,"value":3814,"nodeType":864},{},[],{"data":26464,"marks":26465,"value":3818,"nodeType":864},{},[],{"data":26467,"marks":26468,"value":3823,"nodeType":864},{},[26469],{"type":899},{"data":26471,"marks":26472,"value":3827,"nodeType":864},{},[],{"data":26474,"content":26475,"nodeType":860},{},[26476,26479,26485,26488,26492,26495,26502],{"data":26477,"marks":26478,"value":3834,"nodeType":864},{},[],{"data":26480,"content":26481,"nodeType":883},{"uri":3837},[26482],{"data":26483,"marks":26484,"value":3842,"nodeType":864},{},[],{"data":26486,"marks":26487,"value":3846,"nodeType":864},{},[],{"data":26489,"marks":26490,"value":3851,"nodeType":864},{},[26491],{"type":899},{"data":26493,"marks":26494,"value":3855,"nodeType":864},{},[],{"data":26496,"content":26497,"nodeType":883},{"uri":3858},[26498],{"data":26499,"marks":26500,"value":3864,"nodeType":864},{},[26501],{"type":899},{"data":26503,"marks":26504,"value":3868,"nodeType":864},{},[],{"data":26506,"content":26507,"nodeType":860},{},[26508],{"data":26509,"marks":26510,"value":3875,"nodeType":864},{},[],{"data":26512,"content":26513,"nodeType":1005},{},[],{"data":26515,"content":26516,"nodeType":1009},{},[26517],{"data":26518,"marks":26519,"value":3886,"nodeType":864},{},[26520],{"type":899},{"data":26522,"content":26523,"nodeType":860},{},[26524],{"data":26525,"marks":26526,"value":3894,"nodeType":864},{},[26527],{"type":899},{"data":26529,"content":26530,"nodeType":860},{},[26531],{"data":26532,"marks":26533,"value":3901,"nodeType":864},{},[],{"data":26535,"content":26538,"nodeType":996},{"target":26536},{"sys":26537},{"id":3906,"type":1001,"linkType":1002},[],{"data":26540,"content":26541,"nodeType":860},{},[26542],{"data":26543,"marks":26544,"value":3914,"nodeType":864},{},[],{"data":26546,"content":26547,"nodeType":1005},{},[],{"data":26549,"content":26550,"nodeType":1009},{},[26551],{"data":26552,"marks":26553,"value":3925,"nodeType":864},{},[26554],{"type":899},{"data":26556,"content":26557,"nodeType":860},{},[26558],{"data":26559,"marks":26560,"value":3894,"nodeType":864},{},[26561],{"type":899},{"data":26563,"content":26564,"nodeType":860},{},[26565,26568,26575,26578,26584,26587,26593],{"data":26566,"marks":26567,"value":3939,"nodeType":864},{},[],{"data":26569,"content":26570,"nodeType":883},{"uri":3942},[26571],{"data":26572,"marks":26573,"value":3948,"nodeType":864},{},[26574],{"type":1455},{"data":26576,"marks":26577,"value":3731,"nodeType":864},{},[],{"data":26579,"content":26580,"nodeType":883},{"uri":3954},[26581],{"data":26582,"marks":26583,"value":3959,"nodeType":864},{},[],{"data":26585,"marks":26586,"value":3731,"nodeType":864},{},[],{"data":26588,"content":26589,"nodeType":883},{"uri":3965},[26590],{"data":26591,"marks":26592,"value":3970,"nodeType":864},{},[],{"data":26594,"marks":26595,"value":3974,"nodeType":864},{},[],{"data":26597,"content":26598,"nodeType":860},{},[26599,26602,26609,26612,26616,26619,26623],{"data":26600,"marks":26601,"value":21,"nodeType":864},{},[],{"data":26603,"content":26604,"nodeType":883},{"uri":2411},[26605],{"data":26606,"marks":26607,"value":3988,"nodeType":864},{},[26608],{"type":1455},{"data":26610,"marks":26611,"value":3992,"nodeType":864},{},[],{"data":26613,"marks":26614,"value":3997,"nodeType":864},{},[26615],{"type":899},{"data":26617,"marks":26618,"value":4001,"nodeType":864},{},[],{"data":26620,"marks":26621,"value":4006,"nodeType":864},{},[26622],{"type":2246},{"data":26624,"marks":26625,"value":4010,"nodeType":864},{},[],{"data":26627,"content":26628,"nodeType":860},{},[26629],{"data":26630,"marks":26631,"value":4017,"nodeType":864},{},[],{"data":26633,"content":26634,"nodeType":1005},{},[],{"data":26636,"content":26637,"nodeType":1009},{},[26638],{"data":26639,"marks":26640,"value":4028,"nodeType":864},{},[26641],{"type":899},{"data":26643,"content":26644,"nodeType":860},{},[26645],{"data":26646,"marks":26647,"value":3894,"nodeType":864},{},[26648],{"type":899},{"data":26650,"content":26651,"nodeType":860},{},[26652,26655,26659,26662,26666],{"data":26653,"marks":26654,"value":4042,"nodeType":864},{},[],{"data":26656,"marks":26657,"value":4047,"nodeType":864},{},[26658],{"type":2246},{"data":26660,"marks":26661,"value":4051,"nodeType":864},{},[],{"data":26663,"marks":26664,"value":4056,"nodeType":864},{},[26665],{"type":2246},{"data":26667,"marks":26668,"value":4060,"nodeType":864},{},[],{"data":26670,"content":26671,"nodeType":860},{},[26672],{"data":26673,"marks":26674,"value":4067,"nodeType":864},{},[],{"data":26676,"content":26677,"nodeType":941},{},[26678,26696],{"data":26679,"content":26680,"nodeType":945},{},[26681],{"data":26682,"content":26683,"nodeType":860},{},[26684,26687,26693],{"data":26685,"marks":26686,"value":2761,"nodeType":864},{},[],{"data":26688,"content":26689,"nodeType":883},{"uri":4082},[26690],{"data":26691,"marks":26692,"value":4087,"nodeType":864},{},[],{"data":26694,"marks":26695,"value":4091,"nodeType":864},{},[],{"data":26697,"content":26698,"nodeType":945},{},[26699],{"data":26700,"content":26701,"nodeType":860},{},[26702,26705,26711],{"data":26703,"marks":26704,"value":2761,"nodeType":864},{},[],{"data":26706,"content":26707,"nodeType":883},{"uri":4103},[26708],{"data":26709,"marks":26710,"value":4108,"nodeType":864},{},[],{"data":26712,"marks":26713,"value":4112,"nodeType":864},{},[],{"data":26715,"content":26716,"nodeType":860},{},[26717],{"data":26718,"marks":26719,"value":4119,"nodeType":864},{},[],{"data":26721,"content":26722,"nodeType":1005},{},[],{"data":26724,"content":26725,"nodeType":1009},{},[26726],{"data":26727,"marks":26728,"value":4130,"nodeType":864},{},[26729],{"type":899},{"data":26731,"content":26732,"nodeType":860},{},[26733],{"data":26734,"marks":26735,"value":4138,"nodeType":864},{},[26736],{"type":899},{"data":26738,"content":26739,"nodeType":860},{},[26740,26743,26747,26750,26756,26759,26763,26766,26770],{"data":26741,"marks":26742,"value":4145,"nodeType":864},{},[],{"data":26744,"marks":26745,"value":4150,"nodeType":864},{},[26746],{"type":899},{"data":26748,"marks":26749,"value":4154,"nodeType":864},{},[],{"data":26751,"content":26752,"nodeType":883},{"uri":3237},[26753],{"data":26754,"marks":26755,"value":4161,"nodeType":864},{},[],{"data":26757,"marks":26758,"value":4165,"nodeType":864},{},[],{"data":26760,"marks":26761,"value":4170,"nodeType":864},{},[26762],{"type":899},{"data":26764,"marks":26765,"value":4174,"nodeType":864},{},[],{"data":26767,"marks":26768,"value":4179,"nodeType":864},{},[26769],{"type":899},{"data":26771,"marks":26772,"value":4183,"nodeType":864},{},[],{"data":26774,"content":26775,"nodeType":860},{},[26776],{"data":26777,"marks":26778,"value":4190,"nodeType":864},{},[],{"data":26780,"content":26783,"nodeType":996},{"target":26781},{"sys":26782},{"id":4195,"type":1001,"linkType":1002},[],{"data":26785,"content":26786,"nodeType":1005},{},[],{"data":26788,"content":26789,"nodeType":1009},{},[26790],{"data":26791,"marks":26792,"value":4207,"nodeType":864},{},[26793],{"type":899},{"data":26795,"content":26796,"nodeType":860},{},[26797],{"data":26798,"marks":26799,"value":4215,"nodeType":864},{},[26800],{"type":899},{"data":26802,"content":26803,"nodeType":860},{},[26804,26807,26814,26817,26824],{"data":26805,"marks":26806,"value":4222,"nodeType":864},{},[],{"data":26808,"content":26809,"nodeType":883},{"uri":2561},[26810],{"data":26811,"marks":26812,"value":4230,"nodeType":864},{},[26813],{"type":899},{"data":26815,"marks":26816,"value":4234,"nodeType":864},{},[],{"data":26818,"content":26819,"nodeType":883},{"uri":4237},[26820],{"data":26821,"marks":26822,"value":4243,"nodeType":864},{},[26823],{"type":899},{"data":26825,"marks":26826,"value":4247,"nodeType":864},{},[],{"data":26828,"content":26829,"nodeType":860},{},[26830],{"data":26831,"marks":26832,"value":4254,"nodeType":864},{},[],{"data":26834,"content":26837,"nodeType":996},{"target":26835},{"sys":26836},{"id":4259,"type":1001,"linkType":1002},[],{"data":26839,"content":26840,"nodeType":860},{},[26841],{"data":26842,"marks":26843,"value":4267,"nodeType":864},{},[],{"data":26845,"content":26846,"nodeType":1005},{},[],{"data":26848,"content":26849,"nodeType":1009},{},[26850],{"data":26851,"marks":26852,"value":4278,"nodeType":864},{},[26853],{"type":899},{"data":26855,"content":26856,"nodeType":860},{},[26857],{"data":26858,"marks":26859,"value":4286,"nodeType":864},{},[26860],{"type":899},{"data":26862,"content":26863,"nodeType":860},{},[26864,26867,26871,26874,26881],{"data":26865,"marks":26866,"value":4293,"nodeType":864},{},[],{"data":26868,"marks":26869,"value":4298,"nodeType":864},{},[26870],{"type":2246},{"data":26872,"marks":26873,"value":4302,"nodeType":864},{},[],{"data":26875,"content":26876,"nodeType":883},{"uri":4305},[26877],{"data":26878,"marks":26879,"value":4311,"nodeType":864},{},[26880],{"type":899},{"data":26882,"marks":26883,"value":4315,"nodeType":864},{},[],{"data":26885,"content":26886,"nodeType":860},{},[26887],{"data":26888,"marks":26889,"value":4322,"nodeType":864},{},[],{"data":26891,"content":26892,"nodeType":860},{},[26893],{"data":26894,"marks":26895,"value":4329,"nodeType":864},{},[],{"data":26897,"content":26898,"nodeType":860},{},[26899],{"data":26900,"marks":26901,"value":4336,"nodeType":864},{},[],{"data":26903,"content":26904,"nodeType":1005},{},[],{"data":26906,"content":26907,"nodeType":1009},{},[26908],{"data":26909,"marks":26910,"value":4347,"nodeType":864},{},[26911],{"type":899},{"data":26913,"content":26914,"nodeType":860},{},[26915],{"data":26916,"marks":26917,"value":4355,"nodeType":864},{},[26918],{"type":899},{"data":26920,"content":26921,"nodeType":860},{},[26922],{"data":26923,"marks":26924,"value":4362,"nodeType":864},{},[],{"data":26926,"content":26929,"nodeType":996},{"target":26927},{"sys":26928},{"id":4367,"type":1001,"linkType":1002},[],{"data":26931,"content":26932,"nodeType":860},{},[26933],{"data":26934,"marks":26935,"value":4375,"nodeType":864},{},[],{"data":26937,"content":26938,"nodeType":941},{},[26939,26948],{"data":26940,"content":26941,"nodeType":945},{},[26942],{"data":26943,"content":26944,"nodeType":860},{},[26945],{"data":26946,"marks":26947,"value":4388,"nodeType":864},{},[],{"data":26949,"content":26950,"nodeType":945},{},[26951],{"data":26952,"content":26953,"nodeType":860},{},[26954],{"data":26955,"marks":26956,"value":4398,"nodeType":864},{},[],{"data":26958,"content":26959,"nodeType":860},{},[26960,26963,26970,26973,26977],{"data":26961,"marks":26962,"value":4405,"nodeType":864},{},[],{"data":26964,"content":26965,"nodeType":883},{"uri":4408},[26966],{"data":26967,"marks":26968,"value":4414,"nodeType":864},{},[26969],{"type":899},{"data":26971,"marks":26972,"value":4418,"nodeType":864},{},[],{"data":26974,"marks":26975,"value":4423,"nodeType":864},{},[26976],{"type":2246},{"data":26978,"marks":26979,"value":4427,"nodeType":864},{},[],{"data":26981,"content":26982,"nodeType":1005},{},[],{"data":26984,"content":26985,"nodeType":1009},{},[26986],{"data":26987,"marks":26988,"value":4438,"nodeType":864},{},[26989],{"type":899},{"data":26991,"content":26992,"nodeType":860},{},[26993],{"data":26994,"marks":26995,"value":4446,"nodeType":864},{},[26996],{"type":899},{"data":26998,"content":26999,"nodeType":860},{},[27000],{"data":27001,"marks":27002,"value":4453,"nodeType":864},{},[],{"data":27004,"content":27005,"nodeType":860},{},[27006],{"data":27007,"marks":27008,"value":4460,"nodeType":864},{},[],{"data":27010,"content":27011,"nodeType":1005},{},[],{"data":27013,"content":27014,"nodeType":1009},{},[27015],{"data":27016,"marks":27017,"value":4471,"nodeType":864},{},[27018],{"type":899},{"data":27020,"content":27021,"nodeType":941},{},[27022,27035,27048,27061],{"data":27023,"content":27024,"nodeType":945},{},[27025],{"data":27026,"content":27027,"nodeType":860},{},[27028,27032],{"data":27029,"marks":27030,"value":4485,"nodeType":864},{},[27031],{"type":899},{"data":27033,"marks":27034,"value":4489,"nodeType":864},{},[],{"data":27036,"content":27037,"nodeType":945},{},[27038],{"data":27039,"content":27040,"nodeType":860},{},[27041,27045],{"data":27042,"marks":27043,"value":4500,"nodeType":864},{},[27044],{"type":899},{"data":27046,"marks":27047,"value":4504,"nodeType":864},{},[],{"data":27049,"content":27050,"nodeType":945},{},[27051],{"data":27052,"content":27053,"nodeType":860},{},[27054,27058],{"data":27055,"marks":27056,"value":4515,"nodeType":864},{},[27057],{"type":899},{"data":27059,"marks":27060,"value":4519,"nodeType":864},{},[],{"data":27062,"content":27063,"nodeType":945},{},[27064],{"data":27065,"content":27066,"nodeType":860},{},[27067,27071],{"data":27068,"marks":27069,"value":781,"nodeType":864},{},[27070],{"type":899},{"data":27072,"marks":27073,"value":4533,"nodeType":864},{},[],{"data":27075,"content":27076,"nodeType":1005},{},[],{"data":27078,"content":27079,"nodeType":1009},{},[27080],{"data":27081,"marks":27082,"value":4544,"nodeType":864},{},[27083],{"type":899},{"data":27085,"content":27086,"nodeType":860},{},[27087],{"data":27088,"marks":27089,"value":4551,"nodeType":864},{},[],{"data":27091,"content":27092,"nodeType":4845},{},[27093,27116,27138,27160,27182,27204,27226,27248,27270,27292,27314,27336],{"data":27094,"content":27095,"nodeType":4581},{},[27096,27106],{"data":27097,"content":27098,"nodeType":4569},{},[27099],{"data":27100,"content":27101,"nodeType":860},{},[27102],{"data":27103,"marks":27104,"value":4568,"nodeType":864},{},[27105],{"type":899},{"data":27107,"content":27108,"nodeType":4569},{},[27109],{"data":27110,"content":27111,"nodeType":860},{},[27112],{"data":27113,"marks":27114,"value":4580,"nodeType":864},{},[27115],{"type":899},{"data":27117,"content":27118,"nodeType":4581},{},[27119,27129],{"data":27120,"content":27121,"nodeType":4569},{},[27122],{"data":27123,"content":27124,"nodeType":860},{},[27125],{"data":27126,"marks":27127,"value":4595,"nodeType":864},{},[27128],{"type":899},{"data":27130,"content":27131,"nodeType":4569},{},[27132],{"data":27133,"content":27134,"nodeType":860},{},[27135],{"data":27136,"marks":27137,"value":4605,"nodeType":864},{},[],{"data":27139,"content":27140,"nodeType":4581},{},[27141,27151],{"data":27142,"content":27143,"nodeType":4569},{},[27144],{"data":27145,"content":27146,"nodeType":860},{},[27147],{"data":27148,"marks":27149,"value":4619,"nodeType":864},{},[27150],{"type":899},{"data":27152,"content":27153,"nodeType":4569},{},[27154],{"data":27155,"content":27156,"nodeType":860},{},[27157],{"data":27158,"marks":27159,"value":4629,"nodeType":864},{},[],{"data":27161,"content":27162,"nodeType":4581},{},[27163,27173],{"data":27164,"content":27165,"nodeType":4569},{},[27166],{"data":27167,"content":27168,"nodeType":860},{},[27169],{"data":27170,"marks":27171,"value":4643,"nodeType":864},{},[27172],{"type":899},{"data":27174,"content":27175,"nodeType":4569},{},[27176],{"data":27177,"content":27178,"nodeType":860},{},[27179],{"data":27180,"marks":27181,"value":4653,"nodeType":864},{},[],{"data":27183,"content":27184,"nodeType":4581},{},[27185,27195],{"data":27186,"content":27187,"nodeType":4569},{},[27188],{"data":27189,"content":27190,"nodeType":860},{},[27191],{"data":27192,"marks":27193,"value":4667,"nodeType":864},{},[27194],{"type":899},{"data":27196,"content":27197,"nodeType":4569},{},[27198],{"data":27199,"content":27200,"nodeType":860},{},[27201],{"data":27202,"marks":27203,"value":4677,"nodeType":864},{},[],{"data":27205,"content":27206,"nodeType":4581},{},[27207,27217],{"data":27208,"content":27209,"nodeType":4569},{},[27210],{"data":27211,"content":27212,"nodeType":860},{},[27213],{"data":27214,"marks":27215,"value":4691,"nodeType":864},{},[27216],{"type":899},{"data":27218,"content":27219,"nodeType":4569},{},[27220],{"data":27221,"content":27222,"nodeType":860},{},[27223],{"data":27224,"marks":27225,"value":4701,"nodeType":864},{},[],{"data":27227,"content":27228,"nodeType":4581},{},[27229,27239],{"data":27230,"content":27231,"nodeType":4569},{},[27232],{"data":27233,"content":27234,"nodeType":860},{},[27235],{"data":27236,"marks":27237,"value":4715,"nodeType":864},{},[27238],{"type":899},{"data":27240,"content":27241,"nodeType":4569},{},[27242],{"data":27243,"content":27244,"nodeType":860},{},[27245],{"data":27246,"marks":27247,"value":4725,"nodeType":864},{},[],{"data":27249,"content":27250,"nodeType":4581},{},[27251,27261],{"data":27252,"content":27253,"nodeType":4569},{},[27254],{"data":27255,"content":27256,"nodeType":860},{},[27257],{"data":27258,"marks":27259,"value":4739,"nodeType":864},{},[27260],{"type":899},{"data":27262,"content":27263,"nodeType":4569},{},[27264],{"data":27265,"content":27266,"nodeType":860},{},[27267],{"data":27268,"marks":27269,"value":4749,"nodeType":864},{},[],{"data":27271,"content":27272,"nodeType":4581},{},[27273,27283],{"data":27274,"content":27275,"nodeType":4569},{},[27276],{"data":27277,"content":27278,"nodeType":860},{},[27279],{"data":27280,"marks":27281,"value":4763,"nodeType":864},{},[27282],{"type":899},{"data":27284,"content":27285,"nodeType":4569},{},[27286],{"data":27287,"content":27288,"nodeType":860},{},[27289],{"data":27290,"marks":27291,"value":4773,"nodeType":864},{},[],{"data":27293,"content":27294,"nodeType":4581},{},[27295,27305],{"data":27296,"content":27297,"nodeType":4569},{},[27298],{"data":27299,"content":27300,"nodeType":860},{},[27301],{"data":27302,"marks":27303,"value":4787,"nodeType":864},{},[27304],{"type":899},{"data":27306,"content":27307,"nodeType":4569},{},[27308],{"data":27309,"content":27310,"nodeType":860},{},[27311],{"data":27312,"marks":27313,"value":4797,"nodeType":864},{},[],{"data":27315,"content":27316,"nodeType":4581},{},[27317,27327],{"data":27318,"content":27319,"nodeType":4569},{},[27320],{"data":27321,"content":27322,"nodeType":860},{},[27323],{"data":27324,"marks":27325,"value":4811,"nodeType":864},{},[27326],{"type":899},{"data":27328,"content":27329,"nodeType":4569},{},[27330],{"data":27331,"content":27332,"nodeType":860},{},[27333],{"data":27334,"marks":27335,"value":4821,"nodeType":864},{},[],{"data":27337,"content":27338,"nodeType":4581},{},[27339,27349],{"data":27340,"content":27341,"nodeType":4569},{},[27342],{"data":27343,"content":27344,"nodeType":860},{},[27345],{"data":27346,"marks":27347,"value":4500,"nodeType":864},{},[27348],{"type":899},{"data":27350,"content":27351,"nodeType":4569},{},[27352],{"data":27353,"content":27354,"nodeType":860},{},[27355],{"data":27356,"marks":27357,"value":4844,"nodeType":864},{},[],{"data":27359,"content":27360,"nodeType":1005},{},[],{"data":27362,"content":27363,"nodeType":860},{},[27364,27367,27373],{"data":27365,"marks":27366,"value":4855,"nodeType":864},{},[],{"data":27368,"content":27369,"nodeType":883},{"uri":1700},[27370],{"data":27371,"marks":27372,"value":1703,"nodeType":864},{},[],{"data":27374,"marks":27375,"value":21,"nodeType":864},{},[],{"items":27377},[27378,27380],{"sys":27379,"name":297},{"id":2732},{"sys":27381,"name":2729},{"id":2728},{"items":27383},[27384],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":27385},{"url":4881},"blog/enterprise-browser-vs-browser-extension-which-should-your-security-team-choose",{"json":27388},{"data":27389,"content":27390,"nodeType":856},{},[27391],{"data":27392,"content":27393,"nodeType":860},{},[27394],{"data":27395,"marks":27396,"value":27397,"nodeType":864},{},[],"If you're building a shortlist of browser security vendors, one of the first decisions you hit is an architectural one: full-stack enterprise browser, or browser security extension? ",{"id":11286,"publishedAt":27399},"2026-08-12T11:52:48.566Z",{"items":27401},[27402,27404],{"sys":27403,"name":297},{"id":2732},{"sys":27405,"name":2729},{"id":2728},{"items":27407},[27408,27410,27412,27414,27416,27418,27420,27422,27424,27426,27428,27430],{"sys":27409,"name":297,"slug":298,"tier":31},{"id":294},{"sys":27411,"name":279,"slug":280,"tier":31},{"id":276},{"sys":27413,"name":413,"slug":414,"tier":31},{"id":410},{"sys":27415,"name":386,"slug":387,"tier":45},{"id":383},{"sys":27417,"name":377,"slug":378,"tier":45},{"id":374},{"sys":27419,"name":261,"slug":262,"tier":45},{"id":258},{"sys":27421,"name":315,"slug":316,"tier":45},{"id":312},{"sys":27423,"name":484,"slug":485,"tier":45},{"id":481},{"sys":27425,"name":288,"slug":289,"tier":45},{"id":285},{"sys":27427,"name":624,"slug":625,"tier":45},{"id":621},{"sys":27429,"name":306,"slug":307,"tier":45},{"id":303},{"sys":27431,"name":589,"slug":590,"tier":45},{"id":586},"UhLNLgojmxTmt5rogpt-WncHPs8GJpCJ3gCXZJLR1EE",{"id":27434,"title":27435,"authorsCollection":27436,"content":27440,"extension":228,"faqItemsCollection":28039,"faqTitle":59,"featured":6,"hashTags":59,"meta":28041,"metaTitle":28042,"ogImage":59,"postType":5726,"publishedDate":28043,"relatedBlogPostsCollection":28044,"slug":30131,"stem":30132,"subtitle":59,"summary":30133,"synopsis":30144,"sys":30145,"tagsCollection":30148,"topicsCollection":30154,"__hash__":30204},"blog/blog/verizon-dbir-2026-review.json","What the Verizon DBIR tells us about how breaches happen in 2026",{"items":27437},[27438],{"fullName":3621,"firstName":3622,"jobTitle":3623,"socialLinks":59,"profilePicture":27439},{"url":3625},{"json":27441,"links":27969},{"data":27442,"content":27443,"nodeType":856},{},[27444,27451,27454,27462,27478,27485,27492,27498,27506,27513,27520,27526,27543,27548,27564,27572,27588,27595,27602,27605,27613,27629,27635,27653,27659,27667,27691,27698,27701,27709,27716,27722,27729,27747,27755,27771,27774,27782,27798,27805,27812,27830,27833,27841,27848,27855,27862,27868,27876,27892,27899,27916,27919,27927,27934,27941,27947,27953],{"data":27445,"content":27446,"nodeType":860},{},[27447],{"data":27448,"marks":27449,"value":27450,"nodeType":864},{},[],"The headline finding getting the most airtime in 2026 is that vulnerability exploitation has overtaken credential abuse as the top single initial access vector, jumping to 31% from 20% the year before. The vulnerability management crisis driving this statistic is one of the most important stories in this year's data. But reading it as evidence that identity threats are receding would be a mistake, because the DBIR's own data tells a more complicated and more useful story when you look at the full picture.",{"data":27452,"content":27453,"nodeType":1005},{},[],{"data":27455,"content":27456,"nodeType":1009},{},[27457],{"data":27458,"marks":27459,"value":27461,"nodeType":864},{},[27460],{"type":899},"Vulnerability exploitation has caught up with identity — not replaced it",{"data":27463,"content":27464,"nodeType":860},{},[27465,27469,27474],{"data":27466,"marks":27467,"value":27468,"nodeType":864},{},[],"The DBIR's headline comparison pits vulnerability exploitation (31%) against credential abuse (13%) as individual vectors. That comparison is accurate but incomplete, because the DBIR tracks identity-related initial access across ",{"data":27470,"marks":27471,"value":27473,"nodeType":864},{},[27472],{"type":899},"three",{"data":27475,"marks":27476,"value":27477,"nodeType":864},{},[]," separate categories: phishing (16%), credential abuse (13%), and pretexting (6%). Before interpreting those numbers, there's a methodological wrinkle worth understanding.",{"data":27479,"content":27480,"nodeType":860},{},[27481],{"data":27482,"marks":27483,"value":27484,"nodeType":864},{},[],"This year's report added pretexting as a newly tracked initial access vector, reclassifying some incidents previously counted as credential abuse. The DBIR is transparent about the effect: without that change, credential abuse would have been 16% rather than 13%. On an apples-to-apples basis, identity-related initial access (phishing 16% + credential abuse 16%) comes to 32% — versus 31% for vulnerability exploitation.",{"data":27486,"content":27487,"nodeType":860},{},[27488],{"data":27489,"marks":27490,"value":27491,"nodeType":864},{},[],"To be precise about what moved: phishing held roughly flat year over year, but credential abuse saw a modest decline even on the adjusted basis (from 22% to 16%). Overall, the identity picture is broadly stable. The reason the two categories have converged is that vulnerability exploitation surged 55%, not that identity attacks meaningfully receded.",{"data":27493,"content":27497,"nodeType":996},{"target":27494},{"sys":27495},{"id":27496,"type":1001,"linkType":1002},"5GvSsSY4R6X34ZBMidZ54X",[],{"data":27499,"content":27500,"nodeType":1312},{},[27501],{"data":27502,"marks":27503,"value":27505,"nodeType":864},{},[27504],{"type":899},"The taxonomy gap",{"data":27507,"content":27508,"nodeType":860},{},[27509],{"data":27510,"marks":27511,"value":27512,"nodeType":864},{},[],"It's also worth asking how much the DBIR's initial access taxonomy can tell us. The figure that everyone is citing — Figure 10 — is labelled \"select enumerations,\" and the four tracked vectors (vulnerability exploitation, phishing, credential abuse, pretexting) add up to only 66% of initial access. A third of the picture isn't represented in the headline breakdown at all.",{"data":27514,"content":27515,"nodeType":860},{},[27516],{"data":27517,"marks":27518,"value":27519,"nodeType":864},{},[],"The cluster boundaries and where you draw them also changes the story. The DBIR classifies ClickFix under \"baiting\" — a category that covers malicious downloads and SEO poisoning — rather than phishing, even though the end goal is often the same: getting a user to execute something they shouldn't. Pretexting absorbed incidents that were previously credential abuse, shifting the numbers between categories. These are useful analytical clusters, but they aren't clean divisions of a neatly partitioned attack surface.",{"data":27521,"content":27525,"nodeType":996},{"target":27522},{"sys":27523},{"id":27524,"type":1001,"linkType":1002},"7t6ZcHDycaPOyLstX4r8zl",[],{"data":27527,"content":27528,"nodeType":860},{},[27529,27533,27540],{"data":27530,"marks":27531,"value":27532,"nodeType":864},{},[],"These are identity attacks at scale, and it isn't clear where — or whether — they show up in the DBIR's initial access vectors. This lack of depth in identity and in-browser attack vectors is common in many defensive models, which is why we've created our own ",{"data":27534,"content":27535,"nodeType":883},{"uri":11562},[27536],{"data":27537,"marks":27538,"value":27539,"nodeType":864},{},[],"Browser and Identity Attacks Matrix",{"data":27541,"marks":27542,"value":2924,"nodeType":864},{},[],{"data":27544,"content":27547,"nodeType":996},{"target":27545},{"sys":27546},{"id":18980,"type":1001,"linkType":1002},[],{"data":27549,"content":27550,"nodeType":860},{},[27551,27555,27560],{"data":27552,"marks":27553,"value":27554,"nodeType":864},{},[],"That convergence at initial access also understates the role credentials play across full breach chains. The DBIR states plainly that credential abuse at any point in the breach progression — not just as the first action — appears in ",{"data":27556,"marks":27557,"value":27559,"nodeType":864},{},[27558],{"type":899},"39% of all breaches",{"data":27561,"marks":27562,"value":27563,"nodeType":864},{},[],", making it the single most pervasive technique in the dataset. Credentials don't just open the front door; they unlock lateral movement, privilege escalation, and persistence throughout the attack chain.",{"data":27565,"content":27566,"nodeType":1312},{},[27567],{"data":27568,"marks":27569,"value":27571,"nodeType":864},{},[27570],{"type":899},"The vulnerability treadmill",{"data":27573,"content":27574,"nodeType":860},{},[27575,27579,27584],{"data":27576,"marks":27577,"value":27578,"nodeType":864},{},[],"The vulnerability exploitation surge itself is driven by a structural capacity crisis rather than a shift in attacker preference. Edge devices and VPNs now account for 22% of vulnerability-exploitation breaches, up from 3% the prior year — a ",{"data":27580,"marks":27581,"value":27583,"nodeType":864},{},[27582],{"type":2246},"sevenfold",{"data":27585,"marks":27586,"value":27587,"nodeType":864},{},[]," increase. Organizations face 50% more CISA KEV vulnerabilities to remediate than a year ago, median remediation time has increased from 32 to 43 days, and the volume of vulnerability records in the dataset has grown roughly eightfold.",{"data":27589,"content":27590,"nodeType":860},{},[27591],{"data":27592,"marks":27593,"value":27594,"nodeType":864},{},[],"This trend was already visible in last year's DBIR, when vulnerability exploitation jumped from 15% to 20%. AI-assisted exploit development may be compounding the problem — the DBIR's own data shows 32% of AI-assisted initial access targeting vulnerability exploitation — but the structural capacity crisis was accelerating well before AI became a meaningful factor in the attacker toolkit.",{"data":27596,"content":27597,"nodeType":860},{},[27598],{"data":27599,"marks":27600,"value":27601,"nodeType":864},{},[],"The vulnerability treadmill is accelerating, and the DBIR's remediation data shows defenders losing ground. But this is an additive problem, not a substitution. Both attack surfaces are growing. ",{"data":27603,"content":27604,"nodeType":1005},{},[],{"data":27606,"content":27607,"nodeType":1009},{},[27608],{"data":27609,"marks":27610,"value":27612,"nodeType":864},{},[27611],{"type":899},"Phishing has left the inbox",{"data":27614,"content":27615,"nodeType":860},{},[27616,27620,27625],{"data":27617,"marks":27618,"value":27619,"nodeType":864},{},[],"41% percent of social engineering breaches now involve vectors other than email, with approximately a quarter coming from social media or phone-based channels. Voice phishing simulations show a ",{"data":27621,"marks":27622,"value":27624,"nodeType":864},{},[27623],{"type":899},"40% higher success rate",{"data":27626,"marks":27627,"value":27628,"nodeType":864},{},[]," than email phishing — a median click rate of 2% versus 1.4%.",{"data":27630,"content":27634,"nodeType":996},{"target":27631},{"sys":27632},{"id":27633,"type":1001,"linkType":1002},"7pK8qqIDDNmHmJmlcybNoe",[],{"data":27636,"content":27637,"nodeType":860},{},[27638,27642,27649],{"data":27639,"marks":27640,"value":27641,"nodeType":864},{},[],"Even within the email channel, the data confirms what ",{"data":27643,"content":27644,"nodeType":883},{"uri":11640},[27645],{"data":27646,"marks":27647,"value":27648,"nodeType":864},{},[],"browser-level detection data has been showing",{"data":27650,"marks":27651,"value":27652,"nodeType":864},{},[],": credential harvesting dominates. The DBIR's email security gateway breakdown shows 80% of blocked attacks are credential or session phishing, with only 10% involving malware delivery, 5% callback phishing, and 3% BEC. If you're running an email security gateway, the vast majority of what it catches is credential phishing — and 41% of social engineering is arriving through channels it can't see at all.",{"data":27654,"content":27658,"nodeType":996},{"target":27655},{"sys":27656},{"id":27657,"type":1001,"linkType":1002},"6CvwzQA3gJ8B3RFzLrH7Kp",[],{"data":27660,"content":27661,"nodeType":1312},{},[27662],{"data":27663,"marks":27664,"value":27666,"nodeType":864},{},[27665],{"type":899},"The ClickFix detection gap",{"data":27668,"content":27669,"nodeType":860},{},[27670,27674,27682,27686],{"data":27671,"marks":27672,"value":27673,"nodeType":864},{},[],"The DBIR reports ClickFix at only 2.7% of attacks detected at the browser level. For context, ",{"data":27675,"content":27677,"nodeType":883},{"uri":27676},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection/",[27678],{"data":27679,"marks":27680,"value":27681,"nodeType":864},{},[],"CrowdStrike reported a 563% increase in ClickFix lures",{"data":27683,"marks":27684,"value":27685,"nodeType":864},{},[]," over the same period and Microsoft identified it as the most common initial access point at 47% of observed attacks. Push's own data shows ClickFix at a significantly higher proportion of browser-level detections, ",{"data":27687,"marks":27688,"value":27690,"nodeType":864},{},[27689],{"type":899},"with 4 in 5 delivered via search engines specifically.",{"data":27692,"content":27693,"nodeType":860},{},[27694],{"data":27695,"marks":27696,"value":27697,"nodeType":864},{},[],"The gap is striking, and the most likely explanation is a visibility one. ClickFix attacks result in a malware download or script execution on the endpoint — and without browser-layer context, that execution looks like any other malware delivery. If a contributing organization doesn't have visibility into the browser session that preceded the payload, they'd attribute the incident to \"malware download\" or \"user execution\" rather than ClickFix specifically. The DBIR's 2.7% probably reflects how often contributors could trace the chain back to a ClickFix page, not how often ClickFix was actually the delivery mechanism.",{"data":27699,"content":27700,"nodeType":1005},{},[],{"data":27702,"content":27703,"nodeType":1009},{},[27704],{"data":27705,"marks":27706,"value":27708,"nodeType":864},{},[27707],{"type":899},"Stolen credentials are the ransomware on-ramp",{"data":27710,"content":27711,"nodeType":860},{},[27712],{"data":27713,"marks":27714,"value":27715,"nodeType":864},{},[],"One of the most powerful findings in this year's DBIR is the quantification of the relationship between credential compromise and ransomware outcomes. Fifty percent of ransomware victims had a credential or infostealer event occur within 95 days prior to the ransomware attack, drawing a causal line from credential theft to ransomware deployment.",{"data":27717,"content":27721,"nodeType":996},{"target":27718},{"sys":27719},{"id":27720,"type":1001,"linkType":1002},"3ZwG5UiweFR4fYiDaxJJDm",[],{"data":27723,"content":27724,"nodeType":860},{},[27725],{"data":27726,"marks":27727,"value":27728,"nodeType":864},{},[],"The infostealer supply chain data reinforces the picture. Infostealers are surfacing an average of 2,362 breached corporate credentials per month from organizational email domains in stealer log datasets, and 54% of devices in Initial Access Broker logs had at least one infostealer installed. The 95-day median window is consistent with the known timeline from credential harvest to ransomware deployment.",{"data":27730,"content":27731,"nodeType":860},{},[27732,27736,27743],{"data":27733,"marks":27734,"value":27735,"nodeType":864},{},[],"That timeline reinforces an argument we've been making about ",{"data":27737,"content":27738,"nodeType":883},{"uri":3210},[27739],{"data":27740,"marks":27741,"value":27742,"nodeType":864},{},[],"where the intervention point needs to be",{"data":27744,"marks":27745,"value":27746,"nodeType":864},{},[],": detecting credential compromise upstream — at the point of credential entry, session creation, or stolen credential reuse — rather than waiting for the ransomware deployment that follows weeks or months later.",{"data":27748,"content":27749,"nodeType":1312},{},[27750],{"data":27751,"marks":27752,"value":27754,"nodeType":864},{},[27753],{"type":899},"Post-compromise tradecraft is shifting",{"data":27756,"content":27757,"nodeType":860},{},[27758,27762,27767],{"data":27759,"marks":27760,"value":27761,"nodeType":864},{},[],"The DBIR's post-compromise data adds another dimension. RMM tool abuse by threat actors showed a ",{"data":27763,"marks":27764,"value":27766,"nodeType":864},{},[27765],{"type":899},"240% increase",{"data":27768,"marks":27769,"value":27770,"nodeType":864},{},[]," over the prior year, while traditional backdoor and C2 malware usage fell 27%. Attackers are increasingly living off the land with the same remote access tools IT teams use. Post-compromise detection is getting harder, which makes catching the initial credential compromise upstream that much more valuable.",{"data":27772,"content":27773,"nodeType":1005},{},[],{"data":27775,"content":27776,"nodeType":1009},{},[27777],{"data":27778,"marks":27779,"value":27781,"nodeType":864},{},[27780],{"type":899},"Your vendors are half the problem",{"data":27783,"content":27784,"nodeType":860},{},[27785,27789,27794],{"data":27786,"marks":27787,"value":27788,"nodeType":864},{},[],"Third-party involvement in breaches reached ",{"data":27790,"marks":27791,"value":27793,"nodeType":864},{},[27792],{"type":899},"48%",{"data":27795,"marks":27796,"value":27797,"nodeType":864},{},[]," this year, up from 30% — a 60% increase that follows a prior year where the figure had already doubled.",{"data":27799,"content":27800,"nodeType":860},{},[27801],{"data":27802,"marks":27803,"value":27804,"nodeType":864},{},[],"The DBIR's root cause analysis maps directly to identity security: insecure authentication — absent MFA, improper credential rotation — and lack of least privilege enforcement account for a substantial share of cloud-based third-party incidents. Only 23% of third-party organizations fully remediated missing or improperly secured MFA on cloud accounts, and weak password and permission misconfigurations took a median of 8 months to resolve 50% of findings.",{"data":27806,"content":27807,"nodeType":860},{},[27808],{"data":27809,"marks":27810,"value":27811,"nodeType":864},{},[],"Eight months. That's the median timeline for third-party vendors to resolve the identity hygiene issues that create the attack surface in their environments — environments that your data lives in.",{"data":27813,"content":27814,"nodeType":860},{},[27815,27819,27826],{"data":27816,"marks":27817,"value":27818,"nodeType":864},{},[],"Extend that posture gap across every vendor and third-party integration, and you start to see why the third-party breach figure keeps climbing. Visibility into ",{"data":27820,"content":27821,"nodeType":883},{"uri":4103},[27822],{"data":27823,"marks":27824,"value":27825,"nodeType":864},{},[],"OAuth consent flows and third-party integration sprawl",{"data":27827,"marks":27828,"value":27829,"nodeType":864},{},[]," is the starting point for getting ahead of a supply chain problem that is structurally getting worse.",{"data":27831,"content":27832,"nodeType":1005},{},[],{"data":27834,"content":27835,"nodeType":1009},{},[27836],{"data":27837,"marks":27838,"value":27840,"nodeType":864},{},[27839],{"type":899},"AI is scaling known techniques — and creating new blind spots from the inside",{"data":27842,"content":27843,"nodeType":860},{},[27844],{"data":27845,"marks":27846,"value":27847,"nodeType":864},{},[],"The DBIR's AI analysis this year is grounded in a collaboration with Anthropic covering 793 threat actors who received enforcement action for violating acceptable use policy between March 2025 and February 2026. The findings are measured rather than alarmist: in the median case, actors sought AI assistance across about 15 distinct ATT&CK techniques, 44% of AI-assisted initial access was phishing-related, and less than 2.5% of techniques observed were classified as rare.",{"data":27849,"content":27850,"nodeType":860},{},[27851],{"data":27852,"marks":27853,"value":27854,"nodeType":864},{},[],"AI is currently an operational tool for attackers — automating and scaling known techniques rather than unlocking novel ones. Despite heavy AI-assisted focus on phishing, the DBIR's own incident dataset shows phishing as an initial access vector has barely changed year over year — suggesting AI may be uplifting less-experienced attackers to a higher baseline of lure quality without meaningfully increasing success rates against organizations that already have detection in place.",{"data":27856,"content":27857,"nodeType":860},{},[27858],{"data":27859,"marks":27860,"value":27861,"nodeType":864},{},[],"The more concerning number is the 32% of AI-assisted initial access targeting vulnerability exploitation — compounding the patching capacity crisis discussed earlier in a trend that was already accelerating before AI entered the picture.",{"data":27863,"content":27867,"nodeType":996},{"target":27864},{"sys":27865},{"id":27866,"type":1001,"linkType":1002},"4bFTnVx1SXMQzZSaICCJOn",[],{"data":27869,"content":27870,"nodeType":1312},{},[27871],{"data":27872,"marks":27873,"value":27875,"nodeType":864},{},[27874],{"type":899},"Shadow AI is the bigger problem",{"data":27877,"content":27878,"nodeType":860},{},[27879,27883,27888],{"data":27880,"marks":27881,"value":27882,"nodeType":864},{},[],"The sharper AI risk for most organizations, though, is internal. Forty-five percent of employees are now regular AI users on corporate devices — up from 15%, a threefold increase — and ",{"data":27884,"marks":27885,"value":27887,"nodeType":864},{},[27886],{"type":899},"67% of them use non-corporate accounts",{"data":27889,"marks":27890,"value":27891,"nodeType":864},{},[],". Shadow AI has become the third most common non-malicious insider action in DLP data, a fourfold increase over the prior year, with source code as the leading data type submitted to unauthorized AI platforms by a wide margin.",{"data":27893,"content":27894,"nodeType":860},{},[27895],{"data":27896,"marks":27897,"value":27898,"nodeType":864},{},[],"The browser extension angle is particularly relevant. More than 15% of users had unauthorized AI browser extensions installed, and the DBIR specifically notes that these extensions collect and retain browsing context from internal sites — creating a data exfiltration pathway that operates independently of traditional DLP controls.",{"data":27900,"content":27901,"nodeType":860},{},[27902,27906,27913],{"data":27903,"marks":27904,"value":27905,"nodeType":864},{},[],"This is moving faster than any previous shadow IT wave, and the data loss vector is the browser — where users interact with AI tools, where extensions collect context, and where OAuth consent grants connect AI services to corporate data. Visibility and control at that layer isn't a nice-to-have for AI governance; ",{"data":27907,"content":27908,"nodeType":883},{"uri":11825},[27909],{"data":27910,"marks":27911,"value":27912,"nodeType":864},{},[],"it's the minimum viable starting point",{"data":27914,"marks":27915,"value":2924,"nodeType":864},{},[],{"data":27917,"content":27918,"nodeType":1005},{},[],{"data":27920,"content":27921,"nodeType":1009},{},[27922],{"data":27923,"marks":27924,"value":27926,"nodeType":864},{},[27925],{"type":899},"What this means for defenders",{"data":27928,"content":27929,"nodeType":860},{},[27930],{"data":27931,"marks":27932,"value":27933,"nodeType":864},{},[],"The DBIR's 2026 data paints a picture of converging pressures rather than shifting priorities. Vulnerability exploitation surged, but identity-related initial access is broadly stable and credential abuse at 39% across full breach chains remains the single most pervasive technique in the dataset. Phishing is arriving through channels that email gateways can't see. The infostealer-to-ransomware pipeline now has longitudinal data behind it. Third-party involvement keeps climbing because vendor identity hygiene takes months to remediate. And shadow AI is creating data exposure pathways that most security stacks weren't designed to see.",{"data":27935,"content":27936,"nodeType":860},{},[27937],{"data":27938,"marks":27939,"value":27940,"nodeType":864},{},[],"The common thread across all of these findings is that the browser — where credentials are entered, sessions are created, OAuth consent is granted, AI tools are accessed, and extensions collect data — is the layer where these risks converge and where defenders need visibility and control if they're going to address them at the point of risk rather than after the fact.",{"data":27942,"content":27943,"nodeType":860},{},[27944],{"data":27945,"marks":27946,"value":1682,"nodeType":864},{},[],{"data":27948,"content":27949,"nodeType":860},{},[27950],{"data":27951,"marks":27952,"value":1689,"nodeType":864},{},[],{"data":27954,"content":27955,"nodeType":860},{},[27956,27959,27966],{"data":27957,"marks":27958,"value":21,"nodeType":864},{},[],{"data":27960,"content":27961,"nodeType":883},{"uri":1700},[27962],{"data":27963,"marks":27964,"value":1703,"nodeType":864},{},[27965],{"type":1455},{"data":27967,"marks":27968,"value":21,"nodeType":864},{},[],{"entries":27970},{"hyperlink":27971,"inline":27972,"block":27973},[],[],[27974,27980,28005,28008,28022,28027,28034],{"sys":27975,"__typename":1724,"title":27976,"caption":27976,"layoutMode":59,"file":27977},{"id":27496},"DBIR Figure 10 (p.15) — Initial access vectors, select enumerations",{"url":27978,"width":1736,"height":27979},"https://images.ctfassets.net/y1cdw1ablpvd/18rPvZ4Sw11UCHE7MxzXkd/17d059302242b4034686b13ee3044c8e/image4.png",1521,{"sys":27981,"__typename":1740,"content":27982,"name":28004,"title":59},{"id":27524},{"json":27983},{"nodeType":856,"data":27984,"content":27985},{},[27986],{"nodeType":860,"data":27987,"content":27988},{},[27989,27993,28000],{"nodeType":864,"value":27990,"marks":27991,"data":27992},"Some of the ",[],{},{"nodeType":883,"data":27994,"content":27995},{"uri":1765},[27996],{"nodeType":864,"value":27997,"marks":27998,"data":27999},"most consequential identity-based campaigns of the past 12 months",[],{},{"nodeType":864,"value":28001,"marks":28002,"data":28003}," don't map cleanly to any of these categories — the mass Salesforce campaign that compromised over 1,000 organizations via device code phishing, the Anodot breach chain that pivoted through stored OAuth tokens to reach Snowflake customers, ConsentFix abusing Azure CLI's OAuth flow to bypass MFA entirely.",[],{},"DBIR 2026 IB1",{"sys":28006,"__typename":1724,"title":11754,"caption":19295,"layoutMode":59,"file":28007},{"id":18980},{"url":19297,"width":19298,"height":19299},{"sys":28009,"__typename":1740,"content":28010,"name":28021,"title":59},{"id":27633},{"json":28011},{"data":28012,"content":28013,"nodeType":856},{},[28014],{"data":28015,"content":28016,"nodeType":860},{},[28017],{"data":28018,"marks":28019,"value":28020,"nodeType":864},{},[],"The data is a little confusing. The DBIR draws a line between Phishing (asynchronous — send a message and hope for a click) and Pretexting (synchronous — someone interacting with you in real time). Voice phishing over a phone call is Pretexting in VERIS, not Phishing, even though most practitioners would call it phishing. Browser-based credential harvesting delivered via SEO poisoning or malicious downloads falls under \"Baiting.\" So the 16% phishing figure probably understates the full scope of credential-harvesting social engineering as most defenders would define it.","DBIR IB2",{"sys":28023,"__typename":1724,"title":28024,"caption":28024,"layoutMode":59,"file":28025},{"id":27657},"DBIR Figure 54 (p.49) — Median percentage of email attack types by month",{"url":28026,"width":1736,"height":27979},"https://images.ctfassets.net/y1cdw1ablpvd/4eWtJSz2QhM6QgXXjNuBNs/e6a33a088b7b0fb0dd1649c5d9164b53/image1.png",{"sys":28028,"__typename":1724,"title":28029,"caption":28029,"layoutMode":59,"file":28030},{"id":27720},"DBIR Figure 48 (p.45) — Credential leakage events prior to ransomware",{"url":28031,"width":28032,"height":28033},"https://images.ctfassets.net/y1cdw1ablpvd/26NpMQ31lpHgp5x8FrDumz/f022f1ede66b171dd756d28009a7d4a5/image2.png",1772,776,{"sys":28035,"__typename":1724,"title":28036,"caption":28036,"layoutMode":59,"file":28037},{"id":27866},"DBIR Figure 65 (p.60) — Select data types in DLP events targeting generative AI tools",{"url":28038,"width":1736,"height":27979},"https://images.ctfassets.net/y1cdw1ablpvd/584Txvap6FW9GlFlin9GwB/f5f5488251d9faee7fedc3030d2390b1/image5.png",{"items":28040},[],{},"What the Verizon DBIR tells us about breaches in 2026","2026-05-20T00:00:00.000Z",{"items":28045},[28046,28634,29610],{"__typename":2059,"sys":28047,"content":28049,"title":28621,"synopsis":28622,"hashTags":59,"publishedDate":26293,"slug":28623,"tagsCollection":28624,"authorsCollection":28630},{"id":28048},"217s8zu5idSdX25TUgbPQ1",{"json":28050},{"data":28051,"content":28052,"nodeType":856},{},[28053,28071,28078,28085,28091,28094,28102,28118,28125,28131,28138,28221,28228,28233,28240,28246,28249,28257,28269,28276,28288,28291,28299,28314,28321,28328,28331,28339,28346,28362,28368,28384,28391,28398,28405,28421,28428,28431,28439,28446,28462,28469,28472,28480,28496,28503,28522,28534,28537,28545,28561,28568,28575,28582,28589,28592,28599,28605],{"data":28054,"content":28055,"nodeType":860},{},[28056,28059,28067],{"data":28057,"marks":28058,"value":2761,"nodeType":864},{},[],{"data":28060,"content":28062,"nodeType":883},{"uri":28061},"https://research.esg-global.com/reportaction/515202191/Marketing",[28063],{"data":28064,"marks":28065,"value":28066,"nodeType":864},{},[],"Omdia Browser Management and Security report",{"data":28068,"marks":28069,"value":28070,"nodeType":864},{},[],", based on a survey of 400 IT and security professionals across North America fielded in late 2025, is the most comprehensive industry data to date on how organizations are experiencing, prioritizing, and investing in the secure enterprise browser (SEB) market. ",{"data":28072,"content":28073,"nodeType":860},{},[28074],{"data":28075,"marks":28076,"value":28077,"nodeType":864},{},[],"For us at Push, it externally validates what we've known to be true for some time — the browser is where work happens, where attacks land, and where defenders need to be if they want to detect and stop threats before damage is done.",{"data":28079,"content":28080,"nodeType":860},{},[28081],{"data":28082,"marks":28083,"value":28084,"nodeType":864},{},[],"We pulled out seven findings that matter most for security teams evaluating their approach.",{"data":28086,"content":28090,"nodeType":996},{"target":28087},{"sys":28088},{"id":28089,"type":1001,"linkType":1002},"4aM879egIFYmDvOhzyNI9A",[],{"data":28092,"content":28093,"nodeType":1005},{},[],{"data":28095,"content":28096,"nodeType":1009},{},[28097],{"data":28098,"marks":28099,"value":28101,"nodeType":864},{},[28100],{"type":899},"1. The attacks driving concern are the ones happening inside the browser session",{"data":28103,"content":28104,"nodeType":860},{},[28105,28109,28114],{"data":28106,"marks":28107,"value":28108,"nodeType":864},{},[],"The threat picture is driving everything else in this report, so it's the right place to start. ",{"data":28110,"marks":28111,"value":28113,"nodeType":864},{},[28112],{"type":899},"49% of organizations suffered a successful browser-based attack in the last 12 months.",{"data":28115,"marks":28116,"value":28117,"nodeType":864},{},[]," Among those affected, browser-originated incidents account for roughly 37% of all security incidents — and 68% say that share has grown over the past two years. ",{"data":28119,"content":28120,"nodeType":860},{},[28121],{"data":28122,"marks":28123,"value":28124,"nodeType":864},{},[],"The browser is not an emerging threat vector. It’s worth noting here that these numbers are also likely lower than the reality, since many are only identified later in the kill chain. Without browser-level telemetry they can be difficult to trace back their source — which in the vast majority of cases, even for malware-driven attacks, is the browser. ",{"data":28126,"content":28130,"nodeType":996},{"target":28127},{"sys":28128},{"id":28129,"type":1001,"linkType":1002},"6Kcz8oILKVHmhQIo5Du6V",[],{"data":28132,"content":28133,"nodeType":860},{},[28134],{"data":28135,"marks":28136,"value":28137,"nodeType":864},{},[],"What stands out is that every one of the top attack categories plays out inside the browser session itself — not against the browser as a piece of software, but within the sessions where users interact with applications:",{"data":28139,"content":28140,"nodeType":941},{},[28141,28151,28161,28171,28181,28191,28201,28211],{"data":28142,"content":28143,"nodeType":945},{},[28144],{"data":28145,"content":28146,"nodeType":860},{},[28147],{"data":28148,"marks":28149,"value":28150,"nodeType":864},{},[],"Phishing (40%)",{"data":28152,"content":28153,"nodeType":945},{},[28154],{"data":28155,"content":28156,"nodeType":860},{},[28157],{"data":28158,"marks":28159,"value":28160,"nodeType":864},{},[],"Data loss or leakage (38%)",{"data":28162,"content":28163,"nodeType":945},{},[28164],{"data":28165,"content":28166,"nodeType":860},{},[28167],{"data":28168,"marks":28169,"value":28170,"nodeType":864},{},[],"Malicious browser extensions (34%)",{"data":28172,"content":28173,"nodeType":945},{},[28174],{"data":28175,"content":28176,"nodeType":860},{},[28177],{"data":28178,"marks":28179,"value":28180,"nodeType":864},{},[],"Vulnerable browser extensions (33%)",{"data":28182,"content":28183,"nodeType":945},{},[28184],{"data":28185,"content":28186,"nodeType":860},{},[28187],{"data":28188,"marks":28189,"value":28190,"nodeType":864},{},[],"Malicious scripts (31%)",{"data":28192,"content":28193,"nodeType":945},{},[28194],{"data":28195,"content":28196,"nodeType":860},{},[28197],{"data":28198,"marks":28199,"value":28200,"nodeType":864},{},[],"Credential theft via browser (28%)",{"data":28202,"content":28203,"nodeType":945},{},[28204],{"data":28205,"content":28206,"nodeType":860},{},[28207],{"data":28208,"marks":28209,"value":28210,"nodeType":864},{},[],"Cookie theft (22%)",{"data":28212,"content":28213,"nodeType":945},{},[28214],{"data":28215,"content":28216,"nodeType":860},{},[28217],{"data":28218,"marks":28219,"value":28220,"nodeType":864},{},[],"AiTM attacks (17%)",{"data":28222,"content":28223,"nodeType":860},{},[28224],{"data":28225,"marks":28226,"value":28227,"nodeType":864},{},[],"Phishing, credential theft, cookie theft, and AiTM are attacks that target the user's interaction with a web page — the credential entry, the session creation, the token exchange. Malicious and vulnerable extensions are supply chain risks that operate inside the browser's own execution environment. Data loss happens through the browser when employees upload files, paste data into AI tools, or share information with unsanctioned applications. ",{"data":28229,"content":28232,"nodeType":996},{"target":28230},{"sys":28231},{"id":23546,"type":1001,"linkType":1002},[],{"data":28234,"content":28235,"nodeType":860},{},[28236],{"data":28237,"marks":28238,"value":28239,"nodeType":864},{},[],"None of these are attacks where network-layer traffic inspection, endpoint monitoring, or email scanning provides complete coverage, because the attack surface is the browser session itself.",{"data":28241,"content":28245,"nodeType":996},{"target":28242},{"sys":28243},{"id":28244,"type":1001,"linkType":1002},"5kI5h4Z31ByD73er7voayF",[],{"data":28247,"content":28248,"nodeType":1005},{},[],{"data":28250,"content":28251,"nodeType":1009},{},[28252],{"data":28253,"marks":28254,"value":28256,"nodeType":864},{},[28255],{"type":899},"2. Browser security is now a board-level priority",{"data":28258,"content":28259,"nodeType":860},{},[28260,28265],{"data":28261,"marks":28262,"value":28264,"nodeType":864},{},[28263],{"type":899},"88% of respondents rank browser security as at least a top-five security priority",{"data":28266,"marks":28267,"value":28268,"nodeType":864},{},[],", with more than a quarter (26%) calling it their single top priority. For context, this is a survey that covers the full spectrum of security concerns — cloud, supply chain, AI, insider risk — and browser security has risen above most of them.",{"data":28270,"content":28271,"nodeType":860},{},[28272],{"data":28273,"marks":28274,"value":28275,"nodeType":864},{},[],"This is not aspirational interest. The correlation between priority level and investment is sharp: among those who rank browser security as their top priority, 72% have significantly increased their investment due to emerging threats. Among those who rank it in their top five, that figure is 26%. The organizations that care most are spending the most.",{"data":28277,"content":28278,"nodeType":860},{},[28279,28284],{"data":28280,"marks":28281,"value":28283,"nodeType":864},{},[28282],{"type":899},"86% of respondents have increased their browser security investment in response to emerging threats",{"data":28285,"marks":28286,"value":28287,"nodeType":864},{},[],", with 36% saying the increase was significant. When you ask what's driving that spend, the answer is the threat landscape: the attacks cataloged in the previous section are the reason budgets are moving.",{"data":28289,"content":28290,"nodeType":1005},{},[],{"data":28292,"content":28293,"nodeType":1009},{},[28294],{"data":28295,"marks":28296,"value":28298,"nodeType":864},{},[28297],{"type":899},"3. Real budget is being allocated — and it's growing",{"data":28300,"content":28301,"nodeType":860},{},[28302,28306,28310],{"data":28303,"marks":28304,"value":28305,"nodeType":864},{},[],"Secure enterprise browser solutions already take up ",{"data":28307,"marks":28308,"value":24968,"nodeType":864},{},[28309],{"type":899},{"data":28311,"marks":28312,"value":28313,"nodeType":864},{},[]," — a substantial allocation for a category that didn't exist as a standalone line item a few years ago. And 85% of respondents expect to increase that spend over the next 12–24 months, with a quarter expecting significant increases.",{"data":28315,"content":28316,"nodeType":860},{},[28317],{"data":28318,"marks":28319,"value":28320,"nodeType":864},{},[],"Where the money comes from tells its own story. The most common funding model is a discrete line item within security program budgets (31%) or a dedicated secure browsing budget (30%). When organizations pull from an existing program budget, web security (26%) and endpoint security (21%) are the most common sources — while SASE/SSE accounts for just 9%, despite SASE vendors being the second most popular vendor category. That disconnect between vendor preference and budget origin suggests the SASE-bundled buying motion may be more aspirational than operational.",{"data":28322,"content":28323,"nodeType":860},{},[28324],{"data":28325,"marks":28326,"value":28327,"nodeType":864},{},[],"IT operations leadership is the top stakeholder in 82% of evaluations, with CISO and security leadership at 64% and CIOs at 42%. Day-to-day management sits primarily with IT Ops (77%) and SecOps (50%). This dual stakeholder picture — IT operations driving evaluation, security leadership providing strategic direction — shapes the competitive landscape in ways we'll come back to.",{"data":28329,"content":28330,"nodeType":1005},{},[],{"data":28332,"content":28333,"nodeType":1009},{},[28334],{"data":28335,"marks":28336,"value":28338,"nodeType":864},{},[28337],{"type":899},"4. AI is accelerating both the threat and the use case",{"data":28340,"content":28341,"nodeType":860},{},[28342],{"data":28343,"marks":28344,"value":28345,"nodeType":864},{},[],"AI shows up in this report from two directions, mirroring how it is reshaping the security landscape itself.",{"data":28347,"content":28348,"nodeType":860},{},[28349,28353,28358],{"data":28350,"marks":28351,"value":28352,"nodeType":864},{},[],"On the threat side, ",{"data":28354,"marks":28355,"value":28357,"nodeType":864},{},[28356],{"type":899},"AI-powered targeted phishing and social engineering is the top emerging concern",{"data":28359,"marks":28360,"value":28361,"nodeType":864},{},[],", cited by 75% of respondents as either very concerning or concerning. Data leakage via unsanctioned AI applications comes second at 71%, followed by deepfake/AI-generated malicious content at 69% and credential harvesting via fake AI or SaaS login pages at 66%. Every one of these threat categories involves the browser — AI-enhanced phishing lands in the browser, AI data leakage happens through browser-based AI tools, and fake AI login pages are browser-based credential harvesting.",{"data":28363,"content":28367,"nodeType":996},{"target":28364},{"sys":28365},{"id":28366,"type":1001,"linkType":1002},"2ajv2i5wn2GzKuyynQGlvq",[],{"data":28369,"content":28370,"nodeType":860},{},[28371,28375,28380],{"data":28372,"marks":28373,"value":28374,"nodeType":864},{},[],"On the adoption side, the picture is almost universal — and almost universally under-governed. ",{"data":28376,"marks":28377,"value":28379,"nodeType":864},{},[28378],{"type":899},"92% of organizations now allow employees to use public GenAI applications",{"data":28381,"marks":28382,"value":28383,"nodeType":864},{},[],", and virtually every organization has some kind of policy position: 37% have sanctioned one public app (with everything else unsanctioned), 39% have sanctioned multiple public apps (with others unsanctioned), and 23% restrict employees to a corporate instance while the public versions are unsanctioned. ",{"data":28385,"content":28386,"nodeType":860},{},[28387],{"data":28388,"marks":28389,"value":28390,"nodeType":864},{},[],"Even the 8% who don't allow GenAI at all have taken a policy position. Essentially 100% of organizations have a GenAI policy — but for the vast majority, that policy designates a large portion of public AI tool usage as unsanctioned, which raises the immediate question of whether they have the tooling to actually enforce it.",{"data":28392,"content":28393,"nodeType":860},{},[28394],{"data":28395,"marks":28396,"value":28397,"nodeType":864},{},[],"The answer, based on the current tooling landscape, appears to be: not quite. When Omdia asked how organizations currently secure GenAI usage, 58% rely on secure web gateways — tools that see traffic metadata but cannot observe what a user actually does inside a GenAI session — while 57% use secure browsing solutions and 57% use SaaS security solutions. ",{"data":28399,"content":28400,"nodeType":860},{},[28401],{"data":28402,"marks":28403,"value":28404,"nodeType":864},{},[],"An SWG can tell you that a user visited ChatGPT, but it cannot tell you whether they pasted your company's source code into the prompt. That distinction — between knowing where data went and knowing what the user actually did — is the fundamental gap that browser-layer visibility exists to close, and it is exactly the gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":28406,"content":28407,"nodeType":860},{},[28408,28412,28417],{"data":28409,"marks":28410,"value":28411,"nodeType":864},{},[],"The use case data reflects this. When Omdia asked about the most important use cases for a secure browsing solution, ",{"data":28413,"marks":28414,"value":28416,"nodeType":864},{},[28415],{"type":899},"generative AI application security came in first at 59%",{"data":28418,"marks":28419,"value":28420,"nodeType":864},{},[],", followed by data loss prevention at 51% and general web security enhancement at 42%. The feature priorities tell a consistent story: AI-powered threat detection and response (52%) and advanced GenAI usage controls and monitoring (41%) were the top two capabilities organizations said would be most important in a purchase decision. ",{"data":28422,"content":28423,"nodeType":860},{},[28424],{"data":28425,"marks":28426,"value":28427,"nodeType":864},{},[],"AI is both the top threat concern and the top use case for browser security — and it is a browser problem at both ends, because every LLM interaction, every prompt containing sensitive data, and every AI agent authorization happens inside a browser session.",{"data":28429,"content":28430,"nodeType":1005},{},[],{"data":28432,"content":28433,"nodeType":1009},{},[28434],{"data":28435,"marks":28436,"value":28438,"nodeType":864},{},[28437],{"type":899},"5. Organizations that have deployed secure enterprise browser solutions are seeing real results",{"data":28440,"content":28441,"nodeType":860},{},[28442],{"data":28443,"marks":28444,"value":28445,"nodeType":864},{},[],"One of the most useful sections in Omdia's report is the benefits data — what organizations that have deployed SEB solutions are actually getting out of them.",{"data":28447,"content":28448,"nodeType":860},{},[28449,28453,28458],{"data":28450,"marks":28451,"value":28452,"nodeType":864},{},[],"The top realized benefit is ",{"data":28454,"marks":28455,"value":28457,"nodeType":864},{},[28456],{"type":899},"improved data security, cited by 58% of respondents",{"data":28459,"marks":28460,"value":28461,"nodeType":864},{},[],", followed by fewer security incidents (49%), better visibility and auditing (47%), improved user experience (44%), and simplified configuration and policy management (41%). The picture that emerges is not just a security story but an operational one: organizations are seeing fewer incidents, better visibility, and simpler management alongside the security outcomes.",{"data":28463,"content":28464,"nodeType":860},{},[28465],{"data":28466,"marks":28467,"value":28468,"nodeType":864},{},[],"The 49% who cite fewer security incidents as a realized benefit is the number that matters most here, because it directly connects SEB deployment to measurable risk reduction. Organizations aren't just buying tools and hoping — they're deploying them and seeing fewer successful attacks as a result.",{"data":28470,"content":28471,"nodeType":1005},{},[],{"data":28473,"content":28474,"nodeType":1009},{},[28475],{"data":28476,"marks":28477,"value":28479,"nodeType":864},{},[28478],{"type":899},"6. The market wants protection in existing browsers, not migration",{"data":28481,"content":28482,"nodeType":860},{},[28483,28487,28492],{"data":28484,"marks":28485,"value":28486,"nodeType":864},{},[],"When Omdia asked what attributes matter most in a secure enterprise browser solution, ",{"data":28488,"marks":28489,"value":28491,"nodeType":864},{},[28490],{"type":899},"\"ability to use existing browsers\" ranked as the fourth most important attribute at 48%",{"data":28493,"marks":28494,"value":28495,"nodeType":864},{},[]," — behind only integration with other security tools (57%), controls over generative AI application usage (53%), and centralized policy enforcement (52%). ",{"data":28497,"content":28498,"nodeType":860},{},[28499],{"data":28500,"marks":28501,"value":28502,"nodeType":864},{},[],"That 48% figure, combined with 80% of respondents saying they expect to use an SEB solution as an integrated or alongside component rather than a replacement for existing tools, points to a clear market preference: organizations want browser security that works with their existing browser estate, not a migration to a new one.",{"data":28504,"content":28505,"nodeType":860},{},[28506,28510,28518],{"data":28507,"marks":28508,"value":28509,"nodeType":864},{},[],"This is consistent with what we hear from security leaders directly. As ",{"data":28511,"content":28512,"nodeType":883},{"uri":11674},[28513],{"data":28514,"marks":28515,"value":28517,"nodeType":864},{},[28516],{"type":1455},"Josh Lemos put it: ",{"data":28519,"marks":28520,"value":28521,"nodeType":864},{},[],"\"We looked at the full-stack enterprise browser approach, but converging on a single platform was tough. Push gave me the security instrumentation and context I needed without onerous headwinds.\" The deployment model matters because it determines adoption velocity — and a tool that requires browser migration introduces friction that delays time to value.",{"data":28523,"content":28524,"nodeType":860},{},[28525,28529],{"data":28526,"marks":28527,"value":28528,"nodeType":864},{},[],"Push was built around this insight from day one. As the secure enterprise browser extension for security teams, Push turns any browser — managed or unmanaged, including agentic browsers — into a telemetry source and control point the moment it's installed. It has been rolled out to 100,000 users in under an hour during normal office hours with zero downtime. ",{"data":28530,"marks":28531,"value":28533,"nodeType":864},{},[28532],{"type":899},"That is a deployment model that matches what Omdia's respondents are asking for.",{"data":28535,"content":28536,"nodeType":1005},{},[],{"data":28538,"content":28539,"nodeType":1009},{},[28540],{"data":28541,"marks":28542,"value":28544,"nodeType":864},{},[28543],{"type":899},"7. Dedicated vendors lead over platform plays",{"data":28546,"content":28547,"nodeType":860},{},[28548,28552,28557],{"data":28549,"marks":28550,"value":28551,"nodeType":864},{},[],"When Omdia asked which category of vendor organizations primarily use or expect to use for secure enterprise browsing, ",{"data":28553,"marks":28554,"value":28556,"nodeType":864},{},[28555],{"type":899},"36% chose a dedicated SEB vendor",{"data":28558,"marks":28559,"value":28560,"nodeType":864},{},[]," — the largest single category. SASE/network security vendors came second at 29%, followed by traditional VDI/desktop virtualization vendors at 19% and endpoint platform vendors at 15%.",{"data":28562,"content":28563,"nodeType":860},{},[28564],{"data":28565,"marks":28566,"value":28567,"nodeType":864},{},[],"The dedicated category leads, and the reason isn't just first-mover advantage — it's architectural. The alternative paths each come with structural constraints. SASE and SSE platforms are network-centric: they see traffic metadata and enforce URL categorization, but they can't observe the rendered page inside a browser tab — the DOM structure, the script behavior, the credential entry that distinguishes a legitimate login from an AiTM reverse-proxy kit. ",{"data":28569,"content":28570,"nodeType":860},{},[28571],{"data":28572,"marks":28573,"value":28574,"nodeType":864},{},[],"Endpoint platforms that bolt on browser visibility are still anchored to the OS layer, solving for browser exploit prevention rather than in-session behavioral detection of the attacks that actually dominate — phishing, credential theft, session hijacking, extension compromise. And when large platform vendors acquire browser security capabilities, the integration work takes years rather than months, during which detection depth sits in a transitional state. ",{"data":28576,"content":28577,"nodeType":860},{},[28578],{"data":28579,"marks":28580,"value":28581,"nodeType":864},{},[],"Dedicated browser-native vendors start from a different premise entirely: the browser isn't a supplementary signal feeding into someone else's SASE pipeline or XDR correlation engine — it is the telemetry source and the control point. The browser is the only place where you get simultaneous visibility into both the attacker's technique and the employee's action within the same session, because the phishing page, the credential submission, the token exchange, and the data exfiltration all happen inside the same tab. No network appliance, endpoint agent, or identity provider log can see all of that, because none of them are present where the interaction occurs.",{"data":28583,"content":28584,"nodeType":860},{},[28585],{"data":28586,"marks":28587,"value":28588,"nodeType":864},{},[],"For security teams evaluating SEB solutions, the architecture matters more than the vendor category label. The capabilities Omdia's respondents ranked highest — integration with existing tools, GenAI controls, centralized policy enforcement, and the ability to use existing browsers — all point toward solutions that deliver detection depth through a lightweight deployment model, without browser migration and without the integration debt of a platform acquisition.",{"data":28590,"content":28591,"nodeType":1005},{},[],{"data":28593,"content":28594,"nodeType":860},{},[28595],{"data":28596,"marks":28597,"value":28598,"nodeType":864},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":28600,"content":28601,"nodeType":860},{},[28602],{"data":28603,"marks":28604,"value":1689,"nodeType":864},{},[],{"data":28606,"content":28607,"nodeType":860},{},[28608,28611,28618],{"data":28609,"marks":28610,"value":21,"nodeType":864},{},[],{"data":28612,"content":28613,"nodeType":883},{"uri":1700},[28614],{"data":28615,"marks":28616,"value":13763,"nodeType":864},{},[28617],{"type":1455},{"data":28619,"marks":28620,"value":2719,"nodeType":864},{},[],"7 things Omdia's latest report tells us about the secure enterprise browser market","Unpacking the latest research report from Omdia and what it means for the secure enterprise browser market.","7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",{"items":28625},[28626,28628],{"sys":28627,"name":297},{"id":2732},{"sys":28629,"name":2729},{"id":2728},{"items":28631},[28632],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":28633},{"url":2740},{"__typename":2059,"sys":28635,"content":28637,"title":29597,"synopsis":29598,"hashTags":59,"publishedDate":24225,"slug":29599,"tagsCollection":29600,"authorsCollection":29606},{"id":28636},"3jF1fypt08TNlSoWuoMWhj",{"json":28638},{"data":28639,"content":28640,"nodeType":856},{},[28641,28667,28698,28740,28783,28789,28801,28804,28812,28863,28870,28893,28899,28902,28910,28938,28945,28953,28959,28962,28970,28977,28995,29002,29043,29050,29053,29061,29080,29135,29138,29146,29164,29182,29189,29196,29208,29220,29232,29244,29260,29268,29275,29278,29284,29290,29305,29308,29316,29334,29591],{"data":28642,"content":28643,"nodeType":860},{},[28644,28648,28654,28658,28663],{"data":28645,"marks":28646,"value":28647,"nodeType":864},{},[],"ShinyHunters and the broader SLH (",{"data":28649,"content":28650,"nodeType":883},{"uri":16015},[28651],{"data":28652,"marks":28653,"value":16018,"nodeType":864},{},[],{"data":28655,"marks":28656,"value":28657,"nodeType":864},{},[],") collective have claimed breaches at thousands of organizations over the past twelve months across retail, technology, aviation, financial services, media, gaming, and education, in what amounts to the most sustained data theft and extortion operation in recent cybercrime history. SLH's genealogy traces through a merger of Scattered Spider, Lapsus$, and ShinyHunters, all parts of ",{"data":28659,"marks":28660,"value":28662,"nodeType":864},{},[28661],{"type":899},"the Com",{"data":28664,"marks":28665,"value":28666,"nodeType":864},{},[],", a broader community of English-speaking cybercriminals with international links. ",{"data":28668,"content":28669,"nodeType":860},{},[28670,28674,28682,28686,28694],{"data":28671,"marks":28672,"value":28673,"nodeType":864},{},[],"The confirmed victim list reads like a Fortune 500 directory: Coca-Cola, Cisco, Qantas, Coinbase, ADT, Aflac, SoundCloud, Rockstar Games, Charter Communications, and recently ",{"data":28675,"content":28677,"nodeType":883},{"uri":28676},"https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/",[28678],{"data":28679,"marks":28680,"value":28681,"nodeType":864},{},[],"Instructure",{"data":28683,"marks":28684,"value":28685,"nodeType":864},{},[]," — whose breach ",{"data":28687,"content":28689,"nodeType":883},{"uri":28688},"https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/",[28690],{"data":28691,"marks":28692,"value":28693,"nodeType":864},{},[],"disrupted schools and universities nationwide",{"data":28695,"marks":28696,"value":28697,"nodeType":864},{},[]," during final exams — among dozens more named publicly and likely many more that haven't been (breaches settled quickly behind closed doors don't always make it into the public eye). ShinyHunters alone claimed over 1.5 billion stolen Salesforce records from a single campaign targeting more than 1,000 organizations.",{"data":28699,"content":28700,"nodeType":860},{},[28701,28705,28713,28717,28725,28729,28736],{"data":28702,"marks":28703,"value":28704,"nodeType":864},{},[],"Additional operating clusters, including Cordial Spider and Snarky Spider (which CrowdStrike ",{"data":28706,"content":28708,"nodeType":883},{"uri":28707},"https://cyberscoop.com/crowdstrike-cordial-spider-snarky-spider-extortion-attacks/",[28709],{"data":28710,"marks":28711,"value":28712,"nodeType":864},{},[],"characterizes as the new generation of Scattered Spider",{"data":28714,"marks":28715,"value":28716,"nodeType":864},{},[],") run parallel campaigns against different target sectors, unified not by shared infrastructure but by a shared playbook of techniques that exploit the structural weakness in modern SaaS-first organizations. ",{"data":28718,"content":28720,"nodeType":883},{"uri":28719},"https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-03-12-Vishing-Campaigns-Lead-to-Data-Theft-and-Extortion.txt",[28721],{"data":28722,"marks":28723,"value":28724,"nodeType":864},{},[],"Unit 42 documented",{"data":28726,"marks":28727,"value":28728,"nodeType":864},{},[]," these groups moving from initial compromise to complete data exfiltration in under an hour — faster than most organizations can even begin to respond. Newer groups with links to the SLH ecosystem like CoinbaseCartel have also continued the tradition of weaponizing stolen credentials from the infostealer economy at scale, as ShinyHunters did in the ",{"data":28730,"content":28731,"nodeType":883},{"uri":16553},[28732],{"data":28733,"marks":28734,"value":28735,"nodeType":864},{},[],"2024 Snowflake breach",{"data":28737,"marks":28738,"value":28739,"nodeType":864},{},[]," that compromised over 165 customer environments (and claimed another billion-plus records).",{"data":28741,"content":28742,"nodeType":860},{},[28743,28747,28755,28759,28767,28771,28779],{"data":28744,"marks":28745,"value":28746,"nodeType":864},{},[],"Not every SLH breach is browser-based — the Instructure breach (275 million individuals, ~330 school login portals defaced) began with a Salesforce tenant compromise in September 2025, but resurfaced in May 2026 after attackers exploited a ",{"data":28748,"content":28750,"nodeType":883},{"uri":28749},"https://www.bitdefender.com/en-gb/blog/businessinsights/technical-advisory-shinyhunters-breach-instructure-canvas-lms",[28751],{"data":28752,"marks":28753,"value":28754,"nodeType":864},{},[],"vulnerability affecting Canvas's Free-For-Teacher program",{"data":28756,"marks":28757,"value":28758,"nodeType":864},{},[]," (it's now been confirmed that Instructure \"",{"data":28760,"content":28762,"nodeType":883},{"uri":28761},"https://www.instructure.com/incident_update",[28763],{"data":28764,"marks":28765,"value":28766,"nodeType":864},{},[],"reached a settlement",{"data":28768,"marks":28769,"value":28770,"nodeType":864},{},[],"\" for the deletion of the data, and shut down the free account tier), while the Coinbase breach cost ",{"data":28772,"content":28774,"nodeType":883},{"uri":28773},"https://www.bleepingcomputer.com/news/security/coinbase-discloses-breach-faces-up-to-400-million-in-losses/",[28775],{"data":28776,"marks":28777,"value":28778,"nodeType":864},{},[],"$180M–400M through insider bribery",{"data":28780,"marks":28781,"value":28782,"nodeType":864},{},[]," — but these are the exceptions that prove the rule. ",{"data":28784,"content":28788,"nodeType":996},{"target":28785},{"sys":28786},{"id":28787,"type":1001,"linkType":1002},"4qNrbDyMJIumQfdbh9YVkU",[],{"data":28790,"content":28791,"nodeType":860},{},[28792,28797],{"data":28793,"marks":28794,"value":28796,"nodeType":864},{},[28795],{"type":899},"The vast majority of SLH campaigns over the past year converge on three browser-based attack vectors: vishing combined with AiTM phishing, device code phishing exploiting account authorization flows, and OAuth supply chain attacks through compromised third-party integrators.",{"data":28798,"marks":28799,"value":28800,"nodeType":864},{},[]," Each is well-documented, each has produced confirmed victims at scale, and each is detectable or preventable through browser-layer security controls.",{"data":28802,"content":28803,"nodeType":1005},{},[],{"data":28805,"content":28806,"nodeType":1009},{},[28807],{"data":28808,"marks":28809,"value":28811,"nodeType":864},{},[28810],{"type":899},"Vector 1: Vishing combined with AiTM phishing",{"data":28813,"content":28814,"nodeType":860},{},[28815,28819,28827,28830,28838,28842,28849,28853,28860],{"data":28816,"marks":28817,"value":28818,"nodeType":864},{},[],"The most visible campaign right now pairs targeted voice calls with adversary-in-the-middle phishing pages — an approach that ",{"data":28820,"content":28822,"nodeType":883},{"uri":28821},"https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft",[28823],{"data":28824,"marks":28825,"value":28826,"nodeType":864},{},[],"Mandiant",{"data":28828,"marks":28829,"value":11735,"nodeType":864},{},[],{"data":28831,"content":28833,"nodeType":883},{"uri":28832},"https://www.crowdstrike.com/en-us/blog/defending-against-cordial-spider-and-snarky-spider-with-falcon-shield/",[28834],{"data":28835,"marks":28836,"value":28837,"nodeType":864},{},[]," CrowdStrike",{"data":28839,"marks":28840,"value":28841,"nodeType":864},{},[],", and",{"data":28843,"content":28844,"nodeType":883},{"uri":28719},[28845],{"data":28846,"marks":28847,"value":28848,"nodeType":864},{},[]," Unit 42",{"data":28850,"marks":28851,"value":28852,"nodeType":864},{},[]," have all documented from the incident response side, and which Push has ",{"data":28854,"content":28855,"nodeType":883},{"uri":12879},[28856],{"data":28857,"marks":28858,"value":28859,"nodeType":864},{},[],"documented from inside the attacker's own operator panels",{"data":28861,"marks":28862,"value":2924,"nodeType":864},{},[],{"data":28864,"content":28865,"nodeType":860},{},[28866],{"data":28867,"marks":28868,"value":28869,"nodeType":864},{},[],"An attacker impersonating IT support calls the target employee, establishes urgency — often citing a \"mandatory passkey rollout\" or a \"security compliance update\" — and directs them to a victim-branded AiTM phishing page (typically at a domain like \u003Ccompany>sso.com or \u003Ccompany>internal.com). The attack is processed by a live human in real time, relaying credentials and MFA codes to the legitimate identity provider as they are entered, capturing the resulting session token, and granting the attacker an authenticated session. ",{"data":28871,"content":28872,"nodeType":860},{},[28873,28877,28884,28888],{"data":28874,"marks":28875,"value":28876,"nodeType":864},{},[],"One of the reasons that this method is becoming so widespread is the commoditization of effective tools. Push's ",{"data":28878,"content":28879,"nodeType":883},{"uri":12879},[28880],{"data":28881,"marks":28882,"value":28883,"nodeType":864},{},[],"infiltration of the criminal phishing panels",{"data":28885,"marks":28886,"value":28887,"nodeType":864},{},[]," identified over 400 linked domains across four distinct infrastructure clusters. ",{"data":28889,"marks":28890,"value":28892,"nodeType":864},{},[28891],{"type":899},"This mirrors the pattern that turned AiTM phishing from a specialist capability into an industrialized market with competing PhaaS platforms, but with the added complication that voice phishing as the delivery vector makes the attack invisible to traditional anti-phishing controls at the email layer.",{"data":28894,"content":28898,"nodeType":996},{"target":28895},{"sys":28896},{"id":28897,"type":1001,"linkType":1002},"1Yhthl0PILGW7EmCcZUrNv",[],{"data":28900,"content":28901,"nodeType":1005},{},[],{"data":28903,"content":28904,"nodeType":1009},{},[28905],{"data":28906,"marks":28907,"value":28909,"nodeType":864},{},[28908],{"type":899},"Vector 2: Vishing combined with device code phishing",{"data":28911,"content":28912,"nodeType":860},{},[28913,28916,28923,28927,28934],{"data":28914,"marks":28915,"value":2761,"nodeType":864},{},[],{"data":28917,"content":28918,"nodeType":883},{"uri":23901},[28919],{"data":28920,"marks":28921,"value":28922,"nodeType":864},{},[],"ShinyHunters Salesforce campaign",{"data":28924,"marks":28925,"value":28926,"nodeType":864},{},[]," that ran through 2025 and into 2026 used device code phishing as one of its core methods, ",{"data":28928,"content":28929,"nodeType":883},{"uri":16553},[28930],{"data":28931,"marks":28932,"value":28933,"nodeType":864},{},[],"compromising over 1,000 organizations and claiming 1.5 billion stolen records",{"data":28935,"marks":28936,"value":28937,"nodeType":864},{},[]," — including an attempted extortion of Salesforce itself. The attack involved registering an attacker-controlled \"DataLoader\" application mimicking a legitimate Salesforce tool, configuring it to request broad OAuth scopes including full API access and refresh token generation, and guiding victims through the device authorization flow via vishing calls.",{"data":28939,"content":28940,"nodeType":860},{},[28941],{"data":28942,"marks":28943,"value":28944,"nodeType":864},{},[],"Device code phishing exploits the OAuth 2.0 device authorization grant — a flow designed for devices without browsers, like smart TVs, but used in a wide range of scenarios including CLI logins — by tricking users into entering a code on Microsoft's (or another identity provider's) legitimate verification page. Since the victim is usually signed into the app in their browser, there’s no login at all. They simply navigate to the app’s device code login page and enter an attacker-provided code to grant the attacker an access token. ",{"data":28946,"content":28947,"nodeType":860},{},[28948],{"data":28949,"marks":28950,"value":28952,"nodeType":864},{},[28951],{"type":899},"This is what makes device code phishing structurally different from AiTM: it defeats all MFA (including passkeys) because the attack doesn’t target the login, but the authorization layer instead.",{"data":28954,"content":28958,"nodeType":996},{"target":28955},{"sys":28956},{"id":28957,"type":1001,"linkType":1002},"3ElQz8sLATnR8RY5nVlBGM",[],{"data":28960,"content":28961,"nodeType":1005},{},[],{"data":28963,"content":28964,"nodeType":1009},{},[28965],{"data":28966,"marks":28967,"value":28969,"nodeType":864},{},[28968],{"type":899},"Vector 3: OAuth supply chain attacks through compromised integrators",{"data":28971,"content":28972,"nodeType":860},{},[28973],{"data":28974,"marks":28975,"value":28976,"nodeType":864},{},[],"The third vector does not require the attacker to phish the victim organization's employees at all. Instead, it exploits the OAuth trust relationships that organizations create when they connect third-party SaaS vendors into their environments — and the consequence is that every organization that authorized one of these integrations effectively extended its security boundary to include the vendor's own security posture.",{"data":28978,"content":28979,"nodeType":860},{},[28980,28983,28991],{"data":28981,"marks":28982,"value":2761,"nodeType":864},{},[],{"data":28984,"content":28986,"nodeType":883},{"uri":28985},"https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift",[28987],{"data":28988,"marks":28989,"value":28990,"nodeType":864},{},[],"Salesloft/Drift supply chain attack",{"data":28992,"marks":28993,"value":28994,"nodeType":864},{},[]," demonstrated this at scale in 2025: in an extension of the previously mentioned device code phishing campaign, the attacker compromised Salesloft's GitHub environment, used TruffleHog to find secrets, stole Drift OAuth tokens, and used them to access downstream Salesforce environments. The same pattern was later repeated at Gainsight. ",{"data":28996,"content":28997,"nodeType":860},{},[28998],{"data":28999,"marks":29000,"value":29001,"nodeType":864},{},[],"Along with the previously mentioned device code phishing attacks,  more than 1000 organizations were breached. The attackers then harvested AWS keys, Snowflake credentials, and stored passwords from breached Salesforce instances, compounding the access into progressively wider reach.",{"data":29003,"content":29004,"nodeType":860},{},[29005,29009,29017,29021,29029,29033,29039],{"data":29006,"marks":29007,"value":29008,"nodeType":864},{},[],"The same structural pattern has continued into 2026 with the Anodot supply chain compromise, which has produced confirmed breaches at ",{"data":29010,"content":29012,"nodeType":883},{"uri":29011},"https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/",[29013],{"data":29014,"marks":29015,"value":29016,"nodeType":864},{},[],"Vimeo",{"data":29018,"marks":29019,"value":29020,"nodeType":864},{},[]," (119,000 users), Rockstar Games (78.6 million records), and ",{"data":29022,"content":29024,"nodeType":883},{"uri":29023},"https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/",[29025],{"data":29026,"marks":29027,"value":29028,"nodeType":864},{},[],"Zara/Inditex",{"data":29030,"marks":29031,"value":29032,"nodeType":864},{},[]," (197,000 people), with further downstream victims likely still emerging. The ",{"data":29034,"content":29035,"nodeType":883},{"uri":4103},[29036],{"data":29037,"marks":29038,"value":16114,"nodeType":864},{},[],{"data":29040,"marks":29041,"value":29042,"nodeType":864},{},[],", which involved compromised OAuth tokens from Context.ai cascading into Google Workspace, also reinforces the same attack pattern (though it was likely not a ShinyHunters operation despite being claimed by someone pretending to be them).",{"data":29044,"content":29045,"nodeType":860},{},[29046],{"data":29047,"marks":29048,"value":29049,"nodeType":864},{},[],"A forgotten SaaS integration can easily become the pivot point for downstream compromise. The moment you authorize a third-party integration, your security boundary extends to include that vendor. If the third-party is compromised, every downstream customer organization with an active integration is exposed.",{"data":29051,"content":29052,"nodeType":1005},{},[],{"data":29054,"content":29055,"nodeType":1009},{},[29056],{"data":29057,"marks":29058,"value":29060,"nodeType":864},{},[29059],{"type":899},"The infostealer credential playbook sits alongside these attacks",{"data":29062,"content":29063,"nodeType":860},{},[29064,29068,29076],{"data":29065,"marks":29066,"value":29067,"nodeType":864},{},[],"Alongside the three vectors above, ShinyHunters has a track record of exploiting the infostealer credential economy at scale — and it predates any of them. The 2024 Snowflake campaign — 165+ customer environments compromised, over a billion records stolen from AT&T, Ticketmaster, Santander, and Advance Auto Parts among others — was built entirely on infostealer-harvested credentials replayed against MFA-less tenants, with ",{"data":29069,"content":29071,"nodeType":883},{"uri":29070},"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",[29072],{"data":29073,"marks":29074,"value":29075,"nodeType":864},{},[],"Mandiant's investigation",{"data":29077,"marks":29078,"value":29079,"nodeType":864},{},[]," finding that 80% of compromised accounts had prior breach exposure in datasets dating back to 2020. The credentials were already circulating in criminal marketplaces; ShinyHunters simply purchased and operationalized them at industrial scale.",{"data":29081,"content":29082,"nodeType":860},{},[29083,29087,29095,29099,29107,29111,29119,29123,29131],{"data":29084,"marks":29085,"value":29086,"nodeType":864},{},[],"The same methodology powered the ",{"data":29088,"content":29090,"nodeType":883},{"uri":29089},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials/",[29091],{"data":29092,"marks":29093,"value":29094,"nodeType":864},{},[],"HellCat Jira campaign",{"data":29096,"marks":29097,"value":29098,"nodeType":864},{},[]," through 2024–2025, and has now been industrialized as a standalone operation by ",{"data":29100,"content":29102,"nodeType":883},{"uri":29101},"https://www.halcyon.ai/jp/threat-group/coinbasecartel",[29103],{"data":29104,"marks":29105,"value":29106,"nodeType":864},{},[],"CoinbaseCartel",{"data":29108,"marks":29109,"value":29110,"nodeType":864},{},[],", another criminal group reported to be an offshoot of SLH. CoinbaseCartel's model is familiar: purchase old infostealer credentials, use them to access cloud and development environments, exfiltrate data, and demand ransom. ",{"data":29112,"content":29114,"nodeType":883},{"uri":29113},"https://www.infostealers.com/article/inside-the-coinbase-cartel-how-infostealer-credentials-fueled-a-100-company-ransomware-spree/",[29115],{"data":29116,"marks":29117,"value":29118,"nodeType":864},{},[],"Hudson Rock's analysis",{"data":29120,"marks":29121,"value":29122,"nodeType":864},{},[]," of the group's 170+ claimed victims confirms that roughly 80% had prior infostealer infections predating the attacks. The most recent named victim is ",{"data":29124,"content":29126,"nodeType":883},{"uri":29125},"https://www.bleepingcomputer.com/news/security/grafana-says-stolen-github-token-let-hackers-steal-codebase/",[29127],{"data":29128,"marks":29129,"value":29130,"nodeType":864},{},[],"Grafana",{"data":29132,"marks":29133,"value":29134,"nodeType":864},{},[],", where a GitHub token compromised via the TanStack npm supply chain attack and missed during credential rotation was used to download the codebase and attempt extortion. ",{"data":29136,"content":29137,"nodeType":1005},{},[],{"data":29139,"content":29140,"nodeType":1009},{},[29141],{"data":29142,"marks":29143,"value":29145,"nodeType":864},{},[29144],{"type":899},"These attacks all happen in the browser",{"data":29147,"content":29148,"nodeType":860},{},[29149,29153,29160],{"data":29150,"marks":29151,"value":29152,"nodeType":864},{},[],"Every one of these attack chains is a browser-based attack that either occurs in the browser (AiTM phishing, device code phishing) or could have been prevented at the browser layer (OAuth consent governance). The techniques are interchangeable — the",{"data":29154,"content":29155,"nodeType":883},{"uri":3259},[29156],{"data":29157,"marks":29158,"value":29159,"nodeType":864},{},[]," same criminal kits now offer AiTM and device code phishing side by side",{"data":29161,"marks":29162,"value":29163,"nodeType":864},{},[],", and the same threat actor (ShinyHunters) has used all three vectors across different campaigns within the same twelve-month period.",{"data":29165,"content":29166,"nodeType":860},{},[29167,29171,29178],{"data":29168,"marks":29169,"value":29170,"nodeType":864},{},[],"Additionally, infostealer infections themselves are increasingly delivered through browser-based methods like ",{"data":29172,"content":29174,"nodeType":883},{"uri":29173},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection",[29175],{"data":29176,"marks":29177,"value":315,"nodeType":864},{},[],{"data":29179,"marks":29180,"value":29181,"nodeType":864},{},[],", closing the loop between the credential supply side and the browser-layer detection point.",{"data":29183,"content":29184,"nodeType":1312},{},[29185],{"data":29186,"marks":29187,"value":7533,"nodeType":864},{},[29188],{"type":899},{"data":29190,"content":29191,"nodeType":860},{},[29192],{"data":29193,"marks":29194,"value":29195,"nodeType":864},{},[],"Push operates at the exact point in each of these attack chains where automated intervention can still prevent the compromise. ",{"data":29197,"content":29198,"nodeType":860},{},[29199,29204],{"data":29200,"marks":29201,"value":29203,"nodeType":864},{},[29202],{"type":899},"For vishing + AiTM attacks, ",{"data":29205,"marks":29206,"value":29207,"nodeType":864},{},[],"Push's behavioral phishing detection analyzes and blocks the phishing page in real time by detecting it from the user's browser — regardless of the domains used, hosting infrastructure, or where the URL was delivered.  ",{"data":29209,"content":29210,"nodeType":860},{},[29211,29216],{"data":29212,"marks":29213,"value":29215,"nodeType":864},{},[29214],{"type":899},"For device code phishing,",{"data":29217,"marks":29218,"value":29219,"nodeType":864},{},[]," Push detects the phishing pages associated with device code phishing kits — including generic, technique-class detections that catch new kits without requiring kit-specific signatures. Second, Push provides an additional layer of protection on the legitimate device code authentication pages themselves, preventing users from entering attacker-supplied codes into them. Together, these detections cover both the kit-operated phishing infrastructure and the legitimate auth pages that the attack flow depends on.",{"data":29221,"content":29222,"nodeType":860},{},[29223,29228],{"data":29224,"marks":29225,"value":29227,"nodeType":864},{},[29226],{"type":899},"For OAuth supply chain attacks,",{"data":29229,"marks":29230,"value":29231,"nodeType":864},{},[]," Push's detects and controls OAuth consent flows at the browser layer — capturing which application is requesting access, what scopes it's requesting, and whether the grant should be permitted under organizational policy. Push customers can also block OAuth connection requests as they transit the browser, enabling security teams to stop unwanted integrations being added in the first place. ",{"data":29233,"content":29234,"nodeType":860},{},[29235,29240],{"data":29236,"marks":29237,"value":29239,"nodeType":864},{},[29238],{"type":899},"For the infostealer credential playbook,",{"data":29241,"marks":29242,"value":29243,"nodeType":864},{},[]," Push's stolen credential detection identifies when employees are using credentials that have appeared in breach datasets or dark web feeds — catching the moment a dormant infostealer credential surfaces at a browser-based login, as well as surfacing insecure login methods missing mitigating controls like MFA and enforcing them through in-browser guardrails. And on the supply side, Push's ClickFix detection addresses the browser-based delivery vector that is now the primary method for distributing infostealer malware in the first place.",{"data":29245,"content":29246,"nodeType":860},{},[29247,29250,29257],{"data":29248,"marks":29249,"value":21,"nodeType":864},{},[],{"data":29251,"content":29252,"nodeType":883},{"uri":24926},[29253],{"data":29254,"marks":29255,"value":29256,"nodeType":864},{},[],"Learn more about how you can use Push controls to protect your users from in-browser threats here. ",{"data":29258,"marks":29259,"value":21,"nodeType":864},{},[],{"data":29261,"content":29262,"nodeType":1312},{},[29263],{"data":29264,"marks":29265,"value":29267,"nodeType":864},{},[29266],{"type":899},"Closing thoughts",{"data":29269,"content":29270,"nodeType":860},{},[29271],{"data":29272,"marks":29273,"value":29274,"nodeType":864},{},[],"The campaigns documented in this post are not historical — they are ongoing, with new victims surfacing weekly and the underlying criminal infrastructure still actively developing. But the defensive strategy does not require anticipating which specific group, vector, or target sector comes next, because all of them converge on the same control point: the browser, where the attack begins or the integration decision is made. Organizations with browser-layer detection and OAuth governance in place have defense-in-depth against the full range of techniques these groups employ, regardless of which specific vector any given campaign uses.",{"data":29276,"content":29277,"nodeType":1005},{},[],{"data":29279,"content":29280,"nodeType":860},{},[29281],{"data":29282,"marks":29283,"value":4855,"nodeType":864},{},[],{"data":29285,"content":29286,"nodeType":860},{},[29287],{"data":29288,"marks":29289,"value":1689,"nodeType":864},{},[],{"data":29291,"content":29292,"nodeType":860},{},[29293,29296,29302],{"data":29294,"marks":29295,"value":21,"nodeType":864},{},[],{"data":29297,"content":29298,"nodeType":883},{"uri":14401},[29299],{"data":29300,"marks":29301,"value":1703,"nodeType":864},{},[],{"data":29303,"marks":29304,"value":21,"nodeType":864},{},[],{"data":29306,"content":29307,"nodeType":1005},{},[],{"data":29309,"content":29310,"nodeType":1009},{},[29311],{"data":29312,"marks":29313,"value":29315,"nodeType":864},{},[29314],{"type":899},"Appendix: named ShinyHunters victims since May 2025",{"data":29317,"content":29318,"nodeType":860},{},[29319,29323,29330],{"data":29320,"marks":29321,"value":29322,"nodeType":864},{},[],"To give an indication of the scale, the following table documents all publicly named victims attributed to ShinyHunters specifically since the Salesforce campaign began in May 2025. It is not exhaustive: ShinyHunters has claimed over 1,000 organizations in aggregate across its Salesforce campaigns alone, and many victims have not been publicly named. This list also doesn’t include the billion-plus records compromised in the 2024 Snowflake breaches. The major ransomware attacks executed against M&S, Co-op, and Jaguar Land Rover claimed by the ",{"data":29324,"content":29325,"nodeType":883},{"uri":16015},[29326],{"data":29327,"marks":29328,"value":29329,"nodeType":864},{},[],"Scattered Lapsus$ Hunters \"brand\"",{"data":29331,"marks":29332,"value":29333,"nodeType":864},{},[]," also aren't listed below. ",{"data":29335,"content":29336,"nodeType":4845},{},[29337,29384,29448,29496,29544],{"data":29338,"content":29339,"nodeType":4581},{},[29340,29351,29362,29373],{"data":29341,"content":29342,"nodeType":4569},{},[29343],{"data":29344,"content":29345,"nodeType":860},{},[29346],{"data":29347,"marks":29348,"value":29350,"nodeType":864},{},[29349],{"type":899},"Campaign",{"data":29352,"content":29353,"nodeType":4569},{},[29354],{"data":29355,"content":29356,"nodeType":860},{},[29357],{"data":29358,"marks":29359,"value":29361,"nodeType":864},{},[29360],{"type":899},"Began",{"data":29363,"content":29364,"nodeType":4569},{},[29365],{"data":29366,"content":29367,"nodeType":860},{},[29368],{"data":29369,"marks":29370,"value":29372,"nodeType":864},{},[29371],{"type":899},"Named victims",{"data":29374,"content":29375,"nodeType":4569},{},[29376],{"data":29377,"content":29378,"nodeType":860},{},[29379],{"data":29380,"marks":29381,"value":29383,"nodeType":864},{},[29382],{"type":899},"Confirmed impact",{"data":29385,"content":29386,"nodeType":4581},{},[29387,29411,29421,29431],{"data":29388,"content":29389,"nodeType":4569},{},[29390],{"data":29391,"content":29392,"nodeType":860},{},[29393,29398,29402,29407],{"data":29394,"marks":29395,"value":29397,"nodeType":864},{},[29396],{"type":899},"ShinyHunters Salesforce Vishing",{"data":29399,"marks":29400,"value":29401,"nodeType":864},{},[]," (vishing + device code phishing → Salesforce connected app authorization) \n\n& ",{"data":29403,"marks":29404,"value":29406,"nodeType":864},{},[29405],{"type":899},"Salesloft/Drift Supply Chain",{"data":29408,"marks":29409,"value":29410,"nodeType":864},{},[]," (stolen OAuth tokens → downstream Salesforce access)",{"data":29412,"content":29413,"nodeType":4569},{},[29414],{"data":29415,"content":29416,"nodeType":860},{},[29417],{"data":29418,"marks":29419,"value":29420,"nodeType":864},{},[],"May 2025",{"data":29422,"content":29423,"nodeType":4569},{},[29424],{"data":29425,"content":29426,"nodeType":860},{},[29427],{"data":29428,"marks":29429,"value":29430,"nodeType":864},{},[],"Coca-Cola Europacific Partners, Cisco, Qantas, LVMH, Adidas, Google, Chanel, Pandora, Allianz Life, Air France-KLM, Farmers Insurance, Workday, TransUnion, Stellantis, Kering, Odido, Hallmark, Salesloft (origin), Toast, Avalara, Fastly, Cato Networks, Cloudflare, Palo Alto Networks, Zscaler, Tenable, Elastic, JFrog, CyberArk, Rubrik, BeyondTrust, Proofpoint, Workiva, Mercer Advisors, Beacon Pointe, Ameriprise, Kemper, Udemy, 7-Eleven, Mytheresa, Marcus & Millichap, Carnival, Pitney Bowes, Alert 360, Amtrak, McGraw-Hill, Canada Life, Charter Communications",{"data":29432,"content":29433,"nodeType":4569},{},[29434,29441],{"data":29435,"content":29436,"nodeType":860},{},[29437],{"data":29438,"marks":29439,"value":29440,"nodeType":864},{},[],"49 named victims. Confirmed individual impact includes 23M+ records (Coca-Cola), 5.7M records (Qantas), 6.2M customers (Odido), 4.4M consumers (TransUnion), up to 18M records (Stellantis), 13.5M emails (McGraw-Hill), 8.2M emails (Pitney Bowes), 7.5M emails (Carnival), 7-Eleven: 185K confirmed by HIBP (SSNs, driver's licenses; franchisee data), Charter Communications: millions of records claimed (company disputes scope). ",{"data":29442,"content":29443,"nodeType":860},{},[29444],{"data":29445,"marks":29446,"value":29447,"nodeType":864},{},[],"ShinyHunters claims 1.5B+ Salesforce records across 1,000+ organizations total.",{"data":29449,"content":29450,"nodeType":4581},{},[29451,29466,29476,29486],{"data":29452,"content":29453,"nodeType":4569},{},[29454],{"data":29455,"content":29456,"nodeType":860},{},[29457,29462],{"data":29458,"marks":29459,"value":29461,"nodeType":864},{},[29460],{"type":899},"Vishing + AiTM SSO",{"data":29463,"marks":29464,"value":29465,"nodeType":864},{},[]," (vishing → AiTM phishing page → SSO session capture → SaaS data exfiltration)",{"data":29467,"content":29468,"nodeType":4569},{},[29469],{"data":29470,"content":29471,"nodeType":860},{},[29472],{"data":29473,"marks":29474,"value":29475,"nodeType":864},{},[],"Aug 2025",{"data":29477,"content":29478,"nodeType":4569},{},[29479],{"data":29480,"content":29481,"nodeType":860},{},[29482],{"data":29483,"marks":29484,"value":29485,"nodeType":864},{},[],"SoundCloud, GrubHub, Panera Bread, Match Group, Crunchbase, Betterment, CarMax, Edmunds, CarGurus, Hims & Hers, University of Pennsylvania, Harvard University, Optimizely, TELUS Digital, Crunchyroll, ADT",{"data":29487,"content":29488,"nodeType":4569},{},[29489],{"data":29490,"content":29491,"nodeType":860},{},[29492],{"data":29493,"marks":29494,"value":29495,"nodeType":864},{},[],"16 named victims. Confirmed individual impact includes ~30M records (SoundCloud), ~14M records (Panera), 10M+ records (Match Group), ~20M records (Betterment), 5.5M people (ADT), 1M+ records (UPenn), ~1PB stolen from TELUS Digital ($65M ransom refused).",{"data":29497,"content":29498,"nodeType":4581},{},[29499,29514,29524,29534],{"data":29500,"content":29501,"nodeType":4569},{},[29502],{"data":29503,"content":29504,"nodeType":860},{},[29505,29510],{"data":29506,"marks":29507,"value":29509,"nodeType":864},{},[29508],{"type":899},"Anodot Supply Chain",{"data":29511,"marks":29512,"value":29513,"nodeType":864},{},[]," (stolen OAuth tokens → downstream Snowflake/BigQuery access)",{"data":29515,"content":29516,"nodeType":4569},{},[29517],{"data":29518,"content":29519,"nodeType":860},{},[29520],{"data":29521,"marks":29522,"value":29523,"nodeType":864},{},[],"Apr 2026",{"data":29525,"content":29526,"nodeType":4569},{},[29527],{"data":29528,"content":29529,"nodeType":860},{},[29530],{"data":29531,"marks":29532,"value":29533,"nodeType":864},{},[],"Anodot/Glassbox (origin), Rockstar Games, Vimeo, Zara/Inditex",{"data":29535,"content":29536,"nodeType":4569},{},[29537],{"data":29538,"content":29539,"nodeType":860},{},[29540],{"data":29541,"marks":29542,"value":29543,"nodeType":864},{},[],"4 named victims (12+ total claimed). 78.6M records (Rockstar Games), 197K individuals (Zara), 119K individuals (Vimeo).",{"data":29545,"content":29546,"nodeType":4581},{},[29547,29562,29571,29581],{"data":29548,"content":29549,"nodeType":4569},{},[29550],{"data":29551,"content":29552,"nodeType":860},{},[29553,29558],{"data":29554,"marks":29555,"value":29557,"nodeType":864},{},[29556],{"type":899},"Other SLH-attributed",{"data":29559,"marks":29560,"value":29561,"nodeType":864},{},[]," (misc. vectors including infostealer chains, CI/CD supply chain, SaaS platform compromise)",{"data":29563,"content":29564,"nodeType":4569},{},[29565],{"data":29566,"content":29567,"nodeType":860},{},[29568],{"data":29569,"marks":29570,"value":29420,"nodeType":864},{},[],{"data":29572,"content":29573,"nodeType":4569},{},[29574],{"data":29575,"content":29576,"nodeType":860},{},[29577],{"data":29578,"marks":29579,"value":29580,"nodeType":864},{},[],"UK Legal Aid Agency, Mixpanel, Wynn Resorts, Woflow, Vercel, European Commission, Mercor, Medtronic, Instructure",{"data":29582,"content":29583,"nodeType":4569},{},[29584],{"data":29585,"content":29586,"nodeType":860},{},[29587],{"data":29588,"marks":29589,"value":29590,"nodeType":864},{},[],"10 named victims across varied vectors. Notable: Vercel (Lumma Stealer → Context.ai OAuth app → Google Workspace), European Commission (poisoned Trivy GitHub Action → 340GB across 71 EU entities)",{"data":29592,"content":29593,"nodeType":860},{},[29594],{"data":29595,"marks":29596,"value":21,"nodeType":864},{},[],"The three attack techniques behind ShinyHunters' 2026 campaigns ","ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture. ","analyzing-the-instructure-breach",{"items":29601},[29602,29604],{"sys":29603,"name":13779},{"id":13778},{"sys":29605,"name":342},{"id":13775},{"items":29607},[29608],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":29609},{"url":2740},{"__typename":2059,"sys":29611,"content":29613,"title":30117,"synopsis":30118,"hashTags":59,"publishedDate":30119,"slug":30120,"tagsCollection":30121,"authorsCollection":30127},{"id":29612},"2MWicW07sNEBp59wxYtAiC",{"json":29614},{"data":29615,"content":29616,"nodeType":856},{},[29617,29625,29656,29662,29669,29688,29703,29706,29714,29729,29748,29773,29779,29795,29823,29829,29835,29851,29854,29862,29869,29877,29895,29911,29918,29943,29950,29958,29987,29994,30002,30009,30015,30018,30026,30033,30041,30047,30050,30058,30065,30072,30079,30091,30094,30100],{"data":29618,"content":29619,"nodeType":1009},{},[29620],{"data":29621,"marks":29622,"value":29624,"nodeType":864},{},[29623],{"type":899},"The quantification problem nobody talks about",{"data":29626,"content":29627,"nodeType":860},{},[29628,29632,29640,29644,29652],{"data":29629,"marks":29630,"value":29631,"nodeType":864},{},[],"I was recently teaching ",{"data":29633,"content":29635,"nodeType":883},{"uri":29634},"https://www.sans.org/cyber-security-courses/cybersecurity-leaders/",[29636],{"data":29637,"marks":29638,"value":29639,"nodeType":864},{},[],"SANS LDR551",{"data":29641,"marks":29642,"value":29643,"nodeType":864},{},[],", where we cover some of the flawed approaches used in risk measurement and prioritization — for example, presenting ordinal data in a risk matrix as ratio data, implying that the matrix represents quantitative analysis when it’s more of a best guess. We then look at modeling using ",{"data":29645,"content":29647,"nodeType":883},{"uri":29646},"https://en.wikipedia.org/wiki/Loss_exceedance_curve",[29648],{"data":29649,"marks":29650,"value":29651,"nodeType":864},{},[],"Loss Exceedance Curves",{"data":29653,"marks":29654,"value":29655,"nodeType":864},{},[]," as a more accurate, if much more difficult, approach to quantitative risk assessment.",{"data":29657,"content":29661,"nodeType":996},{"target":29658},{"sys":29659},{"id":29660,"type":1001,"linkType":1002},"4S1wJUm6E1qvyZzwrl2DL",[],{"data":29663,"content":29664,"nodeType":860},{},[29665],{"data":29666,"marks":29667,"value":29668,"nodeType":864},{},[],"The only problem is, we rarely have the time or the data to construct such models. Ask a CISO how they measure risk for credential compromise and other account takeover attacks, and the answer will probably include one or more of the following: a risk assessment, a whiteboard, and a room full of smart people making educated guesses about attack frequency and control strength. ",{"data":29670,"content":29671,"nodeType":860},{},[29672,29676,29684],{"data":29673,"marks":29674,"value":29675,"nodeType":864},{},[],"That isn't a criticism — for most risk scenarios, expert elicitation is the best (and most convenient) available method. Breach cost data is sparse, threat actor behavior is unpredictable, and internal incident history is (ideally!) a limited sample. Quantitative risk frameworks like ",{"data":29677,"content":29679,"nodeType":883},{"uri":29678},"https://www.fairinstitute.org/",[29680],{"data":29681,"marks":29682,"value":29683,"nodeType":864},{},[],"FAIR",{"data":29685,"marks":29686,"value":29687,"nodeType":864},{},[]," give structure to that uncertainty, but they can't conjure data that just doesn't exist.",{"data":29689,"content":29690,"nodeType":860},{},[29691,29695,29700],{"data":29692,"marks":29693,"value":29694,"nodeType":864},{},[],"The results are usually estimates with wide confidence intervals and loss distributions that appear precise, but are hard to defend to a CFO or a board. Finance leaders have seen Monte Carlo simulations before; the capable ones will challenge the quality of the outputs if they doubt the quality of the inputs. ",{"data":29696,"marks":29697,"value":29699,"nodeType":864},{},[29698],{"type":899},"But with the right telemetry, we can get both",{"data":29701,"marks":29702,"value":2924,"nodeType":864},{},[],{"data":29704,"content":29705,"nodeType":1005},{},[],{"data":29707,"content":29708,"nodeType":1009},{},[29709],{"data":29710,"marks":29711,"value":29713,"nodeType":864},{},[29712],{"type":899},"Why the identity attack surface is uniquely measurable",{"data":29715,"content":29716,"nodeType":860},{},[29717,29721,29726],{"data":29718,"marks":29719,"value":29720,"nodeType":864},{},[],"We've written extensively about the shift to identity as a primary attack vector — and the evidence continues to stack up. Credential phishing, device code phishing, ClickFix, adversary-in-the-middle attacks, session hijacking, and SaaS account compromise now account for the majority of breach entry points in most enterprise environments. But the silver lining here is that this shift has created something valuable for risk quantification: ",{"data":29722,"marks":29723,"value":29725,"nodeType":864},{},[29724],{"type":2246},"a highly observable threat surface",{"data":29727,"marks":29728,"value":2924,"nodeType":864},{},[],{"data":29730,"content":29731,"nodeType":860},{},[29732,29736,29744],{"data":29733,"marks":29734,"value":29735,"nodeType":864},{},[],"Identity attacks execute ",{"data":29737,"content":29738,"nodeType":883},{"uri":7549},[29739],{"data":29740,"marks":29741,"value":29743,"nodeType":864},{},[29742],{"type":1455},"in the browser",{"data":29745,"marks":29746,"value":29747,"nodeType":864},{},[],". They leave traces in authentication flows, login behaviors, OAuth integrations, extension activity, and SaaS access patterns — all of which are captured in real time by the Push extension. Unlike network or endpoint attacks, where the signal is often binary and retroactive, browser-based identity threats generate continuous, high-frequency telemetry that maps directly onto the inputs that drive quantitative risk models.",{"data":29749,"content":29750,"nodeType":860},{},[29751,29755,29760,29764,29769],{"data":29752,"marks":29753,"value":29754,"nodeType":864},{},[],"This telemetry directly informs the hardest inputs in any quantitative risk model. One is ",{"data":29756,"marks":29757,"value":29759,"nodeType":864},{},[29758],{"type":899},"Threat Event Frequency (TEF)",{"data":29761,"marks":29762,"value":29763,"nodeType":864},{},[],": how often a threat agent acts against an asset in a given period. For identity risks, this can be answered in how many credential phishing attempts reached your users across all delivery channels (social media, email, malvertising, etc.), or how frequently your users authorize malicious or compromised SaaS apps. Browser-level telemetry can answer these questions with ",{"data":29765,"marks":29766,"value":29768,"nodeType":864},{},[29767],{"type":2246},"observed",{"data":29770,"marks":29771,"value":29772,"nodeType":864},{},[]," data rather than industry lookups and general benchmarks. ",{"data":29774,"content":29778,"nodeType":996},{"target":29775},{"sys":29776},{"id":29777,"type":1001,"linkType":1002},"EvjT68MCWW7nz5q86xe8S",[],{"data":29780,"content":29781,"nodeType":860},{},[29782,29786,29791],{"data":29783,"marks":29784,"value":29785,"nodeType":864},{},[],"The other input to risk modeling that's difficult to express in concrete terms is ",{"data":29787,"marks":29788,"value":29790,"nodeType":864},{},[29789],{"type":899},"vulnerability",{"data":29792,"marks":29793,"value":29794,"nodeType":864},{},[],": the probability a threat becomes a loss event or, more specifically, how likely it is that your controls will fail. ",{"data":29796,"content":29797,"nodeType":860},{},[29798,29802,29809,29813,29820],{"data":29799,"marks":29800,"value":29801,"nodeType":864},{},[],"This is where browser telemetry gets especially concrete. ",{"data":29803,"content":29804,"nodeType":883},{"uri":25338},[29805],{"data":29806,"marks":29807,"value":29808,"nodeType":864},{},[],"Analysis of login telemetry across Push-monitored environments",{"data":29810,"marks":29811,"value":29812,"nodeType":864},{},[]," shows that 1 in 4 logins are still password-only (not SSO), 2 in 5 are not protected by MFA, and 1 in 5 use a weak, breached, or reused password. Many of these logins occur outside the visibility of a central IdP platform like Microsoft, Google or Okta — the result of downstream ",{"data":29814,"content":29815,"nodeType":883},{"uri":11813},[29816],{"data":29817,"marks":29818,"value":29819,"nodeType":864},{},[],"ghost logins",{"data":29821,"marks":29822,"value":1774,"nodeType":864},{},[],{"data":29824,"content":29828,"nodeType":996},{"target":29825},{"sys":29826},{"id":29827,"type":1001,"linkType":1002},"5GctExdVGjHRwKifiP00Fp",[],{"data":29830,"content":29834,"nodeType":996},{"target":29831},{"sys":29832},{"id":29833,"type":1001,"linkType":1002},"2mWToHCJcuB9FMwxxzd67F",[],{"data":29836,"content":29837,"nodeType":860},{},[29838,29842,29847],{"data":29839,"marks":29840,"value":29841,"nodeType":864},{},[],"In a FAIR-based model, TEF and vulnerability together determine ",{"data":29843,"marks":29844,"value":29846,"nodeType":864},{},[29845],{"type":899},"loss event frequency",{"data":29848,"marks":29849,"value":29850,"nodeType":864},{},[],": the foundational driver of the entire risk calculation. Using telemetry from your own environment as the basis for these calculations makes them far more accurate, and more likely to stand up to scrutiny.",{"data":29852,"content":29853,"nodeType":1005},{},[],{"data":29855,"content":29856,"nodeType":1009},{},[29857],{"data":29858,"marks":29859,"value":29861,"nodeType":864},{},[29860],{"type":899},"The attack surface is bigger than most models assume",{"data":29863,"content":29864,"nodeType":860},{},[29865],{"data":29866,"marks":29867,"value":29868,"nodeType":864},{},[],"One of the consistent failures in identity risk modeling is the tendency to model risks defenders can see, and leave the rest off the balance sheet. These omissions create a systematic understatement of exposure that browser-based telemetry can offset.",{"data":29870,"content":29871,"nodeType":1312},{},[29872],{"data":29873,"marks":29874,"value":29876,"nodeType":864},{},[29875],{"type":899},"Shadow AI and OAuth sprawl",{"data":29878,"content":29879,"nodeType":860},{},[29880,29883,29891],{"data":29881,"marks":29882,"value":21,"nodeType":864},{},[],{"data":29884,"content":29885,"nodeType":883},{"uri":4103},[29886],{"data":29887,"marks":29888,"value":29890,"nodeType":864},{},[29889],{"type":1455},"The Vercel breach in April 2026",{"data":29892,"marks":29893,"value":29894,"nodeType":864},{},[]," was the result of an OAuth connection to a third-party AI SaaS tool a developer connected into the organization's Google Workspace tenant (without admin approval). When the AI vendor was compromised, the attacker leveraged stored OAuth tokens to access downstream accounts, ultimately reaching internal dashboards, API keys, and source code. ",{"data":29896,"content":29897,"nodeType":860},{},[29898,29902,29907],{"data":29899,"marks":29900,"value":29901,"nodeType":864},{},[],"Push telemetry across customer environments shows an average of ",{"data":29903,"marks":29904,"value":29906,"nodeType":864},{},[29905],{"type":899},"17 unique AI app integrations per organization in Microsoft and Google alone",{"data":29908,"marks":29909,"value":29910,"nodeType":864},{},[],", most of which security teams would describe as unapproved. These generally don't appear in a conventional risk model that isn't looking for them.",{"data":29912,"content":29913,"nodeType":1312},{},[29914],{"data":29915,"marks":29916,"value":288,"nodeType":864},{},[29917],{"type":899},{"data":29919,"content":29920,"nodeType":860},{},[29921,29925,29934,29939],{"data":29922,"marks":29923,"value":21,"nodeType":864},{},[29924],{"type":899},{"data":29926,"content":29927,"nodeType":883},{"uri":2411},[29928],{"data":29929,"marks":29930,"value":29933,"nodeType":864},{},[29931,29932],{"type":1455},{"type":899},"Analysis of 20,000 unique extensions deployed across Push customer environments",{"data":29935,"marks":29936,"value":29938,"nodeType":864},{},[29937],{"type":899}," found that 46.76% have the permission combinations required for account takeover without user interaction. ",{"data":29940,"marks":29941,"value":29942,"nodeType":864},{},[],"The extensions carrying these permissions aren't flagged by risk scoring systems because the same permissions are used by ad blockers, password managers, and translation tools (the downside of relying on tools that rely on dubious scoring to assess extensions, but I digress). ",{"data":29944,"content":29945,"nodeType":860},{},[29946],{"data":29947,"marks":29948,"value":29949,"nodeType":864},{},[],"What matters for risk quantification isn't the permission set or an arbitrary score assigned by a vendor; it's whether the monitoring exists to detect when a previously-clean extension changes ownership, escalates permissions, or behaves anomalously. Without that monitoring, the exposure is real but unquantified.",{"data":29951,"content":29952,"nodeType":1312},{},[29953],{"data":29954,"marks":29955,"value":29957,"nodeType":864},{},[29956],{"type":899},"ClickFix and non-email delivery channels",{"data":29959,"content":29960,"nodeType":860},{},[29961,29965,29972,29976,29983],{"data":29962,"marks":29963,"value":29964,"nodeType":864},{},[],"ClickFix — where a malicious page silently writes a PowerShell or mshta command into the victim's clipboard and instructs them to paste it — was ",{"data":29966,"content":29967,"nodeType":883},{"uri":13427},[29968],{"data":29969,"marks":29970,"value":29971,"nodeType":864},{},[],"the most common initial access vector observed by Microsoft in 2025",{"data":29973,"marks":29974,"value":29975,"nodeType":864},{},[],", and CrowdStrike reported a",{"data":29977,"content":29978,"nodeType":883},{"uri":3237},[29979],{"data":29980,"marks":29981,"value":29982,"nodeType":864},{},[]," 563% increase in fake CAPTCHA lures",{"data":29984,"marks":29985,"value":29986,"nodeType":864},{},[]," (one of the most common ClickFix styles in which the user has to \"verify they're human\" by running a command on their machine). ",{"data":29988,"content":29989,"nodeType":860},{},[29990],{"data":29991,"marks":29992,"value":29993,"nodeType":864},{},[],"What makes this particularly relevant for risk quantification is the delivery channel: 4 in 5 ClickFix payloads intercepted by Push arrive via search engines, not email. A risk model that estimates threat event frequency from email-based phishing telemetry alone is structurally blind to an entire category of attack that has become one of the most prevalent initial access methods in the landscape.",{"data":29995,"content":29996,"nodeType":1312},{},[29997],{"data":29998,"marks":29999,"value":30001,"nodeType":864},{},[30000],{"type":899},"Authorization attacks",{"data":30003,"content":30004,"nodeType":860},{},[30005],{"data":30006,"marks":30007,"value":30008,"nodeType":864},{},[],"Device code phishing and OAuth consent abuse represent a slightly separate category of identity attack that most risk models don't account for because they operate after the authentication flow has already completed — meaning password strength, MFA coverage, and SSO adoption are irrelevant to whether the attack succeeds. ",{"data":30010,"content":30014,"nodeType":996},{"target":30011},{"sys":30012},{"id":30013,"type":1001,"linkType":1002},"7qtHmxCzBm5664jD6HsCwN",[],{"data":30016,"content":30017,"nodeType":1005},{},[],{"data":30019,"content":30020,"nodeType":1009},{},[30021],{"data":30022,"marks":30023,"value":30025,"nodeType":864},{},[30024],{"type":899},"The key lesson for CISOs",{"data":30027,"content":30028,"nodeType":860},{},[30029],{"data":30030,"marks":30031,"value":30032,"nodeType":864},{},[],"A risk model that measures identity vulnerability purely in terms of authentication hygiene at the IdP layer — how many accounts have MFA, how many use SSO — will correctly quantify one dimension of exposure while completely missing another that is growing faster and is structurally immune to the controls being measured.",{"data":30034,"content":30035,"nodeType":860},{},[30036],{"data":30037,"marks":30038,"value":30040,"nodeType":864},{},[30039],{"type":899},"For a CISO building a risk model, these aren't edge cases. They represent a real attack surface that doesn't show up in models built on conventional network, endpoint, and cloud telemetry. We aren't just talking about better inputs to risk modeling — we're talking about entirely new risk scenarios that aren't being modeled at all, supported by live data.",{"data":30042,"content":30046,"nodeType":996},{"target":30043},{"sys":30044},{"id":30045,"type":1001,"linkType":1002},"2ObEcO1gqz8lrOLCZzfpNw",[],{"data":30048,"content":30049,"nodeType":1005},{},[],{"data":30051,"content":30052,"nodeType":1312},{},[30053],{"data":30054,"marks":30055,"value":30057,"nodeType":864},{},[30056],{"type":899},"Browser telemetry makes a CISO's life easier",{"data":30059,"content":30060,"nodeType":860},{},[30061],{"data":30062,"marks":30063,"value":30064,"nodeType":864},{},[],"Browser-based telemetry changes the conversation a CISO can have with a CFO or board. Instead of \"industry benchmarks suggest our expected annual loss from account compromise is somewhere in this range,\" the answer is, \"We can see how often these attacks are attempted against our users, and we can measure what percentage of our accounts have the controls in place to stop them,\" or \"We know how many shadow AI apps our users self-provision and share data with each month.\" ",{"data":30066,"content":30067,"nodeType":860},{},[30068],{"data":30069,"marks":30070,"value":30071,"nodeType":864},{},[],"Identity risk is only a piece of the quantification problem. Loss magnitude, regulatory exposure, and reputational impact are still extremely hard to estimate regardless of how good your frequency inputs are. ",{"data":30073,"content":30074,"nodeType":860},{},[30075],{"data":30076,"marks":30077,"value":30078,"nodeType":864},{},[],"But the identity attack surface is one of the few areas in security where measurement is genuinely achievable right now, and the gap between what most organizations are modeling and what's actually observable is significant. Shadow SaaS integrations, unapproved AI connections, browser extensions with excessive privileges — these are enumerable risks that don't appear in models built on network, endpoint, and cloud access telemetry alone. ",{"data":30080,"content":30081,"nodeType":860},{},[30082,30087],{"data":30083,"marks":30084,"value":30086,"nodeType":864},{},[30085],{"type":899},"The lesson for CISOs serious about quantitative risk management is this: the frameworks exist, the talent is available, and the bottleneck is almost always data quality. ",{"data":30088,"marks":30089,"value":30090,"nodeType":864},{},[],"Browser telemetry is a good example of the kind of high-fidelity, environment-specific measurement that closes that gap.",{"data":30092,"content":30093,"nodeType":1005},{},[],{"data":30095,"content":30096,"nodeType":860},{},[30097],{"data":30098,"marks":30099,"value":4855,"nodeType":864},{},[],{"data":30101,"content":30102,"nodeType":860},{},[30103,30107,30114],{"data":30104,"marks":30105,"value":30106,"nodeType":864},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see. ",{"data":30108,"content":30110,"nodeType":883},{"uri":30109},"https://pushsecurity.com/book-demo/",[30111],{"data":30112,"marks":30113,"value":13763,"nodeType":864},{},[],{"data":30115,"marks":30116,"value":2719,"nodeType":864},{},[],"The CISO's data problem (and how browser telemetry can help)","How CISOs can use browser telemetry to support cyber risk quantification in areas where traditional data points fall short. ","2026-05-11T00:00:00.000Z","the-cisos-data-problem-and-how-browser-telemetry-can-help",{"items":30122},[30123,30125],{"sys":30124,"name":2729},{"id":2728},{"sys":30126,"name":342},{"id":13775},{"items":30128},[30129],{"fullName":3621,"firstName":3622,"jobTitle":3623,"profilePicture":30130},{"url":3625},"verizon-dbir-2026-review","blog/verizon-dbir-2026-review",{"json":30134},{"data":30135,"content":30136,"nodeType":856},{},[30137],{"data":30138,"content":30139,"nodeType":860},{},[30140],{"data":30141,"marks":30142,"value":30143,"nodeType":864},{},[],"Verizon's 2026 Data Breach Investigations Report landed this week with the largest dataset in the report's 19-year history — more than 22,000 confirmed breaches across 145 countries, nearly double last year's count.","What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.",{"id":30146,"publishedAt":30147},"7sZs2lHCTN8oYc2OIGCIQG","2026-08-12T12:00:55.865Z",{"items":30149},[30150,30152],{"sys":30151,"name":297},{"id":2732},{"sys":30153,"name":13779},{"id":13778},{"items":30155},[30156,30158,30160,30162,30164,30166,30168,30170,30172,30174,30176,30178,30180,30182,30184,30186,30188,30190,30192,30194,30196,30198,30200,30202],{"sys":30157,"name":279,"slug":280,"tier":31},{"id":276},{"sys":30159,"name":413,"slug":414,"tier":31},{"id":410},{"sys":30161,"name":642,"slug":643,"tier":31},{"id":639},{"sys":30163,"name":519,"slug":520,"tier":31},{"id":516},{"sys":30165,"name":297,"slug":298,"tier":31},{"id":294},{"sys":30167,"name":235,"slug":236,"tier":31},{"id":232},{"sys":30169,"name":422,"slug":423,"tier":45},{"id":419},{"sys":30171,"name":315,"slug":316,"tier":45},{"id":312},{"sys":30173,"name":324,"slug":325,"tier":45},{"id":321},{"sys":30175,"name":580,"slug":581,"tier":45},{"id":577},{"sys":30177,"name":537,"slug":538,"tier":45},{"id":534},{"sys":30179,"name":633,"slug":634,"tier":45},{"id":630},{"sys":30181,"name":261,"slug":262,"tier":45},{"id":258},{"sys":30183,"name":475,"slug":476,"tier":45},{"id":472},{"sys":30185,"name":333,"slug":334,"tier":45},{"id":330},{"sys":30187,"name":457,"slug":458,"tier":45},{"id":454},{"sys":30189,"name":288,"slug":289,"tier":45},{"id":285},{"sys":30191,"name":252,"slug":253,"tier":45},{"id":249},{"sys":30193,"name":607,"slug":608,"tier":45},{"id":604},{"sys":30195,"name":650,"slug":651,"tier":45},{"id":647},{"sys":30197,"name":244,"slug":245,"tier":45},{"id":241},{"sys":30199,"name":368,"slug":369,"tier":45},{"id":365},{"sys":30201,"name":571,"slug":572,"tier":45},{"id":568},{"sys":30203,"name":484,"slug":485,"tier":45},{"id":481},"hcNrtVGANdYvnes1Z8X1g9b6b_dm694k5qOhLd1GfaI",{"id":30206,"title":25511,"authorsCollection":30207,"content":30212,"extension":228,"faqItemsCollection":30757,"faqTitle":59,"featured":6,"hashTags":59,"meta":30759,"metaTitle":30760,"ogImage":59,"postType":5726,"publishedDate":25513,"relatedBlogPostsCollection":30761,"slug":25514,"stem":33237,"subtitle":59,"summary":33238,"synopsis":25512,"sys":33248,"tagsCollection":33250,"topicsCollection":33256,"__hash__":33298},"blog/blog/the-case-for-best-of-breed-browser-security.json",{"items":30208},[30209],{"fullName":4878,"firstName":4879,"jobTitle":851,"socialLinks":30210,"profilePicture":30211},[24316],{"url":4881},{"json":30213,"links":30701},{"data":30214,"content":30215,"nodeType":856},{},[30216,30222,30246,30252,30255,30262,30268,30274,30280,30287,30330,30336,30343,30349,30355,30362,30368,30374,30390,30415,30421,30424,30431,30438,30453,30460,30476,30483,30489,30496,30502,30509,30515,30518,30525,30531,30541,30556,30563,30569,30574,30581,30614,30619,30626,30641,30648,30663,30666,30673,30679,30685],{"data":30217,"content":30218,"nodeType":860},{},[30219],{"data":30220,"marks":30221,"value":24954,"nodeType":864},{},[],{"data":30223,"content":30224,"nodeType":860},{},[30225,30228,30234,30237,30243],{"data":30226,"marks":30227,"value":24961,"nodeType":864},{},[],{"data":30229,"content":30230,"nodeType":883},{"uri":2561},[30231],{"data":30232,"marks":30233,"value":24968,"nodeType":864},{},[],{"data":30235,"marks":30236,"value":2232,"nodeType":864},{},[],{"data":30238,"content":30239,"nodeType":883},{"uri":2561},[30240],{"data":30241,"marks":30242,"value":24978,"nodeType":864},{},[],{"data":30244,"marks":30245,"value":2924,"nodeType":864},{},[],{"data":30247,"content":30248,"nodeType":860},{},[30249],{"data":30250,"marks":30251,"value":24988,"nodeType":864},{},[],{"data":30253,"content":30254,"nodeType":1005},{},[],{"data":30256,"content":30257,"nodeType":1009},{},[30258],{"data":30259,"marks":30260,"value":24999,"nodeType":864},{},[30261],{"type":899},{"data":30263,"content":30264,"nodeType":860},{},[30265],{"data":30266,"marks":30267,"value":25006,"nodeType":864},{},[],{"data":30269,"content":30270,"nodeType":860},{},[30271],{"data":30272,"marks":30273,"value":25013,"nodeType":864},{},[],{"data":30275,"content":30276,"nodeType":860},{},[30277],{"data":30278,"marks":30279,"value":25020,"nodeType":864},{},[],{"data":30281,"content":30282,"nodeType":1312},{},[30283],{"data":30284,"marks":30285,"value":25028,"nodeType":864},{},[30286],{"type":899},{"data":30288,"content":30289,"nodeType":860},{},[30290,30293,30300,30303,30309,30312,30318,30321,30327],{"data":30291,"marks":30292,"value":21,"nodeType":864},{},[],{"data":30294,"content":30295,"nodeType":883},{"uri":25037},[30296],{"data":30297,"marks":30298,"value":25043,"nodeType":864},{},[30299],{"type":1455},{"data":30301,"marks":30302,"value":25047,"nodeType":864},{},[],{"data":30304,"content":30305,"nodeType":883},{"uri":25050},[30306],{"data":30307,"marks":30308,"value":25055,"nodeType":864},{},[],{"data":30310,"marks":30311,"value":25059,"nodeType":864},{},[],{"data":30313,"content":30314,"nodeType":883},{"uri":25062},[30315],{"data":30316,"marks":30317,"value":25067,"nodeType":864},{},[],{"data":30319,"marks":30320,"value":25071,"nodeType":864},{},[],{"data":30322,"content":30323,"nodeType":883},{"uri":4082},[30324],{"data":30325,"marks":30326,"value":25078,"nodeType":864},{},[],{"data":30328,"marks":30329,"value":25082,"nodeType":864},{},[],{"data":30331,"content":30332,"nodeType":860},{},[30333],{"data":30334,"marks":30335,"value":25089,"nodeType":864},{},[],{"data":30337,"content":30338,"nodeType":1312},{},[30339],{"data":30340,"marks":30341,"value":25097,"nodeType":864},{},[30342],{"type":899},{"data":30344,"content":30345,"nodeType":860},{},[30346],{"data":30347,"marks":30348,"value":25104,"nodeType":864},{},[],{"data":30350,"content":30351,"nodeType":860},{},[30352],{"data":30353,"marks":30354,"value":25111,"nodeType":864},{},[],{"data":30356,"content":30357,"nodeType":1312},{},[30358],{"data":30359,"marks":30360,"value":25119,"nodeType":864},{},[30361],{"type":899},{"data":30363,"content":30364,"nodeType":860},{},[30365],{"data":30366,"marks":30367,"value":25126,"nodeType":864},{},[],{"data":30369,"content":30370,"nodeType":860},{},[30371],{"data":30372,"marks":30373,"value":25133,"nodeType":864},{},[],{"data":30375,"content":30376,"nodeType":860},{},[30377,30380,30387],{"data":30378,"marks":30379,"value":25140,"nodeType":864},{},[],{"data":30381,"content":30382,"nodeType":883},{"uri":3259},[30383],{"data":30384,"marks":30385,"value":25148,"nodeType":864},{},[30386],{"type":1455},{"data":30388,"marks":30389,"value":25152,"nodeType":864},{},[],{"data":30391,"content":30392,"nodeType":860},{},[30393,30396,30402,30405,30412],{"data":30394,"marks":30395,"value":25159,"nodeType":864},{},[],{"data":30397,"content":30398,"nodeType":883},{"uri":2561},[30399],{"data":30400,"marks":30401,"value":25166,"nodeType":864},{},[],{"data":30403,"marks":30404,"value":25170,"nodeType":864},{},[],{"data":30406,"content":30407,"nodeType":883},{"uri":25173},[30408],{"data":30409,"marks":30410,"value":25179,"nodeType":864},{},[30411],{"type":1455},{"data":30413,"marks":30414,"value":25183,"nodeType":864},{},[],{"data":30416,"content":30417,"nodeType":860},{},[30418],{"data":30419,"marks":30420,"value":25190,"nodeType":864},{},[],{"data":30422,"content":30423,"nodeType":1005},{},[],{"data":30425,"content":30426,"nodeType":1009},{},[30427],{"data":30428,"marks":30429,"value":25201,"nodeType":864},{},[30430],{"type":899},{"data":30432,"content":30433,"nodeType":1312},{},[30434],{"data":30435,"marks":30436,"value":25209,"nodeType":864},{},[30437],{"type":899},{"data":30439,"content":30440,"nodeType":860},{},[30441,30444,30450],{"data":30442,"marks":30443,"value":25216,"nodeType":864},{},[],{"data":30445,"content":30446,"nodeType":883},{"uri":11640},[30447],{"data":30448,"marks":30449,"value":25223,"nodeType":864},{},[],{"data":30451,"marks":30452,"value":25227,"nodeType":864},{},[],{"data":30454,"content":30455,"nodeType":1312},{},[30456],{"data":30457,"marks":30458,"value":25235,"nodeType":864},{},[30459],{"type":899},{"data":30461,"content":30462,"nodeType":860},{},[30463,30466,30473],{"data":30464,"marks":30465,"value":25242,"nodeType":864},{},[],{"data":30467,"content":30468,"nodeType":883},{"uri":13094},[30469],{"data":30470,"marks":30471,"value":25250,"nodeType":864},{},[30472],{"type":1455},{"data":30474,"marks":30475,"value":25254,"nodeType":864},{},[],{"data":30477,"content":30478,"nodeType":1312},{},[30479],{"data":30480,"marks":30481,"value":25262,"nodeType":864},{},[30482],{"type":899},{"data":30484,"content":30485,"nodeType":860},{},[30486],{"data":30487,"marks":30488,"value":25269,"nodeType":864},{},[],{"data":30490,"content":30491,"nodeType":1312},{},[30492],{"data":30493,"marks":30494,"value":25277,"nodeType":864},{},[30495],{"type":899},{"data":30497,"content":30498,"nodeType":860},{},[30499],{"data":30500,"marks":30501,"value":25284,"nodeType":864},{},[],{"data":30503,"content":30504,"nodeType":1312},{},[30505],{"data":30506,"marks":30507,"value":25292,"nodeType":864},{},[30508],{"type":899},{"data":30510,"content":30511,"nodeType":860},{},[30512],{"data":30513,"marks":30514,"value":25299,"nodeType":864},{},[],{"data":30516,"content":30517,"nodeType":1005},{},[],{"data":30519,"content":30520,"nodeType":1009},{},[30521],{"data":30522,"marks":30523,"value":25310,"nodeType":864},{},[30524],{"type":899},{"data":30526,"content":30527,"nodeType":860},{},[30528],{"data":30529,"marks":30530,"value":25317,"nodeType":864},{},[],{"data":30532,"content":30533,"nodeType":1312},{},[30534,30538],{"data":30535,"marks":30536,"value":25325,"nodeType":864},{},[30537],{"type":899},{"data":30539,"marks":30540,"value":1171,"nodeType":864},{},[],{"data":30542,"content":30543,"nodeType":860},{},[30544,30547,30553],{"data":30545,"marks":30546,"value":25335,"nodeType":864},{},[],{"data":30548,"content":30549,"nodeType":883},{"uri":25338},[30550],{"data":30551,"marks":30552,"value":25343,"nodeType":864},{},[],{"data":30554,"marks":30555,"value":25347,"nodeType":864},{},[],{"data":30557,"content":30558,"nodeType":1312},{},[30559],{"data":30560,"marks":30561,"value":25355,"nodeType":864},{},[30562],{"type":899},{"data":30564,"content":30565,"nodeType":860},{},[30566],{"data":30567,"marks":30568,"value":25362,"nodeType":864},{},[],{"data":30570,"content":30573,"nodeType":996},{"target":30571},{"sys":30572},{"id":25367,"type":1001,"linkType":1002},[],{"data":30575,"content":30576,"nodeType":1312},{},[30577],{"data":30578,"marks":30579,"value":25376,"nodeType":864},{},[30580],{"type":899},{"data":30582,"content":30583,"nodeType":860},{},[30584,30587,30593,30596,30602,30605,30611],{"data":30585,"marks":30586,"value":25383,"nodeType":864},{},[],{"data":30588,"content":30589,"nodeType":883},{"uri":11726},[30590],{"data":30591,"marks":30592,"value":11731,"nodeType":864},{},[],{"data":30594,"marks":30595,"value":902,"nodeType":864},{},[],{"data":30597,"content":30598,"nodeType":883},{"uri":11738},[30599],{"data":30600,"marks":30601,"value":19059,"nodeType":864},{},[],{"data":30603,"marks":30604,"value":25402,"nodeType":864},{},[],{"data":30606,"content":30607,"nodeType":883},{"uri":7572},[30608],{"data":30609,"marks":30610,"value":7578,"nodeType":864},{},[],{"data":30612,"marks":30613,"value":25412,"nodeType":864},{},[],{"data":30615,"content":30618,"nodeType":996},{"target":30616},{"sys":30617},{"id":25417,"type":1001,"linkType":1002},[],{"data":30620,"content":30621,"nodeType":1312},{},[30622],{"data":30623,"marks":30624,"value":25426,"nodeType":864},{},[30625],{"type":899},{"data":30627,"content":30628,"nodeType":860},{},[30629,30632,30638],{"data":30630,"marks":30631,"value":25433,"nodeType":864},{},[],{"data":30633,"content":30634,"nodeType":883},{"uri":11640},[30635],{"data":30636,"marks":30637,"value":25440,"nodeType":864},{},[],{"data":30639,"marks":30640,"value":2924,"nodeType":864},{},[],{"data":30642,"content":30643,"nodeType":1312},{},[30644],{"data":30645,"marks":30646,"value":25451,"nodeType":864},{},[30647],{"type":899},{"data":30649,"content":30650,"nodeType":860},{},[30651,30654,30660],{"data":30652,"marks":30653,"value":25458,"nodeType":864},{},[],{"data":30655,"content":30656,"nodeType":883},{"uri":11674},[30657],{"data":30658,"marks":30659,"value":25465,"nodeType":864},{},[],{"data":30661,"marks":30662,"value":25469,"nodeType":864},{},[],{"data":30664,"content":30665,"nodeType":1005},{},[],{"data":30667,"content":30668,"nodeType":1009},{},[30669],{"data":30670,"marks":30671,"value":25480,"nodeType":864},{},[30672],{"type":899},{"data":30674,"content":30675,"nodeType":860},{},[30676],{"data":30677,"marks":30678,"value":25487,"nodeType":864},{},[],{"data":30680,"content":30681,"nodeType":860},{},[30682],{"data":30683,"marks":30684,"value":25494,"nodeType":864},{},[],{"data":30686,"content":30687,"nodeType":860},{},[30688,30691,30698],{"data":30689,"marks":30690,"value":21,"nodeType":864},{},[],{"data":30692,"content":30693,"nodeType":883},{"uri":1700},[30694],{"data":30695,"marks":30696,"value":1703,"nodeType":864},{},[30697],{"type":1455},{"data":30699,"marks":30700,"value":21,"nodeType":864},{},[],{"entries":30702},{"hyperlink":30703,"inline":30704,"block":30705},[],[],[30706,30724],{"sys":30707,"__typename":1740,"content":30708,"name":30723,"title":59},{"id":25367},{"json":30709},{"nodeType":856,"data":30710,"content":30711},{},[30712],{"nodeType":860,"data":30713,"content":30714},{},[30715,30720],{"nodeType":864,"value":30716,"marks":30717,"data":30719},"In a 30-day POV at a ~4,500-employee financial services organization with a mature existing stack, Push detected 6 ClickFix attacks and 10 AiTM phishing attempts that were invisible to every other tool in place",[30718],{"type":899},{},{"nodeType":864,"value":2924,"marks":30721,"data":30722},[],{},"Best of breed blog IB1",{"sys":30725,"__typename":1740,"content":30726,"name":30756,"title":59},{"id":25417},{"json":30727},{"nodeType":856,"data":30728,"content":30729},{},[30730],{"nodeType":860,"data":30731,"content":30732},{},[30733,30737,30743,30747,30752],{"nodeType":864,"value":30734,"marks":30735,"data":30736},"Our ",[],{},{"nodeType":883,"data":30738,"content":30739},{"uri":7572},[30740],{"nodeType":864,"value":13673,"marks":30741,"data":30742},[],{},{"nodeType":864,"value":30744,"marks":30745,"data":30746}," has ",[],{},{"nodeType":864,"value":30748,"marks":30749,"data":30751},"tripled the new detections shipped per month",[30750],{"type":899},{},{"nodeType":864,"value":30753,"marks":30754,"data":30755}," — and as a dedicated browser security vendor, that's where every research dollar goes. When attackers are harnessing AI to develop tooling, deploy and tear-down infrastructure, and operate campaigns at scale, this capability is essential to stay ahead of the increased volume and variation in threats that users are encountering in the browser. ",[],{},"Best of breed blog IB2",{"items":30758},[],{},"The case for best-of-breed browser security",{"items":30762},[30763,31435,32156],{"__typename":2059,"sys":30764,"content":30765,"title":26291,"synopsis":26292,"hashTags":59,"publishedDate":26293,"slug":26294,"tagsCollection":31425,"authorsCollection":31431},{"id":25527},{"json":30766},{"data":30767,"content":30768,"nodeType":856},{},[30769,30774,30780,30786,30792,30795,30802,30808,30818,30828,30833,30839,30842,30849,30855,30860,30866,30872,30965,30971,30974,30981,30987,31042,31055,31060,31066,31069,31076,31082,31089,31095,31101,31126,31132,31139,31145,31151,31157,31164,31170,31176,31182,31185,31192,31202,31208,31214,31221,31227,31233,31240,31246,31301,31314,31329,31336,31342,31349,31355,31361,31367,31372,31379,31385,31391,31396,31402,31408,31414,31419],{"data":30770,"content":30773,"nodeType":996},{"target":30771},{"sys":30772},{"id":25536,"type":1001,"linkType":1002},[],{"data":30775,"content":30776,"nodeType":860},{},[30777],{"data":30778,"marks":30779,"value":25544,"nodeType":864},{},[],{"data":30781,"content":30782,"nodeType":860},{},[30783],{"data":30784,"marks":30785,"value":25551,"nodeType":864},{},[],{"data":30787,"content":30788,"nodeType":860},{},[30789],{"data":30790,"marks":30791,"value":25558,"nodeType":864},{},[],{"data":30793,"content":30794,"nodeType":1005},{},[],{"data":30796,"content":30797,"nodeType":1009},{},[30798],{"data":30799,"marks":30800,"value":25569,"nodeType":864},{},[30801],{"type":899},{"data":30803,"content":30804,"nodeType":860},{},[30805],{"data":30806,"marks":30807,"value":25576,"nodeType":864},{},[],{"data":30809,"content":30810,"nodeType":860},{},[30811,30815],{"data":30812,"marks":30813,"value":25584,"nodeType":864},{},[30814],{"type":899},{"data":30816,"marks":30817,"value":25588,"nodeType":864},{},[],{"data":30819,"content":30820,"nodeType":860},{},[30821,30825],{"data":30822,"marks":30823,"value":25596,"nodeType":864},{},[30824],{"type":899},{"data":30826,"marks":30827,"value":25600,"nodeType":864},{},[],{"data":30829,"content":30832,"nodeType":996},{"target":30830},{"sys":30831},{"id":23546,"type":1001,"linkType":1002},[],{"data":30834,"content":30835,"nodeType":860},{},[30836],{"data":30837,"marks":30838,"value":25612,"nodeType":864},{},[],{"data":30840,"content":30841,"nodeType":1005},{},[],{"data":30843,"content":30844,"nodeType":1009},{},[30845],{"data":30846,"marks":30847,"value":25623,"nodeType":864},{},[30848],{"type":899},{"data":30850,"content":30851,"nodeType":860},{},[30852],{"data":30853,"marks":30854,"value":25630,"nodeType":864},{},[],{"data":30856,"content":30859,"nodeType":996},{"target":30857},{"sys":30858},{"id":25635,"type":1001,"linkType":1002},[],{"data":30861,"content":30862,"nodeType":860},{},[30863],{"data":30864,"marks":30865,"value":25643,"nodeType":864},{},[],{"data":30867,"content":30868,"nodeType":860},{},[30869],{"data":30870,"marks":30871,"value":25650,"nodeType":864},{},[],{"data":30873,"content":30874,"nodeType":941},{},[30875,30891,30907,30923,30939,30952],{"data":30876,"content":30877,"nodeType":945},{},[30878],{"data":30879,"content":30880,"nodeType":860},{},[30881,30884,30888],{"data":30882,"marks":30883,"value":25663,"nodeType":864},{},[],{"data":30885,"marks":30886,"value":25055,"nodeType":864},{},[30887],{"type":899},{"data":30889,"marks":30890,"value":25671,"nodeType":864},{},[],{"data":30892,"content":30893,"nodeType":945},{},[30894],{"data":30895,"content":30896,"nodeType":860},{},[30897,30900,30904],{"data":30898,"marks":30899,"value":25681,"nodeType":864},{},[],{"data":30901,"marks":30902,"value":25686,"nodeType":864},{},[30903],{"type":899},{"data":30905,"marks":30906,"value":25690,"nodeType":864},{},[],{"data":30908,"content":30909,"nodeType":945},{},[30910],{"data":30911,"content":30912,"nodeType":860},{},[30913,30916,30920],{"data":30914,"marks":30915,"value":25700,"nodeType":864},{},[],{"data":30917,"marks":30918,"value":25705,"nodeType":864},{},[30919],{"type":899},{"data":30921,"marks":30922,"value":25709,"nodeType":864},{},[],{"data":30924,"content":30925,"nodeType":945},{},[30926],{"data":30927,"content":30928,"nodeType":860},{},[30929,30932,30936],{"data":30930,"marks":30931,"value":25719,"nodeType":864},{},[],{"data":30933,"marks":30934,"value":25724,"nodeType":864},{},[30935],{"type":899},{"data":30937,"marks":30938,"value":25728,"nodeType":864},{},[],{"data":30940,"content":30941,"nodeType":945},{},[30942],{"data":30943,"content":30944,"nodeType":860},{},[30945,30949],{"data":30946,"marks":30947,"value":18801,"nodeType":864},{},[30948],{"type":899},{"data":30950,"marks":30951,"value":25742,"nodeType":864},{},[],{"data":30953,"content":30954,"nodeType":945},{},[30955],{"data":30956,"content":30957,"nodeType":860},{},[30958,30962],{"data":30959,"marks":30960,"value":25753,"nodeType":864},{},[30961],{"type":899},{"data":30963,"marks":30964,"value":25757,"nodeType":864},{},[],{"data":30966,"content":30967,"nodeType":860},{},[30968],{"data":30969,"marks":30970,"value":25764,"nodeType":864},{},[],{"data":30972,"content":30973,"nodeType":1005},{},[],{"data":30975,"content":30976,"nodeType":1312},{},[30977],{"data":30978,"marks":30979,"value":25775,"nodeType":864},{},[30980],{"type":899},{"data":30982,"content":30983,"nodeType":860},{},[30984],{"data":30985,"marks":30986,"value":25782,"nodeType":864},{},[],{"data":30988,"content":30989,"nodeType":941},{},[30990,31003,31016,31029],{"data":30991,"content":30992,"nodeType":945},{},[30993],{"data":30994,"content":30995,"nodeType":860},{},[30996,30999],{"data":30997,"marks":30998,"value":25795,"nodeType":864},{},[],{"data":31000,"marks":31001,"value":25800,"nodeType":864},{},[31002],{"type":899},{"data":31004,"content":31005,"nodeType":945},{},[31006],{"data":31007,"content":31008,"nodeType":860},{},[31009,31012],{"data":31010,"marks":31011,"value":25810,"nodeType":864},{},[],{"data":31013,"marks":31014,"value":25815,"nodeType":864},{},[31015],{"type":899},{"data":31017,"content":31018,"nodeType":945},{},[31019],{"data":31020,"content":31021,"nodeType":860},{},[31022,31025],{"data":31023,"marks":31024,"value":25825,"nodeType":864},{},[],{"data":31026,"marks":31027,"value":25830,"nodeType":864},{},[31028],{"type":899},{"data":31030,"content":31031,"nodeType":945},{},[31032],{"data":31033,"content":31034,"nodeType":860},{},[31035,31038],{"data":31036,"marks":31037,"value":25840,"nodeType":864},{},[],{"data":31039,"marks":31040,"value":25845,"nodeType":864},{},[31041],{"type":899},{"data":31043,"content":31044,"nodeType":860},{},[31045,31048,31052],{"data":31046,"marks":31047,"value":25852,"nodeType":864},{},[],{"data":31049,"marks":31050,"value":25857,"nodeType":864},{},[31051],{"type":899},{"data":31053,"marks":31054,"value":25861,"nodeType":864},{},[],{"data":31056,"content":31059,"nodeType":996},{"target":31057},{"sys":31058},{"id":25866,"type":1001,"linkType":1002},[],{"data":31061,"content":31062,"nodeType":860},{},[31063],{"data":31064,"marks":31065,"value":25874,"nodeType":864},{},[],{"data":31067,"content":31068,"nodeType":1005},{},[],{"data":31070,"content":31071,"nodeType":1009},{},[31072],{"data":31073,"marks":31074,"value":25885,"nodeType":864},{},[31075],{"type":899},{"data":31077,"content":31078,"nodeType":860},{},[31079],{"data":31080,"marks":31081,"value":25892,"nodeType":864},{},[],{"data":31083,"content":31084,"nodeType":1312},{},[31085],{"data":31086,"marks":31087,"value":25900,"nodeType":864},{},[31088],{"type":899},{"data":31090,"content":31091,"nodeType":860},{},[31092],{"data":31093,"marks":31094,"value":25907,"nodeType":864},{},[],{"data":31096,"content":31097,"nodeType":860},{},[31098],{"data":31099,"marks":31100,"value":25914,"nodeType":864},{},[],{"data":31102,"content":31103,"nodeType":860},{},[31104,31107,31113,31116,31123],{"data":31105,"marks":31106,"value":25921,"nodeType":864},{},[],{"data":31108,"content":31109,"nodeType":883},{"uri":2561},[31110],{"data":31111,"marks":31112,"value":25928,"nodeType":864},{},[],{"data":31114,"marks":31115,"value":25932,"nodeType":864},{},[],{"data":31117,"content":31118,"nodeType":883},{"uri":16203},[31119],{"data":31120,"marks":31121,"value":25940,"nodeType":864},{},[31122],{"type":1455},{"data":31124,"marks":31125,"value":25944,"nodeType":864},{},[],{"data":31127,"content":31128,"nodeType":860},{},[31129],{"data":31130,"marks":31131,"value":25951,"nodeType":864},{},[],{"data":31133,"content":31134,"nodeType":1312},{},[31135],{"data":31136,"marks":31137,"value":25959,"nodeType":864},{},[31138],{"type":899},{"data":31140,"content":31141,"nodeType":860},{},[31142],{"data":31143,"marks":31144,"value":25966,"nodeType":864},{},[],{"data":31146,"content":31147,"nodeType":860},{},[31148],{"data":31149,"marks":31150,"value":25973,"nodeType":864},{},[],{"data":31152,"content":31153,"nodeType":860},{},[31154],{"data":31155,"marks":31156,"value":25980,"nodeType":864},{},[],{"data":31158,"content":31159,"nodeType":1312},{},[31160],{"data":31161,"marks":31162,"value":25988,"nodeType":864},{},[31163],{"type":899},{"data":31165,"content":31166,"nodeType":860},{},[31167],{"data":31168,"marks":31169,"value":25995,"nodeType":864},{},[],{"data":31171,"content":31172,"nodeType":860},{},[31173],{"data":31174,"marks":31175,"value":26002,"nodeType":864},{},[],{"data":31177,"content":31178,"nodeType":860},{},[31179],{"data":31180,"marks":31181,"value":26009,"nodeType":864},{},[],{"data":31183,"content":31184,"nodeType":1005},{},[],{"data":31186,"content":31187,"nodeType":1009},{},[31188],{"data":31189,"marks":31190,"value":26020,"nodeType":864},{},[31191],{"type":899},{"data":31193,"content":31194,"nodeType":860},{},[31195,31199],{"data":31196,"marks":31197,"value":26028,"nodeType":864},{},[31198],{"type":899},{"data":31200,"marks":31201,"value":26032,"nodeType":864},{},[],{"data":31203,"content":31204,"nodeType":860},{},[31205],{"data":31206,"marks":31207,"value":26039,"nodeType":864},{},[],{"data":31209,"content":31210,"nodeType":860},{},[31211],{"data":31212,"marks":31213,"value":26046,"nodeType":864},{},[],{"data":31215,"content":31216,"nodeType":1312},{},[31217],{"data":31218,"marks":31219,"value":26054,"nodeType":864},{},[31220],{"type":899},{"data":31222,"content":31223,"nodeType":860},{},[31224],{"data":31225,"marks":31226,"value":26061,"nodeType":864},{},[],{"data":31228,"content":31229,"nodeType":860},{},[31230],{"data":31231,"marks":31232,"value":26068,"nodeType":864},{},[],{"data":31234,"content":31235,"nodeType":1312},{},[31236],{"data":31237,"marks":31238,"value":26076,"nodeType":864},{},[31239],{"type":899},{"data":31241,"content":31242,"nodeType":860},{},[31243],{"data":31244,"marks":31245,"value":26083,"nodeType":864},{},[],{"data":31247,"content":31248,"nodeType":941},{},[31249,31262,31275,31288],{"data":31250,"content":31251,"nodeType":945},{},[31252],{"data":31253,"content":31254,"nodeType":860},{},[31255,31259],{"data":31256,"marks":31257,"value":26097,"nodeType":864},{},[31258],{"type":899},{"data":31260,"marks":31261,"value":26101,"nodeType":864},{},[],{"data":31263,"content":31264,"nodeType":945},{},[31265],{"data":31266,"content":31267,"nodeType":860},{},[31268,31272],{"data":31269,"marks":31270,"value":26112,"nodeType":864},{},[31271],{"type":899},{"data":31273,"marks":31274,"value":26116,"nodeType":864},{},[],{"data":31276,"content":31277,"nodeType":945},{},[31278],{"data":31279,"content":31280,"nodeType":860},{},[31281,31285],{"data":31282,"marks":31283,"value":26127,"nodeType":864},{},[31284],{"type":899},{"data":31286,"marks":31287,"value":26131,"nodeType":864},{},[],{"data":31289,"content":31290,"nodeType":945},{},[31291],{"data":31292,"content":31293,"nodeType":860},{},[31294,31298],{"data":31295,"marks":31296,"value":26142,"nodeType":864},{},[31297],{"type":899},{"data":31299,"marks":31300,"value":26146,"nodeType":864},{},[],{"data":31302,"content":31303,"nodeType":860},{},[31304,31307,31311],{"data":31305,"marks":31306,"value":26153,"nodeType":864},{},[],{"data":31308,"marks":31309,"value":26158,"nodeType":864},{},[31310],{"type":899},{"data":31312,"marks":31313,"value":26162,"nodeType":864},{},[],{"data":31315,"content":31316,"nodeType":860},{},[31317,31320,31326],{"data":31318,"marks":31319,"value":26169,"nodeType":864},{},[],{"data":31321,"content":31322,"nodeType":883},{"uri":3210},[31323],{"data":31324,"marks":31325,"value":26176,"nodeType":864},{},[],{"data":31327,"marks":31328,"value":26180,"nodeType":864},{},[],{"data":31330,"content":31331,"nodeType":1312},{},[31332],{"data":31333,"marks":31334,"value":26188,"nodeType":864},{},[31335],{"type":899},{"data":31337,"content":31338,"nodeType":860},{},[31339],{"data":31340,"marks":31341,"value":26195,"nodeType":864},{},[],{"data":31343,"content":31344,"nodeType":860},{},[31345],{"data":31346,"marks":31347,"value":26203,"nodeType":864},{},[31348],{"type":899},{"data":31350,"content":31351,"nodeType":860},{},[31352],{"data":31353,"marks":31354,"value":26210,"nodeType":864},{},[],{"data":31356,"content":31357,"nodeType":860},{},[31358],{"data":31359,"marks":31360,"value":26217,"nodeType":864},{},[],{"data":31362,"content":31363,"nodeType":860},{},[31364],{"data":31365,"marks":31366,"value":26224,"nodeType":864},{},[],{"data":31368,"content":31371,"nodeType":996},{"target":31369},{"sys":31370},{"id":26229,"type":1001,"linkType":1002},[],{"data":31373,"content":31374,"nodeType":1312},{},[31375],{"data":31376,"marks":31377,"value":26238,"nodeType":864},{},[31378],{"type":899},{"data":31380,"content":31381,"nodeType":860},{},[31382],{"data":31383,"marks":31384,"value":26245,"nodeType":864},{},[],{"data":31386,"content":31387,"nodeType":860},{},[31388],{"data":31389,"marks":31390,"value":26252,"nodeType":864},{},[],{"data":31392,"content":31395,"nodeType":996},{"target":31393},{"sys":31394},{"id":11598,"type":1001,"linkType":1002},[],{"data":31397,"content":31398,"nodeType":860},{},[31399],{"data":31400,"marks":31401,"value":26264,"nodeType":864},{},[],{"data":31403,"content":31404,"nodeType":860},{},[31405],{"data":31406,"marks":31407,"value":26271,"nodeType":864},{},[],{"data":31409,"content":31410,"nodeType":860},{},[31411],{"data":31412,"marks":31413,"value":26278,"nodeType":864},{},[],{"data":31415,"content":31418,"nodeType":996},{"target":31416},{"sys":31417},{"id":26283,"type":1001,"linkType":1002},[],{"data":31420,"content":31421,"nodeType":860},{},[31422],{"data":31423,"marks":31424,"value":21,"nodeType":864},{},[],{"items":31426},[31427,31429],{"sys":31428,"name":297},{"id":2732},{"sys":31430,"name":2729},{"id":2728},{"items":31432},[31433],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":31434},{"url":4881},{"__typename":2059,"sys":31436,"content":31437,"title":24223,"synopsis":24224,"hashTags":59,"publishedDate":24225,"slug":24226,"tagsCollection":32146,"authorsCollection":32152},{"id":23397},{"json":31438},{"data":31439,"content":31440,"nodeType":856},{},[31441,31456,31471,31486,31491,31494,31501,31507,31513,31519,31525,31532,31535,31542,31548,31554,31560,31565,31572,31587,31593,31599,31612,31619,31643,31656,31662,31686,31693,31717,31723,31730,31745,31751,31757,31762,31768,31775,31790,31796,31812,31818,31821,31828,31834,31909,31915,31928,31931,31956,31971,31977,31983,31986,31993,32008,32014,32020,32035,32038,32045,32051,32081,32087,32102,32117,32122,32125,32131],{"data":31442,"content":31443,"nodeType":860},{},[31444,31447,31453],{"data":31445,"marks":31446,"value":23408,"nodeType":864},{},[],{"data":31448,"content":31449,"nodeType":883},{"uri":23411},[31450],{"data":31451,"marks":31452,"value":23416,"nodeType":864},{},[],{"data":31454,"marks":31455,"value":23420,"nodeType":864},{},[],{"data":31457,"content":31458,"nodeType":860},{},[31459,31462,31468],{"data":31460,"marks":31461,"value":23427,"nodeType":864},{},[],{"data":31463,"content":31464,"nodeType":883},{"uri":23430},[31465],{"data":31466,"marks":31467,"value":23435,"nodeType":864},{},[],{"data":31469,"marks":31470,"value":23439,"nodeType":864},{},[],{"data":31472,"content":31473,"nodeType":860},{},[31474,31477,31483],{"data":31475,"marks":31476,"value":23446,"nodeType":864},{},[],{"data":31478,"content":31479,"nodeType":883},{"uri":11562},[31480],{"data":31481,"marks":31482,"value":11754,"nodeType":864},{},[],{"data":31484,"marks":31485,"value":23456,"nodeType":864},{},[],{"data":31487,"content":31490,"nodeType":996},{"target":31488},{"sys":31489},{"id":23461,"type":1001,"linkType":1002},[],{"data":31492,"content":31493,"nodeType":1005},{},[],{"data":31495,"content":31496,"nodeType":1009},{},[31497],{"data":31498,"marks":31499,"value":23473,"nodeType":864},{},[31500],{"type":899},{"data":31502,"content":31503,"nodeType":860},{},[31504],{"data":31505,"marks":31506,"value":23480,"nodeType":864},{},[],{"data":31508,"content":31509,"nodeType":860},{},[31510],{"data":31511,"marks":31512,"value":23487,"nodeType":864},{},[],{"data":31514,"content":31515,"nodeType":860},{},[31516],{"data":31517,"marks":31518,"value":23494,"nodeType":864},{},[],{"data":31520,"content":31521,"nodeType":860},{},[31522],{"data":31523,"marks":31524,"value":23501,"nodeType":864},{},[],{"data":31526,"content":31527,"nodeType":860},{},[31528],{"data":31529,"marks":31530,"value":23509,"nodeType":864},{},[31531],{"type":899},{"data":31533,"content":31534,"nodeType":1005},{},[],{"data":31536,"content":31537,"nodeType":1009},{},[31538],{"data":31539,"marks":31540,"value":23520,"nodeType":864},{},[31541],{"type":899},{"data":31543,"content":31544,"nodeType":860},{},[31545],{"data":31546,"marks":31547,"value":23527,"nodeType":864},{},[],{"data":31549,"content":31550,"nodeType":860},{},[31551],{"data":31552,"marks":31553,"value":23534,"nodeType":864},{},[],{"data":31555,"content":31556,"nodeType":860},{},[31557],{"data":31558,"marks":31559,"value":23541,"nodeType":864},{},[],{"data":31561,"content":31564,"nodeType":996},{"target":31562},{"sys":31563},{"id":23546,"type":1001,"linkType":1002},[],{"data":31566,"content":31567,"nodeType":1312},{},[31568],{"data":31569,"marks":31570,"value":23555,"nodeType":864},{},[31571],{"type":899},{"data":31573,"content":31574,"nodeType":860},{},[31575,31578,31584],{"data":31576,"marks":31577,"value":23562,"nodeType":864},{},[],{"data":31579,"content":31580,"nodeType":883},{"uri":18939},[31581],{"data":31582,"marks":31583,"value":23569,"nodeType":864},{},[],{"data":31585,"marks":31586,"value":23573,"nodeType":864},{},[],{"data":31588,"content":31589,"nodeType":860},{},[31590],{"data":31591,"marks":31592,"value":23580,"nodeType":864},{},[],{"data":31594,"content":31595,"nodeType":860},{},[31596],{"data":31597,"marks":31598,"value":23587,"nodeType":864},{},[],{"data":31600,"content":31601,"nodeType":860},{},[31602,31605,31609],{"data":31603,"marks":31604,"value":23594,"nodeType":864},{},[],{"data":31606,"marks":31607,"value":23599,"nodeType":864},{},[31608],{"type":899},{"data":31610,"marks":31611,"value":23603,"nodeType":864},{},[],{"data":31613,"content":31614,"nodeType":1312},{},[31615],{"data":31616,"marks":31617,"value":23611,"nodeType":864},{},[31618],{"type":899},{"data":31620,"content":31621,"nodeType":860},{},[31622,31625,31631,31634,31640],{"data":31623,"marks":31624,"value":23618,"nodeType":864},{},[],{"data":31626,"content":31627,"nodeType":883},{"uri":13427},[31628],{"data":31629,"marks":31630,"value":23625,"nodeType":864},{},[],{"data":31632,"marks":31633,"value":23629,"nodeType":864},{},[],{"data":31635,"content":31636,"nodeType":883},{"uri":3237},[31637],{"data":31638,"marks":31639,"value":23636,"nodeType":864},{},[],{"data":31641,"marks":31642,"value":23640,"nodeType":864},{},[],{"data":31644,"content":31645,"nodeType":860},{},[31646,31649,31653],{"data":31647,"marks":31648,"value":23647,"nodeType":864},{},[],{"data":31650,"marks":31651,"value":23652,"nodeType":864},{},[31652],{"type":899},{"data":31654,"marks":31655,"value":23656,"nodeType":864},{},[],{"data":31657,"content":31658,"nodeType":860},{},[31659],{"data":31660,"marks":31661,"value":23663,"nodeType":864},{},[],{"data":31663,"content":31664,"nodeType":860},{},[31665,31668,31674,31677,31683],{"data":31666,"marks":31667,"value":23670,"nodeType":864},{},[],{"data":31669,"content":31670,"nodeType":883},{"uri":11738},[31671],{"data":31672,"marks":31673,"value":19059,"nodeType":864},{},[],{"data":31675,"marks":31676,"value":23680,"nodeType":864},{},[],{"data":31678,"content":31679,"nodeType":883},{"uri":11726},[31680],{"data":31681,"marks":31682,"value":11731,"nodeType":864},{},[],{"data":31684,"marks":31685,"value":23690,"nodeType":864},{},[],{"data":31687,"content":31688,"nodeType":1312},{},[31689],{"data":31690,"marks":31691,"value":23698,"nodeType":864},{},[31692],{"type":899},{"data":31694,"content":31695,"nodeType":860},{},[31696,31699,31705,31708,31714],{"data":31697,"marks":31698,"value":23705,"nodeType":864},{},[],{"data":31700,"content":31701,"nodeType":883},{"uri":23708},[31702],{"data":31703,"marks":31704,"value":23713,"nodeType":864},{},[],{"data":31706,"marks":31707,"value":23717,"nodeType":864},{},[],{"data":31709,"content":31710,"nodeType":883},{"uri":6940},[31711],{"data":31712,"marks":31713,"value":23724,"nodeType":864},{},[],{"data":31715,"marks":31716,"value":23728,"nodeType":864},{},[],{"data":31718,"content":31719,"nodeType":860},{},[31720],{"data":31721,"marks":31722,"value":23735,"nodeType":864},{},[],{"data":31724,"content":31725,"nodeType":1312},{},[31726],{"data":31727,"marks":31728,"value":23743,"nodeType":864},{},[31729],{"type":899},{"data":31731,"content":31732,"nodeType":860},{},[31733,31736,31742],{"data":31734,"marks":31735,"value":23750,"nodeType":864},{},[],{"data":31737,"content":31738,"nodeType":883},{"uri":3259},[31739],{"data":31740,"marks":31741,"value":23757,"nodeType":864},{},[],{"data":31743,"marks":31744,"value":23761,"nodeType":864},{},[],{"data":31746,"content":31747,"nodeType":860},{},[31748],{"data":31749,"marks":31750,"value":23768,"nodeType":864},{},[],{"data":31752,"content":31753,"nodeType":860},{},[31754],{"data":31755,"marks":31756,"value":23775,"nodeType":864},{},[],{"data":31758,"content":31761,"nodeType":996},{"target":31759},{"sys":31760},{"id":23780,"type":1001,"linkType":1002},[],{"data":31763,"content":31764,"nodeType":860},{},[31765],{"data":31766,"marks":31767,"value":23788,"nodeType":864},{},[],{"data":31769,"content":31770,"nodeType":1312},{},[31771],{"data":31772,"marks":31773,"value":23796,"nodeType":864},{},[31774],{"type":899},{"data":31776,"content":31777,"nodeType":860},{},[31778,31781,31787],{"data":31779,"marks":31780,"value":23803,"nodeType":864},{},[],{"data":31782,"content":31783,"nodeType":883},{"uri":2411},[31784],{"data":31785,"marks":31786,"value":23810,"nodeType":864},{},[],{"data":31788,"marks":31789,"value":23814,"nodeType":864},{},[],{"data":31791,"content":31792,"nodeType":860},{},[31793],{"data":31794,"marks":31795,"value":23821,"nodeType":864},{},[],{"data":31797,"content":31798,"nodeType":860},{},[31799,31802,31809],{"data":31800,"marks":31801,"value":23828,"nodeType":864},{},[],{"data":31803,"content":31804,"nodeType":883},{"uri":2411},[31805],{"data":31806,"marks":31807,"value":23836,"nodeType":864},{},[31808],{"type":1455},{"data":31810,"marks":31811,"value":23840,"nodeType":864},{},[],{"data":31813,"content":31814,"nodeType":860},{},[31815],{"data":31816,"marks":31817,"value":23847,"nodeType":864},{},[],{"data":31819,"content":31820,"nodeType":1005},{},[],{"data":31822,"content":31823,"nodeType":1009},{},[31824],{"data":31825,"marks":31826,"value":23858,"nodeType":864},{},[31827],{"type":899},{"data":31829,"content":31830,"nodeType":860},{},[31831],{"data":31832,"marks":31833,"value":23865,"nodeType":864},{},[],{"data":31835,"content":31836,"nodeType":941},{},[31837,31855,31873,31891],{"data":31838,"content":31839,"nodeType":945},{},[31840],{"data":31841,"content":31842,"nodeType":860},{},[31843,31846,31852],{"data":31844,"marks":31845,"value":23878,"nodeType":864},{},[],{"data":31847,"content":31848,"nodeType":883},{"uri":16015},[31849],{"data":31850,"marks":31851,"value":16018,"nodeType":864},{},[],{"data":31853,"marks":31854,"value":23888,"nodeType":864},{},[],{"data":31856,"content":31857,"nodeType":945},{},[31858],{"data":31859,"content":31860,"nodeType":860},{},[31861,31864,31870],{"data":31862,"marks":31863,"value":23898,"nodeType":864},{},[],{"data":31865,"content":31866,"nodeType":883},{"uri":23901},[31867],{"data":31868,"marks":31869,"value":23906,"nodeType":864},{},[],{"data":31871,"marks":31872,"value":23910,"nodeType":864},{},[],{"data":31874,"content":31875,"nodeType":945},{},[31876],{"data":31877,"content":31878,"nodeType":860},{},[31879,31882,31888],{"data":31880,"marks":31881,"value":23878,"nodeType":864},{},[],{"data":31883,"content":31884,"nodeType":883},{"uri":11726},[31885],{"data":31886,"marks":31887,"value":23926,"nodeType":864},{},[],{"data":31889,"marks":31890,"value":23930,"nodeType":864},{},[],{"data":31892,"content":31893,"nodeType":945},{},[31894],{"data":31895,"content":31896,"nodeType":860},{},[31897,31900,31906],{"data":31898,"marks":31899,"value":2761,"nodeType":864},{},[],{"data":31901,"content":31902,"nodeType":883},{"uri":23942},[31903],{"data":31904,"marks":31905,"value":3756,"nodeType":864},{},[],{"data":31907,"marks":31908,"value":23950,"nodeType":864},{},[],{"data":31910,"content":31911,"nodeType":860},{},[31912],{"data":31913,"marks":31914,"value":23957,"nodeType":864},{},[],{"data":31916,"content":31917,"nodeType":860},{},[31918,31921,31925],{"data":31919,"marks":31920,"value":23964,"nodeType":864},{},[],{"data":31922,"marks":31923,"value":23969,"nodeType":864},{},[31924],{"type":899},{"data":31926,"marks":31927,"value":23973,"nodeType":864},{},[],{"data":31929,"content":31930,"nodeType":1005},{},[],{"data":31932,"content":31933,"nodeType":1009},{},[31934,31938,31943,31947,31952],{"data":31935,"marks":31936,"value":23984,"nodeType":864},{},[31937],{"type":899},{"data":31939,"marks":31940,"value":23990,"nodeType":864},{},[31941,31942],{"type":2246},{"type":899},{"data":31944,"marks":31945,"value":23995,"nodeType":864},{},[31946],{"type":899},{"data":31948,"marks":31949,"value":24001,"nodeType":864},{},[31950,31951],{"type":2246},{"type":899},{"data":31953,"marks":31954,"value":24006,"nodeType":864},{},[31955],{"type":899},{"data":31957,"content":31958,"nodeType":860},{},[31959,31962,31968],{"data":31960,"marks":31961,"value":24013,"nodeType":864},{},[],{"data":31963,"content":31964,"nodeType":883},{"uri":18859},[31965],{"data":31966,"marks":31967,"value":24020,"nodeType":864},{},[],{"data":31969,"marks":31970,"value":24024,"nodeType":864},{},[],{"data":31972,"content":31973,"nodeType":860},{},[31974],{"data":31975,"marks":31976,"value":24031,"nodeType":864},{},[],{"data":31978,"content":31979,"nodeType":860},{},[31980],{"data":31981,"marks":31982,"value":24038,"nodeType":864},{},[],{"data":31984,"content":31985,"nodeType":1005},{},[],{"data":31987,"content":31988,"nodeType":1009},{},[31989],{"data":31990,"marks":31991,"value":24049,"nodeType":864},{},[31992],{"type":899},{"data":31994,"content":31995,"nodeType":860},{},[31996,31999,32005],{"data":31997,"marks":31998,"value":24056,"nodeType":864},{},[],{"data":32000,"content":32001,"nodeType":883},{"uri":24059},[32002],{"data":32003,"marks":32004,"value":22093,"nodeType":864},{},[],{"data":32006,"marks":32007,"value":24067,"nodeType":864},{},[],{"data":32009,"content":32010,"nodeType":860},{},[32011],{"data":32012,"marks":32013,"value":24074,"nodeType":864},{},[],{"data":32015,"content":32016,"nodeType":860},{},[32017],{"data":32018,"marks":32019,"value":24081,"nodeType":864},{},[],{"data":32021,"content":32022,"nodeType":860},{},[32023,32026,32032],{"data":32024,"marks":32025,"value":24088,"nodeType":864},{},[],{"data":32027,"content":32028,"nodeType":883},{"uri":24091},[32029],{"data":32030,"marks":32031,"value":22093,"nodeType":864},{},[],{"data":32033,"marks":32034,"value":2924,"nodeType":864},{},[],{"data":32036,"content":32037,"nodeType":1005},{},[],{"data":32039,"content":32040,"nodeType":1009},{},[32041],{"data":32042,"marks":32043,"value":24109,"nodeType":864},{},[32044],{"type":899},{"data":32046,"content":32047,"nodeType":860},{},[32048],{"data":32049,"marks":32050,"value":24116,"nodeType":864},{},[],{"data":32052,"content":32053,"nodeType":941},{},[32054,32063,32072],{"data":32055,"content":32056,"nodeType":945},{},[32057],{"data":32058,"content":32059,"nodeType":860},{},[32060],{"data":32061,"marks":32062,"value":24129,"nodeType":864},{},[],{"data":32064,"content":32065,"nodeType":945},{},[32066],{"data":32067,"content":32068,"nodeType":860},{},[32069],{"data":32070,"marks":32071,"value":24139,"nodeType":864},{},[],{"data":32073,"content":32074,"nodeType":945},{},[32075],{"data":32076,"content":32077,"nodeType":860},{},[32078],{"data":32079,"marks":32080,"value":24149,"nodeType":864},{},[],{"data":32082,"content":32083,"nodeType":860},{},[32084],{"data":32085,"marks":32086,"value":24156,"nodeType":864},{},[],{"data":32088,"content":32089,"nodeType":860},{},[32090,32093,32099],{"data":32091,"marks":32092,"value":24163,"nodeType":864},{},[],{"data":32094,"content":32095,"nodeType":883},{"uri":11562},[32096],{"data":32097,"marks":32098,"value":24170,"nodeType":864},{},[],{"data":32100,"marks":32101,"value":2924,"nodeType":864},{},[],{"data":32103,"content":32104,"nodeType":860},{},[32105,32108,32114],{"data":32106,"marks":32107,"value":24180,"nodeType":864},{},[],{"data":32109,"content":32110,"nodeType":883},{"uri":11536},[32111],{"data":32112,"marks":32113,"value":24187,"nodeType":864},{},[],{"data":32115,"marks":32116,"value":24191,"nodeType":864},{},[],{"data":32118,"content":32121,"nodeType":996},{"target":32119},{"sys":32120},{"id":24196,"type":1001,"linkType":1002},[],{"data":32123,"content":32124,"nodeType":1005},{},[],{"data":32126,"content":32127,"nodeType":860},{},[32128],{"data":32129,"marks":32130,"value":24207,"nodeType":864},{},[],{"data":32132,"content":32133,"nodeType":860},{},[32134,32137,32143],{"data":32135,"marks":32136,"value":2707,"nodeType":864},{},[],{"data":32138,"content":32139,"nodeType":883},{"uri":1700},[32140],{"data":32141,"marks":32142,"value":2715,"nodeType":864},{},[],{"data":32144,"marks":32145,"value":2719,"nodeType":864},{},[],{"items":32147},[32148,32150],{"sys":32149,"name":13779},{"id":13778},{"sys":32151,"name":342},{"id":13775},{"items":32153},[32154],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":32155},{"url":2740},{"__typename":2059,"sys":32157,"content":32158,"title":4865,"synopsis":4866,"hashTags":59,"publishedDate":4867,"slug":4868,"tagsCollection":33227,"authorsCollection":33233},{"id":3628},{"json":32159},{"data":32160,"content":32161,"nodeType":856},{},[32162,32175,32180,32186,32192,32197,32200,32207,32214,32229,32267,32272,32285,32288,32295,32302,32324,32356,32362,32365,32372,32379,32385,32390,32396,32399,32406,32413,32447,32477,32483,32486,32493,32500,32520,32526,32565,32571,32574,32581,32588,32624,32630,32635,32638,32645,32652,32678,32684,32689,32695,32698,32705,32712,32735,32741,32747,32753,32756,32763,32770,32776,32781,32787,32808,32831,32834,32841,32848,32854,32860,32863,32870,32925,32928,32935,32941,33209,33212],{"data":32163,"content":32164,"nodeType":860},{},[32165,32168,32172],{"data":32166,"marks":32167,"value":3639,"nodeType":864},{},[],{"data":32169,"marks":32170,"value":3644,"nodeType":864},{},[32171],{"type":899},{"data":32173,"marks":32174,"value":3648,"nodeType":864},{},[],{"data":32176,"content":32179,"nodeType":996},{"target":32177},{"sys":32178},{"id":3653,"type":1001,"linkType":1002},[],{"data":32181,"content":32182,"nodeType":860},{},[32183],{"data":32184,"marks":32185,"value":3661,"nodeType":864},{},[],{"data":32187,"content":32188,"nodeType":860},{},[32189],{"data":32190,"marks":32191,"value":3668,"nodeType":864},{},[],{"data":32193,"content":32196,"nodeType":996},{"target":32194},{"sys":32195},{"id":3673,"type":1001,"linkType":1002},[],{"data":32198,"content":32199,"nodeType":1005},{},[],{"data":32201,"content":32202,"nodeType":1009},{},[32203],{"data":32204,"marks":32205,"value":3685,"nodeType":864},{},[32206],{"type":899},{"data":32208,"content":32209,"nodeType":860},{},[32210],{"data":32211,"marks":32212,"value":3693,"nodeType":864},{},[32213],{"type":899},{"data":32215,"content":32216,"nodeType":860},{},[32217,32220,32226],{"data":32218,"marks":32219,"value":3700,"nodeType":864},{},[],{"data":32221,"content":32222,"nodeType":883},{"uri":3703},[32223],{"data":32224,"marks":32225,"value":3708,"nodeType":864},{},[],{"data":32227,"marks":32228,"value":3712,"nodeType":864},{},[],{"data":32230,"content":32231,"nodeType":860},{},[32232,32235,32241,32244,32248,32251,32255,32258,32264],{"data":32233,"marks":32234,"value":3719,"nodeType":864},{},[],{"data":32236,"content":32237,"nodeType":883},{"uri":3722},[32238],{"data":32239,"marks":32240,"value":3727,"nodeType":864},{},[],{"data":32242,"marks":32243,"value":3731,"nodeType":864},{},[],{"data":32245,"marks":32246,"value":3736,"nodeType":864},{},[32247],{"type":899},{"data":32249,"marks":32250,"value":2232,"nodeType":864},{},[],{"data":32252,"marks":32253,"value":3744,"nodeType":864},{},[32254],{"type":899},{"data":32256,"marks":32257,"value":3748,"nodeType":864},{},[],{"data":32259,"content":32260,"nodeType":883},{"uri":3751},[32261],{"data":32262,"marks":32263,"value":3756,"nodeType":864},{},[],{"data":32265,"marks":32266,"value":3760,"nodeType":864},{},[],{"data":32268,"content":32271,"nodeType":996},{"target":32269},{"sys":32270},{"id":3765,"type":1001,"linkType":1002},[],{"data":32273,"content":32274,"nodeType":860},{},[32275,32278,32282],{"data":32276,"marks":32277,"value":3773,"nodeType":864},{},[],{"data":32279,"marks":32280,"value":3778,"nodeType":864},{},[32281],{"type":899},{"data":32283,"marks":32284,"value":2924,"nodeType":864},{},[],{"data":32286,"content":32287,"nodeType":1005},{},[],{"data":32289,"content":32290,"nodeType":1009},{},[32291],{"data":32292,"marks":32293,"value":3792,"nodeType":864},{},[32294],{"type":899},{"data":32296,"content":32297,"nodeType":860},{},[32298],{"data":32299,"marks":32300,"value":3693,"nodeType":864},{},[32301],{"type":899},{"data":32303,"content":32304,"nodeType":860},{},[32305,32308,32314,32317,32321],{"data":32306,"marks":32307,"value":3806,"nodeType":864},{},[],{"data":32309,"content":32310,"nodeType":883},{"uri":3809},[32311],{"data":32312,"marks":32313,"value":3814,"nodeType":864},{},[],{"data":32315,"marks":32316,"value":3818,"nodeType":864},{},[],{"data":32318,"marks":32319,"value":3823,"nodeType":864},{},[32320],{"type":899},{"data":32322,"marks":32323,"value":3827,"nodeType":864},{},[],{"data":32325,"content":32326,"nodeType":860},{},[32327,32330,32336,32339,32343,32346,32353],{"data":32328,"marks":32329,"value":3834,"nodeType":864},{},[],{"data":32331,"content":32332,"nodeType":883},{"uri":3837},[32333],{"data":32334,"marks":32335,"value":3842,"nodeType":864},{},[],{"data":32337,"marks":32338,"value":3846,"nodeType":864},{},[],{"data":32340,"marks":32341,"value":3851,"nodeType":864},{},[32342],{"type":899},{"data":32344,"marks":32345,"value":3855,"nodeType":864},{},[],{"data":32347,"content":32348,"nodeType":883},{"uri":3858},[32349],{"data":32350,"marks":32351,"value":3864,"nodeType":864},{},[32352],{"type":899},{"data":32354,"marks":32355,"value":3868,"nodeType":864},{},[],{"data":32357,"content":32358,"nodeType":860},{},[32359],{"data":32360,"marks":32361,"value":3875,"nodeType":864},{},[],{"data":32363,"content":32364,"nodeType":1005},{},[],{"data":32366,"content":32367,"nodeType":1009},{},[32368],{"data":32369,"marks":32370,"value":3886,"nodeType":864},{},[32371],{"type":899},{"data":32373,"content":32374,"nodeType":860},{},[32375],{"data":32376,"marks":32377,"value":3894,"nodeType":864},{},[32378],{"type":899},{"data":32380,"content":32381,"nodeType":860},{},[32382],{"data":32383,"marks":32384,"value":3901,"nodeType":864},{},[],{"data":32386,"content":32389,"nodeType":996},{"target":32387},{"sys":32388},{"id":3906,"type":1001,"linkType":1002},[],{"data":32391,"content":32392,"nodeType":860},{},[32393],{"data":32394,"marks":32395,"value":3914,"nodeType":864},{},[],{"data":32397,"content":32398,"nodeType":1005},{},[],{"data":32400,"content":32401,"nodeType":1009},{},[32402],{"data":32403,"marks":32404,"value":3925,"nodeType":864},{},[32405],{"type":899},{"data":32407,"content":32408,"nodeType":860},{},[32409],{"data":32410,"marks":32411,"value":3894,"nodeType":864},{},[32412],{"type":899},{"data":32414,"content":32415,"nodeType":860},{},[32416,32419,32426,32429,32435,32438,32444],{"data":32417,"marks":32418,"value":3939,"nodeType":864},{},[],{"data":32420,"content":32421,"nodeType":883},{"uri":3942},[32422],{"data":32423,"marks":32424,"value":3948,"nodeType":864},{},[32425],{"type":1455},{"data":32427,"marks":32428,"value":3731,"nodeType":864},{},[],{"data":32430,"content":32431,"nodeType":883},{"uri":3954},[32432],{"data":32433,"marks":32434,"value":3959,"nodeType":864},{},[],{"data":32436,"marks":32437,"value":3731,"nodeType":864},{},[],{"data":32439,"content":32440,"nodeType":883},{"uri":3965},[32441],{"data":32442,"marks":32443,"value":3970,"nodeType":864},{},[],{"data":32445,"marks":32446,"value":3974,"nodeType":864},{},[],{"data":32448,"content":32449,"nodeType":860},{},[32450,32453,32460,32463,32467,32470,32474],{"data":32451,"marks":32452,"value":21,"nodeType":864},{},[],{"data":32454,"content":32455,"nodeType":883},{"uri":2411},[32456],{"data":32457,"marks":32458,"value":3988,"nodeType":864},{},[32459],{"type":1455},{"data":32461,"marks":32462,"value":3992,"nodeType":864},{},[],{"data":32464,"marks":32465,"value":3997,"nodeType":864},{},[32466],{"type":899},{"data":32468,"marks":32469,"value":4001,"nodeType":864},{},[],{"data":32471,"marks":32472,"value":4006,"nodeType":864},{},[32473],{"type":2246},{"data":32475,"marks":32476,"value":4010,"nodeType":864},{},[],{"data":32478,"content":32479,"nodeType":860},{},[32480],{"data":32481,"marks":32482,"value":4017,"nodeType":864},{},[],{"data":32484,"content":32485,"nodeType":1005},{},[],{"data":32487,"content":32488,"nodeType":1009},{},[32489],{"data":32490,"marks":32491,"value":4028,"nodeType":864},{},[32492],{"type":899},{"data":32494,"content":32495,"nodeType":860},{},[32496],{"data":32497,"marks":32498,"value":3894,"nodeType":864},{},[32499],{"type":899},{"data":32501,"content":32502,"nodeType":860},{},[32503,32506,32510,32513,32517],{"data":32504,"marks":32505,"value":4042,"nodeType":864},{},[],{"data":32507,"marks":32508,"value":4047,"nodeType":864},{},[32509],{"type":2246},{"data":32511,"marks":32512,"value":4051,"nodeType":864},{},[],{"data":32514,"marks":32515,"value":4056,"nodeType":864},{},[32516],{"type":2246},{"data":32518,"marks":32519,"value":4060,"nodeType":864},{},[],{"data":32521,"content":32522,"nodeType":860},{},[32523],{"data":32524,"marks":32525,"value":4067,"nodeType":864},{},[],{"data":32527,"content":32528,"nodeType":941},{},[32529,32547],{"data":32530,"content":32531,"nodeType":945},{},[32532],{"data":32533,"content":32534,"nodeType":860},{},[32535,32538,32544],{"data":32536,"marks":32537,"value":2761,"nodeType":864},{},[],{"data":32539,"content":32540,"nodeType":883},{"uri":4082},[32541],{"data":32542,"marks":32543,"value":4087,"nodeType":864},{},[],{"data":32545,"marks":32546,"value":4091,"nodeType":864},{},[],{"data":32548,"content":32549,"nodeType":945},{},[32550],{"data":32551,"content":32552,"nodeType":860},{},[32553,32556,32562],{"data":32554,"marks":32555,"value":2761,"nodeType":864},{},[],{"data":32557,"content":32558,"nodeType":883},{"uri":4103},[32559],{"data":32560,"marks":32561,"value":4108,"nodeType":864},{},[],{"data":32563,"marks":32564,"value":4112,"nodeType":864},{},[],{"data":32566,"content":32567,"nodeType":860},{},[32568],{"data":32569,"marks":32570,"value":4119,"nodeType":864},{},[],{"data":32572,"content":32573,"nodeType":1005},{},[],{"data":32575,"content":32576,"nodeType":1009},{},[32577],{"data":32578,"marks":32579,"value":4130,"nodeType":864},{},[32580],{"type":899},{"data":32582,"content":32583,"nodeType":860},{},[32584],{"data":32585,"marks":32586,"value":4138,"nodeType":864},{},[32587],{"type":899},{"data":32589,"content":32590,"nodeType":860},{},[32591,32594,32598,32601,32607,32610,32614,32617,32621],{"data":32592,"marks":32593,"value":4145,"nodeType":864},{},[],{"data":32595,"marks":32596,"value":4150,"nodeType":864},{},[32597],{"type":899},{"data":32599,"marks":32600,"value":4154,"nodeType":864},{},[],{"data":32602,"content":32603,"nodeType":883},{"uri":3237},[32604],{"data":32605,"marks":32606,"value":4161,"nodeType":864},{},[],{"data":32608,"marks":32609,"value":4165,"nodeType":864},{},[],{"data":32611,"marks":32612,"value":4170,"nodeType":864},{},[32613],{"type":899},{"data":32615,"marks":32616,"value":4174,"nodeType":864},{},[],{"data":32618,"marks":32619,"value":4179,"nodeType":864},{},[32620],{"type":899},{"data":32622,"marks":32623,"value":4183,"nodeType":864},{},[],{"data":32625,"content":32626,"nodeType":860},{},[32627],{"data":32628,"marks":32629,"value":4190,"nodeType":864},{},[],{"data":32631,"content":32634,"nodeType":996},{"target":32632},{"sys":32633},{"id":4195,"type":1001,"linkType":1002},[],{"data":32636,"content":32637,"nodeType":1005},{},[],{"data":32639,"content":32640,"nodeType":1009},{},[32641],{"data":32642,"marks":32643,"value":4207,"nodeType":864},{},[32644],{"type":899},{"data":32646,"content":32647,"nodeType":860},{},[32648],{"data":32649,"marks":32650,"value":4215,"nodeType":864},{},[32651],{"type":899},{"data":32653,"content":32654,"nodeType":860},{},[32655,32658,32665,32668,32675],{"data":32656,"marks":32657,"value":4222,"nodeType":864},{},[],{"data":32659,"content":32660,"nodeType":883},{"uri":2561},[32661],{"data":32662,"marks":32663,"value":4230,"nodeType":864},{},[32664],{"type":899},{"data":32666,"marks":32667,"value":4234,"nodeType":864},{},[],{"data":32669,"content":32670,"nodeType":883},{"uri":4237},[32671],{"data":32672,"marks":32673,"value":4243,"nodeType":864},{},[32674],{"type":899},{"data":32676,"marks":32677,"value":4247,"nodeType":864},{},[],{"data":32679,"content":32680,"nodeType":860},{},[32681],{"data":32682,"marks":32683,"value":4254,"nodeType":864},{},[],{"data":32685,"content":32688,"nodeType":996},{"target":32686},{"sys":32687},{"id":4259,"type":1001,"linkType":1002},[],{"data":32690,"content":32691,"nodeType":860},{},[32692],{"data":32693,"marks":32694,"value":4267,"nodeType":864},{},[],{"data":32696,"content":32697,"nodeType":1005},{},[],{"data":32699,"content":32700,"nodeType":1009},{},[32701],{"data":32702,"marks":32703,"value":4278,"nodeType":864},{},[32704],{"type":899},{"data":32706,"content":32707,"nodeType":860},{},[32708],{"data":32709,"marks":32710,"value":4286,"nodeType":864},{},[32711],{"type":899},{"data":32713,"content":32714,"nodeType":860},{},[32715,32718,32722,32725,32732],{"data":32716,"marks":32717,"value":4293,"nodeType":864},{},[],{"data":32719,"marks":32720,"value":4298,"nodeType":864},{},[32721],{"type":2246},{"data":32723,"marks":32724,"value":4302,"nodeType":864},{},[],{"data":32726,"content":32727,"nodeType":883},{"uri":4305},[32728],{"data":32729,"marks":32730,"value":4311,"nodeType":864},{},[32731],{"type":899},{"data":32733,"marks":32734,"value":4315,"nodeType":864},{},[],{"data":32736,"content":32737,"nodeType":860},{},[32738],{"data":32739,"marks":32740,"value":4322,"nodeType":864},{},[],{"data":32742,"content":32743,"nodeType":860},{},[32744],{"data":32745,"marks":32746,"value":4329,"nodeType":864},{},[],{"data":32748,"content":32749,"nodeType":860},{},[32750],{"data":32751,"marks":32752,"value":4336,"nodeType":864},{},[],{"data":32754,"content":32755,"nodeType":1005},{},[],{"data":32757,"content":32758,"nodeType":1009},{},[32759],{"data":32760,"marks":32761,"value":4347,"nodeType":864},{},[32762],{"type":899},{"data":32764,"content":32765,"nodeType":860},{},[32766],{"data":32767,"marks":32768,"value":4355,"nodeType":864},{},[32769],{"type":899},{"data":32771,"content":32772,"nodeType":860},{},[32773],{"data":32774,"marks":32775,"value":4362,"nodeType":864},{},[],{"data":32777,"content":32780,"nodeType":996},{"target":32778},{"sys":32779},{"id":4367,"type":1001,"linkType":1002},[],{"data":32782,"content":32783,"nodeType":860},{},[32784],{"data":32785,"marks":32786,"value":4375,"nodeType":864},{},[],{"data":32788,"content":32789,"nodeType":941},{},[32790,32799],{"data":32791,"content":32792,"nodeType":945},{},[32793],{"data":32794,"content":32795,"nodeType":860},{},[32796],{"data":32797,"marks":32798,"value":4388,"nodeType":864},{},[],{"data":32800,"content":32801,"nodeType":945},{},[32802],{"data":32803,"content":32804,"nodeType":860},{},[32805],{"data":32806,"marks":32807,"value":4398,"nodeType":864},{},[],{"data":32809,"content":32810,"nodeType":860},{},[32811,32814,32821,32824,32828],{"data":32812,"marks":32813,"value":4405,"nodeType":864},{},[],{"data":32815,"content":32816,"nodeType":883},{"uri":4408},[32817],{"data":32818,"marks":32819,"value":4414,"nodeType":864},{},[32820],{"type":899},{"data":32822,"marks":32823,"value":4418,"nodeType":864},{},[],{"data":32825,"marks":32826,"value":4423,"nodeType":864},{},[32827],{"type":2246},{"data":32829,"marks":32830,"value":4427,"nodeType":864},{},[],{"data":32832,"content":32833,"nodeType":1005},{},[],{"data":32835,"content":32836,"nodeType":1009},{},[32837],{"data":32838,"marks":32839,"value":4438,"nodeType":864},{},[32840],{"type":899},{"data":32842,"content":32843,"nodeType":860},{},[32844],{"data":32845,"marks":32846,"value":4446,"nodeType":864},{},[32847],{"type":899},{"data":32849,"content":32850,"nodeType":860},{},[32851],{"data":32852,"marks":32853,"value":4453,"nodeType":864},{},[],{"data":32855,"content":32856,"nodeType":860},{},[32857],{"data":32858,"marks":32859,"value":4460,"nodeType":864},{},[],{"data":32861,"content":32862,"nodeType":1005},{},[],{"data":32864,"content":32865,"nodeType":1009},{},[32866],{"data":32867,"marks":32868,"value":4471,"nodeType":864},{},[32869],{"type":899},{"data":32871,"content":32872,"nodeType":941},{},[32873,32886,32899,32912],{"data":32874,"content":32875,"nodeType":945},{},[32876],{"data":32877,"content":32878,"nodeType":860},{},[32879,32883],{"data":32880,"marks":32881,"value":4485,"nodeType":864},{},[32882],{"type":899},{"data":32884,"marks":32885,"value":4489,"nodeType":864},{},[],{"data":32887,"content":32888,"nodeType":945},{},[32889],{"data":32890,"content":32891,"nodeType":860},{},[32892,32896],{"data":32893,"marks":32894,"value":4500,"nodeType":864},{},[32895],{"type":899},{"data":32897,"marks":32898,"value":4504,"nodeType":864},{},[],{"data":32900,"content":32901,"nodeType":945},{},[32902],{"data":32903,"content":32904,"nodeType":860},{},[32905,32909],{"data":32906,"marks":32907,"value":4515,"nodeType":864},{},[32908],{"type":899},{"data":32910,"marks":32911,"value":4519,"nodeType":864},{},[],{"data":32913,"content":32914,"nodeType":945},{},[32915],{"data":32916,"content":32917,"nodeType":860},{},[32918,32922],{"data":32919,"marks":32920,"value":781,"nodeType":864},{},[32921],{"type":899},{"data":32923,"marks":32924,"value":4533,"nodeType":864},{},[],{"data":32926,"content":32927,"nodeType":1005},{},[],{"data":32929,"content":32930,"nodeType":1009},{},[32931],{"data":32932,"marks":32933,"value":4544,"nodeType":864},{},[32934],{"type":899},{"data":32936,"content":32937,"nodeType":860},{},[32938],{"data":32939,"marks":32940,"value":4551,"nodeType":864},{},[],{"data":32942,"content":32943,"nodeType":4845},{},[32944,32967,32989,33011,33033,33055,33077,33099,33121,33143,33165,33187],{"data":32945,"content":32946,"nodeType":4581},{},[32947,32957],{"data":32948,"content":32949,"nodeType":4569},{},[32950],{"data":32951,"content":32952,"nodeType":860},{},[32953],{"data":32954,"marks":32955,"value":4568,"nodeType":864},{},[32956],{"type":899},{"data":32958,"content":32959,"nodeType":4569},{},[32960],{"data":32961,"content":32962,"nodeType":860},{},[32963],{"data":32964,"marks":32965,"value":4580,"nodeType":864},{},[32966],{"type":899},{"data":32968,"content":32969,"nodeType":4581},{},[32970,32980],{"data":32971,"content":32972,"nodeType":4569},{},[32973],{"data":32974,"content":32975,"nodeType":860},{},[32976],{"data":32977,"marks":32978,"value":4595,"nodeType":864},{},[32979],{"type":899},{"data":32981,"content":32982,"nodeType":4569},{},[32983],{"data":32984,"content":32985,"nodeType":860},{},[32986],{"data":32987,"marks":32988,"value":4605,"nodeType":864},{},[],{"data":32990,"content":32991,"nodeType":4581},{},[32992,33002],{"data":32993,"content":32994,"nodeType":4569},{},[32995],{"data":32996,"content":32997,"nodeType":860},{},[32998],{"data":32999,"marks":33000,"value":4619,"nodeType":864},{},[33001],{"type":899},{"data":33003,"content":33004,"nodeType":4569},{},[33005],{"data":33006,"content":33007,"nodeType":860},{},[33008],{"data":33009,"marks":33010,"value":4629,"nodeType":864},{},[],{"data":33012,"content":33013,"nodeType":4581},{},[33014,33024],{"data":33015,"content":33016,"nodeType":4569},{},[33017],{"data":33018,"content":33019,"nodeType":860},{},[33020],{"data":33021,"marks":33022,"value":4643,"nodeType":864},{},[33023],{"type":899},{"data":33025,"content":33026,"nodeType":4569},{},[33027],{"data":33028,"content":33029,"nodeType":860},{},[33030],{"data":33031,"marks":33032,"value":4653,"nodeType":864},{},[],{"data":33034,"content":33035,"nodeType":4581},{},[33036,33046],{"data":33037,"content":33038,"nodeType":4569},{},[33039],{"data":33040,"content":33041,"nodeType":860},{},[33042],{"data":33043,"marks":33044,"value":4667,"nodeType":864},{},[33045],{"type":899},{"data":33047,"content":33048,"nodeType":4569},{},[33049],{"data":33050,"content":33051,"nodeType":860},{},[33052],{"data":33053,"marks":33054,"value":4677,"nodeType":864},{},[],{"data":33056,"content":33057,"nodeType":4581},{},[33058,33068],{"data":33059,"content":33060,"nodeType":4569},{},[33061],{"data":33062,"content":33063,"nodeType":860},{},[33064],{"data":33065,"marks":33066,"value":4691,"nodeType":864},{},[33067],{"type":899},{"data":33069,"content":33070,"nodeType":4569},{},[33071],{"data":33072,"content":33073,"nodeType":860},{},[33074],{"data":33075,"marks":33076,"value":4701,"nodeType":864},{},[],{"data":33078,"content":33079,"nodeType":4581},{},[33080,33090],{"data":33081,"content":33082,"nodeType":4569},{},[33083],{"data":33084,"content":33085,"nodeType":860},{},[33086],{"data":33087,"marks":33088,"value":4715,"nodeType":864},{},[33089],{"type":899},{"data":33091,"content":33092,"nodeType":4569},{},[33093],{"data":33094,"content":33095,"nodeType":860},{},[33096],{"data":33097,"marks":33098,"value":4725,"nodeType":864},{},[],{"data":33100,"content":33101,"nodeType":4581},{},[33102,33112],{"data":33103,"content":33104,"nodeType":4569},{},[33105],{"data":33106,"content":33107,"nodeType":860},{},[33108],{"data":33109,"marks":33110,"value":4739,"nodeType":864},{},[33111],{"type":899},{"data":33113,"content":33114,"nodeType":4569},{},[33115],{"data":33116,"content":33117,"nodeType":860},{},[33118],{"data":33119,"marks":33120,"value":4749,"nodeType":864},{},[],{"data":33122,"content":33123,"nodeType":4581},{},[33124,33134],{"data":33125,"content":33126,"nodeType":4569},{},[33127],{"data":33128,"content":33129,"nodeType":860},{},[33130],{"data":33131,"marks":33132,"value":4763,"nodeType":864},{},[33133],{"type":899},{"data":33135,"content":33136,"nodeType":4569},{},[33137],{"data":33138,"content":33139,"nodeType":860},{},[33140],{"data":33141,"marks":33142,"value":4773,"nodeType":864},{},[],{"data":33144,"content":33145,"nodeType":4581},{},[33146,33156],{"data":33147,"content":33148,"nodeType":4569},{},[33149],{"data":33150,"content":33151,"nodeType":860},{},[33152],{"data":33153,"marks":33154,"value":4787,"nodeType":864},{},[33155],{"type":899},{"data":33157,"content":33158,"nodeType":4569},{},[33159],{"data":33160,"content":33161,"nodeType":860},{},[33162],{"data":33163,"marks":33164,"value":4797,"nodeType":864},{},[],{"data":33166,"content":33167,"nodeType":4581},{},[33168,33178],{"data":33169,"content":33170,"nodeType":4569},{},[33171],{"data":33172,"content":33173,"nodeType":860},{},[33174],{"data":33175,"marks":33176,"value":4811,"nodeType":864},{},[33177],{"type":899},{"data":33179,"content":33180,"nodeType":4569},{},[33181],{"data":33182,"content":33183,"nodeType":860},{},[33184],{"data":33185,"marks":33186,"value":4821,"nodeType":864},{},[],{"data":33188,"content":33189,"nodeType":4581},{},[33190,33200],{"data":33191,"content":33192,"nodeType":4569},{},[33193],{"data":33194,"content":33195,"nodeType":860},{},[33196],{"data":33197,"marks":33198,"value":4500,"nodeType":864},{},[33199],{"type":899},{"data":33201,"content":33202,"nodeType":4569},{},[33203],{"data":33204,"content":33205,"nodeType":860},{},[33206],{"data":33207,"marks":33208,"value":4844,"nodeType":864},{},[],{"data":33210,"content":33211,"nodeType":1005},{},[],{"data":33213,"content":33214,"nodeType":860},{},[33215,33218,33224],{"data":33216,"marks":33217,"value":4855,"nodeType":864},{},[],{"data":33219,"content":33220,"nodeType":883},{"uri":1700},[33221],{"data":33222,"marks":33223,"value":1703,"nodeType":864},{},[],{"data":33225,"marks":33226,"value":21,"nodeType":864},{},[],{"items":33228},[33229,33231],{"sys":33230,"name":297},{"id":2732},{"sys":33232,"name":2729},{"id":2728},{"items":33234},[33235],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":33236},{"url":4881},"blog/the-case-for-best-of-breed-browser-security",{"json":33239},{"data":33240,"content":33241,"nodeType":856},{},[33242],{"data":33243,"content":33244,"nodeType":860},{},[33245],{"data":33246,"marks":33247,"value":25512,"nodeType":864},{},[],{"id":24943,"publishedAt":33249},"2026-08-13T09:35:07.376Z",{"items":33251},[33252,33254],{"sys":33253,"name":297},{"id":2732},{"sys":33255,"name":13779},{"id":13778},{"items":33257},[33258,33260,33262,33264,33266,33268,33270,33272,33274,33276,33278,33280,33282,33284,33286,33288,33290,33292,33294,33296],{"sys":33259,"name":297,"slug":298,"tier":31},{"id":294},{"sys":33261,"name":279,"slug":280,"tier":31},{"id":276},{"sys":33263,"name":413,"slug":414,"tier":31},{"id":410},{"sys":33265,"name":519,"slug":520,"tier":31},{"id":516},{"sys":33267,"name":342,"slug":343,"tier":31},{"id":339},{"sys":33269,"name":235,"slug":236,"tier":31},{"id":232},{"sys":33271,"name":261,"slug":262,"tier":45},{"id":258},{"sys":33273,"name":315,"slug":316,"tier":45},{"id":312},{"sys":33275,"name":360,"slug":361,"tier":45},{"id":357},{"sys":33277,"name":386,"slug":387,"tier":45},{"id":383},{"sys":33279,"name":333,"slug":334,"tier":45},{"id":330},{"sys":33281,"name":571,"slug":572,"tier":45},{"id":568},{"sys":33283,"name":484,"slug":485,"tier":45},{"id":481},{"sys":33285,"name":395,"slug":396,"tier":45},{"id":392},{"sys":33287,"name":589,"slug":590,"tier":45},{"id":586},{"sys":33289,"name":288,"slug":289,"tier":45},{"id":285},{"sys":33291,"name":511,"slug":512,"tier":45},{"id":508},{"sys":33293,"name":324,"slug":325,"tier":45},{"id":321},{"sys":33295,"name":580,"slug":581,"tier":45},{"id":577},{"sys":33297,"name":244,"slug":245,"tier":45},{"id":241},"ZdRUl9m2-G3Z9CEGGjFodkTk-e0uWBoLuwQs6a2oEzo",{"id":33300,"title":4865,"authorsCollection":33301,"content":33306,"extension":228,"faqItemsCollection":34581,"faqTitle":59,"featured":6,"hashTags":59,"meta":34583,"metaTitle":34584,"ogImage":59,"postType":5726,"publishedDate":4867,"relatedBlogPostsCollection":34585,"slug":4868,"stem":36209,"subtitle":59,"summary":36210,"synopsis":4866,"sys":36221,"tagsCollection":36223,"topicsCollection":36229,"__hash__":36281},"blog/blog/the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value.json",{"items":33302},[33303],{"fullName":4878,"firstName":4879,"jobTitle":851,"socialLinks":33304,"profilePicture":33305},[24316],{"url":4881},{"json":33307,"links":34375},{"data":33308,"content":33309,"nodeType":856},{},[33310,33323,33328,33334,33340,33345,33348,33355,33362,33377,33415,33420,33433,33436,33443,33450,33472,33504,33510,33513,33520,33527,33533,33538,33544,33547,33554,33561,33595,33625,33631,33634,33641,33648,33668,33674,33713,33719,33722,33729,33736,33772,33778,33783,33786,33793,33800,33826,33832,33837,33843,33846,33853,33860,33883,33889,33895,33901,33904,33911,33918,33924,33929,33935,33956,33979,33982,33989,33996,34002,34008,34011,34018,34073,34076,34083,34089,34357,34360],{"data":33311,"content":33312,"nodeType":860},{},[33313,33316,33320],{"data":33314,"marks":33315,"value":3639,"nodeType":864},{},[],{"data":33317,"marks":33318,"value":3644,"nodeType":864},{},[33319],{"type":899},{"data":33321,"marks":33322,"value":3648,"nodeType":864},{},[],{"data":33324,"content":33327,"nodeType":996},{"target":33325},{"sys":33326},{"id":3653,"type":1001,"linkType":1002},[],{"data":33329,"content":33330,"nodeType":860},{},[33331],{"data":33332,"marks":33333,"value":3661,"nodeType":864},{},[],{"data":33335,"content":33336,"nodeType":860},{},[33337],{"data":33338,"marks":33339,"value":3668,"nodeType":864},{},[],{"data":33341,"content":33344,"nodeType":996},{"target":33342},{"sys":33343},{"id":3673,"type":1001,"linkType":1002},[],{"data":33346,"content":33347,"nodeType":1005},{},[],{"data":33349,"content":33350,"nodeType":1009},{},[33351],{"data":33352,"marks":33353,"value":3685,"nodeType":864},{},[33354],{"type":899},{"data":33356,"content":33357,"nodeType":860},{},[33358],{"data":33359,"marks":33360,"value":3693,"nodeType":864},{},[33361],{"type":899},{"data":33363,"content":33364,"nodeType":860},{},[33365,33368,33374],{"data":33366,"marks":33367,"value":3700,"nodeType":864},{},[],{"data":33369,"content":33370,"nodeType":883},{"uri":3703},[33371],{"data":33372,"marks":33373,"value":3708,"nodeType":864},{},[],{"data":33375,"marks":33376,"value":3712,"nodeType":864},{},[],{"data":33378,"content":33379,"nodeType":860},{},[33380,33383,33389,33392,33396,33399,33403,33406,33412],{"data":33381,"marks":33382,"value":3719,"nodeType":864},{},[],{"data":33384,"content":33385,"nodeType":883},{"uri":3722},[33386],{"data":33387,"marks":33388,"value":3727,"nodeType":864},{},[],{"data":33390,"marks":33391,"value":3731,"nodeType":864},{},[],{"data":33393,"marks":33394,"value":3736,"nodeType":864},{},[33395],{"type":899},{"data":33397,"marks":33398,"value":2232,"nodeType":864},{},[],{"data":33400,"marks":33401,"value":3744,"nodeType":864},{},[33402],{"type":899},{"data":33404,"marks":33405,"value":3748,"nodeType":864},{},[],{"data":33407,"content":33408,"nodeType":883},{"uri":3751},[33409],{"data":33410,"marks":33411,"value":3756,"nodeType":864},{},[],{"data":33413,"marks":33414,"value":3760,"nodeType":864},{},[],{"data":33416,"content":33419,"nodeType":996},{"target":33417},{"sys":33418},{"id":3765,"type":1001,"linkType":1002},[],{"data":33421,"content":33422,"nodeType":860},{},[33423,33426,33430],{"data":33424,"marks":33425,"value":3773,"nodeType":864},{},[],{"data":33427,"marks":33428,"value":3778,"nodeType":864},{},[33429],{"type":899},{"data":33431,"marks":33432,"value":2924,"nodeType":864},{},[],{"data":33434,"content":33435,"nodeType":1005},{},[],{"data":33437,"content":33438,"nodeType":1009},{},[33439],{"data":33440,"marks":33441,"value":3792,"nodeType":864},{},[33442],{"type":899},{"data":33444,"content":33445,"nodeType":860},{},[33446],{"data":33447,"marks":33448,"value":3693,"nodeType":864},{},[33449],{"type":899},{"data":33451,"content":33452,"nodeType":860},{},[33453,33456,33462,33465,33469],{"data":33454,"marks":33455,"value":3806,"nodeType":864},{},[],{"data":33457,"content":33458,"nodeType":883},{"uri":3809},[33459],{"data":33460,"marks":33461,"value":3814,"nodeType":864},{},[],{"data":33463,"marks":33464,"value":3818,"nodeType":864},{},[],{"data":33466,"marks":33467,"value":3823,"nodeType":864},{},[33468],{"type":899},{"data":33470,"marks":33471,"value":3827,"nodeType":864},{},[],{"data":33473,"content":33474,"nodeType":860},{},[33475,33478,33484,33487,33491,33494,33501],{"data":33476,"marks":33477,"value":3834,"nodeType":864},{},[],{"data":33479,"content":33480,"nodeType":883},{"uri":3837},[33481],{"data":33482,"marks":33483,"value":3842,"nodeType":864},{},[],{"data":33485,"marks":33486,"value":3846,"nodeType":864},{},[],{"data":33488,"marks":33489,"value":3851,"nodeType":864},{},[33490],{"type":899},{"data":33492,"marks":33493,"value":3855,"nodeType":864},{},[],{"data":33495,"content":33496,"nodeType":883},{"uri":3858},[33497],{"data":33498,"marks":33499,"value":3864,"nodeType":864},{},[33500],{"type":899},{"data":33502,"marks":33503,"value":3868,"nodeType":864},{},[],{"data":33505,"content":33506,"nodeType":860},{},[33507],{"data":33508,"marks":33509,"value":3875,"nodeType":864},{},[],{"data":33511,"content":33512,"nodeType":1005},{},[],{"data":33514,"content":33515,"nodeType":1009},{},[33516],{"data":33517,"marks":33518,"value":3886,"nodeType":864},{},[33519],{"type":899},{"data":33521,"content":33522,"nodeType":860},{},[33523],{"data":33524,"marks":33525,"value":3894,"nodeType":864},{},[33526],{"type":899},{"data":33528,"content":33529,"nodeType":860},{},[33530],{"data":33531,"marks":33532,"value":3901,"nodeType":864},{},[],{"data":33534,"content":33537,"nodeType":996},{"target":33535},{"sys":33536},{"id":3906,"type":1001,"linkType":1002},[],{"data":33539,"content":33540,"nodeType":860},{},[33541],{"data":33542,"marks":33543,"value":3914,"nodeType":864},{},[],{"data":33545,"content":33546,"nodeType":1005},{},[],{"data":33548,"content":33549,"nodeType":1009},{},[33550],{"data":33551,"marks":33552,"value":3925,"nodeType":864},{},[33553],{"type":899},{"data":33555,"content":33556,"nodeType":860},{},[33557],{"data":33558,"marks":33559,"value":3894,"nodeType":864},{},[33560],{"type":899},{"data":33562,"content":33563,"nodeType":860},{},[33564,33567,33574,33577,33583,33586,33592],{"data":33565,"marks":33566,"value":3939,"nodeType":864},{},[],{"data":33568,"content":33569,"nodeType":883},{"uri":3942},[33570],{"data":33571,"marks":33572,"value":3948,"nodeType":864},{},[33573],{"type":1455},{"data":33575,"marks":33576,"value":3731,"nodeType":864},{},[],{"data":33578,"content":33579,"nodeType":883},{"uri":3954},[33580],{"data":33581,"marks":33582,"value":3959,"nodeType":864},{},[],{"data":33584,"marks":33585,"value":3731,"nodeType":864},{},[],{"data":33587,"content":33588,"nodeType":883},{"uri":3965},[33589],{"data":33590,"marks":33591,"value":3970,"nodeType":864},{},[],{"data":33593,"marks":33594,"value":3974,"nodeType":864},{},[],{"data":33596,"content":33597,"nodeType":860},{},[33598,33601,33608,33611,33615,33618,33622],{"data":33599,"marks":33600,"value":21,"nodeType":864},{},[],{"data":33602,"content":33603,"nodeType":883},{"uri":2411},[33604],{"data":33605,"marks":33606,"value":3988,"nodeType":864},{},[33607],{"type":1455},{"data":33609,"marks":33610,"value":3992,"nodeType":864},{},[],{"data":33612,"marks":33613,"value":3997,"nodeType":864},{},[33614],{"type":899},{"data":33616,"marks":33617,"value":4001,"nodeType":864},{},[],{"data":33619,"marks":33620,"value":4006,"nodeType":864},{},[33621],{"type":2246},{"data":33623,"marks":33624,"value":4010,"nodeType":864},{},[],{"data":33626,"content":33627,"nodeType":860},{},[33628],{"data":33629,"marks":33630,"value":4017,"nodeType":864},{},[],{"data":33632,"content":33633,"nodeType":1005},{},[],{"data":33635,"content":33636,"nodeType":1009},{},[33637],{"data":33638,"marks":33639,"value":4028,"nodeType":864},{},[33640],{"type":899},{"data":33642,"content":33643,"nodeType":860},{},[33644],{"data":33645,"marks":33646,"value":3894,"nodeType":864},{},[33647],{"type":899},{"data":33649,"content":33650,"nodeType":860},{},[33651,33654,33658,33661,33665],{"data":33652,"marks":33653,"value":4042,"nodeType":864},{},[],{"data":33655,"marks":33656,"value":4047,"nodeType":864},{},[33657],{"type":2246},{"data":33659,"marks":33660,"value":4051,"nodeType":864},{},[],{"data":33662,"marks":33663,"value":4056,"nodeType":864},{},[33664],{"type":2246},{"data":33666,"marks":33667,"value":4060,"nodeType":864},{},[],{"data":33669,"content":33670,"nodeType":860},{},[33671],{"data":33672,"marks":33673,"value":4067,"nodeType":864},{},[],{"data":33675,"content":33676,"nodeType":941},{},[33677,33695],{"data":33678,"content":33679,"nodeType":945},{},[33680],{"data":33681,"content":33682,"nodeType":860},{},[33683,33686,33692],{"data":33684,"marks":33685,"value":2761,"nodeType":864},{},[],{"data":33687,"content":33688,"nodeType":883},{"uri":4082},[33689],{"data":33690,"marks":33691,"value":4087,"nodeType":864},{},[],{"data":33693,"marks":33694,"value":4091,"nodeType":864},{},[],{"data":33696,"content":33697,"nodeType":945},{},[33698],{"data":33699,"content":33700,"nodeType":860},{},[33701,33704,33710],{"data":33702,"marks":33703,"value":2761,"nodeType":864},{},[],{"data":33705,"content":33706,"nodeType":883},{"uri":4103},[33707],{"data":33708,"marks":33709,"value":4108,"nodeType":864},{},[],{"data":33711,"marks":33712,"value":4112,"nodeType":864},{},[],{"data":33714,"content":33715,"nodeType":860},{},[33716],{"data":33717,"marks":33718,"value":4119,"nodeType":864},{},[],{"data":33720,"content":33721,"nodeType":1005},{},[],{"data":33723,"content":33724,"nodeType":1009},{},[33725],{"data":33726,"marks":33727,"value":4130,"nodeType":864},{},[33728],{"type":899},{"data":33730,"content":33731,"nodeType":860},{},[33732],{"data":33733,"marks":33734,"value":4138,"nodeType":864},{},[33735],{"type":899},{"data":33737,"content":33738,"nodeType":860},{},[33739,33742,33746,33749,33755,33758,33762,33765,33769],{"data":33740,"marks":33741,"value":4145,"nodeType":864},{},[],{"data":33743,"marks":33744,"value":4150,"nodeType":864},{},[33745],{"type":899},{"data":33747,"marks":33748,"value":4154,"nodeType":864},{},[],{"data":33750,"content":33751,"nodeType":883},{"uri":3237},[33752],{"data":33753,"marks":33754,"value":4161,"nodeType":864},{},[],{"data":33756,"marks":33757,"value":4165,"nodeType":864},{},[],{"data":33759,"marks":33760,"value":4170,"nodeType":864},{},[33761],{"type":899},{"data":33763,"marks":33764,"value":4174,"nodeType":864},{},[],{"data":33766,"marks":33767,"value":4179,"nodeType":864},{},[33768],{"type":899},{"data":33770,"marks":33771,"value":4183,"nodeType":864},{},[],{"data":33773,"content":33774,"nodeType":860},{},[33775],{"data":33776,"marks":33777,"value":4190,"nodeType":864},{},[],{"data":33779,"content":33782,"nodeType":996},{"target":33780},{"sys":33781},{"id":4195,"type":1001,"linkType":1002},[],{"data":33784,"content":33785,"nodeType":1005},{},[],{"data":33787,"content":33788,"nodeType":1009},{},[33789],{"data":33790,"marks":33791,"value":4207,"nodeType":864},{},[33792],{"type":899},{"data":33794,"content":33795,"nodeType":860},{},[33796],{"data":33797,"marks":33798,"value":4215,"nodeType":864},{},[33799],{"type":899},{"data":33801,"content":33802,"nodeType":860},{},[33803,33806,33813,33816,33823],{"data":33804,"marks":33805,"value":4222,"nodeType":864},{},[],{"data":33807,"content":33808,"nodeType":883},{"uri":2561},[33809],{"data":33810,"marks":33811,"value":4230,"nodeType":864},{},[33812],{"type":899},{"data":33814,"marks":33815,"value":4234,"nodeType":864},{},[],{"data":33817,"content":33818,"nodeType":883},{"uri":4237},[33819],{"data":33820,"marks":33821,"value":4243,"nodeType":864},{},[33822],{"type":899},{"data":33824,"marks":33825,"value":4247,"nodeType":864},{},[],{"data":33827,"content":33828,"nodeType":860},{},[33829],{"data":33830,"marks":33831,"value":4254,"nodeType":864},{},[],{"data":33833,"content":33836,"nodeType":996},{"target":33834},{"sys":33835},{"id":4259,"type":1001,"linkType":1002},[],{"data":33838,"content":33839,"nodeType":860},{},[33840],{"data":33841,"marks":33842,"value":4267,"nodeType":864},{},[],{"data":33844,"content":33845,"nodeType":1005},{},[],{"data":33847,"content":33848,"nodeType":1009},{},[33849],{"data":33850,"marks":33851,"value":4278,"nodeType":864},{},[33852],{"type":899},{"data":33854,"content":33855,"nodeType":860},{},[33856],{"data":33857,"marks":33858,"value":4286,"nodeType":864},{},[33859],{"type":899},{"data":33861,"content":33862,"nodeType":860},{},[33863,33866,33870,33873,33880],{"data":33864,"marks":33865,"value":4293,"nodeType":864},{},[],{"data":33867,"marks":33868,"value":4298,"nodeType":864},{},[33869],{"type":2246},{"data":33871,"marks":33872,"value":4302,"nodeType":864},{},[],{"data":33874,"content":33875,"nodeType":883},{"uri":4305},[33876],{"data":33877,"marks":33878,"value":4311,"nodeType":864},{},[33879],{"type":899},{"data":33881,"marks":33882,"value":4315,"nodeType":864},{},[],{"data":33884,"content":33885,"nodeType":860},{},[33886],{"data":33887,"marks":33888,"value":4322,"nodeType":864},{},[],{"data":33890,"content":33891,"nodeType":860},{},[33892],{"data":33893,"marks":33894,"value":4329,"nodeType":864},{},[],{"data":33896,"content":33897,"nodeType":860},{},[33898],{"data":33899,"marks":33900,"value":4336,"nodeType":864},{},[],{"data":33902,"content":33903,"nodeType":1005},{},[],{"data":33905,"content":33906,"nodeType":1009},{},[33907],{"data":33908,"marks":33909,"value":4347,"nodeType":864},{},[33910],{"type":899},{"data":33912,"content":33913,"nodeType":860},{},[33914],{"data":33915,"marks":33916,"value":4355,"nodeType":864},{},[33917],{"type":899},{"data":33919,"content":33920,"nodeType":860},{},[33921],{"data":33922,"marks":33923,"value":4362,"nodeType":864},{},[],{"data":33925,"content":33928,"nodeType":996},{"target":33926},{"sys":33927},{"id":4367,"type":1001,"linkType":1002},[],{"data":33930,"content":33931,"nodeType":860},{},[33932],{"data":33933,"marks":33934,"value":4375,"nodeType":864},{},[],{"data":33936,"content":33937,"nodeType":941},{},[33938,33947],{"data":33939,"content":33940,"nodeType":945},{},[33941],{"data":33942,"content":33943,"nodeType":860},{},[33944],{"data":33945,"marks":33946,"value":4388,"nodeType":864},{},[],{"data":33948,"content":33949,"nodeType":945},{},[33950],{"data":33951,"content":33952,"nodeType":860},{},[33953],{"data":33954,"marks":33955,"value":4398,"nodeType":864},{},[],{"data":33957,"content":33958,"nodeType":860},{},[33959,33962,33969,33972,33976],{"data":33960,"marks":33961,"value":4405,"nodeType":864},{},[],{"data":33963,"content":33964,"nodeType":883},{"uri":4408},[33965],{"data":33966,"marks":33967,"value":4414,"nodeType":864},{},[33968],{"type":899},{"data":33970,"marks":33971,"value":4418,"nodeType":864},{},[],{"data":33973,"marks":33974,"value":4423,"nodeType":864},{},[33975],{"type":2246},{"data":33977,"marks":33978,"value":4427,"nodeType":864},{},[],{"data":33980,"content":33981,"nodeType":1005},{},[],{"data":33983,"content":33984,"nodeType":1009},{},[33985],{"data":33986,"marks":33987,"value":4438,"nodeType":864},{},[33988],{"type":899},{"data":33990,"content":33991,"nodeType":860},{},[33992],{"data":33993,"marks":33994,"value":4446,"nodeType":864},{},[33995],{"type":899},{"data":33997,"content":33998,"nodeType":860},{},[33999],{"data":34000,"marks":34001,"value":4453,"nodeType":864},{},[],{"data":34003,"content":34004,"nodeType":860},{},[34005],{"data":34006,"marks":34007,"value":4460,"nodeType":864},{},[],{"data":34009,"content":34010,"nodeType":1005},{},[],{"data":34012,"content":34013,"nodeType":1009},{},[34014],{"data":34015,"marks":34016,"value":4471,"nodeType":864},{},[34017],{"type":899},{"data":34019,"content":34020,"nodeType":941},{},[34021,34034,34047,34060],{"data":34022,"content":34023,"nodeType":945},{},[34024],{"data":34025,"content":34026,"nodeType":860},{},[34027,34031],{"data":34028,"marks":34029,"value":4485,"nodeType":864},{},[34030],{"type":899},{"data":34032,"marks":34033,"value":4489,"nodeType":864},{},[],{"data":34035,"content":34036,"nodeType":945},{},[34037],{"data":34038,"content":34039,"nodeType":860},{},[34040,34044],{"data":34041,"marks":34042,"value":4500,"nodeType":864},{},[34043],{"type":899},{"data":34045,"marks":34046,"value":4504,"nodeType":864},{},[],{"data":34048,"content":34049,"nodeType":945},{},[34050],{"data":34051,"content":34052,"nodeType":860},{},[34053,34057],{"data":34054,"marks":34055,"value":4515,"nodeType":864},{},[34056],{"type":899},{"data":34058,"marks":34059,"value":4519,"nodeType":864},{},[],{"data":34061,"content":34062,"nodeType":945},{},[34063],{"data":34064,"content":34065,"nodeType":860},{},[34066,34070],{"data":34067,"marks":34068,"value":781,"nodeType":864},{},[34069],{"type":899},{"data":34071,"marks":34072,"value":4533,"nodeType":864},{},[],{"data":34074,"content":34075,"nodeType":1005},{},[],{"data":34077,"content":34078,"nodeType":1009},{},[34079],{"data":34080,"marks":34081,"value":4544,"nodeType":864},{},[34082],{"type":899},{"data":34084,"content":34085,"nodeType":860},{},[34086],{"data":34087,"marks":34088,"value":4551,"nodeType":864},{},[],{"data":34090,"content":34091,"nodeType":4845},{},[34092,34115,34137,34159,34181,34203,34225,34247,34269,34291,34313,34335],{"data":34093,"content":34094,"nodeType":4581},{},[34095,34105],{"data":34096,"content":34097,"nodeType":4569},{},[34098],{"data":34099,"content":34100,"nodeType":860},{},[34101],{"data":34102,"marks":34103,"value":4568,"nodeType":864},{},[34104],{"type":899},{"data":34106,"content":34107,"nodeType":4569},{},[34108],{"data":34109,"content":34110,"nodeType":860},{},[34111],{"data":34112,"marks":34113,"value":4580,"nodeType":864},{},[34114],{"type":899},{"data":34116,"content":34117,"nodeType":4581},{},[34118,34128],{"data":34119,"content":34120,"nodeType":4569},{},[34121],{"data":34122,"content":34123,"nodeType":860},{},[34124],{"data":34125,"marks":34126,"value":4595,"nodeType":864},{},[34127],{"type":899},{"data":34129,"content":34130,"nodeType":4569},{},[34131],{"data":34132,"content":34133,"nodeType":860},{},[34134],{"data":34135,"marks":34136,"value":4605,"nodeType":864},{},[],{"data":34138,"content":34139,"nodeType":4581},{},[34140,34150],{"data":34141,"content":34142,"nodeType":4569},{},[34143],{"data":34144,"content":34145,"nodeType":860},{},[34146],{"data":34147,"marks":34148,"value":4619,"nodeType":864},{},[34149],{"type":899},{"data":34151,"content":34152,"nodeType":4569},{},[34153],{"data":34154,"content":34155,"nodeType":860},{},[34156],{"data":34157,"marks":34158,"value":4629,"nodeType":864},{},[],{"data":34160,"content":34161,"nodeType":4581},{},[34162,34172],{"data":34163,"content":34164,"nodeType":4569},{},[34165],{"data":34166,"content":34167,"nodeType":860},{},[34168],{"data":34169,"marks":34170,"value":4643,"nodeType":864},{},[34171],{"type":899},{"data":34173,"content":34174,"nodeType":4569},{},[34175],{"data":34176,"content":34177,"nodeType":860},{},[34178],{"data":34179,"marks":34180,"value":4653,"nodeType":864},{},[],{"data":34182,"content":34183,"nodeType":4581},{},[34184,34194],{"data":34185,"content":34186,"nodeType":4569},{},[34187],{"data":34188,"content":34189,"nodeType":860},{},[34190],{"data":34191,"marks":34192,"value":4667,"nodeType":864},{},[34193],{"type":899},{"data":34195,"content":34196,"nodeType":4569},{},[34197],{"data":34198,"content":34199,"nodeType":860},{},[34200],{"data":34201,"marks":34202,"value":4677,"nodeType":864},{},[],{"data":34204,"content":34205,"nodeType":4581},{},[34206,34216],{"data":34207,"content":34208,"nodeType":4569},{},[34209],{"data":34210,"content":34211,"nodeType":860},{},[34212],{"data":34213,"marks":34214,"value":4691,"nodeType":864},{},[34215],{"type":899},{"data":34217,"content":34218,"nodeType":4569},{},[34219],{"data":34220,"content":34221,"nodeType":860},{},[34222],{"data":34223,"marks":34224,"value":4701,"nodeType":864},{},[],{"data":34226,"content":34227,"nodeType":4581},{},[34228,34238],{"data":34229,"content":34230,"nodeType":4569},{},[34231],{"data":34232,"content":34233,"nodeType":860},{},[34234],{"data":34235,"marks":34236,"value":4715,"nodeType":864},{},[34237],{"type":899},{"data":34239,"content":34240,"nodeType":4569},{},[34241],{"data":34242,"content":34243,"nodeType":860},{},[34244],{"data":34245,"marks":34246,"value":4725,"nodeType":864},{},[],{"data":34248,"content":34249,"nodeType":4581},{},[34250,34260],{"data":34251,"content":34252,"nodeType":4569},{},[34253],{"data":34254,"content":34255,"nodeType":860},{},[34256],{"data":34257,"marks":34258,"value":4739,"nodeType":864},{},[34259],{"type":899},{"data":34261,"content":34262,"nodeType":4569},{},[34263],{"data":34264,"content":34265,"nodeType":860},{},[34266],{"data":34267,"marks":34268,"value":4749,"nodeType":864},{},[],{"data":34270,"content":34271,"nodeType":4581},{},[34272,34282],{"data":34273,"content":34274,"nodeType":4569},{},[34275],{"data":34276,"content":34277,"nodeType":860},{},[34278],{"data":34279,"marks":34280,"value":4763,"nodeType":864},{},[34281],{"type":899},{"data":34283,"content":34284,"nodeType":4569},{},[34285],{"data":34286,"content":34287,"nodeType":860},{},[34288],{"data":34289,"marks":34290,"value":4773,"nodeType":864},{},[],{"data":34292,"content":34293,"nodeType":4581},{},[34294,34304],{"data":34295,"content":34296,"nodeType":4569},{},[34297],{"data":34298,"content":34299,"nodeType":860},{},[34300],{"data":34301,"marks":34302,"value":4787,"nodeType":864},{},[34303],{"type":899},{"data":34305,"content":34306,"nodeType":4569},{},[34307],{"data":34308,"content":34309,"nodeType":860},{},[34310],{"data":34311,"marks":34312,"value":4797,"nodeType":864},{},[],{"data":34314,"content":34315,"nodeType":4581},{},[34316,34326],{"data":34317,"content":34318,"nodeType":4569},{},[34319],{"data":34320,"content":34321,"nodeType":860},{},[34322],{"data":34323,"marks":34324,"value":4811,"nodeType":864},{},[34325],{"type":899},{"data":34327,"content":34328,"nodeType":4569},{},[34329],{"data":34330,"content":34331,"nodeType":860},{},[34332],{"data":34333,"marks":34334,"value":4821,"nodeType":864},{},[],{"data":34336,"content":34337,"nodeType":4581},{},[34338,34348],{"data":34339,"content":34340,"nodeType":4569},{},[34341],{"data":34342,"content":34343,"nodeType":860},{},[34344],{"data":34345,"marks":34346,"value":4500,"nodeType":864},{},[34347],{"type":899},{"data":34349,"content":34350,"nodeType":4569},{},[34351],{"data":34352,"content":34353,"nodeType":860},{},[34354],{"data":34355,"marks":34356,"value":4844,"nodeType":864},{},[],{"data":34358,"content":34359,"nodeType":1005},{},[],{"data":34361,"content":34362,"nodeType":860},{},[34363,34366,34372],{"data":34364,"marks":34365,"value":4855,"nodeType":864},{},[],{"data":34367,"content":34368,"nodeType":883},{"uri":1700},[34369],{"data":34370,"marks":34371,"value":1703,"nodeType":864},{},[],{"data":34373,"marks":34374,"value":21,"nodeType":864},{},[],{"entries":34376},{"hyperlink":34377,"inline":34378,"block":34379},[],[],[34380,34422,34430,34464,34500,34524,34538],{"sys":34381,"__typename":1740,"content":34382,"name":34421,"title":59},{"id":3653},{"json":34383},{"nodeType":856,"data":34384,"content":34385},{},[34386],{"nodeType":860,"data":34387,"content":34388},{},[34389,34392,34399,34403,34408,34412,34417],{"nodeType":864,"value":3719,"marks":34390,"data":34391},[],{},{"nodeType":883,"data":34393,"content":34394},{"uri":2561},[34395],{"nodeType":864,"value":34396,"marks":34397,"data":34398},"Omdia's 2026 research",[],{},{"nodeType":864,"value":34400,"marks":34401,"data":34402},", browser security is already a top-five priority for ",[],{},{"nodeType":864,"value":34404,"marks":34405,"data":34407},"88% of organizations",[34406],{"type":899},{},{"nodeType":864,"value":34409,"marks":34410,"data":34411},", and the top priority for ",[],{},{"nodeType":864,"value":34413,"marks":34414,"data":34416},"26%",[34415],{"type":899},{},{"nodeType":864,"value":34418,"marks":34419,"data":34420},". Of those that have deployed browser security solutions, the results speak for themselves: security leaders consistently report high satisfaction with the visibility and control they gain at a layer that was previously a blind spot.",[],{},"Top 10 Browser Problems IB1",{"sys":34423,"__typename":1724,"title":34424,"caption":34425,"layoutMode":59,"file":34426},{"id":3673},"top 10 browser security infographic","The top 10 security problems you can solve in the browser, ranked by security value and browser fit.",{"url":34427,"width":34428,"height":34429},"https://images.ctfassets.net/y1cdw1ablpvd/1ARDI5m8UJTN9QXXfbyyeO/ad04834463f3537a724ecfcaa0054fb0/top10_browser_security_infographic_4x__14_.png",2080,2484,{"sys":34431,"__typename":1740,"content":34432,"name":34463,"title":59},{"id":3765},{"json":34433},{"nodeType":856,"data":34434,"content":34435},{},[34436],{"nodeType":860,"data":34437,"content":34438},{},[34439,34443,34450,34454,34459],{"nodeType":864,"value":34440,"marks":34441,"data":34442},"Every login, regardless of method or app, happens inside a browser session. That makes the browser the only layer capable of observing the complete authentication picture. ",[],{},{"nodeType":883,"data":34444,"content":34445},{"uri":25338},[34446],{"nodeType":864,"value":34447,"marks":34448,"data":34449},"Push's telemetry illustrates the gap",[],{},{"nodeType":864,"value":34451,"marks":34452,"data":34453},": of the last million logins observed, ",[],{},{"nodeType":864,"value":34455,"marks":34456,"data":34458},"1 in 4 were password logins rather than SSO, 2 in 5 lacked MFA, and 1 in 5 used a weak, breached, or reused credential",[34457],{"type":899},{},{"nodeType":864,"value":34460,"marks":34461,"data":34462}," — none of which is visible to an IdP that only surfaces authentications flowing through it. ",[],{},"Top 10 Browser Problems IB2",{"sys":34465,"__typename":1740,"content":34466,"name":34499,"title":59},{"id":3906},{"json":34467},{"data":34468,"content":34469,"nodeType":856},{},[34470],{"data":34471,"content":34472,"nodeType":860},{},[34473,34477,34482,34486,34495],{"data":34474,"marks":34475,"value":34476,"nodeType":864},{},[],"The average employee logs into more than 15 applications, the majority with logins outside SSO coverage. IdP policies and SSPM findings have no mechanism to intervene in authentication flows they don't control. ",{"data":34478,"marks":34479,"value":34481,"nodeType":864},{},[34480],{"type":899},"47% of BEC victims had not enforced MFA in their Microsoft 365 environment",{"data":34483,"marks":34484,"value":34485,"nodeType":864},{},[]," (",{"data":34487,"content":34489,"nodeType":883},{"uri":34488},"https://www.s-rminform.com/cyber-insights-report-2026",[34490],{"data":34491,"marks":34492,"value":34494,"nodeType":864},{},[34493],{"type":1455},"S-RM Cyber Insights 2026",{"data":34496,"marks":34497,"value":34498,"nodeType":864},{},[],") — and the gap is larger still once you consider shadow SaaS.","Top 10 Browser Problems IB3",{"sys":34501,"__typename":1740,"content":34502,"name":34523,"title":59},{"id":4195},{"json":34503},{"data":34504,"content":34505,"nodeType":856},{},[34506],{"data":34507,"content":34508,"nodeType":860},{},[34509,34512,34519],{"data":34510,"marks":34511,"value":21,"nodeType":864},{},[],{"data":34513,"content":34514,"nodeType":883},{"uri":6940},[34515],{"data":34516,"marks":34517,"value":11731,"nodeType":864},{},[34518],{"type":1455},{"data":34520,"marks":34521,"value":34522,"nodeType":864},{},[],", a novel technique discovered by Push researchers when we intercepted a live campaign attributed to Russian state-linked APT29, is a notable exception: it is fully browser-native with no endpoint component, using a manipulated OAuth consent flow rather than clipboard-injected malware. ConsentFix is better understood as an OAuth attack than a malware delivery technique — it signals the direction of travel as attackers seek to eliminate the endpoint detection surface entirely and operate purely within browser-native mechanisms like OAuth. ","Top 10 Browser Problems IB4",{"sys":34525,"__typename":1740,"content":34526,"name":34537,"title":59},{"id":4259},{"json":34527},{"data":34528,"content":34529,"nodeType":856},{},[34530],{"data":34531,"content":34532,"nodeType":860},{},[34533],{"data":34534,"marks":34535,"value":34536,"nodeType":864},{},[],"Enterprise AI platforms — Claude, ChatGPT Enterprise, Microsoft Copilot, Gemini for Workspace — increasingly provide native prompt logging and DLP controls on their enterprise plans, and these are richer and more reliable for sanctioned tools than browser session-layer monitoring. The right architecture is complementary: use the browser to enforce which AI tools employees can access and ensure they reach the corporate tenant rather than a personal account, then rely on platform-native controls to govern activity within that environment.","Top 10 Browser Problems IB5",{"sys":34539,"__typename":1740,"content":34540,"name":34580,"title":59},{"id":4367},{"json":34541},{"data":34542,"content":34543,"nodeType":856},{},[34544],{"data":34545,"content":34546,"nodeType":860},{},[34547,34551,34556,34560,34565,34569,34576],{"data":34548,"marks":34549,"value":34550,"nodeType":864},{},[],"The 2025 Verizon DBIR found ",{"data":34552,"marks":34553,"value":34555,"nodeType":864},{},[34554],{"type":899},"54% of ransomware attacks traced back to infostealer-enabled credential theft",{"data":34557,"marks":34558,"value":34559,"nodeType":864},{},[],". Microsoft reports ",{"data":34561,"marks":34562,"value":34564,"nodeType":864},{},[34563],{"type":899},"39,000 session token attacks per day",{"data":34566,"marks":34567,"value":34568,"nodeType":864},{},[],", the majority sourced from infostealer-harvested cookies. The",{"data":34570,"content":34571,"nodeType":883},{"uri":3751},[34572],{"data":34573,"marks":34574,"value":34575,"nodeType":864},{},[]," Snowflake breach",{"data":34577,"marks":34578,"value":34579,"nodeType":864},{},[]," we mentioned earlier was powered entirely by infostealer-harvested credentials: stolen years earlier, never rotated, and used to authenticate directly to tenants that lacked MFA. More than 80% of compromised accounts had prior credential exposure. The Okta breach followed the same pattern, beginning with an infostealer on an engineer's personal device harvesting credentials synced to their personal Google profile on a corporate browser. ","Top 10 Browser Problems IB6",{"items":34582},[],{},"The top 10 security problems you can solve in the browser",{"items":34586},[34587,35095,35767],{"__typename":2059,"sys":34588,"content":34589,"title":28621,"synopsis":28622,"hashTags":59,"publishedDate":26293,"slug":28623,"tagsCollection":35085,"authorsCollection":35091},{"id":28048},{"json":34590},{"data":34591,"content":34592,"nodeType":856},{},[34593,34608,34614,34620,34625,34628,34635,34648,34654,34659,34665,34740,34746,34751,34757,34762,34765,34772,34782,34788,34798,34801,34808,34821,34827,34833,34836,34843,34849,34862,34867,34880,34886,34892,34898,34911,34917,34920,34927,34933,34946,34952,34955,34962,34975,34981,34997,35007,35010,35017,35030,35036,35042,35048,35054,35057,35063,35069],{"data":34594,"content":34595,"nodeType":860},{},[34596,34599,34605],{"data":34597,"marks":34598,"value":2761,"nodeType":864},{},[],{"data":34600,"content":34601,"nodeType":883},{"uri":28061},[34602],{"data":34603,"marks":34604,"value":28066,"nodeType":864},{},[],{"data":34606,"marks":34607,"value":28070,"nodeType":864},{},[],{"data":34609,"content":34610,"nodeType":860},{},[34611],{"data":34612,"marks":34613,"value":28077,"nodeType":864},{},[],{"data":34615,"content":34616,"nodeType":860},{},[34617],{"data":34618,"marks":34619,"value":28084,"nodeType":864},{},[],{"data":34621,"content":34624,"nodeType":996},{"target":34622},{"sys":34623},{"id":28089,"type":1001,"linkType":1002},[],{"data":34626,"content":34627,"nodeType":1005},{},[],{"data":34629,"content":34630,"nodeType":1009},{},[34631],{"data":34632,"marks":34633,"value":28101,"nodeType":864},{},[34634],{"type":899},{"data":34636,"content":34637,"nodeType":860},{},[34638,34641,34645],{"data":34639,"marks":34640,"value":28108,"nodeType":864},{},[],{"data":34642,"marks":34643,"value":28113,"nodeType":864},{},[34644],{"type":899},{"data":34646,"marks":34647,"value":28117,"nodeType":864},{},[],{"data":34649,"content":34650,"nodeType":860},{},[34651],{"data":34652,"marks":34653,"value":28124,"nodeType":864},{},[],{"data":34655,"content":34658,"nodeType":996},{"target":34656},{"sys":34657},{"id":28129,"type":1001,"linkType":1002},[],{"data":34660,"content":34661,"nodeType":860},{},[34662],{"data":34663,"marks":34664,"value":28137,"nodeType":864},{},[],{"data":34666,"content":34667,"nodeType":941},{},[34668,34677,34686,34695,34704,34713,34722,34731],{"data":34669,"content":34670,"nodeType":945},{},[34671],{"data":34672,"content":34673,"nodeType":860},{},[34674],{"data":34675,"marks":34676,"value":28150,"nodeType":864},{},[],{"data":34678,"content":34679,"nodeType":945},{},[34680],{"data":34681,"content":34682,"nodeType":860},{},[34683],{"data":34684,"marks":34685,"value":28160,"nodeType":864},{},[],{"data":34687,"content":34688,"nodeType":945},{},[34689],{"data":34690,"content":34691,"nodeType":860},{},[34692],{"data":34693,"marks":34694,"value":28170,"nodeType":864},{},[],{"data":34696,"content":34697,"nodeType":945},{},[34698],{"data":34699,"content":34700,"nodeType":860},{},[34701],{"data":34702,"marks":34703,"value":28180,"nodeType":864},{},[],{"data":34705,"content":34706,"nodeType":945},{},[34707],{"data":34708,"content":34709,"nodeType":860},{},[34710],{"data":34711,"marks":34712,"value":28190,"nodeType":864},{},[],{"data":34714,"content":34715,"nodeType":945},{},[34716],{"data":34717,"content":34718,"nodeType":860},{},[34719],{"data":34720,"marks":34721,"value":28200,"nodeType":864},{},[],{"data":34723,"content":34724,"nodeType":945},{},[34725],{"data":34726,"content":34727,"nodeType":860},{},[34728],{"data":34729,"marks":34730,"value":28210,"nodeType":864},{},[],{"data":34732,"content":34733,"nodeType":945},{},[34734],{"data":34735,"content":34736,"nodeType":860},{},[34737],{"data":34738,"marks":34739,"value":28220,"nodeType":864},{},[],{"data":34741,"content":34742,"nodeType":860},{},[34743],{"data":34744,"marks":34745,"value":28227,"nodeType":864},{},[],{"data":34747,"content":34750,"nodeType":996},{"target":34748},{"sys":34749},{"id":23546,"type":1001,"linkType":1002},[],{"data":34752,"content":34753,"nodeType":860},{},[34754],{"data":34755,"marks":34756,"value":28239,"nodeType":864},{},[],{"data":34758,"content":34761,"nodeType":996},{"target":34759},{"sys":34760},{"id":28244,"type":1001,"linkType":1002},[],{"data":34763,"content":34764,"nodeType":1005},{},[],{"data":34766,"content":34767,"nodeType":1009},{},[34768],{"data":34769,"marks":34770,"value":28256,"nodeType":864},{},[34771],{"type":899},{"data":34773,"content":34774,"nodeType":860},{},[34775,34779],{"data":34776,"marks":34777,"value":28264,"nodeType":864},{},[34778],{"type":899},{"data":34780,"marks":34781,"value":28268,"nodeType":864},{},[],{"data":34783,"content":34784,"nodeType":860},{},[34785],{"data":34786,"marks":34787,"value":28275,"nodeType":864},{},[],{"data":34789,"content":34790,"nodeType":860},{},[34791,34795],{"data":34792,"marks":34793,"value":28283,"nodeType":864},{},[34794],{"type":899},{"data":34796,"marks":34797,"value":28287,"nodeType":864},{},[],{"data":34799,"content":34800,"nodeType":1005},{},[],{"data":34802,"content":34803,"nodeType":1009},{},[34804],{"data":34805,"marks":34806,"value":28298,"nodeType":864},{},[34807],{"type":899},{"data":34809,"content":34810,"nodeType":860},{},[34811,34814,34818],{"data":34812,"marks":34813,"value":28305,"nodeType":864},{},[],{"data":34815,"marks":34816,"value":24968,"nodeType":864},{},[34817],{"type":899},{"data":34819,"marks":34820,"value":28313,"nodeType":864},{},[],{"data":34822,"content":34823,"nodeType":860},{},[34824],{"data":34825,"marks":34826,"value":28320,"nodeType":864},{},[],{"data":34828,"content":34829,"nodeType":860},{},[34830],{"data":34831,"marks":34832,"value":28327,"nodeType":864},{},[],{"data":34834,"content":34835,"nodeType":1005},{},[],{"data":34837,"content":34838,"nodeType":1009},{},[34839],{"data":34840,"marks":34841,"value":28338,"nodeType":864},{},[34842],{"type":899},{"data":34844,"content":34845,"nodeType":860},{},[34846],{"data":34847,"marks":34848,"value":28345,"nodeType":864},{},[],{"data":34850,"content":34851,"nodeType":860},{},[34852,34855,34859],{"data":34853,"marks":34854,"value":28352,"nodeType":864},{},[],{"data":34856,"marks":34857,"value":28357,"nodeType":864},{},[34858],{"type":899},{"data":34860,"marks":34861,"value":28361,"nodeType":864},{},[],{"data":34863,"content":34866,"nodeType":996},{"target":34864},{"sys":34865},{"id":28366,"type":1001,"linkType":1002},[],{"data":34868,"content":34869,"nodeType":860},{},[34870,34873,34877],{"data":34871,"marks":34872,"value":28374,"nodeType":864},{},[],{"data":34874,"marks":34875,"value":28379,"nodeType":864},{},[34876],{"type":899},{"data":34878,"marks":34879,"value":28383,"nodeType":864},{},[],{"data":34881,"content":34882,"nodeType":860},{},[34883],{"data":34884,"marks":34885,"value":28390,"nodeType":864},{},[],{"data":34887,"content":34888,"nodeType":860},{},[34889],{"data":34890,"marks":34891,"value":28397,"nodeType":864},{},[],{"data":34893,"content":34894,"nodeType":860},{},[34895],{"data":34896,"marks":34897,"value":28404,"nodeType":864},{},[],{"data":34899,"content":34900,"nodeType":860},{},[34901,34904,34908],{"data":34902,"marks":34903,"value":28411,"nodeType":864},{},[],{"data":34905,"marks":34906,"value":28416,"nodeType":864},{},[34907],{"type":899},{"data":34909,"marks":34910,"value":28420,"nodeType":864},{},[],{"data":34912,"content":34913,"nodeType":860},{},[34914],{"data":34915,"marks":34916,"value":28427,"nodeType":864},{},[],{"data":34918,"content":34919,"nodeType":1005},{},[],{"data":34921,"content":34922,"nodeType":1009},{},[34923],{"data":34924,"marks":34925,"value":28438,"nodeType":864},{},[34926],{"type":899},{"data":34928,"content":34929,"nodeType":860},{},[34930],{"data":34931,"marks":34932,"value":28445,"nodeType":864},{},[],{"data":34934,"content":34935,"nodeType":860},{},[34936,34939,34943],{"data":34937,"marks":34938,"value":28452,"nodeType":864},{},[],{"data":34940,"marks":34941,"value":28457,"nodeType":864},{},[34942],{"type":899},{"data":34944,"marks":34945,"value":28461,"nodeType":864},{},[],{"data":34947,"content":34948,"nodeType":860},{},[34949],{"data":34950,"marks":34951,"value":28468,"nodeType":864},{},[],{"data":34953,"content":34954,"nodeType":1005},{},[],{"data":34956,"content":34957,"nodeType":1009},{},[34958],{"data":34959,"marks":34960,"value":28479,"nodeType":864},{},[34961],{"type":899},{"data":34963,"content":34964,"nodeType":860},{},[34965,34968,34972],{"data":34966,"marks":34967,"value":28486,"nodeType":864},{},[],{"data":34969,"marks":34970,"value":28491,"nodeType":864},{},[34971],{"type":899},{"data":34973,"marks":34974,"value":28495,"nodeType":864},{},[],{"data":34976,"content":34977,"nodeType":860},{},[34978],{"data":34979,"marks":34980,"value":28502,"nodeType":864},{},[],{"data":34982,"content":34983,"nodeType":860},{},[34984,34987,34994],{"data":34985,"marks":34986,"value":28509,"nodeType":864},{},[],{"data":34988,"content":34989,"nodeType":883},{"uri":11674},[34990],{"data":34991,"marks":34992,"value":28517,"nodeType":864},{},[34993],{"type":1455},{"data":34995,"marks":34996,"value":28521,"nodeType":864},{},[],{"data":34998,"content":34999,"nodeType":860},{},[35000,35003],{"data":35001,"marks":35002,"value":28528,"nodeType":864},{},[],{"data":35004,"marks":35005,"value":28533,"nodeType":864},{},[35006],{"type":899},{"data":35008,"content":35009,"nodeType":1005},{},[],{"data":35011,"content":35012,"nodeType":1009},{},[35013],{"data":35014,"marks":35015,"value":28544,"nodeType":864},{},[35016],{"type":899},{"data":35018,"content":35019,"nodeType":860},{},[35020,35023,35027],{"data":35021,"marks":35022,"value":28551,"nodeType":864},{},[],{"data":35024,"marks":35025,"value":28556,"nodeType":864},{},[35026],{"type":899},{"data":35028,"marks":35029,"value":28560,"nodeType":864},{},[],{"data":35031,"content":35032,"nodeType":860},{},[35033],{"data":35034,"marks":35035,"value":28567,"nodeType":864},{},[],{"data":35037,"content":35038,"nodeType":860},{},[35039],{"data":35040,"marks":35041,"value":28574,"nodeType":864},{},[],{"data":35043,"content":35044,"nodeType":860},{},[35045],{"data":35046,"marks":35047,"value":28581,"nodeType":864},{},[],{"data":35049,"content":35050,"nodeType":860},{},[35051],{"data":35052,"marks":35053,"value":28588,"nodeType":864},{},[],{"data":35055,"content":35056,"nodeType":1005},{},[],{"data":35058,"content":35059,"nodeType":860},{},[35060],{"data":35061,"marks":35062,"value":28598,"nodeType":864},{},[],{"data":35064,"content":35065,"nodeType":860},{},[35066],{"data":35067,"marks":35068,"value":1689,"nodeType":864},{},[],{"data":35070,"content":35071,"nodeType":860},{},[35072,35075,35082],{"data":35073,"marks":35074,"value":21,"nodeType":864},{},[],{"data":35076,"content":35077,"nodeType":883},{"uri":1700},[35078],{"data":35079,"marks":35080,"value":13763,"nodeType":864},{},[35081],{"type":1455},{"data":35083,"marks":35084,"value":2719,"nodeType":864},{},[],{"items":35086},[35087,35089],{"sys":35088,"name":297},{"id":2732},{"sys":35090,"name":2729},{"id":2728},{"items":35092},[35093],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":35094},{"url":2740},{"__typename":2059,"sys":35096,"content":35097,"title":26291,"synopsis":26292,"hashTags":59,"publishedDate":26293,"slug":26294,"tagsCollection":35757,"authorsCollection":35763},{"id":25527},{"json":35098},{"data":35099,"content":35100,"nodeType":856},{},[35101,35106,35112,35118,35124,35127,35134,35140,35150,35160,35165,35171,35174,35181,35187,35192,35198,35204,35297,35303,35306,35313,35319,35374,35387,35392,35398,35401,35408,35414,35421,35427,35433,35458,35464,35471,35477,35483,35489,35496,35502,35508,35514,35517,35524,35534,35540,35546,35553,35559,35565,35572,35578,35633,35646,35661,35668,35674,35681,35687,35693,35699,35704,35711,35717,35723,35728,35734,35740,35746,35751],{"data":35102,"content":35105,"nodeType":996},{"target":35103},{"sys":35104},{"id":25536,"type":1001,"linkType":1002},[],{"data":35107,"content":35108,"nodeType":860},{},[35109],{"data":35110,"marks":35111,"value":25544,"nodeType":864},{},[],{"data":35113,"content":35114,"nodeType":860},{},[35115],{"data":35116,"marks":35117,"value":25551,"nodeType":864},{},[],{"data":35119,"content":35120,"nodeType":860},{},[35121],{"data":35122,"marks":35123,"value":25558,"nodeType":864},{},[],{"data":35125,"content":35126,"nodeType":1005},{},[],{"data":35128,"content":35129,"nodeType":1009},{},[35130],{"data":35131,"marks":35132,"value":25569,"nodeType":864},{},[35133],{"type":899},{"data":35135,"content":35136,"nodeType":860},{},[35137],{"data":35138,"marks":35139,"value":25576,"nodeType":864},{},[],{"data":35141,"content":35142,"nodeType":860},{},[35143,35147],{"data":35144,"marks":35145,"value":25584,"nodeType":864},{},[35146],{"type":899},{"data":35148,"marks":35149,"value":25588,"nodeType":864},{},[],{"data":35151,"content":35152,"nodeType":860},{},[35153,35157],{"data":35154,"marks":35155,"value":25596,"nodeType":864},{},[35156],{"type":899},{"data":35158,"marks":35159,"value":25600,"nodeType":864},{},[],{"data":35161,"content":35164,"nodeType":996},{"target":35162},{"sys":35163},{"id":23546,"type":1001,"linkType":1002},[],{"data":35166,"content":35167,"nodeType":860},{},[35168],{"data":35169,"marks":35170,"value":25612,"nodeType":864},{},[],{"data":35172,"content":35173,"nodeType":1005},{},[],{"data":35175,"content":35176,"nodeType":1009},{},[35177],{"data":35178,"marks":35179,"value":25623,"nodeType":864},{},[35180],{"type":899},{"data":35182,"content":35183,"nodeType":860},{},[35184],{"data":35185,"marks":35186,"value":25630,"nodeType":864},{},[],{"data":35188,"content":35191,"nodeType":996},{"target":35189},{"sys":35190},{"id":25635,"type":1001,"linkType":1002},[],{"data":35193,"content":35194,"nodeType":860},{},[35195],{"data":35196,"marks":35197,"value":25643,"nodeType":864},{},[],{"data":35199,"content":35200,"nodeType":860},{},[35201],{"data":35202,"marks":35203,"value":25650,"nodeType":864},{},[],{"data":35205,"content":35206,"nodeType":941},{},[35207,35223,35239,35255,35271,35284],{"data":35208,"content":35209,"nodeType":945},{},[35210],{"data":35211,"content":35212,"nodeType":860},{},[35213,35216,35220],{"data":35214,"marks":35215,"value":25663,"nodeType":864},{},[],{"data":35217,"marks":35218,"value":25055,"nodeType":864},{},[35219],{"type":899},{"data":35221,"marks":35222,"value":25671,"nodeType":864},{},[],{"data":35224,"content":35225,"nodeType":945},{},[35226],{"data":35227,"content":35228,"nodeType":860},{},[35229,35232,35236],{"data":35230,"marks":35231,"value":25681,"nodeType":864},{},[],{"data":35233,"marks":35234,"value":25686,"nodeType":864},{},[35235],{"type":899},{"data":35237,"marks":35238,"value":25690,"nodeType":864},{},[],{"data":35240,"content":35241,"nodeType":945},{},[35242],{"data":35243,"content":35244,"nodeType":860},{},[35245,35248,35252],{"data":35246,"marks":35247,"value":25700,"nodeType":864},{},[],{"data":35249,"marks":35250,"value":25705,"nodeType":864},{},[35251],{"type":899},{"data":35253,"marks":35254,"value":25709,"nodeType":864},{},[],{"data":35256,"content":35257,"nodeType":945},{},[35258],{"data":35259,"content":35260,"nodeType":860},{},[35261,35264,35268],{"data":35262,"marks":35263,"value":25719,"nodeType":864},{},[],{"data":35265,"marks":35266,"value":25724,"nodeType":864},{},[35267],{"type":899},{"data":35269,"marks":35270,"value":25728,"nodeType":864},{},[],{"data":35272,"content":35273,"nodeType":945},{},[35274],{"data":35275,"content":35276,"nodeType":860},{},[35277,35281],{"data":35278,"marks":35279,"value":18801,"nodeType":864},{},[35280],{"type":899},{"data":35282,"marks":35283,"value":25742,"nodeType":864},{},[],{"data":35285,"content":35286,"nodeType":945},{},[35287],{"data":35288,"content":35289,"nodeType":860},{},[35290,35294],{"data":35291,"marks":35292,"value":25753,"nodeType":864},{},[35293],{"type":899},{"data":35295,"marks":35296,"value":25757,"nodeType":864},{},[],{"data":35298,"content":35299,"nodeType":860},{},[35300],{"data":35301,"marks":35302,"value":25764,"nodeType":864},{},[],{"data":35304,"content":35305,"nodeType":1005},{},[],{"data":35307,"content":35308,"nodeType":1312},{},[35309],{"data":35310,"marks":35311,"value":25775,"nodeType":864},{},[35312],{"type":899},{"data":35314,"content":35315,"nodeType":860},{},[35316],{"data":35317,"marks":35318,"value":25782,"nodeType":864},{},[],{"data":35320,"content":35321,"nodeType":941},{},[35322,35335,35348,35361],{"data":35323,"content":35324,"nodeType":945},{},[35325],{"data":35326,"content":35327,"nodeType":860},{},[35328,35331],{"data":35329,"marks":35330,"value":25795,"nodeType":864},{},[],{"data":35332,"marks":35333,"value":25800,"nodeType":864},{},[35334],{"type":899},{"data":35336,"content":35337,"nodeType":945},{},[35338],{"data":35339,"content":35340,"nodeType":860},{},[35341,35344],{"data":35342,"marks":35343,"value":25810,"nodeType":864},{},[],{"data":35345,"marks":35346,"value":25815,"nodeType":864},{},[35347],{"type":899},{"data":35349,"content":35350,"nodeType":945},{},[35351],{"data":35352,"content":35353,"nodeType":860},{},[35354,35357],{"data":35355,"marks":35356,"value":25825,"nodeType":864},{},[],{"data":35358,"marks":35359,"value":25830,"nodeType":864},{},[35360],{"type":899},{"data":35362,"content":35363,"nodeType":945},{},[35364],{"data":35365,"content":35366,"nodeType":860},{},[35367,35370],{"data":35368,"marks":35369,"value":25840,"nodeType":864},{},[],{"data":35371,"marks":35372,"value":25845,"nodeType":864},{},[35373],{"type":899},{"data":35375,"content":35376,"nodeType":860},{},[35377,35380,35384],{"data":35378,"marks":35379,"value":25852,"nodeType":864},{},[],{"data":35381,"marks":35382,"value":25857,"nodeType":864},{},[35383],{"type":899},{"data":35385,"marks":35386,"value":25861,"nodeType":864},{},[],{"data":35388,"content":35391,"nodeType":996},{"target":35389},{"sys":35390},{"id":25866,"type":1001,"linkType":1002},[],{"data":35393,"content":35394,"nodeType":860},{},[35395],{"data":35396,"marks":35397,"value":25874,"nodeType":864},{},[],{"data":35399,"content":35400,"nodeType":1005},{},[],{"data":35402,"content":35403,"nodeType":1009},{},[35404],{"data":35405,"marks":35406,"value":25885,"nodeType":864},{},[35407],{"type":899},{"data":35409,"content":35410,"nodeType":860},{},[35411],{"data":35412,"marks":35413,"value":25892,"nodeType":864},{},[],{"data":35415,"content":35416,"nodeType":1312},{},[35417],{"data":35418,"marks":35419,"value":25900,"nodeType":864},{},[35420],{"type":899},{"data":35422,"content":35423,"nodeType":860},{},[35424],{"data":35425,"marks":35426,"value":25907,"nodeType":864},{},[],{"data":35428,"content":35429,"nodeType":860},{},[35430],{"data":35431,"marks":35432,"value":25914,"nodeType":864},{},[],{"data":35434,"content":35435,"nodeType":860},{},[35436,35439,35445,35448,35455],{"data":35437,"marks":35438,"value":25921,"nodeType":864},{},[],{"data":35440,"content":35441,"nodeType":883},{"uri":2561},[35442],{"data":35443,"marks":35444,"value":25928,"nodeType":864},{},[],{"data":35446,"marks":35447,"value":25932,"nodeType":864},{},[],{"data":35449,"content":35450,"nodeType":883},{"uri":16203},[35451],{"data":35452,"marks":35453,"value":25940,"nodeType":864},{},[35454],{"type":1455},{"data":35456,"marks":35457,"value":25944,"nodeType":864},{},[],{"data":35459,"content":35460,"nodeType":860},{},[35461],{"data":35462,"marks":35463,"value":25951,"nodeType":864},{},[],{"data":35465,"content":35466,"nodeType":1312},{},[35467],{"data":35468,"marks":35469,"value":25959,"nodeType":864},{},[35470],{"type":899},{"data":35472,"content":35473,"nodeType":860},{},[35474],{"data":35475,"marks":35476,"value":25966,"nodeType":864},{},[],{"data":35478,"content":35479,"nodeType":860},{},[35480],{"data":35481,"marks":35482,"value":25973,"nodeType":864},{},[],{"data":35484,"content":35485,"nodeType":860},{},[35486],{"data":35487,"marks":35488,"value":25980,"nodeType":864},{},[],{"data":35490,"content":35491,"nodeType":1312},{},[35492],{"data":35493,"marks":35494,"value":25988,"nodeType":864},{},[35495],{"type":899},{"data":35497,"content":35498,"nodeType":860},{},[35499],{"data":35500,"marks":35501,"value":25995,"nodeType":864},{},[],{"data":35503,"content":35504,"nodeType":860},{},[35505],{"data":35506,"marks":35507,"value":26002,"nodeType":864},{},[],{"data":35509,"content":35510,"nodeType":860},{},[35511],{"data":35512,"marks":35513,"value":26009,"nodeType":864},{},[],{"data":35515,"content":35516,"nodeType":1005},{},[],{"data":35518,"content":35519,"nodeType":1009},{},[35520],{"data":35521,"marks":35522,"value":26020,"nodeType":864},{},[35523],{"type":899},{"data":35525,"content":35526,"nodeType":860},{},[35527,35531],{"data":35528,"marks":35529,"value":26028,"nodeType":864},{},[35530],{"type":899},{"data":35532,"marks":35533,"value":26032,"nodeType":864},{},[],{"data":35535,"content":35536,"nodeType":860},{},[35537],{"data":35538,"marks":35539,"value":26039,"nodeType":864},{},[],{"data":35541,"content":35542,"nodeType":860},{},[35543],{"data":35544,"marks":35545,"value":26046,"nodeType":864},{},[],{"data":35547,"content":35548,"nodeType":1312},{},[35549],{"data":35550,"marks":35551,"value":26054,"nodeType":864},{},[35552],{"type":899},{"data":35554,"content":35555,"nodeType":860},{},[35556],{"data":35557,"marks":35558,"value":26061,"nodeType":864},{},[],{"data":35560,"content":35561,"nodeType":860},{},[35562],{"data":35563,"marks":35564,"value":26068,"nodeType":864},{},[],{"data":35566,"content":35567,"nodeType":1312},{},[35568],{"data":35569,"marks":35570,"value":26076,"nodeType":864},{},[35571],{"type":899},{"data":35573,"content":35574,"nodeType":860},{},[35575],{"data":35576,"marks":35577,"value":26083,"nodeType":864},{},[],{"data":35579,"content":35580,"nodeType":941},{},[35581,35594,35607,35620],{"data":35582,"content":35583,"nodeType":945},{},[35584],{"data":35585,"content":35586,"nodeType":860},{},[35587,35591],{"data":35588,"marks":35589,"value":26097,"nodeType":864},{},[35590],{"type":899},{"data":35592,"marks":35593,"value":26101,"nodeType":864},{},[],{"data":35595,"content":35596,"nodeType":945},{},[35597],{"data":35598,"content":35599,"nodeType":860},{},[35600,35604],{"data":35601,"marks":35602,"value":26112,"nodeType":864},{},[35603],{"type":899},{"data":35605,"marks":35606,"value":26116,"nodeType":864},{},[],{"data":35608,"content":35609,"nodeType":945},{},[35610],{"data":35611,"content":35612,"nodeType":860},{},[35613,35617],{"data":35614,"marks":35615,"value":26127,"nodeType":864},{},[35616],{"type":899},{"data":35618,"marks":35619,"value":26131,"nodeType":864},{},[],{"data":35621,"content":35622,"nodeType":945},{},[35623],{"data":35624,"content":35625,"nodeType":860},{},[35626,35630],{"data":35627,"marks":35628,"value":26142,"nodeType":864},{},[35629],{"type":899},{"data":35631,"marks":35632,"value":26146,"nodeType":864},{},[],{"data":35634,"content":35635,"nodeType":860},{},[35636,35639,35643],{"data":35637,"marks":35638,"value":26153,"nodeType":864},{},[],{"data":35640,"marks":35641,"value":26158,"nodeType":864},{},[35642],{"type":899},{"data":35644,"marks":35645,"value":26162,"nodeType":864},{},[],{"data":35647,"content":35648,"nodeType":860},{},[35649,35652,35658],{"data":35650,"marks":35651,"value":26169,"nodeType":864},{},[],{"data":35653,"content":35654,"nodeType":883},{"uri":3210},[35655],{"data":35656,"marks":35657,"value":26176,"nodeType":864},{},[],{"data":35659,"marks":35660,"value":26180,"nodeType":864},{},[],{"data":35662,"content":35663,"nodeType":1312},{},[35664],{"data":35665,"marks":35666,"value":26188,"nodeType":864},{},[35667],{"type":899},{"data":35669,"content":35670,"nodeType":860},{},[35671],{"data":35672,"marks":35673,"value":26195,"nodeType":864},{},[],{"data":35675,"content":35676,"nodeType":860},{},[35677],{"data":35678,"marks":35679,"value":26203,"nodeType":864},{},[35680],{"type":899},{"data":35682,"content":35683,"nodeType":860},{},[35684],{"data":35685,"marks":35686,"value":26210,"nodeType":864},{},[],{"data":35688,"content":35689,"nodeType":860},{},[35690],{"data":35691,"marks":35692,"value":26217,"nodeType":864},{},[],{"data":35694,"content":35695,"nodeType":860},{},[35696],{"data":35697,"marks":35698,"value":26224,"nodeType":864},{},[],{"data":35700,"content":35703,"nodeType":996},{"target":35701},{"sys":35702},{"id":26229,"type":1001,"linkType":1002},[],{"data":35705,"content":35706,"nodeType":1312},{},[35707],{"data":35708,"marks":35709,"value":26238,"nodeType":864},{},[35710],{"type":899},{"data":35712,"content":35713,"nodeType":860},{},[35714],{"data":35715,"marks":35716,"value":26245,"nodeType":864},{},[],{"data":35718,"content":35719,"nodeType":860},{},[35720],{"data":35721,"marks":35722,"value":26252,"nodeType":864},{},[],{"data":35724,"content":35727,"nodeType":996},{"target":35725},{"sys":35726},{"id":11598,"type":1001,"linkType":1002},[],{"data":35729,"content":35730,"nodeType":860},{},[35731],{"data":35732,"marks":35733,"value":26264,"nodeType":864},{},[],{"data":35735,"content":35736,"nodeType":860},{},[35737],{"data":35738,"marks":35739,"value":26271,"nodeType":864},{},[],{"data":35741,"content":35742,"nodeType":860},{},[35743],{"data":35744,"marks":35745,"value":26278,"nodeType":864},{},[],{"data":35747,"content":35750,"nodeType":996},{"target":35748},{"sys":35749},{"id":26283,"type":1001,"linkType":1002},[],{"data":35752,"content":35753,"nodeType":860},{},[35754],{"data":35755,"marks":35756,"value":21,"nodeType":864},{},[],{"items":35758},[35759,35761],{"sys":35760,"name":297},{"id":2732},{"sys":35762,"name":2729},{"id":2728},{"items":35764},[35765],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":35766},{"url":4881},{"__typename":2059,"sys":35768,"content":35769,"title":30117,"synopsis":30118,"hashTags":59,"publishedDate":30119,"slug":30120,"tagsCollection":36199,"authorsCollection":36205},{"id":29612},{"json":35770},{"data":35771,"content":35772,"nodeType":856},{},[35773,35780,35804,35809,35815,35830,35843,35846,35853,35866,35882,35902,35907,35920,35944,35949,35954,35967,35970,35977,35983,35990,36006,36019,36026,36048,36054,36061,36085,36091,36098,36104,36109,36112,36119,36125,36132,36137,36140,36147,36153,36159,36165,36175,36178,36184],{"data":35774,"content":35775,"nodeType":1009},{},[35776],{"data":35777,"marks":35778,"value":29624,"nodeType":864},{},[35779],{"type":899},{"data":35781,"content":35782,"nodeType":860},{},[35783,35786,35792,35795,35801],{"data":35784,"marks":35785,"value":29631,"nodeType":864},{},[],{"data":35787,"content":35788,"nodeType":883},{"uri":29634},[35789],{"data":35790,"marks":35791,"value":29639,"nodeType":864},{},[],{"data":35793,"marks":35794,"value":29643,"nodeType":864},{},[],{"data":35796,"content":35797,"nodeType":883},{"uri":29646},[35798],{"data":35799,"marks":35800,"value":29651,"nodeType":864},{},[],{"data":35802,"marks":35803,"value":29655,"nodeType":864},{},[],{"data":35805,"content":35808,"nodeType":996},{"target":35806},{"sys":35807},{"id":29660,"type":1001,"linkType":1002},[],{"data":35810,"content":35811,"nodeType":860},{},[35812],{"data":35813,"marks":35814,"value":29668,"nodeType":864},{},[],{"data":35816,"content":35817,"nodeType":860},{},[35818,35821,35827],{"data":35819,"marks":35820,"value":29675,"nodeType":864},{},[],{"data":35822,"content":35823,"nodeType":883},{"uri":29678},[35824],{"data":35825,"marks":35826,"value":29683,"nodeType":864},{},[],{"data":35828,"marks":35829,"value":29687,"nodeType":864},{},[],{"data":35831,"content":35832,"nodeType":860},{},[35833,35836,35840],{"data":35834,"marks":35835,"value":29694,"nodeType":864},{},[],{"data":35837,"marks":35838,"value":29699,"nodeType":864},{},[35839],{"type":899},{"data":35841,"marks":35842,"value":2924,"nodeType":864},{},[],{"data":35844,"content":35845,"nodeType":1005},{},[],{"data":35847,"content":35848,"nodeType":1009},{},[35849],{"data":35850,"marks":35851,"value":29713,"nodeType":864},{},[35852],{"type":899},{"data":35854,"content":35855,"nodeType":860},{},[35856,35859,35863],{"data":35857,"marks":35858,"value":29720,"nodeType":864},{},[],{"data":35860,"marks":35861,"value":29725,"nodeType":864},{},[35862],{"type":2246},{"data":35864,"marks":35865,"value":2924,"nodeType":864},{},[],{"data":35867,"content":35868,"nodeType":860},{},[35869,35872,35879],{"data":35870,"marks":35871,"value":29735,"nodeType":864},{},[],{"data":35873,"content":35874,"nodeType":883},{"uri":7549},[35875],{"data":35876,"marks":35877,"value":29743,"nodeType":864},{},[35878],{"type":1455},{"data":35880,"marks":35881,"value":29747,"nodeType":864},{},[],{"data":35883,"content":35884,"nodeType":860},{},[35885,35888,35892,35895,35899],{"data":35886,"marks":35887,"value":29754,"nodeType":864},{},[],{"data":35889,"marks":35890,"value":29759,"nodeType":864},{},[35891],{"type":899},{"data":35893,"marks":35894,"value":29763,"nodeType":864},{},[],{"data":35896,"marks":35897,"value":29768,"nodeType":864},{},[35898],{"type":2246},{"data":35900,"marks":35901,"value":29772,"nodeType":864},{},[],{"data":35903,"content":35906,"nodeType":996},{"target":35904},{"sys":35905},{"id":29777,"type":1001,"linkType":1002},[],{"data":35908,"content":35909,"nodeType":860},{},[35910,35913,35917],{"data":35911,"marks":35912,"value":29785,"nodeType":864},{},[],{"data":35914,"marks":35915,"value":29790,"nodeType":864},{},[35916],{"type":899},{"data":35918,"marks":35919,"value":29794,"nodeType":864},{},[],{"data":35921,"content":35922,"nodeType":860},{},[35923,35926,35932,35935,35941],{"data":35924,"marks":35925,"value":29801,"nodeType":864},{},[],{"data":35927,"content":35928,"nodeType":883},{"uri":25338},[35929],{"data":35930,"marks":35931,"value":29808,"nodeType":864},{},[],{"data":35933,"marks":35934,"value":29812,"nodeType":864},{},[],{"data":35936,"content":35937,"nodeType":883},{"uri":11813},[35938],{"data":35939,"marks":35940,"value":29819,"nodeType":864},{},[],{"data":35942,"marks":35943,"value":1774,"nodeType":864},{},[],{"data":35945,"content":35948,"nodeType":996},{"target":35946},{"sys":35947},{"id":29827,"type":1001,"linkType":1002},[],{"data":35950,"content":35953,"nodeType":996},{"target":35951},{"sys":35952},{"id":29833,"type":1001,"linkType":1002},[],{"data":35955,"content":35956,"nodeType":860},{},[35957,35960,35964],{"data":35958,"marks":35959,"value":29841,"nodeType":864},{},[],{"data":35961,"marks":35962,"value":29846,"nodeType":864},{},[35963],{"type":899},{"data":35965,"marks":35966,"value":29850,"nodeType":864},{},[],{"data":35968,"content":35969,"nodeType":1005},{},[],{"data":35971,"content":35972,"nodeType":1009},{},[35973],{"data":35974,"marks":35975,"value":29861,"nodeType":864},{},[35976],{"type":899},{"data":35978,"content":35979,"nodeType":860},{},[35980],{"data":35981,"marks":35982,"value":29868,"nodeType":864},{},[],{"data":35984,"content":35985,"nodeType":1312},{},[35986],{"data":35987,"marks":35988,"value":29876,"nodeType":864},{},[35989],{"type":899},{"data":35991,"content":35992,"nodeType":860},{},[35993,35996,36003],{"data":35994,"marks":35995,"value":21,"nodeType":864},{},[],{"data":35997,"content":35998,"nodeType":883},{"uri":4103},[35999],{"data":36000,"marks":36001,"value":29890,"nodeType":864},{},[36002],{"type":1455},{"data":36004,"marks":36005,"value":29894,"nodeType":864},{},[],{"data":36007,"content":36008,"nodeType":860},{},[36009,36012,36016],{"data":36010,"marks":36011,"value":29901,"nodeType":864},{},[],{"data":36013,"marks":36014,"value":29906,"nodeType":864},{},[36015],{"type":899},{"data":36017,"marks":36018,"value":29910,"nodeType":864},{},[],{"data":36020,"content":36021,"nodeType":1312},{},[36022],{"data":36023,"marks":36024,"value":288,"nodeType":864},{},[36025],{"type":899},{"data":36027,"content":36028,"nodeType":860},{},[36029,36033,36041,36045],{"data":36030,"marks":36031,"value":21,"nodeType":864},{},[36032],{"type":899},{"data":36034,"content":36035,"nodeType":883},{"uri":2411},[36036],{"data":36037,"marks":36038,"value":29933,"nodeType":864},{},[36039,36040],{"type":1455},{"type":899},{"data":36042,"marks":36043,"value":29938,"nodeType":864},{},[36044],{"type":899},{"data":36046,"marks":36047,"value":29942,"nodeType":864},{},[],{"data":36049,"content":36050,"nodeType":860},{},[36051],{"data":36052,"marks":36053,"value":29949,"nodeType":864},{},[],{"data":36055,"content":36056,"nodeType":1312},{},[36057],{"data":36058,"marks":36059,"value":29957,"nodeType":864},{},[36060],{"type":899},{"data":36062,"content":36063,"nodeType":860},{},[36064,36067,36073,36076,36082],{"data":36065,"marks":36066,"value":29964,"nodeType":864},{},[],{"data":36068,"content":36069,"nodeType":883},{"uri":13427},[36070],{"data":36071,"marks":36072,"value":29971,"nodeType":864},{},[],{"data":36074,"marks":36075,"value":29975,"nodeType":864},{},[],{"data":36077,"content":36078,"nodeType":883},{"uri":3237},[36079],{"data":36080,"marks":36081,"value":29982,"nodeType":864},{},[],{"data":36083,"marks":36084,"value":29986,"nodeType":864},{},[],{"data":36086,"content":36087,"nodeType":860},{},[36088],{"data":36089,"marks":36090,"value":29993,"nodeType":864},{},[],{"data":36092,"content":36093,"nodeType":1312},{},[36094],{"data":36095,"marks":36096,"value":30001,"nodeType":864},{},[36097],{"type":899},{"data":36099,"content":36100,"nodeType":860},{},[36101],{"data":36102,"marks":36103,"value":30008,"nodeType":864},{},[],{"data":36105,"content":36108,"nodeType":996},{"target":36106},{"sys":36107},{"id":30013,"type":1001,"linkType":1002},[],{"data":36110,"content":36111,"nodeType":1005},{},[],{"data":36113,"content":36114,"nodeType":1009},{},[36115],{"data":36116,"marks":36117,"value":30025,"nodeType":864},{},[36118],{"type":899},{"data":36120,"content":36121,"nodeType":860},{},[36122],{"data":36123,"marks":36124,"value":30032,"nodeType":864},{},[],{"data":36126,"content":36127,"nodeType":860},{},[36128],{"data":36129,"marks":36130,"value":30040,"nodeType":864},{},[36131],{"type":899},{"data":36133,"content":36136,"nodeType":996},{"target":36134},{"sys":36135},{"id":30045,"type":1001,"linkType":1002},[],{"data":36138,"content":36139,"nodeType":1005},{},[],{"data":36141,"content":36142,"nodeType":1312},{},[36143],{"data":36144,"marks":36145,"value":30057,"nodeType":864},{},[36146],{"type":899},{"data":36148,"content":36149,"nodeType":860},{},[36150],{"data":36151,"marks":36152,"value":30064,"nodeType":864},{},[],{"data":36154,"content":36155,"nodeType":860},{},[36156],{"data":36157,"marks":36158,"value":30071,"nodeType":864},{},[],{"data":36160,"content":36161,"nodeType":860},{},[36162],{"data":36163,"marks":36164,"value":30078,"nodeType":864},{},[],{"data":36166,"content":36167,"nodeType":860},{},[36168,36172],{"data":36169,"marks":36170,"value":30086,"nodeType":864},{},[36171],{"type":899},{"data":36173,"marks":36174,"value":30090,"nodeType":864},{},[],{"data":36176,"content":36177,"nodeType":1005},{},[],{"data":36179,"content":36180,"nodeType":860},{},[36181],{"data":36182,"marks":36183,"value":4855,"nodeType":864},{},[],{"data":36185,"content":36186,"nodeType":860},{},[36187,36190,36196],{"data":36188,"marks":36189,"value":30106,"nodeType":864},{},[],{"data":36191,"content":36192,"nodeType":883},{"uri":30109},[36193],{"data":36194,"marks":36195,"value":13763,"nodeType":864},{},[],{"data":36197,"marks":36198,"value":2719,"nodeType":864},{},[],{"items":36200},[36201,36203],{"sys":36202,"name":2729},{"id":2728},{"sys":36204,"name":342},{"id":13775},{"items":36206},[36207],{"fullName":3621,"firstName":3622,"jobTitle":3623,"profilePicture":36208},{"url":3625},"blog/the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",{"json":36211},{"data":36212,"content":36213,"nodeType":856},{},[36214],{"data":36215,"content":36216,"nodeType":860},{},[36217],{"data":36218,"marks":36219,"value":36220,"nodeType":864},{},[],"Getting a clear picture of which solution is right for your team means understanding what problem you want to solve, and identifying if the browser is the best place to solve that problem. To help you navigate this, we've ranked the security problems you can solve in the browser by security value and browser fit.",{"id":3628,"publishedAt":36222},"2026-08-12T11:52:50.048Z",{"items":36224},[36225,36227],{"sys":36226,"name":297},{"id":2732},{"sys":36228,"name":2729},{"id":2728},{"items":36230},[36231,36233,36235,36237,36239,36241,36243,36245,36247,36249,36251,36253,36255,36257,36259,36261,36263,36265,36267,36269,36271,36273,36275,36277,36279],{"sys":36232,"name":297,"slug":298,"tier":31},{"id":294},{"sys":36234,"name":413,"slug":414,"tier":31},{"id":410},{"sys":36236,"name":279,"slug":280,"tier":31},{"id":276},{"sys":36238,"name":519,"slug":520,"tier":31},{"id":516},{"sys":36240,"name":235,"slug":236,"tier":31},{"id":232},{"sys":36242,"name":342,"slug":343,"tier":31},{"id":339},{"sys":36244,"name":545,"slug":546,"tier":31},{"id":542},{"sys":36246,"name":261,"slug":262,"tier":45},{"id":258},{"sys":36248,"name":589,"slug":590,"tier":45},{"id":586},{"sys":36250,"name":288,"slug":289,"tier":45},{"id":285},{"sys":36252,"name":484,"slug":485,"tier":45},{"id":481},{"sys":36254,"name":422,"slug":423,"tier":45},{"id":419},{"sys":36256,"name":502,"slug":503,"tier":45},{"id":499},{"sys":36258,"name":333,"slug":334,"tier":45},{"id":330},{"sys":36260,"name":395,"slug":396,"tier":45},{"id":392},{"sys":36262,"name":457,"slug":458,"tier":45},{"id":454},{"sys":36264,"name":315,"slug":316,"tier":45},{"id":312},{"sys":36266,"name":324,"slug":325,"tier":45},{"id":321},{"sys":36268,"name":571,"slug":572,"tier":45},{"id":568},{"sys":36270,"name":368,"slug":369,"tier":45},{"id":365},{"sys":36272,"name":580,"slug":581,"tier":45},{"id":577},{"sys":36274,"name":252,"slug":253,"tier":45},{"id":249},{"sys":36276,"name":475,"slug":476,"tier":45},{"id":472},{"sys":36278,"name":440,"slug":441,"tier":45},{"id":437},{"sys":36280,"name":633,"slug":634,"tier":45},{"id":630},"eheGEg-9k5C4bph8PtOCjFzhTfglI3HL0C87-kCdH4c",{"id":36283,"title":28621,"authorsCollection":36284,"content":36289,"extension":228,"faqItemsCollection":36906,"faqTitle":59,"featured":6,"hashTags":59,"meta":36908,"metaTitle":36909,"ogImage":59,"postType":5726,"publishedDate":26293,"relatedBlogPostsCollection":36910,"slug":28623,"stem":38859,"subtitle":59,"summary":38860,"synopsis":28622,"sys":38871,"tagsCollection":38873,"topicsCollection":38879,"__hash__":38919},"blog/blog/7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market.json",{"items":36285},[36286],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":36287,"profilePicture":36288},[15231],{"url":2740},{"json":36290,"links":36785},{"data":36291,"content":36292,"nodeType":856},{},[36293,36308,36314,36320,36325,36328,36335,36348,36354,36359,36365,36440,36446,36451,36457,36462,36465,36472,36482,36488,36498,36501,36508,36521,36527,36533,36536,36543,36549,36562,36567,36580,36586,36592,36598,36611,36617,36620,36627,36633,36646,36652,36655,36662,36675,36681,36697,36707,36710,36717,36730,36736,36742,36748,36754,36757,36763,36769],{"data":36294,"content":36295,"nodeType":860},{},[36296,36299,36305],{"data":36297,"marks":36298,"value":2761,"nodeType":864},{},[],{"data":36300,"content":36301,"nodeType":883},{"uri":28061},[36302],{"data":36303,"marks":36304,"value":28066,"nodeType":864},{},[],{"data":36306,"marks":36307,"value":28070,"nodeType":864},{},[],{"data":36309,"content":36310,"nodeType":860},{},[36311],{"data":36312,"marks":36313,"value":28077,"nodeType":864},{},[],{"data":36315,"content":36316,"nodeType":860},{},[36317],{"data":36318,"marks":36319,"value":28084,"nodeType":864},{},[],{"data":36321,"content":36324,"nodeType":996},{"target":36322},{"sys":36323},{"id":28089,"type":1001,"linkType":1002},[],{"data":36326,"content":36327,"nodeType":1005},{},[],{"data":36329,"content":36330,"nodeType":1009},{},[36331],{"data":36332,"marks":36333,"value":28101,"nodeType":864},{},[36334],{"type":899},{"data":36336,"content":36337,"nodeType":860},{},[36338,36341,36345],{"data":36339,"marks":36340,"value":28108,"nodeType":864},{},[],{"data":36342,"marks":36343,"value":28113,"nodeType":864},{},[36344],{"type":899},{"data":36346,"marks":36347,"value":28117,"nodeType":864},{},[],{"data":36349,"content":36350,"nodeType":860},{},[36351],{"data":36352,"marks":36353,"value":28124,"nodeType":864},{},[],{"data":36355,"content":36358,"nodeType":996},{"target":36356},{"sys":36357},{"id":28129,"type":1001,"linkType":1002},[],{"data":36360,"content":36361,"nodeType":860},{},[36362],{"data":36363,"marks":36364,"value":28137,"nodeType":864},{},[],{"data":36366,"content":36367,"nodeType":941},{},[36368,36377,36386,36395,36404,36413,36422,36431],{"data":36369,"content":36370,"nodeType":945},{},[36371],{"data":36372,"content":36373,"nodeType":860},{},[36374],{"data":36375,"marks":36376,"value":28150,"nodeType":864},{},[],{"data":36378,"content":36379,"nodeType":945},{},[36380],{"data":36381,"content":36382,"nodeType":860},{},[36383],{"data":36384,"marks":36385,"value":28160,"nodeType":864},{},[],{"data":36387,"content":36388,"nodeType":945},{},[36389],{"data":36390,"content":36391,"nodeType":860},{},[36392],{"data":36393,"marks":36394,"value":28170,"nodeType":864},{},[],{"data":36396,"content":36397,"nodeType":945},{},[36398],{"data":36399,"content":36400,"nodeType":860},{},[36401],{"data":36402,"marks":36403,"value":28180,"nodeType":864},{},[],{"data":36405,"content":36406,"nodeType":945},{},[36407],{"data":36408,"content":36409,"nodeType":860},{},[36410],{"data":36411,"marks":36412,"value":28190,"nodeType":864},{},[],{"data":36414,"content":36415,"nodeType":945},{},[36416],{"data":36417,"content":36418,"nodeType":860},{},[36419],{"data":36420,"marks":36421,"value":28200,"nodeType":864},{},[],{"data":36423,"content":36424,"nodeType":945},{},[36425],{"data":36426,"content":36427,"nodeType":860},{},[36428],{"data":36429,"marks":36430,"value":28210,"nodeType":864},{},[],{"data":36432,"content":36433,"nodeType":945},{},[36434],{"data":36435,"content":36436,"nodeType":860},{},[36437],{"data":36438,"marks":36439,"value":28220,"nodeType":864},{},[],{"data":36441,"content":36442,"nodeType":860},{},[36443],{"data":36444,"marks":36445,"value":28227,"nodeType":864},{},[],{"data":36447,"content":36450,"nodeType":996},{"target":36448},{"sys":36449},{"id":23546,"type":1001,"linkType":1002},[],{"data":36452,"content":36453,"nodeType":860},{},[36454],{"data":36455,"marks":36456,"value":28239,"nodeType":864},{},[],{"data":36458,"content":36461,"nodeType":996},{"target":36459},{"sys":36460},{"id":28244,"type":1001,"linkType":1002},[],{"data":36463,"content":36464,"nodeType":1005},{},[],{"data":36466,"content":36467,"nodeType":1009},{},[36468],{"data":36469,"marks":36470,"value":28256,"nodeType":864},{},[36471],{"type":899},{"data":36473,"content":36474,"nodeType":860},{},[36475,36479],{"data":36476,"marks":36477,"value":28264,"nodeType":864},{},[36478],{"type":899},{"data":36480,"marks":36481,"value":28268,"nodeType":864},{},[],{"data":36483,"content":36484,"nodeType":860},{},[36485],{"data":36486,"marks":36487,"value":28275,"nodeType":864},{},[],{"data":36489,"content":36490,"nodeType":860},{},[36491,36495],{"data":36492,"marks":36493,"value":28283,"nodeType":864},{},[36494],{"type":899},{"data":36496,"marks":36497,"value":28287,"nodeType":864},{},[],{"data":36499,"content":36500,"nodeType":1005},{},[],{"data":36502,"content":36503,"nodeType":1009},{},[36504],{"data":36505,"marks":36506,"value":28298,"nodeType":864},{},[36507],{"type":899},{"data":36509,"content":36510,"nodeType":860},{},[36511,36514,36518],{"data":36512,"marks":36513,"value":28305,"nodeType":864},{},[],{"data":36515,"marks":36516,"value":24968,"nodeType":864},{},[36517],{"type":899},{"data":36519,"marks":36520,"value":28313,"nodeType":864},{},[],{"data":36522,"content":36523,"nodeType":860},{},[36524],{"data":36525,"marks":36526,"value":28320,"nodeType":864},{},[],{"data":36528,"content":36529,"nodeType":860},{},[36530],{"data":36531,"marks":36532,"value":28327,"nodeType":864},{},[],{"data":36534,"content":36535,"nodeType":1005},{},[],{"data":36537,"content":36538,"nodeType":1009},{},[36539],{"data":36540,"marks":36541,"value":28338,"nodeType":864},{},[36542],{"type":899},{"data":36544,"content":36545,"nodeType":860},{},[36546],{"data":36547,"marks":36548,"value":28345,"nodeType":864},{},[],{"data":36550,"content":36551,"nodeType":860},{},[36552,36555,36559],{"data":36553,"marks":36554,"value":28352,"nodeType":864},{},[],{"data":36556,"marks":36557,"value":28357,"nodeType":864},{},[36558],{"type":899},{"data":36560,"marks":36561,"value":28361,"nodeType":864},{},[],{"data":36563,"content":36566,"nodeType":996},{"target":36564},{"sys":36565},{"id":28366,"type":1001,"linkType":1002},[],{"data":36568,"content":36569,"nodeType":860},{},[36570,36573,36577],{"data":36571,"marks":36572,"value":28374,"nodeType":864},{},[],{"data":36574,"marks":36575,"value":28379,"nodeType":864},{},[36576],{"type":899},{"data":36578,"marks":36579,"value":28383,"nodeType":864},{},[],{"data":36581,"content":36582,"nodeType":860},{},[36583],{"data":36584,"marks":36585,"value":28390,"nodeType":864},{},[],{"data":36587,"content":36588,"nodeType":860},{},[36589],{"data":36590,"marks":36591,"value":28397,"nodeType":864},{},[],{"data":36593,"content":36594,"nodeType":860},{},[36595],{"data":36596,"marks":36597,"value":28404,"nodeType":864},{},[],{"data":36599,"content":36600,"nodeType":860},{},[36601,36604,36608],{"data":36602,"marks":36603,"value":28411,"nodeType":864},{},[],{"data":36605,"marks":36606,"value":28416,"nodeType":864},{},[36607],{"type":899},{"data":36609,"marks":36610,"value":28420,"nodeType":864},{},[],{"data":36612,"content":36613,"nodeType":860},{},[36614],{"data":36615,"marks":36616,"value":28427,"nodeType":864},{},[],{"data":36618,"content":36619,"nodeType":1005},{},[],{"data":36621,"content":36622,"nodeType":1009},{},[36623],{"data":36624,"marks":36625,"value":28438,"nodeType":864},{},[36626],{"type":899},{"data":36628,"content":36629,"nodeType":860},{},[36630],{"data":36631,"marks":36632,"value":28445,"nodeType":864},{},[],{"data":36634,"content":36635,"nodeType":860},{},[36636,36639,36643],{"data":36637,"marks":36638,"value":28452,"nodeType":864},{},[],{"data":36640,"marks":36641,"value":28457,"nodeType":864},{},[36642],{"type":899},{"data":36644,"marks":36645,"value":28461,"nodeType":864},{},[],{"data":36647,"content":36648,"nodeType":860},{},[36649],{"data":36650,"marks":36651,"value":28468,"nodeType":864},{},[],{"data":36653,"content":36654,"nodeType":1005},{},[],{"data":36656,"content":36657,"nodeType":1009},{},[36658],{"data":36659,"marks":36660,"value":28479,"nodeType":864},{},[36661],{"type":899},{"data":36663,"content":36664,"nodeType":860},{},[36665,36668,36672],{"data":36666,"marks":36667,"value":28486,"nodeType":864},{},[],{"data":36669,"marks":36670,"value":28491,"nodeType":864},{},[36671],{"type":899},{"data":36673,"marks":36674,"value":28495,"nodeType":864},{},[],{"data":36676,"content":36677,"nodeType":860},{},[36678],{"data":36679,"marks":36680,"value":28502,"nodeType":864},{},[],{"data":36682,"content":36683,"nodeType":860},{},[36684,36687,36694],{"data":36685,"marks":36686,"value":28509,"nodeType":864},{},[],{"data":36688,"content":36689,"nodeType":883},{"uri":11674},[36690],{"data":36691,"marks":36692,"value":28517,"nodeType":864},{},[36693],{"type":1455},{"data":36695,"marks":36696,"value":28521,"nodeType":864},{},[],{"data":36698,"content":36699,"nodeType":860},{},[36700,36703],{"data":36701,"marks":36702,"value":28528,"nodeType":864},{},[],{"data":36704,"marks":36705,"value":28533,"nodeType":864},{},[36706],{"type":899},{"data":36708,"content":36709,"nodeType":1005},{},[],{"data":36711,"content":36712,"nodeType":1009},{},[36713],{"data":36714,"marks":36715,"value":28544,"nodeType":864},{},[36716],{"type":899},{"data":36718,"content":36719,"nodeType":860},{},[36720,36723,36727],{"data":36721,"marks":36722,"value":28551,"nodeType":864},{},[],{"data":36724,"marks":36725,"value":28556,"nodeType":864},{},[36726],{"type":899},{"data":36728,"marks":36729,"value":28560,"nodeType":864},{},[],{"data":36731,"content":36732,"nodeType":860},{},[36733],{"data":36734,"marks":36735,"value":28567,"nodeType":864},{},[],{"data":36737,"content":36738,"nodeType":860},{},[36739],{"data":36740,"marks":36741,"value":28574,"nodeType":864},{},[],{"data":36743,"content":36744,"nodeType":860},{},[36745],{"data":36746,"marks":36747,"value":28581,"nodeType":864},{},[],{"data":36749,"content":36750,"nodeType":860},{},[36751],{"data":36752,"marks":36753,"value":28588,"nodeType":864},{},[],{"data":36755,"content":36756,"nodeType":1005},{},[],{"data":36758,"content":36759,"nodeType":860},{},[36760],{"data":36761,"marks":36762,"value":28598,"nodeType":864},{},[],{"data":36764,"content":36765,"nodeType":860},{},[36766],{"data":36767,"marks":36768,"value":1689,"nodeType":864},{},[],{"data":36770,"content":36771,"nodeType":860},{},[36772,36775,36782],{"data":36773,"marks":36774,"value":21,"nodeType":864},{},[],{"data":36776,"content":36777,"nodeType":883},{"uri":1700},[36778],{"data":36779,"marks":36780,"value":13763,"nodeType":864},{},[36781],{"type":1455},{"data":36783,"marks":36784,"value":2719,"nodeType":864},{},[],{"entries":36786},{"hyperlink":36787,"inline":36788,"block":36789},[],[],[36790,36798,36835,36839,36868],{"sys":36791,"__typename":1724,"title":36792,"caption":36793,"layoutMode":59,"file":36794},{"id":28089},"Omdia report key stats infographic","Headline stats from the latest Omdia report.",{"url":36795,"width":36796,"height":36797},"https://images.ctfassets.net/y1cdw1ablpvd/62TiADpvI65W2gT7RQwlOU/a4aaad376574b1cd963fc0afa5e2942d/omdia-browser-security-infographic_2x__2_.png",1700,1434,{"sys":36799,"__typename":1740,"content":36800,"name":36834,"title":59},{"id":28129},{"json":36801},{"nodeType":856,"data":36802,"content":36803},{},[36804],{"nodeType":860,"data":36805,"content":36806},{},[36807,36811,36818,36822,36830],{"nodeType":864,"value":36808,"marks":36809,"data":36810},"The evidence here isn’t just statistics. The real-world breaches attributed to ",[],{},{"nodeType":883,"data":36812,"content":36813},{"uri":16015},[36814],{"nodeType":864,"value":16018,"marks":36815,"data":36817},[36816],{"type":1455},{},{"nodeType":864,"value":36819,"marks":36820,"data":36821},", including the ",[],{},{"nodeType":883,"data":36823,"content":36824},{"uri":4082},[36825],{"nodeType":864,"value":36826,"marks":36827,"data":36829},"ShinyHunters-branded 2026 hacking spree",[36828],{"type":1455},{},{"nodeType":864,"value":36831,"marks":36832,"data":36833},", clearly underline the real-world threat. ",[],{},"Omdia report IB1",{"sys":36836,"__typename":1717,"type":1718,"ctaText":36837,"buttonLabel":36838,"buttonColour":1721,"buttonUrl":11536},{"id":23546},"Get our latest technical whitepaper to learn about the state of browser-based attacks in 2026 (no sign-up required).","Download Now",{"sys":36840,"__typename":1740,"content":36841,"name":36867,"title":59},{"id":28244},{"json":36842},{"data":36843,"content":36844,"nodeType":856},{},[36845],{"data":36846,"content":36847,"nodeType":860},{},[36848,36852,36863],{"data":36849,"marks":36850,"value":36851,"nodeType":864},{},[],"It's worth noting that AiTM — now the dominant phishing technique in the wild,",{"data":36853,"content":36854,"nodeType":883},{"uri":7549},[36855,36858],{"data":36856,"marks":36857,"value":1171,"nodeType":864},{},[],{"data":36859,"marks":36860,"value":36862,"nodeType":864},{},[36861],{"type":1455},"responsible for 62% of phishing blocked by Microsoft",{"data":36864,"marks":36865,"value":36866,"nodeType":864},{},[]," — shows up at just 17% in Omdia's data. That likely reflects a recognition gap rather than low prevalence: most organizations lack the browser-layer visibility to distinguish an AiTM reverse-proxy attack from a conventional phishing page, which means the real AiTM figure is probably buried inside the 40% who reported phishing generally.","Omdia report IB2",{"sys":36869,"__typename":1740,"content":36870,"name":36905,"title":59},{"id":28366},{"json":36871},{"nodeType":856,"data":36872,"content":36873},{},[36874],{"nodeType":860,"data":36875,"content":36876},{},[36877,36881,36889,36893,36901],{"nodeType":864,"value":36878,"marks":36879,"data":36880},"This is something we’re seeing extensively in the wild. Just about every phishing kit we encounter today is packed with signs of AI use. You can see our ",[],{},{"nodeType":883,"data":36882,"content":36883},{"uri":12879},[36884],{"nodeType":864,"value":36885,"marks":36886,"data":36888},"recent analysis of the Doko’s Panel real-time vishing + AitM kit",[36887],{"type":1455},{},{"nodeType":864,"value":36890,"marks":36891,"data":36892}," for one example of this. AI development of kits and tools is rapidly driving down the time for attackers to adopt and scale new capabilities — the ",[],{},{"nodeType":883,"data":36894,"content":36895},{"uri":3259},[36896],{"nodeType":864,"value":36897,"marks":36898,"data":36900},"37x increase in device code phishing in 2026",[36899],{"type":1455},{},{"nodeType":864,"value":36902,"marks":36903,"data":36904}," being another indicator of this (we've observed heavy AI tool use across multiple kits and campaigns, with the EvilTokens kit gaining particular notoriety for its abuse of the Railway platform's AI features).",[],{},"Omdia report IB3",{"items":36907},[],{},"7 things Omdia's latest report tells us about the SEB market",{"items":36911},[36912,37584,38026],{"__typename":2059,"sys":36913,"content":36914,"title":26291,"synopsis":26292,"hashTags":59,"publishedDate":26293,"slug":26294,"tagsCollection":37574,"authorsCollection":37580},{"id":25527},{"json":36915},{"data":36916,"content":36917,"nodeType":856},{},[36918,36923,36929,36935,36941,36944,36951,36957,36967,36977,36982,36988,36991,36998,37004,37009,37015,37021,37114,37120,37123,37130,37136,37191,37204,37209,37215,37218,37225,37231,37238,37244,37250,37275,37281,37288,37294,37300,37306,37313,37319,37325,37331,37334,37341,37351,37357,37363,37370,37376,37382,37389,37395,37450,37463,37478,37485,37491,37498,37504,37510,37516,37521,37528,37534,37540,37545,37551,37557,37563,37568],{"data":36919,"content":36922,"nodeType":996},{"target":36920},{"sys":36921},{"id":25536,"type":1001,"linkType":1002},[],{"data":36924,"content":36925,"nodeType":860},{},[36926],{"data":36927,"marks":36928,"value":25544,"nodeType":864},{},[],{"data":36930,"content":36931,"nodeType":860},{},[36932],{"data":36933,"marks":36934,"value":25551,"nodeType":864},{},[],{"data":36936,"content":36937,"nodeType":860},{},[36938],{"data":36939,"marks":36940,"value":25558,"nodeType":864},{},[],{"data":36942,"content":36943,"nodeType":1005},{},[],{"data":36945,"content":36946,"nodeType":1009},{},[36947],{"data":36948,"marks":36949,"value":25569,"nodeType":864},{},[36950],{"type":899},{"data":36952,"content":36953,"nodeType":860},{},[36954],{"data":36955,"marks":36956,"value":25576,"nodeType":864},{},[],{"data":36958,"content":36959,"nodeType":860},{},[36960,36964],{"data":36961,"marks":36962,"value":25584,"nodeType":864},{},[36963],{"type":899},{"data":36965,"marks":36966,"value":25588,"nodeType":864},{},[],{"data":36968,"content":36969,"nodeType":860},{},[36970,36974],{"data":36971,"marks":36972,"value":25596,"nodeType":864},{},[36973],{"type":899},{"data":36975,"marks":36976,"value":25600,"nodeType":864},{},[],{"data":36978,"content":36981,"nodeType":996},{"target":36979},{"sys":36980},{"id":23546,"type":1001,"linkType":1002},[],{"data":36983,"content":36984,"nodeType":860},{},[36985],{"data":36986,"marks":36987,"value":25612,"nodeType":864},{},[],{"data":36989,"content":36990,"nodeType":1005},{},[],{"data":36992,"content":36993,"nodeType":1009},{},[36994],{"data":36995,"marks":36996,"value":25623,"nodeType":864},{},[36997],{"type":899},{"data":36999,"content":37000,"nodeType":860},{},[37001],{"data":37002,"marks":37003,"value":25630,"nodeType":864},{},[],{"data":37005,"content":37008,"nodeType":996},{"target":37006},{"sys":37007},{"id":25635,"type":1001,"linkType":1002},[],{"data":37010,"content":37011,"nodeType":860},{},[37012],{"data":37013,"marks":37014,"value":25643,"nodeType":864},{},[],{"data":37016,"content":37017,"nodeType":860},{},[37018],{"data":37019,"marks":37020,"value":25650,"nodeType":864},{},[],{"data":37022,"content":37023,"nodeType":941},{},[37024,37040,37056,37072,37088,37101],{"data":37025,"content":37026,"nodeType":945},{},[37027],{"data":37028,"content":37029,"nodeType":860},{},[37030,37033,37037],{"data":37031,"marks":37032,"value":25663,"nodeType":864},{},[],{"data":37034,"marks":37035,"value":25055,"nodeType":864},{},[37036],{"type":899},{"data":37038,"marks":37039,"value":25671,"nodeType":864},{},[],{"data":37041,"content":37042,"nodeType":945},{},[37043],{"data":37044,"content":37045,"nodeType":860},{},[37046,37049,37053],{"data":37047,"marks":37048,"value":25681,"nodeType":864},{},[],{"data":37050,"marks":37051,"value":25686,"nodeType":864},{},[37052],{"type":899},{"data":37054,"marks":37055,"value":25690,"nodeType":864},{},[],{"data":37057,"content":37058,"nodeType":945},{},[37059],{"data":37060,"content":37061,"nodeType":860},{},[37062,37065,37069],{"data":37063,"marks":37064,"value":25700,"nodeType":864},{},[],{"data":37066,"marks":37067,"value":25705,"nodeType":864},{},[37068],{"type":899},{"data":37070,"marks":37071,"value":25709,"nodeType":864},{},[],{"data":37073,"content":37074,"nodeType":945},{},[37075],{"data":37076,"content":37077,"nodeType":860},{},[37078,37081,37085],{"data":37079,"marks":37080,"value":25719,"nodeType":864},{},[],{"data":37082,"marks":37083,"value":25724,"nodeType":864},{},[37084],{"type":899},{"data":37086,"marks":37087,"value":25728,"nodeType":864},{},[],{"data":37089,"content":37090,"nodeType":945},{},[37091],{"data":37092,"content":37093,"nodeType":860},{},[37094,37098],{"data":37095,"marks":37096,"value":18801,"nodeType":864},{},[37097],{"type":899},{"data":37099,"marks":37100,"value":25742,"nodeType":864},{},[],{"data":37102,"content":37103,"nodeType":945},{},[37104],{"data":37105,"content":37106,"nodeType":860},{},[37107,37111],{"data":37108,"marks":37109,"value":25753,"nodeType":864},{},[37110],{"type":899},{"data":37112,"marks":37113,"value":25757,"nodeType":864},{},[],{"data":37115,"content":37116,"nodeType":860},{},[37117],{"data":37118,"marks":37119,"value":25764,"nodeType":864},{},[],{"data":37121,"content":37122,"nodeType":1005},{},[],{"data":37124,"content":37125,"nodeType":1312},{},[37126],{"data":37127,"marks":37128,"value":25775,"nodeType":864},{},[37129],{"type":899},{"data":37131,"content":37132,"nodeType":860},{},[37133],{"data":37134,"marks":37135,"value":25782,"nodeType":864},{},[],{"data":37137,"content":37138,"nodeType":941},{},[37139,37152,37165,37178],{"data":37140,"content":37141,"nodeType":945},{},[37142],{"data":37143,"content":37144,"nodeType":860},{},[37145,37148],{"data":37146,"marks":37147,"value":25795,"nodeType":864},{},[],{"data":37149,"marks":37150,"value":25800,"nodeType":864},{},[37151],{"type":899},{"data":37153,"content":37154,"nodeType":945},{},[37155],{"data":37156,"content":37157,"nodeType":860},{},[37158,37161],{"data":37159,"marks":37160,"value":25810,"nodeType":864},{},[],{"data":37162,"marks":37163,"value":25815,"nodeType":864},{},[37164],{"type":899},{"data":37166,"content":37167,"nodeType":945},{},[37168],{"data":37169,"content":37170,"nodeType":860},{},[37171,37174],{"data":37172,"marks":37173,"value":25825,"nodeType":864},{},[],{"data":37175,"marks":37176,"value":25830,"nodeType":864},{},[37177],{"type":899},{"data":37179,"content":37180,"nodeType":945},{},[37181],{"data":37182,"content":37183,"nodeType":860},{},[37184,37187],{"data":37185,"marks":37186,"value":25840,"nodeType":864},{},[],{"data":37188,"marks":37189,"value":25845,"nodeType":864},{},[37190],{"type":899},{"data":37192,"content":37193,"nodeType":860},{},[37194,37197,37201],{"data":37195,"marks":37196,"value":25852,"nodeType":864},{},[],{"data":37198,"marks":37199,"value":25857,"nodeType":864},{},[37200],{"type":899},{"data":37202,"marks":37203,"value":25861,"nodeType":864},{},[],{"data":37205,"content":37208,"nodeType":996},{"target":37206},{"sys":37207},{"id":25866,"type":1001,"linkType":1002},[],{"data":37210,"content":37211,"nodeType":860},{},[37212],{"data":37213,"marks":37214,"value":25874,"nodeType":864},{},[],{"data":37216,"content":37217,"nodeType":1005},{},[],{"data":37219,"content":37220,"nodeType":1009},{},[37221],{"data":37222,"marks":37223,"value":25885,"nodeType":864},{},[37224],{"type":899},{"data":37226,"content":37227,"nodeType":860},{},[37228],{"data":37229,"marks":37230,"value":25892,"nodeType":864},{},[],{"data":37232,"content":37233,"nodeType":1312},{},[37234],{"data":37235,"marks":37236,"value":25900,"nodeType":864},{},[37237],{"type":899},{"data":37239,"content":37240,"nodeType":860},{},[37241],{"data":37242,"marks":37243,"value":25907,"nodeType":864},{},[],{"data":37245,"content":37246,"nodeType":860},{},[37247],{"data":37248,"marks":37249,"value":25914,"nodeType":864},{},[],{"data":37251,"content":37252,"nodeType":860},{},[37253,37256,37262,37265,37272],{"data":37254,"marks":37255,"value":25921,"nodeType":864},{},[],{"data":37257,"content":37258,"nodeType":883},{"uri":2561},[37259],{"data":37260,"marks":37261,"value":25928,"nodeType":864},{},[],{"data":37263,"marks":37264,"value":25932,"nodeType":864},{},[],{"data":37266,"content":37267,"nodeType":883},{"uri":16203},[37268],{"data":37269,"marks":37270,"value":25940,"nodeType":864},{},[37271],{"type":1455},{"data":37273,"marks":37274,"value":25944,"nodeType":864},{},[],{"data":37276,"content":37277,"nodeType":860},{},[37278],{"data":37279,"marks":37280,"value":25951,"nodeType":864},{},[],{"data":37282,"content":37283,"nodeType":1312},{},[37284],{"data":37285,"marks":37286,"value":25959,"nodeType":864},{},[37287],{"type":899},{"data":37289,"content":37290,"nodeType":860},{},[37291],{"data":37292,"marks":37293,"value":25966,"nodeType":864},{},[],{"data":37295,"content":37296,"nodeType":860},{},[37297],{"data":37298,"marks":37299,"value":25973,"nodeType":864},{},[],{"data":37301,"content":37302,"nodeType":860},{},[37303],{"data":37304,"marks":37305,"value":25980,"nodeType":864},{},[],{"data":37307,"content":37308,"nodeType":1312},{},[37309],{"data":37310,"marks":37311,"value":25988,"nodeType":864},{},[37312],{"type":899},{"data":37314,"content":37315,"nodeType":860},{},[37316],{"data":37317,"marks":37318,"value":25995,"nodeType":864},{},[],{"data":37320,"content":37321,"nodeType":860},{},[37322],{"data":37323,"marks":37324,"value":26002,"nodeType":864},{},[],{"data":37326,"content":37327,"nodeType":860},{},[37328],{"data":37329,"marks":37330,"value":26009,"nodeType":864},{},[],{"data":37332,"content":37333,"nodeType":1005},{},[],{"data":37335,"content":37336,"nodeType":1009},{},[37337],{"data":37338,"marks":37339,"value":26020,"nodeType":864},{},[37340],{"type":899},{"data":37342,"content":37343,"nodeType":860},{},[37344,37348],{"data":37345,"marks":37346,"value":26028,"nodeType":864},{},[37347],{"type":899},{"data":37349,"marks":37350,"value":26032,"nodeType":864},{},[],{"data":37352,"content":37353,"nodeType":860},{},[37354],{"data":37355,"marks":37356,"value":26039,"nodeType":864},{},[],{"data":37358,"content":37359,"nodeType":860},{},[37360],{"data":37361,"marks":37362,"value":26046,"nodeType":864},{},[],{"data":37364,"content":37365,"nodeType":1312},{},[37366],{"data":37367,"marks":37368,"value":26054,"nodeType":864},{},[37369],{"type":899},{"data":37371,"content":37372,"nodeType":860},{},[37373],{"data":37374,"marks":37375,"value":26061,"nodeType":864},{},[],{"data":37377,"content":37378,"nodeType":860},{},[37379],{"data":37380,"marks":37381,"value":26068,"nodeType":864},{},[],{"data":37383,"content":37384,"nodeType":1312},{},[37385],{"data":37386,"marks":37387,"value":26076,"nodeType":864},{},[37388],{"type":899},{"data":37390,"content":37391,"nodeType":860},{},[37392],{"data":37393,"marks":37394,"value":26083,"nodeType":864},{},[],{"data":37396,"content":37397,"nodeType":941},{},[37398,37411,37424,37437],{"data":37399,"content":37400,"nodeType":945},{},[37401],{"data":37402,"content":37403,"nodeType":860},{},[37404,37408],{"data":37405,"marks":37406,"value":26097,"nodeType":864},{},[37407],{"type":899},{"data":37409,"marks":37410,"value":26101,"nodeType":864},{},[],{"data":37412,"content":37413,"nodeType":945},{},[37414],{"data":37415,"content":37416,"nodeType":860},{},[37417,37421],{"data":37418,"marks":37419,"value":26112,"nodeType":864},{},[37420],{"type":899},{"data":37422,"marks":37423,"value":26116,"nodeType":864},{},[],{"data":37425,"content":37426,"nodeType":945},{},[37427],{"data":37428,"content":37429,"nodeType":860},{},[37430,37434],{"data":37431,"marks":37432,"value":26127,"nodeType":864},{},[37433],{"type":899},{"data":37435,"marks":37436,"value":26131,"nodeType":864},{},[],{"data":37438,"content":37439,"nodeType":945},{},[37440],{"data":37441,"content":37442,"nodeType":860},{},[37443,37447],{"data":37444,"marks":37445,"value":26142,"nodeType":864},{},[37446],{"type":899},{"data":37448,"marks":37449,"value":26146,"nodeType":864},{},[],{"data":37451,"content":37452,"nodeType":860},{},[37453,37456,37460],{"data":37454,"marks":37455,"value":26153,"nodeType":864},{},[],{"data":37457,"marks":37458,"value":26158,"nodeType":864},{},[37459],{"type":899},{"data":37461,"marks":37462,"value":26162,"nodeType":864},{},[],{"data":37464,"content":37465,"nodeType":860},{},[37466,37469,37475],{"data":37467,"marks":37468,"value":26169,"nodeType":864},{},[],{"data":37470,"content":37471,"nodeType":883},{"uri":3210},[37472],{"data":37473,"marks":37474,"value":26176,"nodeType":864},{},[],{"data":37476,"marks":37477,"value":26180,"nodeType":864},{},[],{"data":37479,"content":37480,"nodeType":1312},{},[37481],{"data":37482,"marks":37483,"value":26188,"nodeType":864},{},[37484],{"type":899},{"data":37486,"content":37487,"nodeType":860},{},[37488],{"data":37489,"marks":37490,"value":26195,"nodeType":864},{},[],{"data":37492,"content":37493,"nodeType":860},{},[37494],{"data":37495,"marks":37496,"value":26203,"nodeType":864},{},[37497],{"type":899},{"data":37499,"content":37500,"nodeType":860},{},[37501],{"data":37502,"marks":37503,"value":26210,"nodeType":864},{},[],{"data":37505,"content":37506,"nodeType":860},{},[37507],{"data":37508,"marks":37509,"value":26217,"nodeType":864},{},[],{"data":37511,"content":37512,"nodeType":860},{},[37513],{"data":37514,"marks":37515,"value":26224,"nodeType":864},{},[],{"data":37517,"content":37520,"nodeType":996},{"target":37518},{"sys":37519},{"id":26229,"type":1001,"linkType":1002},[],{"data":37522,"content":37523,"nodeType":1312},{},[37524],{"data":37525,"marks":37526,"value":26238,"nodeType":864},{},[37527],{"type":899},{"data":37529,"content":37530,"nodeType":860},{},[37531],{"data":37532,"marks":37533,"value":26245,"nodeType":864},{},[],{"data":37535,"content":37536,"nodeType":860},{},[37537],{"data":37538,"marks":37539,"value":26252,"nodeType":864},{},[],{"data":37541,"content":37544,"nodeType":996},{"target":37542},{"sys":37543},{"id":11598,"type":1001,"linkType":1002},[],{"data":37546,"content":37547,"nodeType":860},{},[37548],{"data":37549,"marks":37550,"value":26264,"nodeType":864},{},[],{"data":37552,"content":37553,"nodeType":860},{},[37554],{"data":37555,"marks":37556,"value":26271,"nodeType":864},{},[],{"data":37558,"content":37559,"nodeType":860},{},[37560],{"data":37561,"marks":37562,"value":26278,"nodeType":864},{},[],{"data":37564,"content":37567,"nodeType":996},{"target":37565},{"sys":37566},{"id":26283,"type":1001,"linkType":1002},[],{"data":37569,"content":37570,"nodeType":860},{},[37571],{"data":37572,"marks":37573,"value":21,"nodeType":864},{},[],{"items":37575},[37576,37578],{"sys":37577,"name":297},{"id":2732},{"sys":37579,"name":2729},{"id":2728},{"items":37581},[37582],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":37583},{"url":4881},{"__typename":2059,"sys":37585,"content":37586,"title":30117,"synopsis":30118,"hashTags":59,"publishedDate":30119,"slug":30120,"tagsCollection":38016,"authorsCollection":38022},{"id":29612},{"json":37587},{"data":37588,"content":37589,"nodeType":856},{},[37590,37597,37621,37626,37632,37647,37660,37663,37670,37683,37699,37719,37724,37737,37761,37766,37771,37784,37787,37794,37800,37807,37823,37836,37843,37865,37871,37878,37902,37908,37915,37921,37926,37929,37936,37942,37949,37954,37957,37964,37970,37976,37982,37992,37995,38001],{"data":37591,"content":37592,"nodeType":1009},{},[37593],{"data":37594,"marks":37595,"value":29624,"nodeType":864},{},[37596],{"type":899},{"data":37598,"content":37599,"nodeType":860},{},[37600,37603,37609,37612,37618],{"data":37601,"marks":37602,"value":29631,"nodeType":864},{},[],{"data":37604,"content":37605,"nodeType":883},{"uri":29634},[37606],{"data":37607,"marks":37608,"value":29639,"nodeType":864},{},[],{"data":37610,"marks":37611,"value":29643,"nodeType":864},{},[],{"data":37613,"content":37614,"nodeType":883},{"uri":29646},[37615],{"data":37616,"marks":37617,"value":29651,"nodeType":864},{},[],{"data":37619,"marks":37620,"value":29655,"nodeType":864},{},[],{"data":37622,"content":37625,"nodeType":996},{"target":37623},{"sys":37624},{"id":29660,"type":1001,"linkType":1002},[],{"data":37627,"content":37628,"nodeType":860},{},[37629],{"data":37630,"marks":37631,"value":29668,"nodeType":864},{},[],{"data":37633,"content":37634,"nodeType":860},{},[37635,37638,37644],{"data":37636,"marks":37637,"value":29675,"nodeType":864},{},[],{"data":37639,"content":37640,"nodeType":883},{"uri":29678},[37641],{"data":37642,"marks":37643,"value":29683,"nodeType":864},{},[],{"data":37645,"marks":37646,"value":29687,"nodeType":864},{},[],{"data":37648,"content":37649,"nodeType":860},{},[37650,37653,37657],{"data":37651,"marks":37652,"value":29694,"nodeType":864},{},[],{"data":37654,"marks":37655,"value":29699,"nodeType":864},{},[37656],{"type":899},{"data":37658,"marks":37659,"value":2924,"nodeType":864},{},[],{"data":37661,"content":37662,"nodeType":1005},{},[],{"data":37664,"content":37665,"nodeType":1009},{},[37666],{"data":37667,"marks":37668,"value":29713,"nodeType":864},{},[37669],{"type":899},{"data":37671,"content":37672,"nodeType":860},{},[37673,37676,37680],{"data":37674,"marks":37675,"value":29720,"nodeType":864},{},[],{"data":37677,"marks":37678,"value":29725,"nodeType":864},{},[37679],{"type":2246},{"data":37681,"marks":37682,"value":2924,"nodeType":864},{},[],{"data":37684,"content":37685,"nodeType":860},{},[37686,37689,37696],{"data":37687,"marks":37688,"value":29735,"nodeType":864},{},[],{"data":37690,"content":37691,"nodeType":883},{"uri":7549},[37692],{"data":37693,"marks":37694,"value":29743,"nodeType":864},{},[37695],{"type":1455},{"data":37697,"marks":37698,"value":29747,"nodeType":864},{},[],{"data":37700,"content":37701,"nodeType":860},{},[37702,37705,37709,37712,37716],{"data":37703,"marks":37704,"value":29754,"nodeType":864},{},[],{"data":37706,"marks":37707,"value":29759,"nodeType":864},{},[37708],{"type":899},{"data":37710,"marks":37711,"value":29763,"nodeType":864},{},[],{"data":37713,"marks":37714,"value":29768,"nodeType":864},{},[37715],{"type":2246},{"data":37717,"marks":37718,"value":29772,"nodeType":864},{},[],{"data":37720,"content":37723,"nodeType":996},{"target":37721},{"sys":37722},{"id":29777,"type":1001,"linkType":1002},[],{"data":37725,"content":37726,"nodeType":860},{},[37727,37730,37734],{"data":37728,"marks":37729,"value":29785,"nodeType":864},{},[],{"data":37731,"marks":37732,"value":29790,"nodeType":864},{},[37733],{"type":899},{"data":37735,"marks":37736,"value":29794,"nodeType":864},{},[],{"data":37738,"content":37739,"nodeType":860},{},[37740,37743,37749,37752,37758],{"data":37741,"marks":37742,"value":29801,"nodeType":864},{},[],{"data":37744,"content":37745,"nodeType":883},{"uri":25338},[37746],{"data":37747,"marks":37748,"value":29808,"nodeType":864},{},[],{"data":37750,"marks":37751,"value":29812,"nodeType":864},{},[],{"data":37753,"content":37754,"nodeType":883},{"uri":11813},[37755],{"data":37756,"marks":37757,"value":29819,"nodeType":864},{},[],{"data":37759,"marks":37760,"value":1774,"nodeType":864},{},[],{"data":37762,"content":37765,"nodeType":996},{"target":37763},{"sys":37764},{"id":29827,"type":1001,"linkType":1002},[],{"data":37767,"content":37770,"nodeType":996},{"target":37768},{"sys":37769},{"id":29833,"type":1001,"linkType":1002},[],{"data":37772,"content":37773,"nodeType":860},{},[37774,37777,37781],{"data":37775,"marks":37776,"value":29841,"nodeType":864},{},[],{"data":37778,"marks":37779,"value":29846,"nodeType":864},{},[37780],{"type":899},{"data":37782,"marks":37783,"value":29850,"nodeType":864},{},[],{"data":37785,"content":37786,"nodeType":1005},{},[],{"data":37788,"content":37789,"nodeType":1009},{},[37790],{"data":37791,"marks":37792,"value":29861,"nodeType":864},{},[37793],{"type":899},{"data":37795,"content":37796,"nodeType":860},{},[37797],{"data":37798,"marks":37799,"value":29868,"nodeType":864},{},[],{"data":37801,"content":37802,"nodeType":1312},{},[37803],{"data":37804,"marks":37805,"value":29876,"nodeType":864},{},[37806],{"type":899},{"data":37808,"content":37809,"nodeType":860},{},[37810,37813,37820],{"data":37811,"marks":37812,"value":21,"nodeType":864},{},[],{"data":37814,"content":37815,"nodeType":883},{"uri":4103},[37816],{"data":37817,"marks":37818,"value":29890,"nodeType":864},{},[37819],{"type":1455},{"data":37821,"marks":37822,"value":29894,"nodeType":864},{},[],{"data":37824,"content":37825,"nodeType":860},{},[37826,37829,37833],{"data":37827,"marks":37828,"value":29901,"nodeType":864},{},[],{"data":37830,"marks":37831,"value":29906,"nodeType":864},{},[37832],{"type":899},{"data":37834,"marks":37835,"value":29910,"nodeType":864},{},[],{"data":37837,"content":37838,"nodeType":1312},{},[37839],{"data":37840,"marks":37841,"value":288,"nodeType":864},{},[37842],{"type":899},{"data":37844,"content":37845,"nodeType":860},{},[37846,37850,37858,37862],{"data":37847,"marks":37848,"value":21,"nodeType":864},{},[37849],{"type":899},{"data":37851,"content":37852,"nodeType":883},{"uri":2411},[37853],{"data":37854,"marks":37855,"value":29933,"nodeType":864},{},[37856,37857],{"type":1455},{"type":899},{"data":37859,"marks":37860,"value":29938,"nodeType":864},{},[37861],{"type":899},{"data":37863,"marks":37864,"value":29942,"nodeType":864},{},[],{"data":37866,"content":37867,"nodeType":860},{},[37868],{"data":37869,"marks":37870,"value":29949,"nodeType":864},{},[],{"data":37872,"content":37873,"nodeType":1312},{},[37874],{"data":37875,"marks":37876,"value":29957,"nodeType":864},{},[37877],{"type":899},{"data":37879,"content":37880,"nodeType":860},{},[37881,37884,37890,37893,37899],{"data":37882,"marks":37883,"value":29964,"nodeType":864},{},[],{"data":37885,"content":37886,"nodeType":883},{"uri":13427},[37887],{"data":37888,"marks":37889,"value":29971,"nodeType":864},{},[],{"data":37891,"marks":37892,"value":29975,"nodeType":864},{},[],{"data":37894,"content":37895,"nodeType":883},{"uri":3237},[37896],{"data":37897,"marks":37898,"value":29982,"nodeType":864},{},[],{"data":37900,"marks":37901,"value":29986,"nodeType":864},{},[],{"data":37903,"content":37904,"nodeType":860},{},[37905],{"data":37906,"marks":37907,"value":29993,"nodeType":864},{},[],{"data":37909,"content":37910,"nodeType":1312},{},[37911],{"data":37912,"marks":37913,"value":30001,"nodeType":864},{},[37914],{"type":899},{"data":37916,"content":37917,"nodeType":860},{},[37918],{"data":37919,"marks":37920,"value":30008,"nodeType":864},{},[],{"data":37922,"content":37925,"nodeType":996},{"target":37923},{"sys":37924},{"id":30013,"type":1001,"linkType":1002},[],{"data":37927,"content":37928,"nodeType":1005},{},[],{"data":37930,"content":37931,"nodeType":1009},{},[37932],{"data":37933,"marks":37934,"value":30025,"nodeType":864},{},[37935],{"type":899},{"data":37937,"content":37938,"nodeType":860},{},[37939],{"data":37940,"marks":37941,"value":30032,"nodeType":864},{},[],{"data":37943,"content":37944,"nodeType":860},{},[37945],{"data":37946,"marks":37947,"value":30040,"nodeType":864},{},[37948],{"type":899},{"data":37950,"content":37953,"nodeType":996},{"target":37951},{"sys":37952},{"id":30045,"type":1001,"linkType":1002},[],{"data":37955,"content":37956,"nodeType":1005},{},[],{"data":37958,"content":37959,"nodeType":1312},{},[37960],{"data":37961,"marks":37962,"value":30057,"nodeType":864},{},[37963],{"type":899},{"data":37965,"content":37966,"nodeType":860},{},[37967],{"data":37968,"marks":37969,"value":30064,"nodeType":864},{},[],{"data":37971,"content":37972,"nodeType":860},{},[37973],{"data":37974,"marks":37975,"value":30071,"nodeType":864},{},[],{"data":37977,"content":37978,"nodeType":860},{},[37979],{"data":37980,"marks":37981,"value":30078,"nodeType":864},{},[],{"data":37983,"content":37984,"nodeType":860},{},[37985,37989],{"data":37986,"marks":37987,"value":30086,"nodeType":864},{},[37988],{"type":899},{"data":37990,"marks":37991,"value":30090,"nodeType":864},{},[],{"data":37993,"content":37994,"nodeType":1005},{},[],{"data":37996,"content":37997,"nodeType":860},{},[37998],{"data":37999,"marks":38000,"value":4855,"nodeType":864},{},[],{"data":38002,"content":38003,"nodeType":860},{},[38004,38007,38013],{"data":38005,"marks":38006,"value":30106,"nodeType":864},{},[],{"data":38008,"content":38009,"nodeType":883},{"uri":30109},[38010],{"data":38011,"marks":38012,"value":13763,"nodeType":864},{},[],{"data":38014,"marks":38015,"value":2719,"nodeType":864},{},[],{"items":38017},[38018,38020],{"sys":38019,"name":2729},{"id":2728},{"sys":38021,"name":342},{"id":13775},{"items":38023},[38024],{"fullName":3621,"firstName":3622,"jobTitle":3623,"profilePicture":38025},{"url":3625},{"__typename":2059,"sys":38027,"content":38028,"title":29597,"synopsis":29598,"hashTags":59,"publishedDate":24225,"slug":29599,"tagsCollection":38849,"authorsCollection":38855},{"id":28636},{"json":38029},{"data":38030,"content":38031,"nodeType":856},{},[38032,38054,38078,38111,38144,38149,38159,38162,38169,38211,38217,38236,38241,38244,38251,38275,38281,38288,38293,38296,38303,38309,38324,38330,38363,38369,38372,38379,38394,38436,38439,38446,38461,38476,38483,38489,38499,38509,38519,38529,38544,38551,38557,38560,38566,38572,38587,38590,38597,38612,38843],{"data":38033,"content":38034,"nodeType":860},{},[38035,38038,38044,38047,38051],{"data":38036,"marks":38037,"value":28647,"nodeType":864},{},[],{"data":38039,"content":38040,"nodeType":883},{"uri":16015},[38041],{"data":38042,"marks":38043,"value":16018,"nodeType":864},{},[],{"data":38045,"marks":38046,"value":28657,"nodeType":864},{},[],{"data":38048,"marks":38049,"value":28662,"nodeType":864},{},[38050],{"type":899},{"data":38052,"marks":38053,"value":28666,"nodeType":864},{},[],{"data":38055,"content":38056,"nodeType":860},{},[38057,38060,38066,38069,38075],{"data":38058,"marks":38059,"value":28673,"nodeType":864},{},[],{"data":38061,"content":38062,"nodeType":883},{"uri":28676},[38063],{"data":38064,"marks":38065,"value":28681,"nodeType":864},{},[],{"data":38067,"marks":38068,"value":28685,"nodeType":864},{},[],{"data":38070,"content":38071,"nodeType":883},{"uri":28688},[38072],{"data":38073,"marks":38074,"value":28693,"nodeType":864},{},[],{"data":38076,"marks":38077,"value":28697,"nodeType":864},{},[],{"data":38079,"content":38080,"nodeType":860},{},[38081,38084,38090,38093,38099,38102,38108],{"data":38082,"marks":38083,"value":28704,"nodeType":864},{},[],{"data":38085,"content":38086,"nodeType":883},{"uri":28707},[38087],{"data":38088,"marks":38089,"value":28712,"nodeType":864},{},[],{"data":38091,"marks":38092,"value":28716,"nodeType":864},{},[],{"data":38094,"content":38095,"nodeType":883},{"uri":28719},[38096],{"data":38097,"marks":38098,"value":28724,"nodeType":864},{},[],{"data":38100,"marks":38101,"value":28728,"nodeType":864},{},[],{"data":38103,"content":38104,"nodeType":883},{"uri":16553},[38105],{"data":38106,"marks":38107,"value":28735,"nodeType":864},{},[],{"data":38109,"marks":38110,"value":28739,"nodeType":864},{},[],{"data":38112,"content":38113,"nodeType":860},{},[38114,38117,38123,38126,38132,38135,38141],{"data":38115,"marks":38116,"value":28746,"nodeType":864},{},[],{"data":38118,"content":38119,"nodeType":883},{"uri":28749},[38120],{"data":38121,"marks":38122,"value":28754,"nodeType":864},{},[],{"data":38124,"marks":38125,"value":28758,"nodeType":864},{},[],{"data":38127,"content":38128,"nodeType":883},{"uri":28761},[38129],{"data":38130,"marks":38131,"value":28766,"nodeType":864},{},[],{"data":38133,"marks":38134,"value":28770,"nodeType":864},{},[],{"data":38136,"content":38137,"nodeType":883},{"uri":28773},[38138],{"data":38139,"marks":38140,"value":28778,"nodeType":864},{},[],{"data":38142,"marks":38143,"value":28782,"nodeType":864},{},[],{"data":38145,"content":38148,"nodeType":996},{"target":38146},{"sys":38147},{"id":28787,"type":1001,"linkType":1002},[],{"data":38150,"content":38151,"nodeType":860},{},[38152,38156],{"data":38153,"marks":38154,"value":28796,"nodeType":864},{},[38155],{"type":899},{"data":38157,"marks":38158,"value":28800,"nodeType":864},{},[],{"data":38160,"content":38161,"nodeType":1005},{},[],{"data":38163,"content":38164,"nodeType":1009},{},[38165],{"data":38166,"marks":38167,"value":28811,"nodeType":864},{},[38168],{"type":899},{"data":38170,"content":38171,"nodeType":860},{},[38172,38175,38181,38184,38190,38193,38199,38202,38208],{"data":38173,"marks":38174,"value":28818,"nodeType":864},{},[],{"data":38176,"content":38177,"nodeType":883},{"uri":28821},[38178],{"data":38179,"marks":38180,"value":28826,"nodeType":864},{},[],{"data":38182,"marks":38183,"value":11735,"nodeType":864},{},[],{"data":38185,"content":38186,"nodeType":883},{"uri":28832},[38187],{"data":38188,"marks":38189,"value":28837,"nodeType":864},{},[],{"data":38191,"marks":38192,"value":28841,"nodeType":864},{},[],{"data":38194,"content":38195,"nodeType":883},{"uri":28719},[38196],{"data":38197,"marks":38198,"value":28848,"nodeType":864},{},[],{"data":38200,"marks":38201,"value":28852,"nodeType":864},{},[],{"data":38203,"content":38204,"nodeType":883},{"uri":12879},[38205],{"data":38206,"marks":38207,"value":28859,"nodeType":864},{},[],{"data":38209,"marks":38210,"value":2924,"nodeType":864},{},[],{"data":38212,"content":38213,"nodeType":860},{},[38214],{"data":38215,"marks":38216,"value":28869,"nodeType":864},{},[],{"data":38218,"content":38219,"nodeType":860},{},[38220,38223,38229,38232],{"data":38221,"marks":38222,"value":28876,"nodeType":864},{},[],{"data":38224,"content":38225,"nodeType":883},{"uri":12879},[38226],{"data":38227,"marks":38228,"value":28883,"nodeType":864},{},[],{"data":38230,"marks":38231,"value":28887,"nodeType":864},{},[],{"data":38233,"marks":38234,"value":28892,"nodeType":864},{},[38235],{"type":899},{"data":38237,"content":38240,"nodeType":996},{"target":38238},{"sys":38239},{"id":28897,"type":1001,"linkType":1002},[],{"data":38242,"content":38243,"nodeType":1005},{},[],{"data":38245,"content":38246,"nodeType":1009},{},[38247],{"data":38248,"marks":38249,"value":28909,"nodeType":864},{},[38250],{"type":899},{"data":38252,"content":38253,"nodeType":860},{},[38254,38257,38263,38266,38272],{"data":38255,"marks":38256,"value":2761,"nodeType":864},{},[],{"data":38258,"content":38259,"nodeType":883},{"uri":23901},[38260],{"data":38261,"marks":38262,"value":28922,"nodeType":864},{},[],{"data":38264,"marks":38265,"value":28926,"nodeType":864},{},[],{"data":38267,"content":38268,"nodeType":883},{"uri":16553},[38269],{"data":38270,"marks":38271,"value":28933,"nodeType":864},{},[],{"data":38273,"marks":38274,"value":28937,"nodeType":864},{},[],{"data":38276,"content":38277,"nodeType":860},{},[38278],{"data":38279,"marks":38280,"value":28944,"nodeType":864},{},[],{"data":38282,"content":38283,"nodeType":860},{},[38284],{"data":38285,"marks":38286,"value":28952,"nodeType":864},{},[38287],{"type":899},{"data":38289,"content":38292,"nodeType":996},{"target":38290},{"sys":38291},{"id":28957,"type":1001,"linkType":1002},[],{"data":38294,"content":38295,"nodeType":1005},{},[],{"data":38297,"content":38298,"nodeType":1009},{},[38299],{"data":38300,"marks":38301,"value":28969,"nodeType":864},{},[38302],{"type":899},{"data":38304,"content":38305,"nodeType":860},{},[38306],{"data":38307,"marks":38308,"value":28976,"nodeType":864},{},[],{"data":38310,"content":38311,"nodeType":860},{},[38312,38315,38321],{"data":38313,"marks":38314,"value":2761,"nodeType":864},{},[],{"data":38316,"content":38317,"nodeType":883},{"uri":28985},[38318],{"data":38319,"marks":38320,"value":28990,"nodeType":864},{},[],{"data":38322,"marks":38323,"value":28994,"nodeType":864},{},[],{"data":38325,"content":38326,"nodeType":860},{},[38327],{"data":38328,"marks":38329,"value":29001,"nodeType":864},{},[],{"data":38331,"content":38332,"nodeType":860},{},[38333,38336,38342,38345,38351,38354,38360],{"data":38334,"marks":38335,"value":29008,"nodeType":864},{},[],{"data":38337,"content":38338,"nodeType":883},{"uri":29011},[38339],{"data":38340,"marks":38341,"value":29016,"nodeType":864},{},[],{"data":38343,"marks":38344,"value":29020,"nodeType":864},{},[],{"data":38346,"content":38347,"nodeType":883},{"uri":29023},[38348],{"data":38349,"marks":38350,"value":29028,"nodeType":864},{},[],{"data":38352,"marks":38353,"value":29032,"nodeType":864},{},[],{"data":38355,"content":38356,"nodeType":883},{"uri":4103},[38357],{"data":38358,"marks":38359,"value":16114,"nodeType":864},{},[],{"data":38361,"marks":38362,"value":29042,"nodeType":864},{},[],{"data":38364,"content":38365,"nodeType":860},{},[38366],{"data":38367,"marks":38368,"value":29049,"nodeType":864},{},[],{"data":38370,"content":38371,"nodeType":1005},{},[],{"data":38373,"content":38374,"nodeType":1009},{},[38375],{"data":38376,"marks":38377,"value":29060,"nodeType":864},{},[38378],{"type":899},{"data":38380,"content":38381,"nodeType":860},{},[38382,38385,38391],{"data":38383,"marks":38384,"value":29067,"nodeType":864},{},[],{"data":38386,"content":38387,"nodeType":883},{"uri":29070},[38388],{"data":38389,"marks":38390,"value":29075,"nodeType":864},{},[],{"data":38392,"marks":38393,"value":29079,"nodeType":864},{},[],{"data":38395,"content":38396,"nodeType":860},{},[38397,38400,38406,38409,38415,38418,38424,38427,38433],{"data":38398,"marks":38399,"value":29086,"nodeType":864},{},[],{"data":38401,"content":38402,"nodeType":883},{"uri":29089},[38403],{"data":38404,"marks":38405,"value":29094,"nodeType":864},{},[],{"data":38407,"marks":38408,"value":29098,"nodeType":864},{},[],{"data":38410,"content":38411,"nodeType":883},{"uri":29101},[38412],{"data":38413,"marks":38414,"value":29106,"nodeType":864},{},[],{"data":38416,"marks":38417,"value":29110,"nodeType":864},{},[],{"data":38419,"content":38420,"nodeType":883},{"uri":29113},[38421],{"data":38422,"marks":38423,"value":29118,"nodeType":864},{},[],{"data":38425,"marks":38426,"value":29122,"nodeType":864},{},[],{"data":38428,"content":38429,"nodeType":883},{"uri":29125},[38430],{"data":38431,"marks":38432,"value":29130,"nodeType":864},{},[],{"data":38434,"marks":38435,"value":29134,"nodeType":864},{},[],{"data":38437,"content":38438,"nodeType":1005},{},[],{"data":38440,"content":38441,"nodeType":1009},{},[38442],{"data":38443,"marks":38444,"value":29145,"nodeType":864},{},[38445],{"type":899},{"data":38447,"content":38448,"nodeType":860},{},[38449,38452,38458],{"data":38450,"marks":38451,"value":29152,"nodeType":864},{},[],{"data":38453,"content":38454,"nodeType":883},{"uri":3259},[38455],{"data":38456,"marks":38457,"value":29159,"nodeType":864},{},[],{"data":38459,"marks":38460,"value":29163,"nodeType":864},{},[],{"data":38462,"content":38463,"nodeType":860},{},[38464,38467,38473],{"data":38465,"marks":38466,"value":29170,"nodeType":864},{},[],{"data":38468,"content":38469,"nodeType":883},{"uri":29173},[38470],{"data":38471,"marks":38472,"value":315,"nodeType":864},{},[],{"data":38474,"marks":38475,"value":29181,"nodeType":864},{},[],{"data":38477,"content":38478,"nodeType":1312},{},[38479],{"data":38480,"marks":38481,"value":7533,"nodeType":864},{},[38482],{"type":899},{"data":38484,"content":38485,"nodeType":860},{},[38486],{"data":38487,"marks":38488,"value":29195,"nodeType":864},{},[],{"data":38490,"content":38491,"nodeType":860},{},[38492,38496],{"data":38493,"marks":38494,"value":29203,"nodeType":864},{},[38495],{"type":899},{"data":38497,"marks":38498,"value":29207,"nodeType":864},{},[],{"data":38500,"content":38501,"nodeType":860},{},[38502,38506],{"data":38503,"marks":38504,"value":29215,"nodeType":864},{},[38505],{"type":899},{"data":38507,"marks":38508,"value":29219,"nodeType":864},{},[],{"data":38510,"content":38511,"nodeType":860},{},[38512,38516],{"data":38513,"marks":38514,"value":29227,"nodeType":864},{},[38515],{"type":899},{"data":38517,"marks":38518,"value":29231,"nodeType":864},{},[],{"data":38520,"content":38521,"nodeType":860},{},[38522,38526],{"data":38523,"marks":38524,"value":29239,"nodeType":864},{},[38525],{"type":899},{"data":38527,"marks":38528,"value":29243,"nodeType":864},{},[],{"data":38530,"content":38531,"nodeType":860},{},[38532,38535,38541],{"data":38533,"marks":38534,"value":21,"nodeType":864},{},[],{"data":38536,"content":38537,"nodeType":883},{"uri":24926},[38538],{"data":38539,"marks":38540,"value":29256,"nodeType":864},{},[],{"data":38542,"marks":38543,"value":21,"nodeType":864},{},[],{"data":38545,"content":38546,"nodeType":1312},{},[38547],{"data":38548,"marks":38549,"value":29267,"nodeType":864},{},[38550],{"type":899},{"data":38552,"content":38553,"nodeType":860},{},[38554],{"data":38555,"marks":38556,"value":29274,"nodeType":864},{},[],{"data":38558,"content":38559,"nodeType":1005},{},[],{"data":38561,"content":38562,"nodeType":860},{},[38563],{"data":38564,"marks":38565,"value":4855,"nodeType":864},{},[],{"data":38567,"content":38568,"nodeType":860},{},[38569],{"data":38570,"marks":38571,"value":1689,"nodeType":864},{},[],{"data":38573,"content":38574,"nodeType":860},{},[38575,38578,38584],{"data":38576,"marks":38577,"value":21,"nodeType":864},{},[],{"data":38579,"content":38580,"nodeType":883},{"uri":14401},[38581],{"data":38582,"marks":38583,"value":1703,"nodeType":864},{},[],{"data":38585,"marks":38586,"value":21,"nodeType":864},{},[],{"data":38588,"content":38589,"nodeType":1005},{},[],{"data":38591,"content":38592,"nodeType":1009},{},[38593],{"data":38594,"marks":38595,"value":29315,"nodeType":864},{},[38596],{"type":899},{"data":38598,"content":38599,"nodeType":860},{},[38600,38603,38609],{"data":38601,"marks":38602,"value":29322,"nodeType":864},{},[],{"data":38604,"content":38605,"nodeType":883},{"uri":16015},[38606],{"data":38607,"marks":38608,"value":29329,"nodeType":864},{},[],{"data":38610,"marks":38611,"value":29333,"nodeType":864},{},[],{"data":38613,"content":38614,"nodeType":4845},{},[38615,38658,38714,38757,38800],{"data":38616,"content":38617,"nodeType":4581},{},[38618,38628,38638,38648],{"data":38619,"content":38620,"nodeType":4569},{},[38621],{"data":38622,"content":38623,"nodeType":860},{},[38624],{"data":38625,"marks":38626,"value":29350,"nodeType":864},{},[38627],{"type":899},{"data":38629,"content":38630,"nodeType":4569},{},[38631],{"data":38632,"content":38633,"nodeType":860},{},[38634],{"data":38635,"marks":38636,"value":29361,"nodeType":864},{},[38637],{"type":899},{"data":38639,"content":38640,"nodeType":4569},{},[38641],{"data":38642,"content":38643,"nodeType":860},{},[38644],{"data":38645,"marks":38646,"value":29372,"nodeType":864},{},[38647],{"type":899},{"data":38649,"content":38650,"nodeType":4569},{},[38651],{"data":38652,"content":38653,"nodeType":860},{},[38654],{"data":38655,"marks":38656,"value":29383,"nodeType":864},{},[38657],{"type":899},{"data":38659,"content":38660,"nodeType":4581},{},[38661,38681,38690,38699],{"data":38662,"content":38663,"nodeType":4569},{},[38664],{"data":38665,"content":38666,"nodeType":860},{},[38667,38671,38674,38678],{"data":38668,"marks":38669,"value":29397,"nodeType":864},{},[38670],{"type":899},{"data":38672,"marks":38673,"value":29401,"nodeType":864},{},[],{"data":38675,"marks":38676,"value":29406,"nodeType":864},{},[38677],{"type":899},{"data":38679,"marks":38680,"value":29410,"nodeType":864},{},[],{"data":38682,"content":38683,"nodeType":4569},{},[38684],{"data":38685,"content":38686,"nodeType":860},{},[38687],{"data":38688,"marks":38689,"value":29420,"nodeType":864},{},[],{"data":38691,"content":38692,"nodeType":4569},{},[38693],{"data":38694,"content":38695,"nodeType":860},{},[38696],{"data":38697,"marks":38698,"value":29430,"nodeType":864},{},[],{"data":38700,"content":38701,"nodeType":4569},{},[38702,38708],{"data":38703,"content":38704,"nodeType":860},{},[38705],{"data":38706,"marks":38707,"value":29440,"nodeType":864},{},[],{"data":38709,"content":38710,"nodeType":860},{},[38711],{"data":38712,"marks":38713,"value":29447,"nodeType":864},{},[],{"data":38715,"content":38716,"nodeType":4581},{},[38717,38730,38739,38748],{"data":38718,"content":38719,"nodeType":4569},{},[38720],{"data":38721,"content":38722,"nodeType":860},{},[38723,38727],{"data":38724,"marks":38725,"value":29461,"nodeType":864},{},[38726],{"type":899},{"data":38728,"marks":38729,"value":29465,"nodeType":864},{},[],{"data":38731,"content":38732,"nodeType":4569},{},[38733],{"data":38734,"content":38735,"nodeType":860},{},[38736],{"data":38737,"marks":38738,"value":29475,"nodeType":864},{},[],{"data":38740,"content":38741,"nodeType":4569},{},[38742],{"data":38743,"content":38744,"nodeType":860},{},[38745],{"data":38746,"marks":38747,"value":29485,"nodeType":864},{},[],{"data":38749,"content":38750,"nodeType":4569},{},[38751],{"data":38752,"content":38753,"nodeType":860},{},[38754],{"data":38755,"marks":38756,"value":29495,"nodeType":864},{},[],{"data":38758,"content":38759,"nodeType":4581},{},[38760,38773,38782,38791],{"data":38761,"content":38762,"nodeType":4569},{},[38763],{"data":38764,"content":38765,"nodeType":860},{},[38766,38770],{"data":38767,"marks":38768,"value":29509,"nodeType":864},{},[38769],{"type":899},{"data":38771,"marks":38772,"value":29513,"nodeType":864},{},[],{"data":38774,"content":38775,"nodeType":4569},{},[38776],{"data":38777,"content":38778,"nodeType":860},{},[38779],{"data":38780,"marks":38781,"value":29523,"nodeType":864},{},[],{"data":38783,"content":38784,"nodeType":4569},{},[38785],{"data":38786,"content":38787,"nodeType":860},{},[38788],{"data":38789,"marks":38790,"value":29533,"nodeType":864},{},[],{"data":38792,"content":38793,"nodeType":4569},{},[38794],{"data":38795,"content":38796,"nodeType":860},{},[38797],{"data":38798,"marks":38799,"value":29543,"nodeType":864},{},[],{"data":38801,"content":38802,"nodeType":4581},{},[38803,38816,38825,38834],{"data":38804,"content":38805,"nodeType":4569},{},[38806],{"data":38807,"content":38808,"nodeType":860},{},[38809,38813],{"data":38810,"marks":38811,"value":29557,"nodeType":864},{},[38812],{"type":899},{"data":38814,"marks":38815,"value":29561,"nodeType":864},{},[],{"data":38817,"content":38818,"nodeType":4569},{},[38819],{"data":38820,"content":38821,"nodeType":860},{},[38822],{"data":38823,"marks":38824,"value":29420,"nodeType":864},{},[],{"data":38826,"content":38827,"nodeType":4569},{},[38828],{"data":38829,"content":38830,"nodeType":860},{},[38831],{"data":38832,"marks":38833,"value":29580,"nodeType":864},{},[],{"data":38835,"content":38836,"nodeType":4569},{},[38837],{"data":38838,"content":38839,"nodeType":860},{},[38840],{"data":38841,"marks":38842,"value":29590,"nodeType":864},{},[],{"data":38844,"content":38845,"nodeType":860},{},[38846],{"data":38847,"marks":38848,"value":21,"nodeType":864},{},[],{"items":38850},[38851,38853],{"sys":38852,"name":13779},{"id":13778},{"sys":38854,"name":342},{"id":13775},{"items":38856},[38857],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":38858},{"url":2740},"blog/7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",{"json":38861},{"data":38862,"content":38863,"nodeType":856},{},[38864],{"data":38865,"content":38866,"nodeType":860},{},[38867],{"data":38868,"marks":38869,"value":38870,"nodeType":864},{},[],"New research from Omdia has put hard numbers behind something security teams have been feeling for the past two years: the browser has become the primary attack surface in the enterprise, organizations are investing accordingly, and the results are already measurable.",{"id":28048,"publishedAt":38872},"2026-08-12T11:52:51.573Z",{"items":38874},[38875,38877],{"sys":38876,"name":297},{"id":2732},{"sys":38878,"name":2729},{"id":2728},{"items":38880},[38881,38883,38885,38887,38889,38891,38893,38895,38897,38899,38901,38903,38905,38907,38909,38911,38913,38915,38917],{"sys":38882,"name":297,"slug":298,"tier":31},{"id":294},{"sys":38884,"name":642,"slug":643,"tier":31},{"id":639},{"sys":38886,"name":279,"slug":280,"tier":31},{"id":276},{"sys":38888,"name":519,"slug":520,"tier":31},{"id":516},{"sys":38890,"name":413,"slug":414,"tier":31},{"id":410},{"sys":38892,"name":235,"slug":236,"tier":31},{"id":232},{"sys":38894,"name":386,"slug":387,"tier":45},{"id":383},{"sys":38896,"name":580,"slug":581,"tier":45},{"id":577},{"sys":38898,"name":261,"slug":262,"tier":45},{"id":258},{"sys":38900,"name":324,"slug":325,"tier":45},{"id":321},{"sys":38902,"name":571,"slug":572,"tier":45},{"id":568},{"sys":38904,"name":288,"slug":289,"tier":45},{"id":285},{"sys":38906,"name":368,"slug":369,"tier":45},{"id":365},{"sys":38908,"name":315,"slug":316,"tier":45},{"id":312},{"sys":38910,"name":360,"slug":361,"tier":45},{"id":357},{"sys":38912,"name":252,"slug":253,"tier":45},{"id":249},{"sys":38914,"name":511,"slug":512,"tier":45},{"id":508},{"sys":38916,"name":624,"slug":625,"tier":45},{"id":621},{"sys":38918,"name":244,"slug":245,"tier":45},{"id":241},"R6qLSR-i1d8ltg2tNiiwocbWu7Y3b4pT4C_MTKlUwec",{"id":38921,"title":26291,"authorsCollection":38922,"content":38927,"extension":228,"faqItemsCollection":39700,"faqTitle":59,"featured":6,"hashTags":59,"meta":39702,"metaTitle":39703,"ogImage":59,"postType":5726,"publishedDate":26293,"relatedBlogPostsCollection":39704,"slug":26294,"stem":41932,"subtitle":59,"summary":41933,"synopsis":26292,"sys":41944,"tagsCollection":41946,"topicsCollection":41952,"__hash__":42000},"blog/blog/how-to-avoid-the-browser-security-buyers-trap.json",{"items":38923},[38924],{"fullName":4878,"firstName":4879,"jobTitle":851,"socialLinks":38925,"profilePicture":38926},[24316],{"url":4881},{"json":38928,"links":39587},{"data":38929,"content":38930,"nodeType":856},{},[38931,38936,38942,38948,38954,38957,38964,38970,38980,38990,38995,39001,39004,39011,39017,39022,39028,39034,39127,39133,39136,39143,39149,39204,39217,39222,39228,39231,39238,39244,39251,39257,39263,39288,39294,39301,39307,39313,39319,39326,39332,39338,39344,39347,39354,39364,39370,39376,39383,39389,39395,39402,39408,39463,39476,39491,39498,39504,39511,39517,39523,39529,39534,39541,39547,39553,39558,39564,39570,39576,39581],{"data":38932,"content":38935,"nodeType":996},{"target":38933},{"sys":38934},{"id":25536,"type":1001,"linkType":1002},[],{"data":38937,"content":38938,"nodeType":860},{},[38939],{"data":38940,"marks":38941,"value":25544,"nodeType":864},{},[],{"data":38943,"content":38944,"nodeType":860},{},[38945],{"data":38946,"marks":38947,"value":25551,"nodeType":864},{},[],{"data":38949,"content":38950,"nodeType":860},{},[38951],{"data":38952,"marks":38953,"value":25558,"nodeType":864},{},[],{"data":38955,"content":38956,"nodeType":1005},{},[],{"data":38958,"content":38959,"nodeType":1009},{},[38960],{"data":38961,"marks":38962,"value":25569,"nodeType":864},{},[38963],{"type":899},{"data":38965,"content":38966,"nodeType":860},{},[38967],{"data":38968,"marks":38969,"value":25576,"nodeType":864},{},[],{"data":38971,"content":38972,"nodeType":860},{},[38973,38977],{"data":38974,"marks":38975,"value":25584,"nodeType":864},{},[38976],{"type":899},{"data":38978,"marks":38979,"value":25588,"nodeType":864},{},[],{"data":38981,"content":38982,"nodeType":860},{},[38983,38987],{"data":38984,"marks":38985,"value":25596,"nodeType":864},{},[38986],{"type":899},{"data":38988,"marks":38989,"value":25600,"nodeType":864},{},[],{"data":38991,"content":38994,"nodeType":996},{"target":38992},{"sys":38993},{"id":23546,"type":1001,"linkType":1002},[],{"data":38996,"content":38997,"nodeType":860},{},[38998],{"data":38999,"marks":39000,"value":25612,"nodeType":864},{},[],{"data":39002,"content":39003,"nodeType":1005},{},[],{"data":39005,"content":39006,"nodeType":1009},{},[39007],{"data":39008,"marks":39009,"value":25623,"nodeType":864},{},[39010],{"type":899},{"data":39012,"content":39013,"nodeType":860},{},[39014],{"data":39015,"marks":39016,"value":25630,"nodeType":864},{},[],{"data":39018,"content":39021,"nodeType":996},{"target":39019},{"sys":39020},{"id":25635,"type":1001,"linkType":1002},[],{"data":39023,"content":39024,"nodeType":860},{},[39025],{"data":39026,"marks":39027,"value":25643,"nodeType":864},{},[],{"data":39029,"content":39030,"nodeType":860},{},[39031],{"data":39032,"marks":39033,"value":25650,"nodeType":864},{},[],{"data":39035,"content":39036,"nodeType":941},{},[39037,39053,39069,39085,39101,39114],{"data":39038,"content":39039,"nodeType":945},{},[39040],{"data":39041,"content":39042,"nodeType":860},{},[39043,39046,39050],{"data":39044,"marks":39045,"value":25663,"nodeType":864},{},[],{"data":39047,"marks":39048,"value":25055,"nodeType":864},{},[39049],{"type":899},{"data":39051,"marks":39052,"value":25671,"nodeType":864},{},[],{"data":39054,"content":39055,"nodeType":945},{},[39056],{"data":39057,"content":39058,"nodeType":860},{},[39059,39062,39066],{"data":39060,"marks":39061,"value":25681,"nodeType":864},{},[],{"data":39063,"marks":39064,"value":25686,"nodeType":864},{},[39065],{"type":899},{"data":39067,"marks":39068,"value":25690,"nodeType":864},{},[],{"data":39070,"content":39071,"nodeType":945},{},[39072],{"data":39073,"content":39074,"nodeType":860},{},[39075,39078,39082],{"data":39076,"marks":39077,"value":25700,"nodeType":864},{},[],{"data":39079,"marks":39080,"value":25705,"nodeType":864},{},[39081],{"type":899},{"data":39083,"marks":39084,"value":25709,"nodeType":864},{},[],{"data":39086,"content":39087,"nodeType":945},{},[39088],{"data":39089,"content":39090,"nodeType":860},{},[39091,39094,39098],{"data":39092,"marks":39093,"value":25719,"nodeType":864},{},[],{"data":39095,"marks":39096,"value":25724,"nodeType":864},{},[39097],{"type":899},{"data":39099,"marks":39100,"value":25728,"nodeType":864},{},[],{"data":39102,"content":39103,"nodeType":945},{},[39104],{"data":39105,"content":39106,"nodeType":860},{},[39107,39111],{"data":39108,"marks":39109,"value":18801,"nodeType":864},{},[39110],{"type":899},{"data":39112,"marks":39113,"value":25742,"nodeType":864},{},[],{"data":39115,"content":39116,"nodeType":945},{},[39117],{"data":39118,"content":39119,"nodeType":860},{},[39120,39124],{"data":39121,"marks":39122,"value":25753,"nodeType":864},{},[39123],{"type":899},{"data":39125,"marks":39126,"value":25757,"nodeType":864},{},[],{"data":39128,"content":39129,"nodeType":860},{},[39130],{"data":39131,"marks":39132,"value":25764,"nodeType":864},{},[],{"data":39134,"content":39135,"nodeType":1005},{},[],{"data":39137,"content":39138,"nodeType":1312},{},[39139],{"data":39140,"marks":39141,"value":25775,"nodeType":864},{},[39142],{"type":899},{"data":39144,"content":39145,"nodeType":860},{},[39146],{"data":39147,"marks":39148,"value":25782,"nodeType":864},{},[],{"data":39150,"content":39151,"nodeType":941},{},[39152,39165,39178,39191],{"data":39153,"content":39154,"nodeType":945},{},[39155],{"data":39156,"content":39157,"nodeType":860},{},[39158,39161],{"data":39159,"marks":39160,"value":25795,"nodeType":864},{},[],{"data":39162,"marks":39163,"value":25800,"nodeType":864},{},[39164],{"type":899},{"data":39166,"content":39167,"nodeType":945},{},[39168],{"data":39169,"content":39170,"nodeType":860},{},[39171,39174],{"data":39172,"marks":39173,"value":25810,"nodeType":864},{},[],{"data":39175,"marks":39176,"value":25815,"nodeType":864},{},[39177],{"type":899},{"data":39179,"content":39180,"nodeType":945},{},[39181],{"data":39182,"content":39183,"nodeType":860},{},[39184,39187],{"data":39185,"marks":39186,"value":25825,"nodeType":864},{},[],{"data":39188,"marks":39189,"value":25830,"nodeType":864},{},[39190],{"type":899},{"data":39192,"content":39193,"nodeType":945},{},[39194],{"data":39195,"content":39196,"nodeType":860},{},[39197,39200],{"data":39198,"marks":39199,"value":25840,"nodeType":864},{},[],{"data":39201,"marks":39202,"value":25845,"nodeType":864},{},[39203],{"type":899},{"data":39205,"content":39206,"nodeType":860},{},[39207,39210,39214],{"data":39208,"marks":39209,"value":25852,"nodeType":864},{},[],{"data":39211,"marks":39212,"value":25857,"nodeType":864},{},[39213],{"type":899},{"data":39215,"marks":39216,"value":25861,"nodeType":864},{},[],{"data":39218,"content":39221,"nodeType":996},{"target":39219},{"sys":39220},{"id":25866,"type":1001,"linkType":1002},[],{"data":39223,"content":39224,"nodeType":860},{},[39225],{"data":39226,"marks":39227,"value":25874,"nodeType":864},{},[],{"data":39229,"content":39230,"nodeType":1005},{},[],{"data":39232,"content":39233,"nodeType":1009},{},[39234],{"data":39235,"marks":39236,"value":25885,"nodeType":864},{},[39237],{"type":899},{"data":39239,"content":39240,"nodeType":860},{},[39241],{"data":39242,"marks":39243,"value":25892,"nodeType":864},{},[],{"data":39245,"content":39246,"nodeType":1312},{},[39247],{"data":39248,"marks":39249,"value":25900,"nodeType":864},{},[39250],{"type":899},{"data":39252,"content":39253,"nodeType":860},{},[39254],{"data":39255,"marks":39256,"value":25907,"nodeType":864},{},[],{"data":39258,"content":39259,"nodeType":860},{},[39260],{"data":39261,"marks":39262,"value":25914,"nodeType":864},{},[],{"data":39264,"content":39265,"nodeType":860},{},[39266,39269,39275,39278,39285],{"data":39267,"marks":39268,"value":25921,"nodeType":864},{},[],{"data":39270,"content":39271,"nodeType":883},{"uri":2561},[39272],{"data":39273,"marks":39274,"value":25928,"nodeType":864},{},[],{"data":39276,"marks":39277,"value":25932,"nodeType":864},{},[],{"data":39279,"content":39280,"nodeType":883},{"uri":16203},[39281],{"data":39282,"marks":39283,"value":25940,"nodeType":864},{},[39284],{"type":1455},{"data":39286,"marks":39287,"value":25944,"nodeType":864},{},[],{"data":39289,"content":39290,"nodeType":860},{},[39291],{"data":39292,"marks":39293,"value":25951,"nodeType":864},{},[],{"data":39295,"content":39296,"nodeType":1312},{},[39297],{"data":39298,"marks":39299,"value":25959,"nodeType":864},{},[39300],{"type":899},{"data":39302,"content":39303,"nodeType":860},{},[39304],{"data":39305,"marks":39306,"value":25966,"nodeType":864},{},[],{"data":39308,"content":39309,"nodeType":860},{},[39310],{"data":39311,"marks":39312,"value":25973,"nodeType":864},{},[],{"data":39314,"content":39315,"nodeType":860},{},[39316],{"data":39317,"marks":39318,"value":25980,"nodeType":864},{},[],{"data":39320,"content":39321,"nodeType":1312},{},[39322],{"data":39323,"marks":39324,"value":25988,"nodeType":864},{},[39325],{"type":899},{"data":39327,"content":39328,"nodeType":860},{},[39329],{"data":39330,"marks":39331,"value":25995,"nodeType":864},{},[],{"data":39333,"content":39334,"nodeType":860},{},[39335],{"data":39336,"marks":39337,"value":26002,"nodeType":864},{},[],{"data":39339,"content":39340,"nodeType":860},{},[39341],{"data":39342,"marks":39343,"value":26009,"nodeType":864},{},[],{"data":39345,"content":39346,"nodeType":1005},{},[],{"data":39348,"content":39349,"nodeType":1009},{},[39350],{"data":39351,"marks":39352,"value":26020,"nodeType":864},{},[39353],{"type":899},{"data":39355,"content":39356,"nodeType":860},{},[39357,39361],{"data":39358,"marks":39359,"value":26028,"nodeType":864},{},[39360],{"type":899},{"data":39362,"marks":39363,"value":26032,"nodeType":864},{},[],{"data":39365,"content":39366,"nodeType":860},{},[39367],{"data":39368,"marks":39369,"value":26039,"nodeType":864},{},[],{"data":39371,"content":39372,"nodeType":860},{},[39373],{"data":39374,"marks":39375,"value":26046,"nodeType":864},{},[],{"data":39377,"content":39378,"nodeType":1312},{},[39379],{"data":39380,"marks":39381,"value":26054,"nodeType":864},{},[39382],{"type":899},{"data":39384,"content":39385,"nodeType":860},{},[39386],{"data":39387,"marks":39388,"value":26061,"nodeType":864},{},[],{"data":39390,"content":39391,"nodeType":860},{},[39392],{"data":39393,"marks":39394,"value":26068,"nodeType":864},{},[],{"data":39396,"content":39397,"nodeType":1312},{},[39398],{"data":39399,"marks":39400,"value":26076,"nodeType":864},{},[39401],{"type":899},{"data":39403,"content":39404,"nodeType":860},{},[39405],{"data":39406,"marks":39407,"value":26083,"nodeType":864},{},[],{"data":39409,"content":39410,"nodeType":941},{},[39411,39424,39437,39450],{"data":39412,"content":39413,"nodeType":945},{},[39414],{"data":39415,"content":39416,"nodeType":860},{},[39417,39421],{"data":39418,"marks":39419,"value":26097,"nodeType":864},{},[39420],{"type":899},{"data":39422,"marks":39423,"value":26101,"nodeType":864},{},[],{"data":39425,"content":39426,"nodeType":945},{},[39427],{"data":39428,"content":39429,"nodeType":860},{},[39430,39434],{"data":39431,"marks":39432,"value":26112,"nodeType":864},{},[39433],{"type":899},{"data":39435,"marks":39436,"value":26116,"nodeType":864},{},[],{"data":39438,"content":39439,"nodeType":945},{},[39440],{"data":39441,"content":39442,"nodeType":860},{},[39443,39447],{"data":39444,"marks":39445,"value":26127,"nodeType":864},{},[39446],{"type":899},{"data":39448,"marks":39449,"value":26131,"nodeType":864},{},[],{"data":39451,"content":39452,"nodeType":945},{},[39453],{"data":39454,"content":39455,"nodeType":860},{},[39456,39460],{"data":39457,"marks":39458,"value":26142,"nodeType":864},{},[39459],{"type":899},{"data":39461,"marks":39462,"value":26146,"nodeType":864},{},[],{"data":39464,"content":39465,"nodeType":860},{},[39466,39469,39473],{"data":39467,"marks":39468,"value":26153,"nodeType":864},{},[],{"data":39470,"marks":39471,"value":26158,"nodeType":864},{},[39472],{"type":899},{"data":39474,"marks":39475,"value":26162,"nodeType":864},{},[],{"data":39477,"content":39478,"nodeType":860},{},[39479,39482,39488],{"data":39480,"marks":39481,"value":26169,"nodeType":864},{},[],{"data":39483,"content":39484,"nodeType":883},{"uri":3210},[39485],{"data":39486,"marks":39487,"value":26176,"nodeType":864},{},[],{"data":39489,"marks":39490,"value":26180,"nodeType":864},{},[],{"data":39492,"content":39493,"nodeType":1312},{},[39494],{"data":39495,"marks":39496,"value":26188,"nodeType":864},{},[39497],{"type":899},{"data":39499,"content":39500,"nodeType":860},{},[39501],{"data":39502,"marks":39503,"value":26195,"nodeType":864},{},[],{"data":39505,"content":39506,"nodeType":860},{},[39507],{"data":39508,"marks":39509,"value":26203,"nodeType":864},{},[39510],{"type":899},{"data":39512,"content":39513,"nodeType":860},{},[39514],{"data":39515,"marks":39516,"value":26210,"nodeType":864},{},[],{"data":39518,"content":39519,"nodeType":860},{},[39520],{"data":39521,"marks":39522,"value":26217,"nodeType":864},{},[],{"data":39524,"content":39525,"nodeType":860},{},[39526],{"data":39527,"marks":39528,"value":26224,"nodeType":864},{},[],{"data":39530,"content":39533,"nodeType":996},{"target":39531},{"sys":39532},{"id":26229,"type":1001,"linkType":1002},[],{"data":39535,"content":39536,"nodeType":1312},{},[39537],{"data":39538,"marks":39539,"value":26238,"nodeType":864},{},[39540],{"type":899},{"data":39542,"content":39543,"nodeType":860},{},[39544],{"data":39545,"marks":39546,"value":26245,"nodeType":864},{},[],{"data":39548,"content":39549,"nodeType":860},{},[39550],{"data":39551,"marks":39552,"value":26252,"nodeType":864},{},[],{"data":39554,"content":39557,"nodeType":996},{"target":39555},{"sys":39556},{"id":11598,"type":1001,"linkType":1002},[],{"data":39559,"content":39560,"nodeType":860},{},[39561],{"data":39562,"marks":39563,"value":26264,"nodeType":864},{},[],{"data":39565,"content":39566,"nodeType":860},{},[39567],{"data":39568,"marks":39569,"value":26271,"nodeType":864},{},[],{"data":39571,"content":39572,"nodeType":860},{},[39573],{"data":39574,"marks":39575,"value":26278,"nodeType":864},{},[],{"data":39577,"content":39580,"nodeType":996},{"target":39578},{"sys":39579},{"id":26283,"type":1001,"linkType":1002},[],{"data":39582,"content":39583,"nodeType":860},{},[39584],{"data":39585,"marks":39586,"value":21,"nodeType":864},{},[],{"entries":39588},{"hyperlink":39589,"inline":39590,"block":39591},[],[],[39592,39618,39620,39656,39679,39693,39696],{"sys":39593,"__typename":1740,"content":39594,"name":39617,"title":59},{"id":25536},{"json":39595},{"nodeType":856,"data":39596,"content":39597},{},[39598,39610],{"nodeType":860,"data":39599,"content":39600},{},[39601,39606],{"nodeType":864,"value":39602,"marks":39603,"data":39605},"TL;DR:",[39604],{"type":899},{},{"nodeType":864,"value":39607,"marks":39608,"data":39609}," Not all browser security investments address the same threat. Seraphic (Crowdstrike) focuses on browser exploitation, SquareX (ZScaler) on malware sandboxing, LayerX on internal governance. None of these address the attacks that are actually causing the most damaging breaches today: identity theft, credential abuse, and session hijacking that play out entirely inside the browser using legitimate authentication flows. Push Security is built specifically for that threat model — delivering the greatest coverage against the most damaging attacks, without the user friction, operational management burden, or stability risks associated with other solutions.",[],{},{"nodeType":860,"data":39611,"content":39612},{},[39613],{"nodeType":864,"value":39614,"marks":39615,"data":39616},"\n",[],{},"Browser security buyer's trap IB1",{"sys":39619,"__typename":1717,"type":1718,"ctaText":36837,"buttonLabel":36838,"buttonColour":1721,"buttonUrl":11536},{"id":23546},{"sys":39621,"__typename":1740,"content":39622,"name":39655,"title":59},{"id":25635},{"json":39623},{"data":39624,"content":39625,"nodeType":856},{},[39626],{"data":39627,"content":39628,"nodeType":860},{},[39629,39633,39640,39643,39651],{"data":39630,"marks":39631,"value":39632,"nodeType":864},{},[],"You can read about ",{"data":39634,"content":39635,"nodeType":883},{"uri":16015},[39636],{"data":39637,"marks":39638,"value":16018,"nodeType":864},{},[39639],{"type":1455},{"data":39641,"marks":39642,"value":902,"nodeType":864},{},[],{"data":39644,"content":39645,"nodeType":883},{"uri":4082},[39646],{"data":39647,"marks":39648,"value":39650,"nodeType":864},{},[39649],{"type":1455},"ShinyHunters’ 2026 campaigns and TTPs",{"data":39652,"marks":39653,"value":39654,"nodeType":864},{},[]," in our dedicated blog posts. ","Browser security buyer's trap IB2",{"sys":39657,"__typename":1740,"content":39658,"name":39678,"title":59},{"id":25866},{"json":39659},{"data":39660,"content":39661,"nodeType":856},{},[39662],{"data":39663,"content":39664,"nodeType":860},{},[39665,39669,39674],{"data":39666,"marks":39667,"value":39668,"nodeType":864},{},[],"It's worth heading off the obvious counterargument: ",{"data":39670,"marks":39671,"value":39673,"nodeType":864},{},[39672],{"type":899},"won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? ",{"data":39675,"marks":39676,"value":39677,"nodeType":864},{},[],"Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development. ","Browser security buyer's trap IB3",{"sys":39680,"__typename":1740,"content":39681,"name":39692,"title":59},{"id":26229},{"json":39682},{"nodeType":856,"data":39683,"content":39684},{},[39685],{"nodeType":860,"data":39686,"content":39687},{},[39688],{"nodeType":864,"value":39689,"marks":39690,"data":39691},"Solutions optimized for browser exploitation are defending against a shrinking attack category. Browser vendors are very good at closing those vulnerabilities, quickly. The ROI trajectory points the wrong way.",[],{},"Browser security buyer's trap IB4",{"sys":39694,"__typename":1724,"title":24916,"caption":24917,"layoutMode":59,"file":39695},{"id":11598},{"url":24919,"width":24920,"height":24921},{"sys":39697,"__typename":1717,"type":1718,"ctaText":39698,"buttonLabel":39699,"buttonColour":1721,"buttonUrl":14401},{"id":26283},"Ready to learn more about Push? Book a demo with one of our team. ","Book a Demo",{"items":39701},[],{},"Solving for attacks that happen in, not on the browser",{"items":39705},[39706,40657,41490],{"__typename":2059,"sys":39707,"content":39709,"title":40643,"synopsis":40644,"hashTags":59,"publishedDate":40645,"slug":40646,"tagsCollection":40647,"authorsCollection":40653},{"id":39708},"1jfqiWQlL6qkn3i9yjNbFB",{"json":39710},{"data":39711,"content":39712,"nodeType":856},{},[39713,39720,39741,39753,39760,39768,39775,39797,39804,39811,39818,39830,39836,39839,39847,39863,39882,39992,39997,40004,40010,40018,40025,40037,40044,40050,40057,40081,40088,40095,40101,40104,40112,40119,40127,40134,40150,40157,40164,40172,40179,40186,40194,40201,40208,40211,40219,40226,40234,40241,40248,40255,40262,40270,40277,40309,40316,40323,40329,40336,40344,40351,40429,40435,40443,40459,40466,40472,40479,40495,40498,40506,40513,40520,40526,40533,40577,40584,40591,40598,40604,40607,40615,40621,40627],{"data":39714,"content":39715,"nodeType":860},{},[39716],{"data":39717,"marks":39718,"value":39719,"nodeType":864},{},[],"In March, our threat hunting engine flagged something it hadn’t seen before.",{"data":39721,"content":39722,"nodeType":860},{},[39723,39727,39737],{"data":39724,"marks":39725,"value":39726,"nodeType":864},{},[],"Our research team had already been tracking the growing use of ",{"data":39728,"content":39732,"nodeType":39736},{"target":39729},{"sys":39730},{"id":39731,"type":1001,"linkType":1002},"2U6QpQ9rkY8x5ES48okHZB",[39733],{"data":39734,"marks":39735,"value":441,"nodeType":864},{},[],"entry-hyperlink",{"data":39738,"marks":39739,"value":39740,"nodeType":864},{},[]," tied to phishing campaigns. Malvertising frequently targets users via Google Search results, inserting malicious ads or redirects in place of legitimate ads, and using the familiar context of the search results page to trick users into clicking.",{"data":39742,"content":39743,"nodeType":860},{},[39744,39748],{"data":39745,"marks":39746,"value":39747,"nodeType":864},{},[],"To defend Push customers against this threat, we needed a way to spot malicious activity arising from clicking on Google ads. ",{"data":39749,"marks":39750,"value":39752,"nodeType":864},{},[39751],{"type":2246},"But how to separate signal from noise?",{"data":39754,"content":39755,"nodeType":860},{},[39756],{"data":39757,"marks":39758,"value":39759,"nodeType":864},{},[],"Our hunt combined the skills of human researchers and AI agents to find 12 meaningful results from trillions of browser events visible to the Push extension across our install base.",{"data":39761,"content":39762,"nodeType":860},{},[39763],{"data":39764,"marks":39765,"value":39767,"nodeType":864},{},[39766],{"type":899},"Of those, one was novel. ",{"data":39769,"content":39770,"nodeType":860},{},[39771],{"data":39772,"marks":39773,"value":39774,"nodeType":864},{},[],"A user had searched for NotebookLM, clicked a paid Google ad, and gotten redirected to a page impersonating NotebookLM. The page itself was just a facade fronting a Cloudflare Pages-hosted phishing kit with a WebAssembly C2 connector. To the user, it looked like a completely on-brand NotebookLM page, and if they had run the fake install prompt, they would have installed malware. (Note: NotebookLM doesn’t even require a local install, but the page was convincing enough — and AI platforms are changing so quickly — that the lure was extremely believable.)",{"data":39776,"content":39777,"nodeType":860},{},[39778,39783,39793],{"data":39779,"marks":39780,"value":39782,"nodeType":864},{},[39781],{"type":899},"We had found our first in-the-wild ",{"data":39784,"content":39788,"nodeType":39736},{"target":39785},{"sys":39786},{"id":39787,"type":1001,"linkType":1002},"7bG71Eo43crbIHKzczooVS",[39789],{"data":39790,"marks":39791,"value":13698,"nodeType":864},{},[39792],{"type":899},{"data":39794,"marks":39795,"value":2924,"nodeType":864},{},[39796],{"type":899},{"data":39798,"content":39799,"nodeType":860},{},[39800],{"data":39801,"marks":39802,"value":39803,"nodeType":864},{},[],"Within minutes, our analysis agents created detections, and researchers shipped a new detection to every Push customer. ",{"data":39805,"content":39806,"nodeType":860},{},[39807],{"data":39808,"marks":39809,"value":39810,"nodeType":864},{},[],"Eighteen months ago, it would have taken a human analyst days or even weeks to unpack the attack, comb through web requests, de-obfuscate web code, trace JavaScript execution, and extract signals of tactics, techniques, and procedures (TTPs) beyond short-lived single-use IOCs like domain name, then get their work coded up as a detection and deployed to customers. ",{"data":39812,"content":39813,"nodeType":860},{},[39814],{"data":39815,"marks":39816,"value":39817,"nodeType":864},{},[],"That was viable when new tools or techniques showed up once or twice a quarter. It doesn’t stand a chance when attack evolutions occur weekly or even daily. That’s the reality now with AI-generated adversary tools.",{"data":39819,"content":39820,"nodeType":860},{},[39821,39826],{"data":39822,"marks":39823,"value":39825,"nodeType":864},{},[39824],{"type":899},"So, can AI agents replace human threat researchers?",{"data":39827,"marks":39828,"value":39829,"nodeType":864},{},[]," That’s the wrong question. Can AI agents massively scale the expertise of a seasoned human threat hunter without getting bored of repetitive tasks, missing pertinent but easily overlooked details, or creating operational siloes dependent on one person’s knowledge — and do its work continuously across trillions of data points? Yes, absolutely.",{"data":39831,"content":39835,"nodeType":996},{"target":39832},{"sys":39833},{"id":39834,"type":1001,"linkType":1002},"3OiZ7BrViCTTMmHUAbloEt",[],{"data":39837,"content":39838,"nodeType":1005},{},[],{"data":39840,"content":39841,"nodeType":1009},{},[39842],{"data":39843,"marks":39844,"value":39846,"nodeType":864},{},[39845],{"type":899},"Why scaling browser threat detection requires more than more analysts",{"data":39848,"content":39849,"nodeType":860},{},[39850,39854,39859],{"data":39851,"marks":39852,"value":39853,"nodeType":864},{},[],"Already this year, we’ve ",{"data":39855,"marks":39856,"value":39858,"nodeType":864},{},[39857],{"type":899},"tripled",{"data":39860,"marks":39861,"value":39862,"nodeType":864},{},[]," the cumulative number of detections shipped to Push customers using this pipeline. That output points to the first problem we set out to solve by employing AI agents: Scaling our research team’s considerable expertise.",{"data":39864,"content":39865,"nodeType":860},{},[39866,39870,39878],{"data":39867,"marks":39868,"value":39869,"nodeType":864},{},[],"Push’s R&D team are experts at understanding and unpacking modern browser-based attacks. This is essential when you consider how quickly attacks themselves are evolving. When we created the ",{"data":39871,"content":39874,"nodeType":39736},{"target":39872},{"sys":39873},{"id":23397,"type":1001,"linkType":1002},[39875],{"data":39876,"marks":39877,"value":11754,"nodeType":864},{},[],{"data":39879,"marks":39880,"value":39881,"nodeType":864},{},[]," in 2023 (then called the SaaS Attacks Matrix), many of the ideas in it were theoretical. Not anymore. ",{"data":39883,"content":39884,"nodeType":941},{},[39885,39895,39918],{"data":39886,"content":39887,"nodeType":945},{},[39888],{"data":39889,"content":39890,"nodeType":860},{},[39891],{"data":39892,"marks":39893,"value":39894,"nodeType":864},{},[],"We’ve tracked the rise of AiTM phish kits from their status as MFA-bypassing novelties to the emergence of an entire criminal ecosystem built around increasingly sophisticated Phishing-as-a-Service tools. ",{"data":39896,"content":39897,"nodeType":945},{},[39898],{"data":39899,"content":39900,"nodeType":860},{},[39901,39905,39914],{"data":39902,"marks":39903,"value":39904,"nodeType":864},{},[],"We imagined the simple but effective power of using device code authorization for phishing three years ago; in the last few months, we’ve detected a 37x increase in ",{"data":39906,"content":39909,"nodeType":39736},{"target":39907},{"sys":39908},{"id":19308,"type":1001,"linkType":1002},[39910],{"data":39911,"marks":39912,"value":39913,"nodeType":864},{},[],"device code phishing attacks",{"data":39915,"marks":39916,"value":39917,"nodeType":864},{},[]," across our install base. ",{"data":39919,"content":39920,"nodeType":945},{},[39921],{"data":39922,"content":39923,"nodeType":860},{},[39924,39928,39937,39941,39950,39954,39964,39967,39975,39978,39988],{"data":39925,"marks":39926,"value":39927,"nodeType":864},{},[],"We were also the first to detect a novel post-authorization attack we dubbed ",{"data":39929,"content":39933,"nodeType":39736},{"target":39930},{"sys":39931},{"id":39932,"type":1001,"linkType":1002},"71EaaK7lfl6bQBbkAU0qjv",[39934],{"data":39935,"marks":39936,"value":11731,"nodeType":864},{},[],{"data":39938,"marks":39939,"value":39940,"nodeType":864},{},[]," that combines OAuth consent phishing and ClickFix-style user prompts; reported on the rise of the ridiculously simple yet effective ",{"data":39942,"content":39945,"nodeType":39736},{"target":39943},{"sys":39944},{"id":39787,"type":1001,"linkType":1002},[39946],{"data":39947,"marks":39948,"value":39949,"nodeType":864},{},[],"InstallFix technique",{"data":39951,"marks":39952,"value":39953,"nodeType":864},{},[]," described earlier; and detected an array of other ",{"data":39955,"content":39959,"nodeType":39736},{"target":39956},{"sys":39957},{"id":39958,"type":1001,"linkType":1002},"2YmiesBvJHGw4wiKEKzLUq",[39960],{"data":39961,"marks":39962,"value":39963,"nodeType":864},{},[],"creative",{"data":39965,"marks":39966,"value":1171,"nodeType":864},{},[],{"data":39968,"content":39971,"nodeType":39736},{"target":39969},{"sys":39970},{"id":39731,"type":1001,"linkType":1002},[39972],{"data":39973,"marks":39974,"value":520,"nodeType":864},{},[],{"data":39976,"marks":39977,"value":1171,"nodeType":864},{},[],{"data":39979,"content":39983,"nodeType":39736},{"target":39980},{"sys":39981},{"id":39982,"type":1001,"linkType":1002},"6Zosy4SU0LpjlaSWX75peb",[39984],{"data":39985,"marks":39986,"value":39987,"nodeType":864},{},[],"campaigns",{"data":39989,"marks":39990,"value":39991,"nodeType":864},{},[]," tied to malvertising scams.",{"data":39993,"content":39996,"nodeType":996},{"target":39994},{"sys":39995},{"id":18980,"type":1001,"linkType":1002},[],{"data":39998,"content":39999,"nodeType":860},{},[40000],{"data":40001,"marks":40002,"value":40003,"nodeType":864},{},[],"With an agentic approach, we could scale this expertise and reduce the time it takes to go from technique discovery to production-ready detection. This speed is critical now because adversaries are also using AI tools to do their work, exploding the number of trivial-to-rotate indicators of compromise and overwhelming existing detection workflows that lack an equivalent machine speed.",{"data":40005,"content":40009,"nodeType":996},{"target":40006},{"sys":40007},{"id":40008,"type":1001,"linkType":1002},"1u00uFbC4xsvP9lqahXbgD",[],{"data":40011,"content":40012,"nodeType":1312},{},[40013],{"data":40014,"marks":40015,"value":40017,"nodeType":864},{},[40016],{"type":899},"Scaling behavioral detections, not just making bigger blocklists",{"data":40019,"content":40020,"nodeType":860},{},[40021],{"data":40022,"marks":40023,"value":40024,"nodeType":864},{},[],"But output numbers alone don’t tell the story of successful detections. That’s the other problem we set out to solve at scale: Most secure browser solutions rely on detection logic based on blocking known-bad indicators like domains, IPs, and URLs.",{"data":40026,"content":40027,"nodeType":860},{},[40028,40033],{"data":40029,"marks":40030,"value":40032,"nodeType":864},{},[40031],{"type":899},"If your solution offers 1,000 detections, and they’re all based on known-bad indicators that are easily rotated, then you’ve got 1,000 detections that worked once and will likely never fire again. ",{"data":40034,"marks":40035,"value":40036,"nodeType":864},{},[],"They certainly won’t catch subtle adaptations in adversary techniques that don’t rely on infrastructure changes, which are easy for attackers to swap anyway. ",{"data":40038,"content":40039,"nodeType":860},{},[40040],{"data":40041,"marks":40042,"value":40043,"nodeType":864},{},[],"Push does it differently. Our detection engine is focused on hunting for tactics, techniques, and procedures: the behavioral fingerprints of an attack, not just the infrastructure it runs on. ",{"data":40045,"content":40049,"nodeType":996},{"target":40046},{"sys":40047},{"id":40048,"type":1001,"linkType":1002},"5jR3YVUiusHGnXDOyrgYpr",[],{"data":40051,"content":40052,"nodeType":860},{},[40053],{"data":40054,"marks":40055,"value":40056,"nodeType":864},{},[],"Instead of blocking based on known-bad domains, URLs, and IPs, our detections are built around user-level and page-level behaviors like what scripts load, how redirects behave, what events fire, what actions a user takes and what happens next, etc. (In fact, Push detections don’t even use any infrastructure-based IOCs, though customers can write their own custom detections if they have a specific IOC they’re keeping an eye on.)",{"data":40058,"content":40059,"nodeType":860},{},[40060,40065,40076],{"data":40061,"marks":40062,"value":40064,"nodeType":864},{},[40063],{"type":899},"All the detections we write would survive infrastructure rotation by adversaries, and many of our existing detections have caught never-before-seen evolutions in TTPs. That’s because we focus on the top of the ",{"data":40066,"content":40070,"nodeType":39736},{"target":40067},{"sys":40068},{"id":40069,"type":1001,"linkType":1002},"1qegIy4rMdm5XZXnIEoKpE",[40071],{"data":40072,"marks":40073,"value":40075,"nodeType":864},{},[40074],{"type":899},"Pyramid of Pain",{"data":40077,"marks":40078,"value":40080,"nodeType":864},{},[40079],{"type":899},", the indicators that are hardest for attackers to change.",{"data":40082,"content":40083,"nodeType":860},{},[40084],{"data":40085,"marks":40086,"value":40087,"nodeType":864},{},[],"This focus on detecting TTPs has always been our approach. But with the acceleration in both attack types and the ease with which adversaries rotate infrastructure, we needed to build capabilities that scaled our knowledge. ",{"data":40089,"content":40090,"nodeType":860},{},[40091],{"data":40092,"marks":40093,"value":40094,"nodeType":864},{},[],"We did this not by replacing researchers, but by continuously activating their expertise. You can hear what our CEO and Co-founder Adam had to say about this below. ",{"data":40096,"content":40100,"nodeType":996},{"target":40097},{"sys":40098},{"id":40099,"type":1001,"linkType":1002},"C9gr4nF3f6CW45Aol9xij",[],{"data":40102,"content":40103,"nodeType":1005},{},[],{"data":40105,"content":40106,"nodeType":1009},{},[40107],{"data":40108,"marks":40109,"value":40111,"nodeType":864},{},[40110],{"type":899},"Core principles for agentic threat hunting",{"data":40113,"content":40114,"nodeType":860},{},[40115],{"data":40116,"marks":40117,"value":40118,"nodeType":864},{},[],"Three principles make Push's agentic threat hunting and detection engineering pipeline work:",{"data":40120,"content":40121,"nodeType":1312},{},[40122],{"data":40123,"marks":40124,"value":40126,"nodeType":864},{},[40125],{"type":899},"Context matters more than custom models",{"data":40128,"content":40129,"nodeType":860},{},[40130],{"data":40131,"marks":40132,"value":40133,"nodeType":864},{},[],"We’re not AI researchers; we’re security researchers — we aren't trying to compete in building the most intelligent models. And in our view, AI models are quickly becoming commoditized like cloud infrastructure, anyway. Luckily, the commercial models today already excel at understanding web code. We just need to harness their power with our expertise.",{"data":40135,"content":40136,"nodeType":860},{},[40137,40141,40146],{"data":40138,"marks":40139,"value":40140,"nodeType":864},{},[],"So at Push, we use a variety of commercial AI models and tools in complementary ways. What matters most is the telemetry they analyze, and that’s where Push’s existing product infrastructure shines: We’re already deployed into over ",{"data":40142,"marks":40143,"value":40145,"nodeType":864},{},[40144],{"type":899},"3 million browsers worldwide",{"data":40147,"marks":40148,"value":40149,"nodeType":864},{},[],", and the Push browser extension includes a component that operates as a flight recorder to locally record everything that matters inside a browser session.",{"data":40151,"content":40152,"nodeType":860},{},[40153],{"data":40154,"marks":40155,"value":40156,"nodeType":864},{},[],"This universe of metadata — DOM elements, tab context, script execution, network traffic, user actions, credential entry, etc. — becomes the searchable corpus for hunts. Metadata is stored locally in users’ browsers and only queried during targeted threat hunts. ",{"data":40158,"content":40159,"nodeType":860},{},[40160],{"data":40161,"marks":40162,"value":40163,"nodeType":864},{},[],"This approach avoids dragnet collection of sensitive data. Instead, we focus on collecting metadata and distilling that into patterns and insights that provide context for agents to perform their analysis. This means that Push also does not train or fine-tune models on customer data.",{"data":40165,"content":40166,"nodeType":1312},{},[40167],{"data":40168,"marks":40169,"value":40171,"nodeType":864},{},[40170],{"type":899},"Agents are only as good as the context you give them. Good context is researcher-led",{"data":40173,"content":40174,"nodeType":860},{},[40175],{"data":40176,"marks":40177,"value":40178,"nodeType":864},{},[],"AI agents don’t know how to identify the TTPs of browser-based attacks until you give them the right context, and Push researchers have spent years unpacking these techniques and tools. Agents at Push consume our internal knowledge base of identified TTPs, and both humans and agents perform meta-analyses to check their work. The agents have access to large libraries of traces of human interactions with real phishing kits. This is a powerful dataset to build on.",{"data":40180,"content":40181,"nodeType":860},{},[40182],{"data":40183,"marks":40184,"value":40185,"nodeType":864},{},[],"When we don’t get the results we want from AI models, the question is “What context is it missing? What does our human team know that the agents don’t, and how can we give them that context — do they need data, tools, better workflows?” That closes the gap in performance and keeps quality high.",{"data":40187,"content":40188,"nodeType":1312},{},[40189],{"data":40190,"marks":40191,"value":40193,"nodeType":864},{},[40192],{"type":899},"Integrated architecture that makes agentic AI the throughput layer, not a bolt-on",{"data":40195,"content":40196,"nodeType":860},{},[40197],{"data":40198,"marks":40199,"value":40200,"nodeType":864},{},[],"The constraint we’re trying to break by using AI isn’t knowledge, it’s throughput. Our researchers deeply understand the techniques and tools. An agentic pipeline can apply that understanding continuously across millions of browsers and trillions of events, ingest new external signals, generate hunt hypotheses, triage results, and return only the findings that warrant escalation.",{"data":40202,"content":40203,"nodeType":860},{},[40204],{"data":40205,"marks":40206,"value":40207,"nodeType":864},{},[],"This approach relies on tight integration of our product and our agentic workflows. We’ll take a closer look at that in the next section.",{"data":40209,"content":40210,"nodeType":1005},{},[],{"data":40212,"content":40213,"nodeType":1009},{},[40214],{"data":40215,"marks":40216,"value":40218,"nodeType":864},{},[40217],{"type":899},"How the agentic detection pipeline runs",{"data":40220,"content":40221,"nodeType":860},{},[40222],{"data":40223,"marks":40224,"value":40225,"nodeType":864},{},[],"Now let’s look at how agentic threat detection actually works, and some of the emerging best practices we’ve identified. We'll cover two example hunts, one initiated autonomously by the agents themselves, and one by our research team. ",{"data":40227,"content":40228,"nodeType":1312},{},[40229],{"data":40230,"marks":40231,"value":40233,"nodeType":864},{},[40232],{"type":899},"Example 1: Autonomous threat hunt",{"data":40235,"content":40236,"nodeType":860},{},[40237],{"data":40238,"marks":40239,"value":40240,"nodeType":864},{},[],"Push’s threat hunting pipeline ingested context from research articles describing a new attack technique, and an agent developed hypotheses on what to hunt for across Push’s install base to identify instances of this attack. ",{"data":40242,"content":40243,"nodeType":860},{},[40244],{"data":40245,"marks":40246,"value":40247,"nodeType":864},{},[],"The agent crafted detection queries and then refined them to reduce false positives. The successful query ran across stored metadata and returned results, validating that there were zero false positives. ",{"data":40249,"content":40250,"nodeType":860},{},[40251],{"data":40252,"marks":40253,"value":40254,"nodeType":864},{},[],"The validated query became a scheduled job that runs on a regular cadence to monitor for potentially malicious signals. A triage agent then received any matches, did an initial analysis, and passed anything that looked suspicious to another agent to perform deeper analysis. This deep analysis agent wields the full investigative toolkit that a human researcher would — using Push’s internal knowledge base, domain age and registration analysis, URLScan and whois lookups, DOM image analysis, and contextual analysis of page-level and user-level behaviors, etc.",{"data":40256,"content":40257,"nodeType":860},{},[40258],{"data":40259,"marks":40260,"value":40261,"nodeType":864},{},[],"Within a few minutes, it can filter a thousand or more signals in a hunt trace down to a handful with meaning and provide an actionable assessment. Then, once the TTP was well-understood, other agents wrote and refined detections that can raise alerts for customers when an event of this type is seen. The Push platform immediately applies the customer’s configured security controls, such as blocking users from interacting with malicious pages.",{"data":40263,"content":40264,"nodeType":1312},{},[40265],{"data":40266,"marks":40267,"value":40269,"nodeType":864},{},[40268],{"type":899},"Example 2: Human-initiated threat hunt",{"data":40271,"content":40272,"nodeType":860},{},[40273],{"data":40274,"marks":40275,"value":40276,"nodeType":864},{},[],"Now, going back to the example from the beginning of the article: InstallFix. This hunt started with a thorny problem our research team needed to solve: How to detect bad things downstream of a user interacting with a Google ad? We needed a way to pinpoint the bad links from the good ones.",{"data":40278,"content":40279,"nodeType":860},{},[40280,40284,40289,40292,40297,40300,40305],{"data":40281,"marks":40282,"value":40283,"nodeType":864},{},[],"Our researchers collaborated with agents to formulate the right parameters for hunt queries, taking into account that good ads are normally bought by companies with marketing budgets, so therefore ads will be expected to redirect to pages hosted on custom domains, not shared domains like ",{"data":40285,"marks":40286,"value":40288,"nodeType":864},{},[40287],{"type":899},"*pages.dev",{"data":40290,"marks":40291,"value":3731,"nodeType":864},{},[],{"data":40293,"marks":40294,"value":40296,"nodeType":864},{},[40295],{"type":899},"*workers.dev",{"data":40298,"marks":40299,"value":3731,"nodeType":864},{},[],{"data":40301,"marks":40302,"value":40304,"nodeType":864},{},[40303],{"type":899},"*squarespace.com",{"data":40306,"marks":40307,"value":40308,"nodeType":864},{},[],", etc.",{"data":40310,"content":40311,"nodeType":860},{},[40312],{"data":40313,"marks":40314,"value":40315,"nodeType":864},{},[],"Our AI agents already understood key TTPs that indicated potential maliciousness on a page: password prompts, file downloads, OAuth integrations, clipboard copies, and similar user prompts that are frequently abused.",{"data":40317,"content":40318,"nodeType":860},{},[40319],{"data":40320,"marks":40321,"value":40322,"nodeType":864},{},[],"The agent ran several queries that returned matching browsing traces — the term we use for sequences of events in a session or tab context — where the user clicked a Google ad, was redirected to a page on a shared hosting domain, and then clicked a button to copy content to their clipboard.",{"data":40324,"content":40328,"nodeType":996},{"target":40325},{"sys":40326},{"id":40327,"type":1001,"linkType":1002},"4IWOrWuvbwzWRJUkINiwKH",[],{"data":40330,"content":40331,"nodeType":860},{},[40332],{"data":40333,"marks":40334,"value":40335,"nodeType":864},{},[],"We got back high-fidelity findings and then tuned the query into a continuous detection that leveraged existing detection logic around related techniques. This process also effectively back-tests new detections, so we know we’re not going to generate a lot of false positives. Result: A new detection against a new technique, plus several improvements to existing detections.",{"data":40337,"content":40338,"nodeType":1312},{},[40339],{"data":40340,"marks":40341,"value":40343,"nodeType":864},{},[40342],{"type":899},"What infrastructure is needed for agentic threat hunting?",{"data":40345,"content":40346,"nodeType":860},{},[40347],{"data":40348,"marks":40349,"value":40350,"nodeType":864},{},[],"Both of these examples illustrate the end-to-end workflows supported by this pipeline. From an infrastructure perspective, you can think about the pipeline as composed of:",{"data":40352,"content":40353,"nodeType":941},{},[40354,40369,40384,40399,40414],{"data":40355,"content":40356,"nodeType":945},{},[40357],{"data":40358,"content":40359,"nodeType":860},{},[40360,40365],{"data":40361,"marks":40362,"value":40364,"nodeType":864},{},[40363],{"type":899},"A flight recorder: ",{"data":40366,"marks":40367,"value":40368,"nodeType":864},{},[],"The Push extension-powered capability that collects and locally stores browser event metadata from users’ browsers.",{"data":40370,"content":40371,"nodeType":945},{},[40372],{"data":40373,"content":40374,"nodeType":860},{},[40375,40380],{"data":40376,"marks":40377,"value":40379,"nodeType":864},{},[40378],{"type":899},"A knowledge base:",{"data":40381,"marks":40382,"value":40383,"nodeType":864},{},[]," Structured knowledge about what Push knows about TTPs and its existing body of detection logic, as well as externally sourced signals of new attack trends.",{"data":40385,"content":40386,"nodeType":945},{},[40387],{"data":40388,"content":40389,"nodeType":860},{},[40390,40395],{"data":40391,"marks":40392,"value":40394,"nodeType":864},{},[40393],{"type":899},"Agents as tools: ",{"data":40396,"marks":40397,"value":40398,"nodeType":864},{},[],"Role-segmented agents that work as a team to triage, investigate, develop hunt queries, return analyses, write detections, and review each others’ work for completeness and accuracy.",{"data":40400,"content":40401,"nodeType":945},{},[40402],{"data":40403,"content":40404,"nodeType":860},{},[40405,40410],{"data":40406,"marks":40407,"value":40409,"nodeType":864},{},[40408],{"type":899},"Humans in the loop: ",{"data":40411,"marks":40412,"value":40413,"nodeType":864},{},[],"Human researchers who collaborate with agents to initiate hunts and tune detections.",{"data":40415,"content":40416,"nodeType":945},{},[40417],{"data":40418,"content":40419,"nodeType":860},{},[40420,40425],{"data":40421,"marks":40422,"value":40424,"nodeType":864},{},[40423],{"type":899},"Platform controls: ",{"data":40426,"marks":40427,"value":40428,"nodeType":864},{},[],"The Push administrator-configured controls that specify how to respond to detected events like AiTM phishing, tuneable by scope, user groups, browser profiles, apps, etc.",{"data":40430,"content":40434,"nodeType":996},{"target":40431},{"sys":40432},{"id":40433,"type":1001,"linkType":1002},"7FY0vCBUXOt4vnudFuKALC",[],{"data":40436,"content":40437,"nodeType":1312},{},[40438],{"data":40439,"marks":40440,"value":40442,"nodeType":864},{},[40441],{"type":899},"What are the best practices for agentic threat detection?",{"data":40444,"content":40445,"nodeType":860},{},[40446,40450,40455],{"data":40447,"marks":40448,"value":40449,"nodeType":864},{},[],"To be effective, agents must specialize and focus. This is the ",{"data":40451,"marks":40452,"value":40454,"nodeType":864},{},[40453],{"type":899},"agents as tools",{"data":40456,"marks":40457,"value":40458,"nodeType":864},{},[]," concept. When we’re asking AI agents to take massive amounts of data and make a high-level decision about a signal in observed browser events, they must work as a team, finding intelligent ways to condense information without losing important context or hallucinating.",{"data":40460,"content":40461,"nodeType":860},{},[40462],{"data":40463,"marks":40464,"value":40465,"nodeType":864},{},[],"Creating a hierarchy of agent jobs — including agents to perform meta-analyses to catch mistakes and verify conclusions — makes the agents effective by giving them a manageable focus that controls the size of context windows.",{"data":40467,"content":40471,"nodeType":996},{"target":40468},{"sys":40469},{"id":40470,"type":1001,"linkType":1002},"3fzJCknMUmh4Z7YnhBSbsT",[],{"data":40473,"content":40474,"nodeType":860},{},[40475],{"data":40476,"marks":40477,"value":40478,"nodeType":864},{},[],"Creating an agentic workflow requires operationalizing your internal knowledge in a repeatable and trustworthy way. Sharing rich context from human discoveries is the key to getting the best results out of agents. ",{"data":40480,"content":40481,"nodeType":860},{},[40482,40486,40491],{"data":40483,"marks":40484,"value":40485,"nodeType":864},{},[],"It's vital too that the agent uses ",{"data":40487,"marks":40488,"value":40490,"nodeType":864},{},[40489],{"type":899},"privacy-preserving methods and infrastructure.",{"data":40492,"marks":40493,"value":40494,"nodeType":864},{},[]," The Push agent is designed to respect customer and user privacy while enabling high-fidelity detections. We do this by collecting broad browser metadata but storing it locally in users’ browsers and only querying that metadata during active threat hunting investigations.",{"data":40496,"content":40497,"nodeType":1005},{},[],{"data":40499,"content":40500,"nodeType":1009},{},[40501],{"data":40502,"marks":40503,"value":40505,"nodeType":864},{},[40504],{"type":899},"The compounding effect and how it benefits Push customers",{"data":40507,"content":40508,"nodeType":860},{},[40509],{"data":40510,"marks":40511,"value":40512,"nodeType":864},{},[],"At Push, we think about our detection capability as two learning loops with a compounding effect: An inner loop that serves as our real-time detection and response engine for known attacker techniques, and an outer loop that is the continuous learning our agents do as they hunt for new threats, analyze emerging behaviors, and create new detections. ",{"data":40514,"content":40515,"nodeType":860},{},[40516],{"data":40517,"marks":40518,"value":40519,"nodeType":864},{},[],"The outer loop feeds the inner loop, and vice versa.",{"data":40521,"content":40525,"nodeType":996},{"target":40522},{"sys":40523},{"id":40524,"type":1001,"linkType":1002},"1Jjqll7IIX2QRxN37gjFMH",[],{"data":40527,"content":40528,"nodeType":860},{},[40529],{"data":40530,"marks":40531,"value":40532,"nodeType":864},{},[],"Customers benefit from this approach because it means they:",{"data":40534,"content":40535,"nodeType":941},{},[40536,40557,40567],{"data":40537,"content":40538,"nodeType":945},{},[40539],{"data":40540,"content":40541,"nodeType":860},{},[40542,40546,40553],{"data":40543,"marks":40544,"value":40545,"nodeType":864},{},[],"Regularly receive ready-made detections against both known and emerging browser-based threats, without having to write their own detections. (Push also provides the ability to write your own ",{"data":40547,"content":40549,"nodeType":883},{"uri":40548},"/help/audience/engineering/resources/custom-detections",[40550],{"data":40551,"marks":40552,"value":1578,"nodeType":864},{},[],{"data":40554,"marks":40555,"value":40556,"nodeType":864},{},[],", too, for environment-specific use cases.)",{"data":40558,"content":40559,"nodeType":945},{},[40560],{"data":40561,"content":40562,"nodeType":860},{},[40563],{"data":40564,"marks":40565,"value":40566,"nodeType":864},{},[],"Can configure Push’s response actions based on their security goals and environment. Agents act as the threat-hunting and detection engineering team; Push customers set the thresholds for how they want to respond. For example, customers can use Push controls to block all AiTM phishing attacks (or even carve out exceptions for their own incident responders to be able to visit malicious pages with just a warning), and agents continually feed new indicators into detection logic for that class of attack.",{"data":40568,"content":40569,"nodeType":945},{},[40570],{"data":40571,"content":40572,"nodeType":860},{},[40573],{"data":40574,"marks":40575,"value":40576,"nodeType":864},{},[],"Get pre-digested and actionable intelligence from every detection, with extremely high fidelity.",{"data":40578,"content":40579,"nodeType":860},{},[40580],{"data":40581,"marks":40582,"value":40583,"nodeType":864},{},[],"This all equates to your own advanced browser threat protection, without requiring the specialized in-house expertise we’ve spent years building.",{"data":40585,"content":40586,"nodeType":860},{},[40587],{"data":40588,"marks":40589,"value":40590,"nodeType":864},{},[],"If you’re a Push customer, you already know that we regularly collaborate with security teams to identify and refine detection use cases, and assist with investigations. In the past few months alone, we’ve worked closely with teams targeted by device code phishing, and InstallFix and ClickFix campaigns, among others. ",{"data":40592,"content":40593,"nodeType":860},{},[40594],{"data":40595,"marks":40596,"value":40597,"nodeType":864},{},[],"If you’re not a customer and are curious about how Push’s agentic threat hunting and detection engineering capabilities can address your use cases, please get in touch.",{"data":40599,"content":40603,"nodeType":996},{"target":40600},{"sys":40601},{"id":40602,"type":1001,"linkType":1002},"607jrBjlD1vtcbkDfD04DE",[],{"data":40605,"content":40606,"nodeType":1005},{},[],{"data":40608,"content":40609,"nodeType":1009},{},[40610],{"data":40611,"marks":40612,"value":40614,"nodeType":864},{},[40613],{"type":899},"Learn more",{"data":40616,"content":40617,"nodeType":860},{},[40618],{"data":40619,"marks":40620,"value":1682,"nodeType":864},{},[],{"data":40622,"content":40623,"nodeType":860},{},[40624],{"data":40625,"marks":40626,"value":1689,"nodeType":864},{},[],{"data":40628,"content":40629,"nodeType":860},{},[40630,40633,40640],{"data":40631,"marks":40632,"value":2707,"nodeType":864},{},[],{"data":40634,"content":40636,"nodeType":883},{"uri":40635},"/demo",[40637],{"data":40638,"marks":40639,"value":2715,"nodeType":864},{},[],{"data":40641,"marks":40642,"value":2719,"nodeType":864},{},[],"Can AI replace a threat researcher? What we learned building an agentic threat hunting pipeline","How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.","2026-05-12T00:00:00.000Z","can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",{"items":40648},[40649,40651],{"sys":40650,"name":13779},{"id":13778},{"sys":40652,"name":342},{"id":13775},{"items":40654},[40655],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":40656},{"url":853},{"__typename":2059,"sys":40658,"content":40659,"title":29597,"synopsis":29598,"hashTags":59,"publishedDate":24225,"slug":29599,"tagsCollection":41480,"authorsCollection":41486},{"id":28636},{"json":40660},{"data":40661,"content":40662,"nodeType":856},{},[40663,40685,40709,40742,40775,40780,40790,40793,40800,40842,40848,40867,40872,40875,40882,40906,40912,40919,40924,40927,40934,40940,40955,40961,40994,41000,41003,41010,41025,41067,41070,41077,41092,41107,41114,41120,41130,41140,41150,41160,41175,41182,41188,41191,41197,41203,41218,41221,41228,41243,41474],{"data":40664,"content":40665,"nodeType":860},{},[40666,40669,40675,40678,40682],{"data":40667,"marks":40668,"value":28647,"nodeType":864},{},[],{"data":40670,"content":40671,"nodeType":883},{"uri":16015},[40672],{"data":40673,"marks":40674,"value":16018,"nodeType":864},{},[],{"data":40676,"marks":40677,"value":28657,"nodeType":864},{},[],{"data":40679,"marks":40680,"value":28662,"nodeType":864},{},[40681],{"type":899},{"data":40683,"marks":40684,"value":28666,"nodeType":864},{},[],{"data":40686,"content":40687,"nodeType":860},{},[40688,40691,40697,40700,40706],{"data":40689,"marks":40690,"value":28673,"nodeType":864},{},[],{"data":40692,"content":40693,"nodeType":883},{"uri":28676},[40694],{"data":40695,"marks":40696,"value":28681,"nodeType":864},{},[],{"data":40698,"marks":40699,"value":28685,"nodeType":864},{},[],{"data":40701,"content":40702,"nodeType":883},{"uri":28688},[40703],{"data":40704,"marks":40705,"value":28693,"nodeType":864},{},[],{"data":40707,"marks":40708,"value":28697,"nodeType":864},{},[],{"data":40710,"content":40711,"nodeType":860},{},[40712,40715,40721,40724,40730,40733,40739],{"data":40713,"marks":40714,"value":28704,"nodeType":864},{},[],{"data":40716,"content":40717,"nodeType":883},{"uri":28707},[40718],{"data":40719,"marks":40720,"value":28712,"nodeType":864},{},[],{"data":40722,"marks":40723,"value":28716,"nodeType":864},{},[],{"data":40725,"content":40726,"nodeType":883},{"uri":28719},[40727],{"data":40728,"marks":40729,"value":28724,"nodeType":864},{},[],{"data":40731,"marks":40732,"value":28728,"nodeType":864},{},[],{"data":40734,"content":40735,"nodeType":883},{"uri":16553},[40736],{"data":40737,"marks":40738,"value":28735,"nodeType":864},{},[],{"data":40740,"marks":40741,"value":28739,"nodeType":864},{},[],{"data":40743,"content":40744,"nodeType":860},{},[40745,40748,40754,40757,40763,40766,40772],{"data":40746,"marks":40747,"value":28746,"nodeType":864},{},[],{"data":40749,"content":40750,"nodeType":883},{"uri":28749},[40751],{"data":40752,"marks":40753,"value":28754,"nodeType":864},{},[],{"data":40755,"marks":40756,"value":28758,"nodeType":864},{},[],{"data":40758,"content":40759,"nodeType":883},{"uri":28761},[40760],{"data":40761,"marks":40762,"value":28766,"nodeType":864},{},[],{"data":40764,"marks":40765,"value":28770,"nodeType":864},{},[],{"data":40767,"content":40768,"nodeType":883},{"uri":28773},[40769],{"data":40770,"marks":40771,"value":28778,"nodeType":864},{},[],{"data":40773,"marks":40774,"value":28782,"nodeType":864},{},[],{"data":40776,"content":40779,"nodeType":996},{"target":40777},{"sys":40778},{"id":28787,"type":1001,"linkType":1002},[],{"data":40781,"content":40782,"nodeType":860},{},[40783,40787],{"data":40784,"marks":40785,"value":28796,"nodeType":864},{},[40786],{"type":899},{"data":40788,"marks":40789,"value":28800,"nodeType":864},{},[],{"data":40791,"content":40792,"nodeType":1005},{},[],{"data":40794,"content":40795,"nodeType":1009},{},[40796],{"data":40797,"marks":40798,"value":28811,"nodeType":864},{},[40799],{"type":899},{"data":40801,"content":40802,"nodeType":860},{},[40803,40806,40812,40815,40821,40824,40830,40833,40839],{"data":40804,"marks":40805,"value":28818,"nodeType":864},{},[],{"data":40807,"content":40808,"nodeType":883},{"uri":28821},[40809],{"data":40810,"marks":40811,"value":28826,"nodeType":864},{},[],{"data":40813,"marks":40814,"value":11735,"nodeType":864},{},[],{"data":40816,"content":40817,"nodeType":883},{"uri":28832},[40818],{"data":40819,"marks":40820,"value":28837,"nodeType":864},{},[],{"data":40822,"marks":40823,"value":28841,"nodeType":864},{},[],{"data":40825,"content":40826,"nodeType":883},{"uri":28719},[40827],{"data":40828,"marks":40829,"value":28848,"nodeType":864},{},[],{"data":40831,"marks":40832,"value":28852,"nodeType":864},{},[],{"data":40834,"content":40835,"nodeType":883},{"uri":12879},[40836],{"data":40837,"marks":40838,"value":28859,"nodeType":864},{},[],{"data":40840,"marks":40841,"value":2924,"nodeType":864},{},[],{"data":40843,"content":40844,"nodeType":860},{},[40845],{"data":40846,"marks":40847,"value":28869,"nodeType":864},{},[],{"data":40849,"content":40850,"nodeType":860},{},[40851,40854,40860,40863],{"data":40852,"marks":40853,"value":28876,"nodeType":864},{},[],{"data":40855,"content":40856,"nodeType":883},{"uri":12879},[40857],{"data":40858,"marks":40859,"value":28883,"nodeType":864},{},[],{"data":40861,"marks":40862,"value":28887,"nodeType":864},{},[],{"data":40864,"marks":40865,"value":28892,"nodeType":864},{},[40866],{"type":899},{"data":40868,"content":40871,"nodeType":996},{"target":40869},{"sys":40870},{"id":28897,"type":1001,"linkType":1002},[],{"data":40873,"content":40874,"nodeType":1005},{},[],{"data":40876,"content":40877,"nodeType":1009},{},[40878],{"data":40879,"marks":40880,"value":28909,"nodeType":864},{},[40881],{"type":899},{"data":40883,"content":40884,"nodeType":860},{},[40885,40888,40894,40897,40903],{"data":40886,"marks":40887,"value":2761,"nodeType":864},{},[],{"data":40889,"content":40890,"nodeType":883},{"uri":23901},[40891],{"data":40892,"marks":40893,"value":28922,"nodeType":864},{},[],{"data":40895,"marks":40896,"value":28926,"nodeType":864},{},[],{"data":40898,"content":40899,"nodeType":883},{"uri":16553},[40900],{"data":40901,"marks":40902,"value":28933,"nodeType":864},{},[],{"data":40904,"marks":40905,"value":28937,"nodeType":864},{},[],{"data":40907,"content":40908,"nodeType":860},{},[40909],{"data":40910,"marks":40911,"value":28944,"nodeType":864},{},[],{"data":40913,"content":40914,"nodeType":860},{},[40915],{"data":40916,"marks":40917,"value":28952,"nodeType":864},{},[40918],{"type":899},{"data":40920,"content":40923,"nodeType":996},{"target":40921},{"sys":40922},{"id":28957,"type":1001,"linkType":1002},[],{"data":40925,"content":40926,"nodeType":1005},{},[],{"data":40928,"content":40929,"nodeType":1009},{},[40930],{"data":40931,"marks":40932,"value":28969,"nodeType":864},{},[40933],{"type":899},{"data":40935,"content":40936,"nodeType":860},{},[40937],{"data":40938,"marks":40939,"value":28976,"nodeType":864},{},[],{"data":40941,"content":40942,"nodeType":860},{},[40943,40946,40952],{"data":40944,"marks":40945,"value":2761,"nodeType":864},{},[],{"data":40947,"content":40948,"nodeType":883},{"uri":28985},[40949],{"data":40950,"marks":40951,"value":28990,"nodeType":864},{},[],{"data":40953,"marks":40954,"value":28994,"nodeType":864},{},[],{"data":40956,"content":40957,"nodeType":860},{},[40958],{"data":40959,"marks":40960,"value":29001,"nodeType":864},{},[],{"data":40962,"content":40963,"nodeType":860},{},[40964,40967,40973,40976,40982,40985,40991],{"data":40965,"marks":40966,"value":29008,"nodeType":864},{},[],{"data":40968,"content":40969,"nodeType":883},{"uri":29011},[40970],{"data":40971,"marks":40972,"value":29016,"nodeType":864},{},[],{"data":40974,"marks":40975,"value":29020,"nodeType":864},{},[],{"data":40977,"content":40978,"nodeType":883},{"uri":29023},[40979],{"data":40980,"marks":40981,"value":29028,"nodeType":864},{},[],{"data":40983,"marks":40984,"value":29032,"nodeType":864},{},[],{"data":40986,"content":40987,"nodeType":883},{"uri":4103},[40988],{"data":40989,"marks":40990,"value":16114,"nodeType":864},{},[],{"data":40992,"marks":40993,"value":29042,"nodeType":864},{},[],{"data":40995,"content":40996,"nodeType":860},{},[40997],{"data":40998,"marks":40999,"value":29049,"nodeType":864},{},[],{"data":41001,"content":41002,"nodeType":1005},{},[],{"data":41004,"content":41005,"nodeType":1009},{},[41006],{"data":41007,"marks":41008,"value":29060,"nodeType":864},{},[41009],{"type":899},{"data":41011,"content":41012,"nodeType":860},{},[41013,41016,41022],{"data":41014,"marks":41015,"value":29067,"nodeType":864},{},[],{"data":41017,"content":41018,"nodeType":883},{"uri":29070},[41019],{"data":41020,"marks":41021,"value":29075,"nodeType":864},{},[],{"data":41023,"marks":41024,"value":29079,"nodeType":864},{},[],{"data":41026,"content":41027,"nodeType":860},{},[41028,41031,41037,41040,41046,41049,41055,41058,41064],{"data":41029,"marks":41030,"value":29086,"nodeType":864},{},[],{"data":41032,"content":41033,"nodeType":883},{"uri":29089},[41034],{"data":41035,"marks":41036,"value":29094,"nodeType":864},{},[],{"data":41038,"marks":41039,"value":29098,"nodeType":864},{},[],{"data":41041,"content":41042,"nodeType":883},{"uri":29101},[41043],{"data":41044,"marks":41045,"value":29106,"nodeType":864},{},[],{"data":41047,"marks":41048,"value":29110,"nodeType":864},{},[],{"data":41050,"content":41051,"nodeType":883},{"uri":29113},[41052],{"data":41053,"marks":41054,"value":29118,"nodeType":864},{},[],{"data":41056,"marks":41057,"value":29122,"nodeType":864},{},[],{"data":41059,"content":41060,"nodeType":883},{"uri":29125},[41061],{"data":41062,"marks":41063,"value":29130,"nodeType":864},{},[],{"data":41065,"marks":41066,"value":29134,"nodeType":864},{},[],{"data":41068,"content":41069,"nodeType":1005},{},[],{"data":41071,"content":41072,"nodeType":1009},{},[41073],{"data":41074,"marks":41075,"value":29145,"nodeType":864},{},[41076],{"type":899},{"data":41078,"content":41079,"nodeType":860},{},[41080,41083,41089],{"data":41081,"marks":41082,"value":29152,"nodeType":864},{},[],{"data":41084,"content":41085,"nodeType":883},{"uri":3259},[41086],{"data":41087,"marks":41088,"value":29159,"nodeType":864},{},[],{"data":41090,"marks":41091,"value":29163,"nodeType":864},{},[],{"data":41093,"content":41094,"nodeType":860},{},[41095,41098,41104],{"data":41096,"marks":41097,"value":29170,"nodeType":864},{},[],{"data":41099,"content":41100,"nodeType":883},{"uri":29173},[41101],{"data":41102,"marks":41103,"value":315,"nodeType":864},{},[],{"data":41105,"marks":41106,"value":29181,"nodeType":864},{},[],{"data":41108,"content":41109,"nodeType":1312},{},[41110],{"data":41111,"marks":41112,"value":7533,"nodeType":864},{},[41113],{"type":899},{"data":41115,"content":41116,"nodeType":860},{},[41117],{"data":41118,"marks":41119,"value":29195,"nodeType":864},{},[],{"data":41121,"content":41122,"nodeType":860},{},[41123,41127],{"data":41124,"marks":41125,"value":29203,"nodeType":864},{},[41126],{"type":899},{"data":41128,"marks":41129,"value":29207,"nodeType":864},{},[],{"data":41131,"content":41132,"nodeType":860},{},[41133,41137],{"data":41134,"marks":41135,"value":29215,"nodeType":864},{},[41136],{"type":899},{"data":41138,"marks":41139,"value":29219,"nodeType":864},{},[],{"data":41141,"content":41142,"nodeType":860},{},[41143,41147],{"data":41144,"marks":41145,"value":29227,"nodeType":864},{},[41146],{"type":899},{"data":41148,"marks":41149,"value":29231,"nodeType":864},{},[],{"data":41151,"content":41152,"nodeType":860},{},[41153,41157],{"data":41154,"marks":41155,"value":29239,"nodeType":864},{},[41156],{"type":899},{"data":41158,"marks":41159,"value":29243,"nodeType":864},{},[],{"data":41161,"content":41162,"nodeType":860},{},[41163,41166,41172],{"data":41164,"marks":41165,"value":21,"nodeType":864},{},[],{"data":41167,"content":41168,"nodeType":883},{"uri":24926},[41169],{"data":41170,"marks":41171,"value":29256,"nodeType":864},{},[],{"data":41173,"marks":41174,"value":21,"nodeType":864},{},[],{"data":41176,"content":41177,"nodeType":1312},{},[41178],{"data":41179,"marks":41180,"value":29267,"nodeType":864},{},[41181],{"type":899},{"data":41183,"content":41184,"nodeType":860},{},[41185],{"data":41186,"marks":41187,"value":29274,"nodeType":864},{},[],{"data":41189,"content":41190,"nodeType":1005},{},[],{"data":41192,"content":41193,"nodeType":860},{},[41194],{"data":41195,"marks":41196,"value":4855,"nodeType":864},{},[],{"data":41198,"content":41199,"nodeType":860},{},[41200],{"data":41201,"marks":41202,"value":1689,"nodeType":864},{},[],{"data":41204,"content":41205,"nodeType":860},{},[41206,41209,41215],{"data":41207,"marks":41208,"value":21,"nodeType":864},{},[],{"data":41210,"content":41211,"nodeType":883},{"uri":14401},[41212],{"data":41213,"marks":41214,"value":1703,"nodeType":864},{},[],{"data":41216,"marks":41217,"value":21,"nodeType":864},{},[],{"data":41219,"content":41220,"nodeType":1005},{},[],{"data":41222,"content":41223,"nodeType":1009},{},[41224],{"data":41225,"marks":41226,"value":29315,"nodeType":864},{},[41227],{"type":899},{"data":41229,"content":41230,"nodeType":860},{},[41231,41234,41240],{"data":41232,"marks":41233,"value":29322,"nodeType":864},{},[],{"data":41235,"content":41236,"nodeType":883},{"uri":16015},[41237],{"data":41238,"marks":41239,"value":29329,"nodeType":864},{},[],{"data":41241,"marks":41242,"value":29333,"nodeType":864},{},[],{"data":41244,"content":41245,"nodeType":4845},{},[41246,41289,41345,41388,41431],{"data":41247,"content":41248,"nodeType":4581},{},[41249,41259,41269,41279],{"data":41250,"content":41251,"nodeType":4569},{},[41252],{"data":41253,"content":41254,"nodeType":860},{},[41255],{"data":41256,"marks":41257,"value":29350,"nodeType":864},{},[41258],{"type":899},{"data":41260,"content":41261,"nodeType":4569},{},[41262],{"data":41263,"content":41264,"nodeType":860},{},[41265],{"data":41266,"marks":41267,"value":29361,"nodeType":864},{},[41268],{"type":899},{"data":41270,"content":41271,"nodeType":4569},{},[41272],{"data":41273,"content":41274,"nodeType":860},{},[41275],{"data":41276,"marks":41277,"value":29372,"nodeType":864},{},[41278],{"type":899},{"data":41280,"content":41281,"nodeType":4569},{},[41282],{"data":41283,"content":41284,"nodeType":860},{},[41285],{"data":41286,"marks":41287,"value":29383,"nodeType":864},{},[41288],{"type":899},{"data":41290,"content":41291,"nodeType":4581},{},[41292,41312,41321,41330],{"data":41293,"content":41294,"nodeType":4569},{},[41295],{"data":41296,"content":41297,"nodeType":860},{},[41298,41302,41305,41309],{"data":41299,"marks":41300,"value":29397,"nodeType":864},{},[41301],{"type":899},{"data":41303,"marks":41304,"value":29401,"nodeType":864},{},[],{"data":41306,"marks":41307,"value":29406,"nodeType":864},{},[41308],{"type":899},{"data":41310,"marks":41311,"value":29410,"nodeType":864},{},[],{"data":41313,"content":41314,"nodeType":4569},{},[41315],{"data":41316,"content":41317,"nodeType":860},{},[41318],{"data":41319,"marks":41320,"value":29420,"nodeType":864},{},[],{"data":41322,"content":41323,"nodeType":4569},{},[41324],{"data":41325,"content":41326,"nodeType":860},{},[41327],{"data":41328,"marks":41329,"value":29430,"nodeType":864},{},[],{"data":41331,"content":41332,"nodeType":4569},{},[41333,41339],{"data":41334,"content":41335,"nodeType":860},{},[41336],{"data":41337,"marks":41338,"value":29440,"nodeType":864},{},[],{"data":41340,"content":41341,"nodeType":860},{},[41342],{"data":41343,"marks":41344,"value":29447,"nodeType":864},{},[],{"data":41346,"content":41347,"nodeType":4581},{},[41348,41361,41370,41379],{"data":41349,"content":41350,"nodeType":4569},{},[41351],{"data":41352,"content":41353,"nodeType":860},{},[41354,41358],{"data":41355,"marks":41356,"value":29461,"nodeType":864},{},[41357],{"type":899},{"data":41359,"marks":41360,"value":29465,"nodeType":864},{},[],{"data":41362,"content":41363,"nodeType":4569},{},[41364],{"data":41365,"content":41366,"nodeType":860},{},[41367],{"data":41368,"marks":41369,"value":29475,"nodeType":864},{},[],{"data":41371,"content":41372,"nodeType":4569},{},[41373],{"data":41374,"content":41375,"nodeType":860},{},[41376],{"data":41377,"marks":41378,"value":29485,"nodeType":864},{},[],{"data":41380,"content":41381,"nodeType":4569},{},[41382],{"data":41383,"content":41384,"nodeType":860},{},[41385],{"data":41386,"marks":41387,"value":29495,"nodeType":864},{},[],{"data":41389,"content":41390,"nodeType":4581},{},[41391,41404,41413,41422],{"data":41392,"content":41393,"nodeType":4569},{},[41394],{"data":41395,"content":41396,"nodeType":860},{},[41397,41401],{"data":41398,"marks":41399,"value":29509,"nodeType":864},{},[41400],{"type":899},{"data":41402,"marks":41403,"value":29513,"nodeType":864},{},[],{"data":41405,"content":41406,"nodeType":4569},{},[41407],{"data":41408,"content":41409,"nodeType":860},{},[41410],{"data":41411,"marks":41412,"value":29523,"nodeType":864},{},[],{"data":41414,"content":41415,"nodeType":4569},{},[41416],{"data":41417,"content":41418,"nodeType":860},{},[41419],{"data":41420,"marks":41421,"value":29533,"nodeType":864},{},[],{"data":41423,"content":41424,"nodeType":4569},{},[41425],{"data":41426,"content":41427,"nodeType":860},{},[41428],{"data":41429,"marks":41430,"value":29543,"nodeType":864},{},[],{"data":41432,"content":41433,"nodeType":4581},{},[41434,41447,41456,41465],{"data":41435,"content":41436,"nodeType":4569},{},[41437],{"data":41438,"content":41439,"nodeType":860},{},[41440,41444],{"data":41441,"marks":41442,"value":29557,"nodeType":864},{},[41443],{"type":899},{"data":41445,"marks":41446,"value":29561,"nodeType":864},{},[],{"data":41448,"content":41449,"nodeType":4569},{},[41450],{"data":41451,"content":41452,"nodeType":860},{},[41453],{"data":41454,"marks":41455,"value":29420,"nodeType":864},{},[],{"data":41457,"content":41458,"nodeType":4569},{},[41459],{"data":41460,"content":41461,"nodeType":860},{},[41462],{"data":41463,"marks":41464,"value":29580,"nodeType":864},{},[],{"data":41466,"content":41467,"nodeType":4569},{},[41468],{"data":41469,"content":41470,"nodeType":860},{},[41471],{"data":41472,"marks":41473,"value":29590,"nodeType":864},{},[],{"data":41475,"content":41476,"nodeType":860},{},[41477],{"data":41478,"marks":41479,"value":21,"nodeType":864},{},[],{"items":41481},[41482,41484],{"sys":41483,"name":13779},{"id":13778},{"sys":41485,"name":342},{"id":13775},{"items":41487},[41488],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":41489},{"url":2740},{"__typename":2059,"sys":41491,"content":41492,"title":30117,"synopsis":30118,"hashTags":59,"publishedDate":30119,"slug":30120,"tagsCollection":41922,"authorsCollection":41928},{"id":29612},{"json":41493},{"data":41494,"content":41495,"nodeType":856},{},[41496,41503,41527,41532,41538,41553,41566,41569,41576,41589,41605,41625,41630,41643,41667,41672,41677,41690,41693,41700,41706,41713,41729,41742,41749,41771,41777,41784,41808,41814,41821,41827,41832,41835,41842,41848,41855,41860,41863,41870,41876,41882,41888,41898,41901,41907],{"data":41497,"content":41498,"nodeType":1009},{},[41499],{"data":41500,"marks":41501,"value":29624,"nodeType":864},{},[41502],{"type":899},{"data":41504,"content":41505,"nodeType":860},{},[41506,41509,41515,41518,41524],{"data":41507,"marks":41508,"value":29631,"nodeType":864},{},[],{"data":41510,"content":41511,"nodeType":883},{"uri":29634},[41512],{"data":41513,"marks":41514,"value":29639,"nodeType":864},{},[],{"data":41516,"marks":41517,"value":29643,"nodeType":864},{},[],{"data":41519,"content":41520,"nodeType":883},{"uri":29646},[41521],{"data":41522,"marks":41523,"value":29651,"nodeType":864},{},[],{"data":41525,"marks":41526,"value":29655,"nodeType":864},{},[],{"data":41528,"content":41531,"nodeType":996},{"target":41529},{"sys":41530},{"id":29660,"type":1001,"linkType":1002},[],{"data":41533,"content":41534,"nodeType":860},{},[41535],{"data":41536,"marks":41537,"value":29668,"nodeType":864},{},[],{"data":41539,"content":41540,"nodeType":860},{},[41541,41544,41550],{"data":41542,"marks":41543,"value":29675,"nodeType":864},{},[],{"data":41545,"content":41546,"nodeType":883},{"uri":29678},[41547],{"data":41548,"marks":41549,"value":29683,"nodeType":864},{},[],{"data":41551,"marks":41552,"value":29687,"nodeType":864},{},[],{"data":41554,"content":41555,"nodeType":860},{},[41556,41559,41563],{"data":41557,"marks":41558,"value":29694,"nodeType":864},{},[],{"data":41560,"marks":41561,"value":29699,"nodeType":864},{},[41562],{"type":899},{"data":41564,"marks":41565,"value":2924,"nodeType":864},{},[],{"data":41567,"content":41568,"nodeType":1005},{},[],{"data":41570,"content":41571,"nodeType":1009},{},[41572],{"data":41573,"marks":41574,"value":29713,"nodeType":864},{},[41575],{"type":899},{"data":41577,"content":41578,"nodeType":860},{},[41579,41582,41586],{"data":41580,"marks":41581,"value":29720,"nodeType":864},{},[],{"data":41583,"marks":41584,"value":29725,"nodeType":864},{},[41585],{"type":2246},{"data":41587,"marks":41588,"value":2924,"nodeType":864},{},[],{"data":41590,"content":41591,"nodeType":860},{},[41592,41595,41602],{"data":41593,"marks":41594,"value":29735,"nodeType":864},{},[],{"data":41596,"content":41597,"nodeType":883},{"uri":7549},[41598],{"data":41599,"marks":41600,"value":29743,"nodeType":864},{},[41601],{"type":1455},{"data":41603,"marks":41604,"value":29747,"nodeType":864},{},[],{"data":41606,"content":41607,"nodeType":860},{},[41608,41611,41615,41618,41622],{"data":41609,"marks":41610,"value":29754,"nodeType":864},{},[],{"data":41612,"marks":41613,"value":29759,"nodeType":864},{},[41614],{"type":899},{"data":41616,"marks":41617,"value":29763,"nodeType":864},{},[],{"data":41619,"marks":41620,"value":29768,"nodeType":864},{},[41621],{"type":2246},{"data":41623,"marks":41624,"value":29772,"nodeType":864},{},[],{"data":41626,"content":41629,"nodeType":996},{"target":41627},{"sys":41628},{"id":29777,"type":1001,"linkType":1002},[],{"data":41631,"content":41632,"nodeType":860},{},[41633,41636,41640],{"data":41634,"marks":41635,"value":29785,"nodeType":864},{},[],{"data":41637,"marks":41638,"value":29790,"nodeType":864},{},[41639],{"type":899},{"data":41641,"marks":41642,"value":29794,"nodeType":864},{},[],{"data":41644,"content":41645,"nodeType":860},{},[41646,41649,41655,41658,41664],{"data":41647,"marks":41648,"value":29801,"nodeType":864},{},[],{"data":41650,"content":41651,"nodeType":883},{"uri":25338},[41652],{"data":41653,"marks":41654,"value":29808,"nodeType":864},{},[],{"data":41656,"marks":41657,"value":29812,"nodeType":864},{},[],{"data":41659,"content":41660,"nodeType":883},{"uri":11813},[41661],{"data":41662,"marks":41663,"value":29819,"nodeType":864},{},[],{"data":41665,"marks":41666,"value":1774,"nodeType":864},{},[],{"data":41668,"content":41671,"nodeType":996},{"target":41669},{"sys":41670},{"id":29827,"type":1001,"linkType":1002},[],{"data":41673,"content":41676,"nodeType":996},{"target":41674},{"sys":41675},{"id":29833,"type":1001,"linkType":1002},[],{"data":41678,"content":41679,"nodeType":860},{},[41680,41683,41687],{"data":41681,"marks":41682,"value":29841,"nodeType":864},{},[],{"data":41684,"marks":41685,"value":29846,"nodeType":864},{},[41686],{"type":899},{"data":41688,"marks":41689,"value":29850,"nodeType":864},{},[],{"data":41691,"content":41692,"nodeType":1005},{},[],{"data":41694,"content":41695,"nodeType":1009},{},[41696],{"data":41697,"marks":41698,"value":29861,"nodeType":864},{},[41699],{"type":899},{"data":41701,"content":41702,"nodeType":860},{},[41703],{"data":41704,"marks":41705,"value":29868,"nodeType":864},{},[],{"data":41707,"content":41708,"nodeType":1312},{},[41709],{"data":41710,"marks":41711,"value":29876,"nodeType":864},{},[41712],{"type":899},{"data":41714,"content":41715,"nodeType":860},{},[41716,41719,41726],{"data":41717,"marks":41718,"value":21,"nodeType":864},{},[],{"data":41720,"content":41721,"nodeType":883},{"uri":4103},[41722],{"data":41723,"marks":41724,"value":29890,"nodeType":864},{},[41725],{"type":1455},{"data":41727,"marks":41728,"value":29894,"nodeType":864},{},[],{"data":41730,"content":41731,"nodeType":860},{},[41732,41735,41739],{"data":41733,"marks":41734,"value":29901,"nodeType":864},{},[],{"data":41736,"marks":41737,"value":29906,"nodeType":864},{},[41738],{"type":899},{"data":41740,"marks":41741,"value":29910,"nodeType":864},{},[],{"data":41743,"content":41744,"nodeType":1312},{},[41745],{"data":41746,"marks":41747,"value":288,"nodeType":864},{},[41748],{"type":899},{"data":41750,"content":41751,"nodeType":860},{},[41752,41756,41764,41768],{"data":41753,"marks":41754,"value":21,"nodeType":864},{},[41755],{"type":899},{"data":41757,"content":41758,"nodeType":883},{"uri":2411},[41759],{"data":41760,"marks":41761,"value":29933,"nodeType":864},{},[41762,41763],{"type":1455},{"type":899},{"data":41765,"marks":41766,"value":29938,"nodeType":864},{},[41767],{"type":899},{"data":41769,"marks":41770,"value":29942,"nodeType":864},{},[],{"data":41772,"content":41773,"nodeType":860},{},[41774],{"data":41775,"marks":41776,"value":29949,"nodeType":864},{},[],{"data":41778,"content":41779,"nodeType":1312},{},[41780],{"data":41781,"marks":41782,"value":29957,"nodeType":864},{},[41783],{"type":899},{"data":41785,"content":41786,"nodeType":860},{},[41787,41790,41796,41799,41805],{"data":41788,"marks":41789,"value":29964,"nodeType":864},{},[],{"data":41791,"content":41792,"nodeType":883},{"uri":13427},[41793],{"data":41794,"marks":41795,"value":29971,"nodeType":864},{},[],{"data":41797,"marks":41798,"value":29975,"nodeType":864},{},[],{"data":41800,"content":41801,"nodeType":883},{"uri":3237},[41802],{"data":41803,"marks":41804,"value":29982,"nodeType":864},{},[],{"data":41806,"marks":41807,"value":29986,"nodeType":864},{},[],{"data":41809,"content":41810,"nodeType":860},{},[41811],{"data":41812,"marks":41813,"value":29993,"nodeType":864},{},[],{"data":41815,"content":41816,"nodeType":1312},{},[41817],{"data":41818,"marks":41819,"value":30001,"nodeType":864},{},[41820],{"type":899},{"data":41822,"content":41823,"nodeType":860},{},[41824],{"data":41825,"marks":41826,"value":30008,"nodeType":864},{},[],{"data":41828,"content":41831,"nodeType":996},{"target":41829},{"sys":41830},{"id":30013,"type":1001,"linkType":1002},[],{"data":41833,"content":41834,"nodeType":1005},{},[],{"data":41836,"content":41837,"nodeType":1009},{},[41838],{"data":41839,"marks":41840,"value":30025,"nodeType":864},{},[41841],{"type":899},{"data":41843,"content":41844,"nodeType":860},{},[41845],{"data":41846,"marks":41847,"value":30032,"nodeType":864},{},[],{"data":41849,"content":41850,"nodeType":860},{},[41851],{"data":41852,"marks":41853,"value":30040,"nodeType":864},{},[41854],{"type":899},{"data":41856,"content":41859,"nodeType":996},{"target":41857},{"sys":41858},{"id":30045,"type":1001,"linkType":1002},[],{"data":41861,"content":41862,"nodeType":1005},{},[],{"data":41864,"content":41865,"nodeType":1312},{},[41866],{"data":41867,"marks":41868,"value":30057,"nodeType":864},{},[41869],{"type":899},{"data":41871,"content":41872,"nodeType":860},{},[41873],{"data":41874,"marks":41875,"value":30064,"nodeType":864},{},[],{"data":41877,"content":41878,"nodeType":860},{},[41879],{"data":41880,"marks":41881,"value":30071,"nodeType":864},{},[],{"data":41883,"content":41884,"nodeType":860},{},[41885],{"data":41886,"marks":41887,"value":30078,"nodeType":864},{},[],{"data":41889,"content":41890,"nodeType":860},{},[41891,41895],{"data":41892,"marks":41893,"value":30086,"nodeType":864},{},[41894],{"type":899},{"data":41896,"marks":41897,"value":30090,"nodeType":864},{},[],{"data":41899,"content":41900,"nodeType":1005},{},[],{"data":41902,"content":41903,"nodeType":860},{},[41904],{"data":41905,"marks":41906,"value":4855,"nodeType":864},{},[],{"data":41908,"content":41909,"nodeType":860},{},[41910,41913,41919],{"data":41911,"marks":41912,"value":30106,"nodeType":864},{},[],{"data":41914,"content":41915,"nodeType":883},{"uri":30109},[41916],{"data":41917,"marks":41918,"value":13763,"nodeType":864},{},[],{"data":41920,"marks":41921,"value":2719,"nodeType":864},{},[],{"items":41923},[41924,41926],{"sys":41925,"name":2729},{"id":2728},{"sys":41927,"name":342},{"id":13775},{"items":41929},[41930],{"fullName":3621,"firstName":3622,"jobTitle":3623,"profilePicture":41931},{"url":3625},"blog/how-to-avoid-the-browser-security-buyers-trap",{"json":41934},{"data":41935,"content":41936,"nodeType":856},{},[41937],{"data":41938,"content":41939,"nodeType":860},{},[41940],{"data":41941,"marks":41942,"value":41943,"nodeType":864},{},[],"Securing the browser vs. securing the organization via the browser — what's the difference? Most browser security solutions defend against the browser being hacked, but these aren't the attacks that are actually leading to major breaches. ",{"id":25527,"publishedAt":41945},"2026-08-13T09:35:09.806Z",{"items":41947},[41948,41950],{"sys":41949,"name":297},{"id":2732},{"sys":41951,"name":2729},{"id":2728},{"items":41953},[41954,41956,41958,41960,41962,41964,41966,41968,41970,41972,41974,41976,41978,41980,41982,41984,41986,41988,41990,41992,41994,41996,41998],{"sys":41955,"name":297,"slug":298,"tier":31},{"id":294},{"sys":41957,"name":279,"slug":280,"tier":31},{"id":276},{"sys":41959,"name":413,"slug":414,"tier":31},{"id":410},{"sys":41961,"name":519,"slug":520,"tier":31},{"id":516},{"sys":41963,"name":342,"slug":343,"tier":31},{"id":339},{"sys":41965,"name":386,"slug":387,"tier":45},{"id":383},{"sys":41967,"name":511,"slug":512,"tier":45},{"id":508},{"sys":41969,"name":261,"slug":262,"tier":45},{"id":258},{"sys":41971,"name":571,"slug":572,"tier":45},{"id":568},{"sys":41973,"name":333,"slug":334,"tier":45},{"id":330},{"sys":41975,"name":324,"slug":325,"tier":45},{"id":321},{"sys":41977,"name":484,"slug":485,"tier":45},{"id":481},{"sys":41979,"name":315,"slug":316,"tier":45},{"id":312},{"sys":41981,"name":360,"slug":361,"tier":45},{"id":357},{"sys":41983,"name":395,"slug":396,"tier":45},{"id":392},{"sys":41985,"name":589,"slug":590,"tier":45},{"id":586},{"sys":41987,"name":288,"slug":289,"tier":45},{"id":285},{"sys":41989,"name":502,"slug":503,"tier":45},{"id":499},{"sys":41991,"name":457,"slug":458,"tier":45},{"id":454},{"sys":41993,"name":377,"slug":378,"tier":45},{"id":374},{"sys":41995,"name":624,"slug":625,"tier":45},{"id":621},{"sys":41997,"name":368,"slug":369,"tier":45},{"id":365},{"sys":41999,"name":244,"slug":245,"tier":45},{"id":241},"5C3_54ldAqXGDnFfNyrEkB5PAE-NWpPCxwC0yi4pkDk",{"id":42002,"title":30117,"authorsCollection":42003,"content":42007,"extension":228,"faqItemsCollection":42546,"faqTitle":59,"featured":6,"hashTags":59,"meta":42548,"metaTitle":42549,"ogImage":59,"postType":5726,"publishedDate":30119,"relatedBlogPostsCollection":42550,"slug":30120,"stem":44953,"subtitle":59,"summary":44954,"synopsis":30118,"sys":44965,"tagsCollection":44967,"topicsCollection":44973,"__hash__":45021},"blog/blog/the-cisos-data-problem-and-how-browser-telemetry-can-help.json",{"items":42004},[42005],{"fullName":3621,"firstName":3622,"jobTitle":3623,"socialLinks":59,"profilePicture":42006},{"url":3625},{"json":42008,"links":42437},{"data":42009,"content":42010,"nodeType":856},{},[42011,42018,42042,42047,42053,42068,42081,42084,42091,42104,42120,42140,42145,42158,42182,42187,42192,42205,42208,42215,42221,42228,42244,42257,42264,42286,42292,42299,42323,42329,42336,42342,42347,42350,42357,42363,42370,42375,42378,42385,42391,42397,42403,42413,42416,42422],{"data":42012,"content":42013,"nodeType":1009},{},[42014],{"data":42015,"marks":42016,"value":29624,"nodeType":864},{},[42017],{"type":899},{"data":42019,"content":42020,"nodeType":860},{},[42021,42024,42030,42033,42039],{"data":42022,"marks":42023,"value":29631,"nodeType":864},{},[],{"data":42025,"content":42026,"nodeType":883},{"uri":29634},[42027],{"data":42028,"marks":42029,"value":29639,"nodeType":864},{},[],{"data":42031,"marks":42032,"value":29643,"nodeType":864},{},[],{"data":42034,"content":42035,"nodeType":883},{"uri":29646},[42036],{"data":42037,"marks":42038,"value":29651,"nodeType":864},{},[],{"data":42040,"marks":42041,"value":29655,"nodeType":864},{},[],{"data":42043,"content":42046,"nodeType":996},{"target":42044},{"sys":42045},{"id":29660,"type":1001,"linkType":1002},[],{"data":42048,"content":42049,"nodeType":860},{},[42050],{"data":42051,"marks":42052,"value":29668,"nodeType":864},{},[],{"data":42054,"content":42055,"nodeType":860},{},[42056,42059,42065],{"data":42057,"marks":42058,"value":29675,"nodeType":864},{},[],{"data":42060,"content":42061,"nodeType":883},{"uri":29678},[42062],{"data":42063,"marks":42064,"value":29683,"nodeType":864},{},[],{"data":42066,"marks":42067,"value":29687,"nodeType":864},{},[],{"data":42069,"content":42070,"nodeType":860},{},[42071,42074,42078],{"data":42072,"marks":42073,"value":29694,"nodeType":864},{},[],{"data":42075,"marks":42076,"value":29699,"nodeType":864},{},[42077],{"type":899},{"data":42079,"marks":42080,"value":2924,"nodeType":864},{},[],{"data":42082,"content":42083,"nodeType":1005},{},[],{"data":42085,"content":42086,"nodeType":1009},{},[42087],{"data":42088,"marks":42089,"value":29713,"nodeType":864},{},[42090],{"type":899},{"data":42092,"content":42093,"nodeType":860},{},[42094,42097,42101],{"data":42095,"marks":42096,"value":29720,"nodeType":864},{},[],{"data":42098,"marks":42099,"value":29725,"nodeType":864},{},[42100],{"type":2246},{"data":42102,"marks":42103,"value":2924,"nodeType":864},{},[],{"data":42105,"content":42106,"nodeType":860},{},[42107,42110,42117],{"data":42108,"marks":42109,"value":29735,"nodeType":864},{},[],{"data":42111,"content":42112,"nodeType":883},{"uri":7549},[42113],{"data":42114,"marks":42115,"value":29743,"nodeType":864},{},[42116],{"type":1455},{"data":42118,"marks":42119,"value":29747,"nodeType":864},{},[],{"data":42121,"content":42122,"nodeType":860},{},[42123,42126,42130,42133,42137],{"data":42124,"marks":42125,"value":29754,"nodeType":864},{},[],{"data":42127,"marks":42128,"value":29759,"nodeType":864},{},[42129],{"type":899},{"data":42131,"marks":42132,"value":29763,"nodeType":864},{},[],{"data":42134,"marks":42135,"value":29768,"nodeType":864},{},[42136],{"type":2246},{"data":42138,"marks":42139,"value":29772,"nodeType":864},{},[],{"data":42141,"content":42144,"nodeType":996},{"target":42142},{"sys":42143},{"id":29777,"type":1001,"linkType":1002},[],{"data":42146,"content":42147,"nodeType":860},{},[42148,42151,42155],{"data":42149,"marks":42150,"value":29785,"nodeType":864},{},[],{"data":42152,"marks":42153,"value":29790,"nodeType":864},{},[42154],{"type":899},{"data":42156,"marks":42157,"value":29794,"nodeType":864},{},[],{"data":42159,"content":42160,"nodeType":860},{},[42161,42164,42170,42173,42179],{"data":42162,"marks":42163,"value":29801,"nodeType":864},{},[],{"data":42165,"content":42166,"nodeType":883},{"uri":25338},[42167],{"data":42168,"marks":42169,"value":29808,"nodeType":864},{},[],{"data":42171,"marks":42172,"value":29812,"nodeType":864},{},[],{"data":42174,"content":42175,"nodeType":883},{"uri":11813},[42176],{"data":42177,"marks":42178,"value":29819,"nodeType":864},{},[],{"data":42180,"marks":42181,"value":1774,"nodeType":864},{},[],{"data":42183,"content":42186,"nodeType":996},{"target":42184},{"sys":42185},{"id":29827,"type":1001,"linkType":1002},[],{"data":42188,"content":42191,"nodeType":996},{"target":42189},{"sys":42190},{"id":29833,"type":1001,"linkType":1002},[],{"data":42193,"content":42194,"nodeType":860},{},[42195,42198,42202],{"data":42196,"marks":42197,"value":29841,"nodeType":864},{},[],{"data":42199,"marks":42200,"value":29846,"nodeType":864},{},[42201],{"type":899},{"data":42203,"marks":42204,"value":29850,"nodeType":864},{},[],{"data":42206,"content":42207,"nodeType":1005},{},[],{"data":42209,"content":42210,"nodeType":1009},{},[42211],{"data":42212,"marks":42213,"value":29861,"nodeType":864},{},[42214],{"type":899},{"data":42216,"content":42217,"nodeType":860},{},[42218],{"data":42219,"marks":42220,"value":29868,"nodeType":864},{},[],{"data":42222,"content":42223,"nodeType":1312},{},[42224],{"data":42225,"marks":42226,"value":29876,"nodeType":864},{},[42227],{"type":899},{"data":42229,"content":42230,"nodeType":860},{},[42231,42234,42241],{"data":42232,"marks":42233,"value":21,"nodeType":864},{},[],{"data":42235,"content":42236,"nodeType":883},{"uri":4103},[42237],{"data":42238,"marks":42239,"value":29890,"nodeType":864},{},[42240],{"type":1455},{"data":42242,"marks":42243,"value":29894,"nodeType":864},{},[],{"data":42245,"content":42246,"nodeType":860},{},[42247,42250,42254],{"data":42248,"marks":42249,"value":29901,"nodeType":864},{},[],{"data":42251,"marks":42252,"value":29906,"nodeType":864},{},[42253],{"type":899},{"data":42255,"marks":42256,"value":29910,"nodeType":864},{},[],{"data":42258,"content":42259,"nodeType":1312},{},[42260],{"data":42261,"marks":42262,"value":288,"nodeType":864},{},[42263],{"type":899},{"data":42265,"content":42266,"nodeType":860},{},[42267,42271,42279,42283],{"data":42268,"marks":42269,"value":21,"nodeType":864},{},[42270],{"type":899},{"data":42272,"content":42273,"nodeType":883},{"uri":2411},[42274],{"data":42275,"marks":42276,"value":29933,"nodeType":864},{},[42277,42278],{"type":1455},{"type":899},{"data":42280,"marks":42281,"value":29938,"nodeType":864},{},[42282],{"type":899},{"data":42284,"marks":42285,"value":29942,"nodeType":864},{},[],{"data":42287,"content":42288,"nodeType":860},{},[42289],{"data":42290,"marks":42291,"value":29949,"nodeType":864},{},[],{"data":42293,"content":42294,"nodeType":1312},{},[42295],{"data":42296,"marks":42297,"value":29957,"nodeType":864},{},[42298],{"type":899},{"data":42300,"content":42301,"nodeType":860},{},[42302,42305,42311,42314,42320],{"data":42303,"marks":42304,"value":29964,"nodeType":864},{},[],{"data":42306,"content":42307,"nodeType":883},{"uri":13427},[42308],{"data":42309,"marks":42310,"value":29971,"nodeType":864},{},[],{"data":42312,"marks":42313,"value":29975,"nodeType":864},{},[],{"data":42315,"content":42316,"nodeType":883},{"uri":3237},[42317],{"data":42318,"marks":42319,"value":29982,"nodeType":864},{},[],{"data":42321,"marks":42322,"value":29986,"nodeType":864},{},[],{"data":42324,"content":42325,"nodeType":860},{},[42326],{"data":42327,"marks":42328,"value":29993,"nodeType":864},{},[],{"data":42330,"content":42331,"nodeType":1312},{},[42332],{"data":42333,"marks":42334,"value":30001,"nodeType":864},{},[42335],{"type":899},{"data":42337,"content":42338,"nodeType":860},{},[42339],{"data":42340,"marks":42341,"value":30008,"nodeType":864},{},[],{"data":42343,"content":42346,"nodeType":996},{"target":42344},{"sys":42345},{"id":30013,"type":1001,"linkType":1002},[],{"data":42348,"content":42349,"nodeType":1005},{},[],{"data":42351,"content":42352,"nodeType":1009},{},[42353],{"data":42354,"marks":42355,"value":30025,"nodeType":864},{},[42356],{"type":899},{"data":42358,"content":42359,"nodeType":860},{},[42360],{"data":42361,"marks":42362,"value":30032,"nodeType":864},{},[],{"data":42364,"content":42365,"nodeType":860},{},[42366],{"data":42367,"marks":42368,"value":30040,"nodeType":864},{},[42369],{"type":899},{"data":42371,"content":42374,"nodeType":996},{"target":42372},{"sys":42373},{"id":30045,"type":1001,"linkType":1002},[],{"data":42376,"content":42377,"nodeType":1005},{},[],{"data":42379,"content":42380,"nodeType":1312},{},[42381],{"data":42382,"marks":42383,"value":30057,"nodeType":864},{},[42384],{"type":899},{"data":42386,"content":42387,"nodeType":860},{},[42388],{"data":42389,"marks":42390,"value":30064,"nodeType":864},{},[],{"data":42392,"content":42393,"nodeType":860},{},[42394],{"data":42395,"marks":42396,"value":30071,"nodeType":864},{},[],{"data":42398,"content":42399,"nodeType":860},{},[42400],{"data":42401,"marks":42402,"value":30078,"nodeType":864},{},[],{"data":42404,"content":42405,"nodeType":860},{},[42406,42410],{"data":42407,"marks":42408,"value":30086,"nodeType":864},{},[42409],{"type":899},{"data":42411,"marks":42412,"value":30090,"nodeType":864},{},[],{"data":42414,"content":42415,"nodeType":1005},{},[],{"data":42417,"content":42418,"nodeType":860},{},[42419],{"data":42420,"marks":42421,"value":4855,"nodeType":864},{},[],{"data":42423,"content":42424,"nodeType":860},{},[42425,42428,42434],{"data":42426,"marks":42427,"value":30106,"nodeType":864},{},[],{"data":42429,"content":42430,"nodeType":883},{"uri":30109},[42431],{"data":42432,"marks":42433,"value":13763,"nodeType":864},{},[],{"data":42435,"marks":42436,"value":2719,"nodeType":864},{},[],{"entries":42438},{"hyperlink":42439,"inline":42440,"block":42441},[],[],[42442,42448,42462,42489,42496,42538],{"sys":42443,"__typename":1724,"title":42444,"caption":42444,"layoutMode":59,"file":42445},{"id":29660},"Risk Matrix-style risk modeling versus Loss Exceedance Curve.",{"url":42446,"width":1736,"height":42447},"https://images.ctfassets.net/y1cdw1ablpvd/2bkhvxg1zeLZnrTyzQXQjd/58cfb711a8825b5861a47ef18db8b661/image1.png",1033,{"sys":42449,"__typename":1740,"content":42450,"name":42461,"title":59},{"id":29777},{"json":42451},{"nodeType":856,"data":42452,"content":42453},{},[42454],{"nodeType":860,"data":42455,"content":42456},{},[42457],{"nodeType":864,"value":42458,"marks":42459,"data":42460},"Models that estimate TEF without factoring in browser-borne attacks are systemically undercounting. One key example of this is email-delivered phishing data. Roughly 1 in 3 phishing payloads intercepted by Push are delivered outside of email, meaning an email-only risk assessment is missing the attacks happening over channels like social media, search ads, and messaging apps that most risk models ignore entirely — places where the success chance is far higher because of the lack of control (and because users don't expect it). ",[],{},"CISO data problem IB1",{"sys":42463,"__typename":1740,"content":42464,"name":42488,"title":59},{"id":29827},{"json":42465},{"nodeType":856,"data":42466,"content":42467},{},[42468],{"nodeType":860,"data":42469,"content":42470},{},[42471,42476,42483],{"nodeType":864,"value":42472,"marks":42473,"data":42475},"There are many examples of ghost logins being exploited by attackers in the wild, but the landmark case remains 2024's ",[42474],{"type":899},{},{"nodeType":883,"data":42477,"content":42478},{"uri":3751},[42479],{"nodeType":864,"value":3756,"marks":42480,"data":42482},[42481],{"type":899},{},{"nodeType":864,"value":42484,"marks":42485,"data":42487},", in which 165 organizations were breached using compromised credentials that had been sitting online since 2020. MFA was missing in every case. ",[42486],{"type":899},{},"CISO data problem IB3",{"sys":42490,"__typename":1724,"title":42491,"caption":42491,"layoutMode":59,"file":42492},{"id":29833},"Data from Push login telemetry across customer environments.",{"url":42493,"width":42494,"height":42495},"https://images.ctfassets.net/y1cdw1ablpvd/67iyvaMRSinyWAPqNFRity/5650febed866df4656160006d7415588/Frame_1__2_.png",2160,496,{"sys":42497,"__typename":1740,"content":42498,"name":42537,"title":59},{"id":30013},{"json":42499},{"nodeType":856,"data":42500,"content":42501},{},[42502,42519],{"nodeType":860,"data":42503,"content":42504},{},[42505,42508,42515],{"nodeType":864,"value":3256,"marks":42506,"data":42507},[],{},{"nodeType":883,"data":42509,"content":42510},{"uri":3259},[42511],{"nodeType":864,"value":42512,"marks":42513,"data":42514},"37x increase in device code phishing attacks since the start of 2026",[],{},{"nodeType":864,"value":42516,"marks":42517,"data":42518},", with at least 12 distinct kits now offering the technique, while established AiTM vendors like Tycoon are now adding authorization-focused options alongside their existing session token and credential harvesting capabilities. ",[],{},{"nodeType":860,"data":42520,"content":42521},{},[42522,42526,42533],{"nodeType":864,"value":42523,"marks":42524,"data":42525},"Device code phishing has featured heavily in ",[],{},{"nodeType":883,"data":42527,"content":42528},{"uri":4082},[42529],{"nodeType":864,"value":42530,"marks":42531,"data":42532},"ShinyHunters campaigns",[],{},{"nodeType":864,"value":42534,"marks":42535,"data":42536}," in 2025 and 2026 along with AiTM phishing and OAuth token abuse, often paired with voice-based lure delivery that misses traditional endpoint controls (but inevitably leads the victim to a webpage in the browser where the payload is delivered). ",[],{},"CISO data problem IB2",{"sys":42539,"__typename":1724,"title":42540,"caption":42541,"layoutMode":59,"file":42542},{"id":30045},"Precision improvements with browser telemetry.","Precision risk assessment improvements with browser telemetry.",{"url":42543,"width":42544,"height":42545},"https://images.ctfassets.net/y1cdw1ablpvd/1hpJGD6oVLcvalCTuFBia3/547b689a199b5b4ac3b2e7ddb9f3079d/blog-inline-fair-model-v4_1.png",2200,1520,{"items":42547},[],{},"Why modern attack data is missing in your threat analysis",{"items":42551},[42552,43385,44033],{"__typename":2059,"sys":42553,"content":42554,"title":29597,"synopsis":29598,"hashTags":59,"publishedDate":24225,"slug":29599,"tagsCollection":43375,"authorsCollection":43381},{"id":28636},{"json":42555},{"data":42556,"content":42557,"nodeType":856},{},[42558,42580,42604,42637,42670,42675,42685,42688,42695,42737,42743,42762,42767,42770,42777,42801,42807,42814,42819,42822,42829,42835,42850,42856,42889,42895,42898,42905,42920,42962,42965,42972,42987,43002,43009,43015,43025,43035,43045,43055,43070,43077,43083,43086,43092,43098,43113,43116,43123,43138,43369],{"data":42559,"content":42560,"nodeType":860},{},[42561,42564,42570,42573,42577],{"data":42562,"marks":42563,"value":28647,"nodeType":864},{},[],{"data":42565,"content":42566,"nodeType":883},{"uri":16015},[42567],{"data":42568,"marks":42569,"value":16018,"nodeType":864},{},[],{"data":42571,"marks":42572,"value":28657,"nodeType":864},{},[],{"data":42574,"marks":42575,"value":28662,"nodeType":864},{},[42576],{"type":899},{"data":42578,"marks":42579,"value":28666,"nodeType":864},{},[],{"data":42581,"content":42582,"nodeType":860},{},[42583,42586,42592,42595,42601],{"data":42584,"marks":42585,"value":28673,"nodeType":864},{},[],{"data":42587,"content":42588,"nodeType":883},{"uri":28676},[42589],{"data":42590,"marks":42591,"value":28681,"nodeType":864},{},[],{"data":42593,"marks":42594,"value":28685,"nodeType":864},{},[],{"data":42596,"content":42597,"nodeType":883},{"uri":28688},[42598],{"data":42599,"marks":42600,"value":28693,"nodeType":864},{},[],{"data":42602,"marks":42603,"value":28697,"nodeType":864},{},[],{"data":42605,"content":42606,"nodeType":860},{},[42607,42610,42616,42619,42625,42628,42634],{"data":42608,"marks":42609,"value":28704,"nodeType":864},{},[],{"data":42611,"content":42612,"nodeType":883},{"uri":28707},[42613],{"data":42614,"marks":42615,"value":28712,"nodeType":864},{},[],{"data":42617,"marks":42618,"value":28716,"nodeType":864},{},[],{"data":42620,"content":42621,"nodeType":883},{"uri":28719},[42622],{"data":42623,"marks":42624,"value":28724,"nodeType":864},{},[],{"data":42626,"marks":42627,"value":28728,"nodeType":864},{},[],{"data":42629,"content":42630,"nodeType":883},{"uri":16553},[42631],{"data":42632,"marks":42633,"value":28735,"nodeType":864},{},[],{"data":42635,"marks":42636,"value":28739,"nodeType":864},{},[],{"data":42638,"content":42639,"nodeType":860},{},[42640,42643,42649,42652,42658,42661,42667],{"data":42641,"marks":42642,"value":28746,"nodeType":864},{},[],{"data":42644,"content":42645,"nodeType":883},{"uri":28749},[42646],{"data":42647,"marks":42648,"value":28754,"nodeType":864},{},[],{"data":42650,"marks":42651,"value":28758,"nodeType":864},{},[],{"data":42653,"content":42654,"nodeType":883},{"uri":28761},[42655],{"data":42656,"marks":42657,"value":28766,"nodeType":864},{},[],{"data":42659,"marks":42660,"value":28770,"nodeType":864},{},[],{"data":42662,"content":42663,"nodeType":883},{"uri":28773},[42664],{"data":42665,"marks":42666,"value":28778,"nodeType":864},{},[],{"data":42668,"marks":42669,"value":28782,"nodeType":864},{},[],{"data":42671,"content":42674,"nodeType":996},{"target":42672},{"sys":42673},{"id":28787,"type":1001,"linkType":1002},[],{"data":42676,"content":42677,"nodeType":860},{},[42678,42682],{"data":42679,"marks":42680,"value":28796,"nodeType":864},{},[42681],{"type":899},{"data":42683,"marks":42684,"value":28800,"nodeType":864},{},[],{"data":42686,"content":42687,"nodeType":1005},{},[],{"data":42689,"content":42690,"nodeType":1009},{},[42691],{"data":42692,"marks":42693,"value":28811,"nodeType":864},{},[42694],{"type":899},{"data":42696,"content":42697,"nodeType":860},{},[42698,42701,42707,42710,42716,42719,42725,42728,42734],{"data":42699,"marks":42700,"value":28818,"nodeType":864},{},[],{"data":42702,"content":42703,"nodeType":883},{"uri":28821},[42704],{"data":42705,"marks":42706,"value":28826,"nodeType":864},{},[],{"data":42708,"marks":42709,"value":11735,"nodeType":864},{},[],{"data":42711,"content":42712,"nodeType":883},{"uri":28832},[42713],{"data":42714,"marks":42715,"value":28837,"nodeType":864},{},[],{"data":42717,"marks":42718,"value":28841,"nodeType":864},{},[],{"data":42720,"content":42721,"nodeType":883},{"uri":28719},[42722],{"data":42723,"marks":42724,"value":28848,"nodeType":864},{},[],{"data":42726,"marks":42727,"value":28852,"nodeType":864},{},[],{"data":42729,"content":42730,"nodeType":883},{"uri":12879},[42731],{"data":42732,"marks":42733,"value":28859,"nodeType":864},{},[],{"data":42735,"marks":42736,"value":2924,"nodeType":864},{},[],{"data":42738,"content":42739,"nodeType":860},{},[42740],{"data":42741,"marks":42742,"value":28869,"nodeType":864},{},[],{"data":42744,"content":42745,"nodeType":860},{},[42746,42749,42755,42758],{"data":42747,"marks":42748,"value":28876,"nodeType":864},{},[],{"data":42750,"content":42751,"nodeType":883},{"uri":12879},[42752],{"data":42753,"marks":42754,"value":28883,"nodeType":864},{},[],{"data":42756,"marks":42757,"value":28887,"nodeType":864},{},[],{"data":42759,"marks":42760,"value":28892,"nodeType":864},{},[42761],{"type":899},{"data":42763,"content":42766,"nodeType":996},{"target":42764},{"sys":42765},{"id":28897,"type":1001,"linkType":1002},[],{"data":42768,"content":42769,"nodeType":1005},{},[],{"data":42771,"content":42772,"nodeType":1009},{},[42773],{"data":42774,"marks":42775,"value":28909,"nodeType":864},{},[42776],{"type":899},{"data":42778,"content":42779,"nodeType":860},{},[42780,42783,42789,42792,42798],{"data":42781,"marks":42782,"value":2761,"nodeType":864},{},[],{"data":42784,"content":42785,"nodeType":883},{"uri":23901},[42786],{"data":42787,"marks":42788,"value":28922,"nodeType":864},{},[],{"data":42790,"marks":42791,"value":28926,"nodeType":864},{},[],{"data":42793,"content":42794,"nodeType":883},{"uri":16553},[42795],{"data":42796,"marks":42797,"value":28933,"nodeType":864},{},[],{"data":42799,"marks":42800,"value":28937,"nodeType":864},{},[],{"data":42802,"content":42803,"nodeType":860},{},[42804],{"data":42805,"marks":42806,"value":28944,"nodeType":864},{},[],{"data":42808,"content":42809,"nodeType":860},{},[42810],{"data":42811,"marks":42812,"value":28952,"nodeType":864},{},[42813],{"type":899},{"data":42815,"content":42818,"nodeType":996},{"target":42816},{"sys":42817},{"id":28957,"type":1001,"linkType":1002},[],{"data":42820,"content":42821,"nodeType":1005},{},[],{"data":42823,"content":42824,"nodeType":1009},{},[42825],{"data":42826,"marks":42827,"value":28969,"nodeType":864},{},[42828],{"type":899},{"data":42830,"content":42831,"nodeType":860},{},[42832],{"data":42833,"marks":42834,"value":28976,"nodeType":864},{},[],{"data":42836,"content":42837,"nodeType":860},{},[42838,42841,42847],{"data":42839,"marks":42840,"value":2761,"nodeType":864},{},[],{"data":42842,"content":42843,"nodeType":883},{"uri":28985},[42844],{"data":42845,"marks":42846,"value":28990,"nodeType":864},{},[],{"data":42848,"marks":42849,"value":28994,"nodeType":864},{},[],{"data":42851,"content":42852,"nodeType":860},{},[42853],{"data":42854,"marks":42855,"value":29001,"nodeType":864},{},[],{"data":42857,"content":42858,"nodeType":860},{},[42859,42862,42868,42871,42877,42880,42886],{"data":42860,"marks":42861,"value":29008,"nodeType":864},{},[],{"data":42863,"content":42864,"nodeType":883},{"uri":29011},[42865],{"data":42866,"marks":42867,"value":29016,"nodeType":864},{},[],{"data":42869,"marks":42870,"value":29020,"nodeType":864},{},[],{"data":42872,"content":42873,"nodeType":883},{"uri":29023},[42874],{"data":42875,"marks":42876,"value":29028,"nodeType":864},{},[],{"data":42878,"marks":42879,"value":29032,"nodeType":864},{},[],{"data":42881,"content":42882,"nodeType":883},{"uri":4103},[42883],{"data":42884,"marks":42885,"value":16114,"nodeType":864},{},[],{"data":42887,"marks":42888,"value":29042,"nodeType":864},{},[],{"data":42890,"content":42891,"nodeType":860},{},[42892],{"data":42893,"marks":42894,"value":29049,"nodeType":864},{},[],{"data":42896,"content":42897,"nodeType":1005},{},[],{"data":42899,"content":42900,"nodeType":1009},{},[42901],{"data":42902,"marks":42903,"value":29060,"nodeType":864},{},[42904],{"type":899},{"data":42906,"content":42907,"nodeType":860},{},[42908,42911,42917],{"data":42909,"marks":42910,"value":29067,"nodeType":864},{},[],{"data":42912,"content":42913,"nodeType":883},{"uri":29070},[42914],{"data":42915,"marks":42916,"value":29075,"nodeType":864},{},[],{"data":42918,"marks":42919,"value":29079,"nodeType":864},{},[],{"data":42921,"content":42922,"nodeType":860},{},[42923,42926,42932,42935,42941,42944,42950,42953,42959],{"data":42924,"marks":42925,"value":29086,"nodeType":864},{},[],{"data":42927,"content":42928,"nodeType":883},{"uri":29089},[42929],{"data":42930,"marks":42931,"value":29094,"nodeType":864},{},[],{"data":42933,"marks":42934,"value":29098,"nodeType":864},{},[],{"data":42936,"content":42937,"nodeType":883},{"uri":29101},[42938],{"data":42939,"marks":42940,"value":29106,"nodeType":864},{},[],{"data":42942,"marks":42943,"value":29110,"nodeType":864},{},[],{"data":42945,"content":42946,"nodeType":883},{"uri":29113},[42947],{"data":42948,"marks":42949,"value":29118,"nodeType":864},{},[],{"data":42951,"marks":42952,"value":29122,"nodeType":864},{},[],{"data":42954,"content":42955,"nodeType":883},{"uri":29125},[42956],{"data":42957,"marks":42958,"value":29130,"nodeType":864},{},[],{"data":42960,"marks":42961,"value":29134,"nodeType":864},{},[],{"data":42963,"content":42964,"nodeType":1005},{},[],{"data":42966,"content":42967,"nodeType":1009},{},[42968],{"data":42969,"marks":42970,"value":29145,"nodeType":864},{},[42971],{"type":899},{"data":42973,"content":42974,"nodeType":860},{},[42975,42978,42984],{"data":42976,"marks":42977,"value":29152,"nodeType":864},{},[],{"data":42979,"content":42980,"nodeType":883},{"uri":3259},[42981],{"data":42982,"marks":42983,"value":29159,"nodeType":864},{},[],{"data":42985,"marks":42986,"value":29163,"nodeType":864},{},[],{"data":42988,"content":42989,"nodeType":860},{},[42990,42993,42999],{"data":42991,"marks":42992,"value":29170,"nodeType":864},{},[],{"data":42994,"content":42995,"nodeType":883},{"uri":29173},[42996],{"data":42997,"marks":42998,"value":315,"nodeType":864},{},[],{"data":43000,"marks":43001,"value":29181,"nodeType":864},{},[],{"data":43003,"content":43004,"nodeType":1312},{},[43005],{"data":43006,"marks":43007,"value":7533,"nodeType":864},{},[43008],{"type":899},{"data":43010,"content":43011,"nodeType":860},{},[43012],{"data":43013,"marks":43014,"value":29195,"nodeType":864},{},[],{"data":43016,"content":43017,"nodeType":860},{},[43018,43022],{"data":43019,"marks":43020,"value":29203,"nodeType":864},{},[43021],{"type":899},{"data":43023,"marks":43024,"value":29207,"nodeType":864},{},[],{"data":43026,"content":43027,"nodeType":860},{},[43028,43032],{"data":43029,"marks":43030,"value":29215,"nodeType":864},{},[43031],{"type":899},{"data":43033,"marks":43034,"value":29219,"nodeType":864},{},[],{"data":43036,"content":43037,"nodeType":860},{},[43038,43042],{"data":43039,"marks":43040,"value":29227,"nodeType":864},{},[43041],{"type":899},{"data":43043,"marks":43044,"value":29231,"nodeType":864},{},[],{"data":43046,"content":43047,"nodeType":860},{},[43048,43052],{"data":43049,"marks":43050,"value":29239,"nodeType":864},{},[43051],{"type":899},{"data":43053,"marks":43054,"value":29243,"nodeType":864},{},[],{"data":43056,"content":43057,"nodeType":860},{},[43058,43061,43067],{"data":43059,"marks":43060,"value":21,"nodeType":864},{},[],{"data":43062,"content":43063,"nodeType":883},{"uri":24926},[43064],{"data":43065,"marks":43066,"value":29256,"nodeType":864},{},[],{"data":43068,"marks":43069,"value":21,"nodeType":864},{},[],{"data":43071,"content":43072,"nodeType":1312},{},[43073],{"data":43074,"marks":43075,"value":29267,"nodeType":864},{},[43076],{"type":899},{"data":43078,"content":43079,"nodeType":860},{},[43080],{"data":43081,"marks":43082,"value":29274,"nodeType":864},{},[],{"data":43084,"content":43085,"nodeType":1005},{},[],{"data":43087,"content":43088,"nodeType":860},{},[43089],{"data":43090,"marks":43091,"value":4855,"nodeType":864},{},[],{"data":43093,"content":43094,"nodeType":860},{},[43095],{"data":43096,"marks":43097,"value":1689,"nodeType":864},{},[],{"data":43099,"content":43100,"nodeType":860},{},[43101,43104,43110],{"data":43102,"marks":43103,"value":21,"nodeType":864},{},[],{"data":43105,"content":43106,"nodeType":883},{"uri":14401},[43107],{"data":43108,"marks":43109,"value":1703,"nodeType":864},{},[],{"data":43111,"marks":43112,"value":21,"nodeType":864},{},[],{"data":43114,"content":43115,"nodeType":1005},{},[],{"data":43117,"content":43118,"nodeType":1009},{},[43119],{"data":43120,"marks":43121,"value":29315,"nodeType":864},{},[43122],{"type":899},{"data":43124,"content":43125,"nodeType":860},{},[43126,43129,43135],{"data":43127,"marks":43128,"value":29322,"nodeType":864},{},[],{"data":43130,"content":43131,"nodeType":883},{"uri":16015},[43132],{"data":43133,"marks":43134,"value":29329,"nodeType":864},{},[],{"data":43136,"marks":43137,"value":29333,"nodeType":864},{},[],{"data":43139,"content":43140,"nodeType":4845},{},[43141,43184,43240,43283,43326],{"data":43142,"content":43143,"nodeType":4581},{},[43144,43154,43164,43174],{"data":43145,"content":43146,"nodeType":4569},{},[43147],{"data":43148,"content":43149,"nodeType":860},{},[43150],{"data":43151,"marks":43152,"value":29350,"nodeType":864},{},[43153],{"type":899},{"data":43155,"content":43156,"nodeType":4569},{},[43157],{"data":43158,"content":43159,"nodeType":860},{},[43160],{"data":43161,"marks":43162,"value":29361,"nodeType":864},{},[43163],{"type":899},{"data":43165,"content":43166,"nodeType":4569},{},[43167],{"data":43168,"content":43169,"nodeType":860},{},[43170],{"data":43171,"marks":43172,"value":29372,"nodeType":864},{},[43173],{"type":899},{"data":43175,"content":43176,"nodeType":4569},{},[43177],{"data":43178,"content":43179,"nodeType":860},{},[43180],{"data":43181,"marks":43182,"value":29383,"nodeType":864},{},[43183],{"type":899},{"data":43185,"content":43186,"nodeType":4581},{},[43187,43207,43216,43225],{"data":43188,"content":43189,"nodeType":4569},{},[43190],{"data":43191,"content":43192,"nodeType":860},{},[43193,43197,43200,43204],{"data":43194,"marks":43195,"value":29397,"nodeType":864},{},[43196],{"type":899},{"data":43198,"marks":43199,"value":29401,"nodeType":864},{},[],{"data":43201,"marks":43202,"value":29406,"nodeType":864},{},[43203],{"type":899},{"data":43205,"marks":43206,"value":29410,"nodeType":864},{},[],{"data":43208,"content":43209,"nodeType":4569},{},[43210],{"data":43211,"content":43212,"nodeType":860},{},[43213],{"data":43214,"marks":43215,"value":29420,"nodeType":864},{},[],{"data":43217,"content":43218,"nodeType":4569},{},[43219],{"data":43220,"content":43221,"nodeType":860},{},[43222],{"data":43223,"marks":43224,"value":29430,"nodeType":864},{},[],{"data":43226,"content":43227,"nodeType":4569},{},[43228,43234],{"data":43229,"content":43230,"nodeType":860},{},[43231],{"data":43232,"marks":43233,"value":29440,"nodeType":864},{},[],{"data":43235,"content":43236,"nodeType":860},{},[43237],{"data":43238,"marks":43239,"value":29447,"nodeType":864},{},[],{"data":43241,"content":43242,"nodeType":4581},{},[43243,43256,43265,43274],{"data":43244,"content":43245,"nodeType":4569},{},[43246],{"data":43247,"content":43248,"nodeType":860},{},[43249,43253],{"data":43250,"marks":43251,"value":29461,"nodeType":864},{},[43252],{"type":899},{"data":43254,"marks":43255,"value":29465,"nodeType":864},{},[],{"data":43257,"content":43258,"nodeType":4569},{},[43259],{"data":43260,"content":43261,"nodeType":860},{},[43262],{"data":43263,"marks":43264,"value":29475,"nodeType":864},{},[],{"data":43266,"content":43267,"nodeType":4569},{},[43268],{"data":43269,"content":43270,"nodeType":860},{},[43271],{"data":43272,"marks":43273,"value":29485,"nodeType":864},{},[],{"data":43275,"content":43276,"nodeType":4569},{},[43277],{"data":43278,"content":43279,"nodeType":860},{},[43280],{"data":43281,"marks":43282,"value":29495,"nodeType":864},{},[],{"data":43284,"content":43285,"nodeType":4581},{},[43286,43299,43308,43317],{"data":43287,"content":43288,"nodeType":4569},{},[43289],{"data":43290,"content":43291,"nodeType":860},{},[43292,43296],{"data":43293,"marks":43294,"value":29509,"nodeType":864},{},[43295],{"type":899},{"data":43297,"marks":43298,"value":29513,"nodeType":864},{},[],{"data":43300,"content":43301,"nodeType":4569},{},[43302],{"data":43303,"content":43304,"nodeType":860},{},[43305],{"data":43306,"marks":43307,"value":29523,"nodeType":864},{},[],{"data":43309,"content":43310,"nodeType":4569},{},[43311],{"data":43312,"content":43313,"nodeType":860},{},[43314],{"data":43315,"marks":43316,"value":29533,"nodeType":864},{},[],{"data":43318,"content":43319,"nodeType":4569},{},[43320],{"data":43321,"content":43322,"nodeType":860},{},[43323],{"data":43324,"marks":43325,"value":29543,"nodeType":864},{},[],{"data":43327,"content":43328,"nodeType":4581},{},[43329,43342,43351,43360],{"data":43330,"content":43331,"nodeType":4569},{},[43332],{"data":43333,"content":43334,"nodeType":860},{},[43335,43339],{"data":43336,"marks":43337,"value":29557,"nodeType":864},{},[43338],{"type":899},{"data":43340,"marks":43341,"value":29561,"nodeType":864},{},[],{"data":43343,"content":43344,"nodeType":4569},{},[43345],{"data":43346,"content":43347,"nodeType":860},{},[43348],{"data":43349,"marks":43350,"value":29420,"nodeType":864},{},[],{"data":43352,"content":43353,"nodeType":4569},{},[43354],{"data":43355,"content":43356,"nodeType":860},{},[43357],{"data":43358,"marks":43359,"value":29580,"nodeType":864},{},[],{"data":43361,"content":43362,"nodeType":4569},{},[43363],{"data":43364,"content":43365,"nodeType":860},{},[43366],{"data":43367,"marks":43368,"value":29590,"nodeType":864},{},[],{"data":43370,"content":43371,"nodeType":860},{},[43372],{"data":43373,"marks":43374,"value":21,"nodeType":864},{},[],{"items":43376},[43377,43379],{"sys":43378,"name":13779},{"id":13778},{"sys":43380,"name":342},{"id":13775},{"items":43382},[43383],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":43384},{"url":2740},{"__typename":2059,"sys":43386,"content":43387,"title":16898,"synopsis":16899,"hashTags":59,"publishedDate":16900,"slug":16901,"tagsCollection":44023,"authorsCollection":44029},{"id":16149},{"json":43388},{"data":43389,"content":43390,"nodeType":856},{},[43391,43414,43440,43446,43451,43454,43461,43467,43472,43487,43493,43500,43516,43529,43535,43541,43544,43551,43557,43563,43618,43624,43631,43641,43647,43653,43658,43665,43671,43677,43683,43689,43694,43701,43707,43778,43783,43786,43793,43799,43812,43818,43824,43829,43845,43848,43855,43861,43866,43882,43888,43894,43899,43902,43909,43915,43921,43926,43932,43937,43942,43962,43967,43977,43983,43989],{"data":43392,"content":43393,"nodeType":860},{},[43394,43397,43404,43407,43411],{"data":43395,"marks":43396,"value":16160,"nodeType":864},{},[],{"data":43398,"content":43399,"nodeType":883},{"uri":16015},[43400],{"data":43401,"marks":43402,"value":16168,"nodeType":864},{},[43403],{"type":1455},{"data":43405,"marks":43406,"value":16172,"nodeType":864},{},[],{"data":43408,"marks":43409,"value":16177,"nodeType":864},{},[43410],{"type":899},{"data":43412,"marks":43413,"value":11546,"nodeType":864},{},[],{"data":43415,"content":43416,"nodeType":860},{},[43417,43420,43427,43430,43437],{"data":43418,"marks":43419,"value":16187,"nodeType":864},{},[],{"data":43421,"content":43422,"nodeType":883},{"uri":16190},[43423],{"data":43424,"marks":43425,"value":16196,"nodeType":864},{},[43426],{"type":1455},{"data":43428,"marks":43429,"value":16200,"nodeType":864},{},[],{"data":43431,"content":43432,"nodeType":883},{"uri":16203},[43433],{"data":43434,"marks":43435,"value":16209,"nodeType":864},{},[43436],{"type":1455},{"data":43438,"marks":43439,"value":16213,"nodeType":864},{},[],{"data":43441,"content":43442,"nodeType":860},{},[43443],{"data":43444,"marks":43445,"value":16220,"nodeType":864},{},[],{"data":43447,"content":43450,"nodeType":996},{"target":43448},{"sys":43449},{"id":16225,"type":1001,"linkType":1002},[],{"data":43452,"content":43453,"nodeType":1005},{},[],{"data":43455,"content":43456,"nodeType":1009},{},[43457],{"data":43458,"marks":43459,"value":16237,"nodeType":864},{},[43460],{"type":899},{"data":43462,"content":43463,"nodeType":860},{},[43464],{"data":43465,"marks":43466,"value":16244,"nodeType":864},{},[],{"data":43468,"content":43471,"nodeType":996},{"target":43469},{"sys":43470},{"id":16249,"type":1001,"linkType":1002},[],{"data":43473,"content":43474,"nodeType":860},{},[43475,43478,43484],{"data":43476,"marks":43477,"value":16257,"nodeType":864},{},[],{"data":43479,"content":43480,"nodeType":883},{"uri":16260},[43481],{"data":43482,"marks":43483,"value":16265,"nodeType":864},{},[],{"data":43485,"marks":43486,"value":16269,"nodeType":864},{},[],{"data":43488,"content":43489,"nodeType":860},{},[43490],{"data":43491,"marks":43492,"value":16276,"nodeType":864},{},[],{"data":43494,"content":43495,"nodeType":1312},{},[43496],{"data":43497,"marks":43498,"value":16284,"nodeType":864},{},[43499],{"type":899},{"data":43501,"content":43502,"nodeType":860},{},[43503,43506,43513],{"data":43504,"marks":43505,"value":16291,"nodeType":864},{},[],{"data":43507,"content":43508,"nodeType":883},{"uri":16294},[43509],{"data":43510,"marks":43511,"value":16300,"nodeType":864},{},[43512],{"type":1455},{"data":43514,"marks":43515,"value":16304,"nodeType":864},{},[],{"data":43517,"content":43518,"nodeType":860},{},[43519,43522,43526],{"data":43520,"marks":43521,"value":16311,"nodeType":864},{},[],{"data":43523,"marks":43524,"value":16316,"nodeType":864},{},[43525],{"type":2246},{"data":43527,"marks":43528,"value":16320,"nodeType":864},{},[],{"data":43530,"content":43531,"nodeType":860},{},[43532],{"data":43533,"marks":43534,"value":16327,"nodeType":864},{},[],{"data":43536,"content":43537,"nodeType":860},{},[43538],{"data":43539,"marks":43540,"value":16334,"nodeType":864},{},[],{"data":43542,"content":43543,"nodeType":1005},{},[],{"data":43545,"content":43546,"nodeType":1009},{},[43547],{"data":43548,"marks":43549,"value":16345,"nodeType":864},{},[43550],{"type":899},{"data":43552,"content":43553,"nodeType":860},{},[43554],{"data":43555,"marks":43556,"value":16352,"nodeType":864},{},[],{"data":43558,"content":43559,"nodeType":860},{},[43560],{"data":43561,"marks":43562,"value":16359,"nodeType":864},{},[],{"data":43564,"content":43565,"nodeType":941},{},[43566,43579,43592,43605],{"data":43567,"content":43568,"nodeType":945},{},[43569],{"data":43570,"content":43571,"nodeType":860},{},[43572,43576],{"data":43573,"marks":43574,"value":16373,"nodeType":864},{},[43575],{"type":899},{"data":43577,"marks":43578,"value":16377,"nodeType":864},{},[],{"data":43580,"content":43581,"nodeType":945},{},[43582],{"data":43583,"content":43584,"nodeType":860},{},[43585,43589],{"data":43586,"marks":43587,"value":16388,"nodeType":864},{},[43588],{"type":899},{"data":43590,"marks":43591,"value":16392,"nodeType":864},{},[],{"data":43593,"content":43594,"nodeType":945},{},[43595],{"data":43596,"content":43597,"nodeType":860},{},[43598,43602],{"data":43599,"marks":43600,"value":16403,"nodeType":864},{},[43601],{"type":899},{"data":43603,"marks":43604,"value":16407,"nodeType":864},{},[],{"data":43606,"content":43607,"nodeType":945},{},[43608],{"data":43609,"content":43610,"nodeType":860},{},[43611,43615],{"data":43612,"marks":43613,"value":16418,"nodeType":864},{},[43614],{"type":899},{"data":43616,"marks":43617,"value":16422,"nodeType":864},{},[],{"data":43619,"content":43620,"nodeType":860},{},[43621],{"data":43622,"marks":43623,"value":16429,"nodeType":864},{},[],{"data":43625,"content":43626,"nodeType":1312},{},[43627],{"data":43628,"marks":43629,"value":16437,"nodeType":864},{},[43630],{"type":899},{"data":43632,"content":43633,"nodeType":860},{},[43634,43638],{"data":43635,"marks":43636,"value":16445,"nodeType":864},{},[43637],{"type":899},{"data":43639,"marks":43640,"value":16449,"nodeType":864},{},[],{"data":43642,"content":43643,"nodeType":860},{},[43644],{"data":43645,"marks":43646,"value":16456,"nodeType":864},{},[],{"data":43648,"content":43649,"nodeType":860},{},[43650],{"data":43651,"marks":43652,"value":16463,"nodeType":864},{},[],{"data":43654,"content":43657,"nodeType":996},{"target":43655},{"sys":43656},{"id":16468,"type":1001,"linkType":1002},[],{"data":43659,"content":43660,"nodeType":1312},{},[43661],{"data":43662,"marks":43663,"value":16477,"nodeType":864},{},[43664],{"type":899},{"data":43666,"content":43667,"nodeType":860},{},[43668],{"data":43669,"marks":43670,"value":16484,"nodeType":864},{},[],{"data":43672,"content":43673,"nodeType":860},{},[43674],{"data":43675,"marks":43676,"value":16491,"nodeType":864},{},[],{"data":43678,"content":43679,"nodeType":860},{},[43680],{"data":43681,"marks":43682,"value":16498,"nodeType":864},{},[],{"data":43684,"content":43685,"nodeType":860},{},[43686],{"data":43687,"marks":43688,"value":16505,"nodeType":864},{},[],{"data":43690,"content":43693,"nodeType":996},{"target":43691},{"sys":43692},{"id":16510,"type":1001,"linkType":1002},[],{"data":43695,"content":43696,"nodeType":1312},{},[43697],{"data":43698,"marks":43699,"value":16519,"nodeType":864},{},[43700],{"type":899},{"data":43702,"content":43703,"nodeType":860},{},[43704],{"data":43705,"marks":43706,"value":16526,"nodeType":864},{},[],{"data":43708,"content":43709,"nodeType":941},{},[43710,43749],{"data":43711,"content":43712,"nodeType":945},{},[43713],{"data":43714,"content":43715,"nodeType":860},{},[43716,43719,43726,43729,43736,43739,43746],{"data":43717,"marks":43718,"value":16539,"nodeType":864},{},[],{"data":43720,"content":43721,"nodeType":883},{"uri":16015},[43722],{"data":43723,"marks":43724,"value":16018,"nodeType":864},{},[43725],{"type":1455},{"data":43727,"marks":43728,"value":16550,"nodeType":864},{},[],{"data":43730,"content":43731,"nodeType":883},{"uri":16553},[43732],{"data":43733,"marks":43734,"value":16559,"nodeType":864},{},[43735],{"type":1455},{"data":43737,"marks":43738,"value":16563,"nodeType":864},{},[],{"data":43740,"content":43741,"nodeType":883},{"uri":16566},[43742],{"data":43743,"marks":43744,"value":16572,"nodeType":864},{},[43745],{"type":1455},{"data":43747,"marks":43748,"value":16576,"nodeType":864},{},[],{"data":43750,"content":43751,"nodeType":945},{},[43752],{"data":43753,"content":43754,"nodeType":860},{},[43755,43758,43765,43768,43775],{"data":43756,"marks":43757,"value":16586,"nodeType":864},{},[],{"data":43759,"content":43760,"nodeType":883},{"uri":16027},[43761],{"data":43762,"marks":43763,"value":16030,"nodeType":864},{},[43764],{"type":1455},{"data":43766,"marks":43767,"value":16597,"nodeType":864},{},[],{"data":43769,"content":43770,"nodeType":883},{"uri":16600},[43771],{"data":43772,"marks":43773,"value":16606,"nodeType":864},{},[43774],{"type":1455},{"data":43776,"marks":43777,"value":16610,"nodeType":864},{},[],{"data":43779,"content":43782,"nodeType":996},{"target":43780},{"sys":43781},{"id":16615,"type":1001,"linkType":1002},[],{"data":43784,"content":43785,"nodeType":1005},{},[],{"data":43787,"content":43788,"nodeType":1009},{},[43789],{"data":43790,"marks":43791,"value":16627,"nodeType":864},{},[43792],{"type":899},{"data":43794,"content":43795,"nodeType":860},{},[43796],{"data":43797,"marks":43798,"value":16634,"nodeType":864},{},[],{"data":43800,"content":43801,"nodeType":860},{},[43802,43805,43809],{"data":43803,"marks":43804,"value":16641,"nodeType":864},{},[],{"data":43806,"marks":43807,"value":16646,"nodeType":864},{},[43808],{"type":899},{"data":43810,"marks":43811,"value":16650,"nodeType":864},{},[],{"data":43813,"content":43814,"nodeType":860},{},[43815],{"data":43816,"marks":43817,"value":16657,"nodeType":864},{},[],{"data":43819,"content":43820,"nodeType":860},{},[43821],{"data":43822,"marks":43823,"value":16664,"nodeType":864},{},[],{"data":43825,"content":43828,"nodeType":996},{"target":43826},{"sys":43827},{"id":16669,"type":1001,"linkType":1002},[],{"data":43830,"content":43831,"nodeType":860},{},[43832,43835,43842],{"data":43833,"marks":43834,"value":16677,"nodeType":864},{},[],{"data":43836,"content":43837,"nodeType":883},{"uri":11738},[43838],{"data":43839,"marks":43840,"value":16685,"nodeType":864},{},[43841],{"type":1455},{"data":43843,"marks":43844,"value":16689,"nodeType":864},{},[],{"data":43846,"content":43847,"nodeType":1005},{},[],{"data":43849,"content":43850,"nodeType":1009},{},[43851],{"data":43852,"marks":43853,"value":2578,"nodeType":864},{},[43854],{"type":899},{"data":43856,"content":43857,"nodeType":860},{},[43858],{"data":43859,"marks":43860,"value":16706,"nodeType":864},{},[],{"data":43862,"content":43865,"nodeType":996},{"target":43863},{"sys":43864},{"id":16711,"type":1001,"linkType":1002},[],{"data":43867,"content":43868,"nodeType":860},{},[43869,43872,43879],{"data":43870,"marks":43871,"value":16719,"nodeType":864},{},[],{"data":43873,"content":43874,"nodeType":883},{"uri":11825},[43875],{"data":43876,"marks":43877,"value":16727,"nodeType":864},{},[43878],{"type":1455},{"data":43880,"marks":43881,"value":11546,"nodeType":864},{},[],{"data":43883,"content":43884,"nodeType":860},{},[43885],{"data":43886,"marks":43887,"value":16737,"nodeType":864},{},[],{"data":43889,"content":43890,"nodeType":860},{},[43891],{"data":43892,"marks":43893,"value":16744,"nodeType":864},{},[],{"data":43895,"content":43898,"nodeType":996},{"target":43896},{"sys":43897},{"id":16749,"type":1001,"linkType":1002},[],{"data":43900,"content":43901,"nodeType":1005},{},[],{"data":43903,"content":43904,"nodeType":1009},{},[43905],{"data":43906,"marks":43907,"value":7533,"nodeType":864},{},[43908],{"type":899},{"data":43910,"content":43911,"nodeType":860},{},[43912],{"data":43913,"marks":43914,"value":16767,"nodeType":864},{},[],{"data":43916,"content":43917,"nodeType":860},{},[43918],{"data":43919,"marks":43920,"value":16774,"nodeType":864},{},[],{"data":43922,"content":43925,"nodeType":996},{"target":43923},{"sys":43924},{"id":16779,"type":1001,"linkType":1002},[],{"data":43927,"content":43928,"nodeType":860},{},[43929],{"data":43930,"marks":43931,"value":16787,"nodeType":864},{},[],{"data":43933,"content":43936,"nodeType":996},{"target":43934},{"sys":43935},{"id":16792,"type":1001,"linkType":1002},[],{"data":43938,"content":43941,"nodeType":996},{"target":43939},{"sys":43940},{"id":16798,"type":1001,"linkType":1002},[],{"data":43943,"content":43944,"nodeType":860},{},[43945,43948,43952,43955,43959],{"data":43946,"marks":43947,"value":16806,"nodeType":864},{},[],{"data":43949,"marks":43950,"value":16811,"nodeType":864},{},[43951],{"type":899},{"data":43953,"marks":43954,"value":16815,"nodeType":864},{},[],{"data":43956,"marks":43957,"value":16820,"nodeType":864},{},[43958],{"type":899},{"data":43960,"marks":43961,"value":16824,"nodeType":864},{},[],{"data":43963,"content":43966,"nodeType":996},{"target":43964},{"sys":43965},{"id":16829,"type":1001,"linkType":1002},[],{"data":43968,"content":43969,"nodeType":1312},{},[43970,43973],{"data":43971,"marks":43972,"value":16837,"nodeType":864},{},[],{"data":43974,"marks":43975,"value":16842,"nodeType":864},{},[43976],{"type":899},{"data":43978,"content":43979,"nodeType":860},{},[43980],{"data":43981,"marks":43982,"value":16849,"nodeType":864},{},[],{"data":43984,"content":43985,"nodeType":860},{},[43986],{"data":43987,"marks":43988,"value":16856,"nodeType":864},{},[],{"data":43990,"content":43991,"nodeType":860},{},[43992,43995,44001,44004,44011,44014,44020],{"data":43993,"marks":43994,"value":16863,"nodeType":864},{},[],{"data":43996,"content":43997,"nodeType":883},{"uri":16866},[43998],{"data":43999,"marks":44000,"value":16871,"nodeType":864},{},[],{"data":44002,"marks":44003,"value":3731,"nodeType":864},{},[],{"data":44005,"content":44006,"nodeType":883},{"uri":16877},[44007],{"data":44008,"marks":44009,"value":16883,"nodeType":864},{},[44010],{"type":1455},{"data":44012,"marks":44013,"value":16887,"nodeType":864},{},[],{"data":44015,"content":44016,"nodeType":883},{"uri":1700},[44017],{"data":44018,"marks":44019,"value":16894,"nodeType":864},{},[],{"data":44021,"marks":44022,"value":2924,"nodeType":864},{},[],{"items":44024},[44025,44027],{"sys":44026,"name":13779},{"id":13778},{"sys":44028,"name":342},{"id":13775},{"items":44030},[44031],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":44032},{"url":2740},{"__typename":2059,"sys":44034,"content":44036,"title":44939,"synopsis":44940,"hashTags":59,"publishedDate":44941,"slug":44942,"tagsCollection":44943,"authorsCollection":44949},{"id":44035},"10hUzI9iiY8fFtmlA0M9Ne",{"json":44037},{"data":44038,"content":44039,"nodeType":856},{},[44040,44047,44053,44072,44075,44083,44090,44097,44100,44108,44115,44286,44293,44300,44303,44311,44318,44325,44332,44339,44342,44350,44369,44376,44384,44391,44536,44555,44563,44570,44705,44724,44730,44733,44741,44748,44755,44762,44765,44773,44813,44844,44851,44857,44860,44867,44874,44881,44888,44891,44899,44906],{"data":44041,"content":44042,"nodeType":860},{},[44043],{"data":44044,"marks":44045,"value":44046,"nodeType":864},{},[],"On the morning of March 11, employees at Stryker Corporation offices across 79 countries turned on their laptops and found them wiped and unusable. Personal phones enrolled in the company's BYOD program had been factory reset overnight, taking photos, banking apps, and authenticator tokens with them. Login pages had also been defaced with the logo of Handala, a persona operated by Iran's Ministry of Intelligence and Security (MOIS).",{"data":44048,"content":44052,"nodeType":996},{"target":44049},{"sys":44050},{"id":44051,"type":1001,"linkType":1002},"6JtlGFq0RDoW9g6zyAcPvn",[],{"data":44054,"content":44055,"nodeType":860},{},[44056,44060,44068],{"data":44057,"marks":44058,"value":44059,"nodeType":864},{},[],"In a break from the standard Handala playbook, there was no ransomware, no malware, and no exploit chain. The attacker ",{"data":44061,"content":44063,"nodeType":883},{"uri":44062},"https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/",[44064],{"data":44065,"marks":44066,"value":44067,"nodeType":864},{},[],"simply logged into Microsoft Intune",{"data":44069,"marks":44070,"value":44071,"nodeType":864},{},[]," with compromised Global Administrator credentials, abused a legitimate feature, and wiped over 80,000 systems, servers, and mobile devices.",{"data":44073,"content":44074,"nodeType":1005},{},[],{"data":44076,"content":44077,"nodeType":1009},{},[44078],{"data":44079,"marks":44080,"value":44082,"nodeType":864},{},[44081],{"type":899},"What a Handala attack was supposed to look like",{"data":44084,"content":44085,"nodeType":860},{},[44086],{"data":44087,"marks":44088,"value":44089,"nodeType":864},{},[],"Handala has a reputation for being a manual, hands-on intrusion team whose TTPs have typically included VPN credential brute-force for initial access (hundreds of logon attempts from commercial VPN nodes), supply chain compromise via managed service providers, RDP as the primary lateral movement method, ADRecon for Active Directory enumeration, LSASS credential dumping via comsvcs.dll, and GPO logon scripts for wiper distribution.",{"data":44091,"content":44092,"nodeType":860},{},[44093],{"data":44094,"marks":44095,"value":44096,"nodeType":864},{},[],"If you had invested in detection logic around Handala's documented toolkit (BiBi Wiper file extensions, Cl Wiper's EldoS RawDisk driver calls, No-Justice partition table manipulation, Karma Shell's Base64-with-XOR web shell patterns) none of it would have fired. Wiper malware signatures, web shell indicators, RawDisk driver loading, MBR/GPT manipulation, SharePoint exploitation patterns, anomalous RDP/SMB lateral movement: all reasonable detection priorities given the group's threat intelligence profile, but all irrelevant when it mattered most.",{"data":44098,"content":44099,"nodeType":1005},{},[],{"data":44101,"content":44102,"nodeType":1009},{},[44103],{"data":44104,"marks":44105,"value":44107,"nodeType":864},{},[44106],{"type":899},"What Handala actually did",{"data":44109,"content":44110,"nodeType":860},{},[44111],{"data":44112,"marks":44113,"value":44114,"nodeType":864},{},[],"The Stryker attack departs from the documented baseline across the kill chain.",{"data":44116,"content":44117,"nodeType":4845},{},[44118,44154,44187,44220,44253],{"data":44119,"content":44120,"nodeType":4581},{},[44121,44132,44143],{"data":44122,"content":44123,"nodeType":14464},{},[44124],{"data":44125,"content":44126,"nodeType":860},{},[44127],{"data":44128,"marks":44129,"value":44131,"nodeType":864},{},[44130],{"type":899},"Kill chain phase",{"data":44133,"content":44134,"nodeType":14464},{},[44135],{"data":44136,"content":44137,"nodeType":860},{},[44138],{"data":44139,"marks":44140,"value":44142,"nodeType":864},{},[44141],{"type":899},"Historical TTP",{"data":44144,"content":44145,"nodeType":14464},{},[44146],{"data":44147,"content":44148,"nodeType":860},{},[44149],{"data":44150,"marks":44151,"value":44153,"nodeType":864},{},[44152],{"type":899},"Stryker TTP",{"data":44155,"content":44156,"nodeType":4581},{},[44157,44167,44177],{"data":44158,"content":44159,"nodeType":4569},{},[44160],{"data":44161,"content":44162,"nodeType":860},{},[44163],{"data":44164,"marks":44165,"value":44166,"nodeType":864},{},[],"Initial access",{"data":44168,"content":44169,"nodeType":4569},{},[44170],{"data":44171,"content":44172,"nodeType":860},{},[44173],{"data":44174,"marks":44175,"value":44176,"nodeType":864},{},[],"VPN credential brute-force, supply chain compromise of managed service providers and IT vendors, spearphishing with wiper delivery, exploitation of SharePoint and Windows server vulnerabilities",{"data":44178,"content":44179,"nodeType":4569},{},[44180],{"data":44181,"content":44182,"nodeType":860},{},[44183],{"data":44184,"marks":44185,"value":44186,"nodeType":864},{},[],"Identity compromise targeting Microsoft Entra ID",{"data":44188,"content":44189,"nodeType":4581},{},[44190,44200,44210],{"data":44191,"content":44192,"nodeType":4569},{},[44193],{"data":44194,"content":44195,"nodeType":860},{},[44196],{"data":44197,"marks":44198,"value":44199,"nodeType":864},{},[],"Persistence",{"data":44201,"content":44202,"nodeType":4569},{},[44203],{"data":44204,"content":44205,"nodeType":860},{},[44206],{"data":44207,"marks":44208,"value":44209,"nodeType":864},{},[],"Web shells (Karma Shell, reGeorg)",{"data":44211,"content":44212,"nodeType":4569},{},[44213],{"data":44214,"content":44215,"nodeType":860},{},[44216],{"data":44217,"marks":44218,"value":44219,"nodeType":864},{},[],"Global Administrator access to cloud tenant, no persistence mechanism needed",{"data":44221,"content":44222,"nodeType":4581},{},[44223,44233,44243],{"data":44224,"content":44225,"nodeType":4569},{},[44226],{"data":44227,"content":44228,"nodeType":860},{},[44229],{"data":44230,"marks":44231,"value":44232,"nodeType":864},{},[],"Lateral movement",{"data":44234,"content":44235,"nodeType":4569},{},[44236],{"data":44237,"content":44238,"nodeType":860},{},[44239],{"data":44240,"marks":44241,"value":44242,"nodeType":864},{},[],"RDP, SMB, FTP, Mimikatz",{"data":44244,"content":44245,"nodeType":4569},{},[44246],{"data":44247,"content":44248,"nodeType":860},{},[44249],{"data":44250,"marks":44251,"value":44252,"nodeType":864},{},[],"None required, Intune console provides global reach from a single session",{"data":44254,"content":44255,"nodeType":4581},{},[44256,44266,44276],{"data":44257,"content":44258,"nodeType":4569},{},[44259],{"data":44260,"content":44261,"nodeType":860},{},[44262],{"data":44263,"marks":44264,"value":44265,"nodeType":864},{},[],"Impact",{"data":44267,"content":44268,"nodeType":4569},{},[44269],{"data":44270,"content":44271,"nodeType":860},{},[44272],{"data":44273,"marks":44274,"value":44275,"nodeType":864},{},[],"Custom wiper malware (BiBi, Cl Wiper, No-Justice, Hatef)",{"data":44277,"content":44278,"nodeType":4569},{},[44279],{"data":44280,"content":44281,"nodeType":860},{},[44282],{"data":44283,"marks":44284,"value":44285,"nodeType":864},{},[],"Microsoft Intune Remote Wipe, a legitimate built-in administrative feature",{"data":44287,"content":44288,"nodeType":860},{},[44289],{"data":44290,"marks":44291,"value":44292,"nodeType":864},{},[],"An organization with detections built around malware signatures, file system manipulation, and anomalous process execution would be unprepared for an attack with zero malware artifacts, where every action was a legitimate administrative command.",{"data":44294,"content":44295,"nodeType":860},{},[44296],{"data":44297,"marks":44298,"value":44299,"nodeType":864},{},[],"But while the methods were different, the core objective — mass destruction of data — is entirely consistent with previous campaigns, just through a legitimate management plane rather than custom malware.",{"data":44301,"content":44302,"nodeType":1005},{},[],{"data":44304,"content":44305,"nodeType":1009},{},[44306],{"data":44307,"marks":44308,"value":44310,"nodeType":864},{},[44309],{"type":899},"The kill chain looks different now",{"data":44312,"content":44313,"nodeType":860},{},[44314],{"data":44315,"marks":44316,"value":44317,"nodeType":864},{},[],"The attack path was devastatingly simple. It didn't require lateral movement because there was nothing to move laterally through. It didn't require privilege escalation because they directly compromised a global administrator account. Every device managed by Intune was already within reach.",{"data":44319,"content":44320,"nodeType":860},{},[44321],{"data":44322,"marks":44323,"value":44324,"nodeType":864},{},[],"The traditional network-centric kill chain collapses into: compromise identity, access management plane, execute objective.",{"data":44326,"content":44327,"nodeType":860},{},[44328],{"data":44329,"marks":44330,"value":44331,"nodeType":864},{},[],"This is not specific to Iran-aligned actors. Russian groups are leveraging AITM phishing kits and abusing Microsoft 365 OAuth tokens via consent attacks. Scattered Spider built an operational model around social engineering and SSO account takeover. And now Handala has demonstrated that a nation-state destructive operation can be executed entirely by abusing legitimate enterprise tooling.",{"data":44333,"content":44334,"nodeType":860},{},[44335],{"data":44336,"marks":44337,"value":44338,"nodeType":864},{},[],"This kind of attack is more direct, faster to execute, and carries a significantly lower barrier to entry. You don't need custom malware and exploit development when you can log in using as-a-Service kits or partner with an access brokering specialist.",{"data":44340,"content":44341,"nodeType":1005},{},[],{"data":44343,"content":44344,"nodeType":1009},{},[44345],{"data":44346,"marks":44347,"value":44349,"nodeType":864},{},[44348],{"type":899},"The big picture of Iranian cyber TTPs",{"data":44351,"content":44352,"nodeType":860},{},[44353,44357,44365],{"data":44354,"marks":44355,"value":44356,"nodeType":864},{},[],"Iran's offensive cyber capability is split between two rival intelligence bureaucracies. The Ministry of Intelligence and Security (MOIS) runs groups like APT34, MuddyWater, Scarred Manticore, and Void Manticore (Handala), which tend toward long-dwell espionage and coordinated destructive operations, often using a ",{"data":44358,"content":44360,"nodeType":883},{"uri":44359},"https://research.checkpoint.com/2024/bad-karma-no-justice-void-manticore-destructive-activities-in-israel/",[44361],{"data":44362,"marks":44363,"value":44364,"nodeType":864},{},[],"documented dual-actor handoff model",{"data":44366,"marks":44367,"value":44368,"nodeType":864},{},[]," where Scarred Manticore conducts stealthy espionage before handing targets to Void Manticore (Handala) for destruction.",{"data":44370,"content":44371,"nodeType":860},{},[44372],{"data":44373,"marks":44374,"value":44375,"nodeType":864},{},[],"The Islamic Revolutionary Guard Corps (IRGC) runs a wider set of groups, including APT33/Peach Sandstorm, APT35/Charming Kitten, APT42, Tortoiseshell/Imperial Kitten, Cotton Sandstorm, and CyberAv3ngers. IRGC groups cover espionage, destructive attacks, influence operations, election interference, ICS targeting across U.S. water and wastewater facilities), and individual surveillance.",{"data":44377,"content":44378,"nodeType":1312},{},[44379],{"data":44380,"marks":44381,"value":44383,"nodeType":864},{},[44382],{"type":899},"IRGC groups have already shifted to identity-first TTPs",{"data":44385,"content":44386,"nodeType":860},{},[44387],{"data":44388,"marks":44389,"value":44390,"nodeType":864},{},[],"On the IRGC side, the shift toward identity-centric operations is well-documented:",{"data":44392,"content":44393,"nodeType":941},{},[44394,44445,44483,44510],{"data":44395,"content":44396,"nodeType":945},{},[44397],{"data":44398,"content":44399,"nodeType":860},{},[44400,44405,44409,44417,44421,44429,44433,44441],{"data":44401,"marks":44402,"value":44404,"nodeType":864},{},[44403],{"type":899},"APT33/Peach Sandstorm",{"data":44406,"marks":44407,"value":44408,"nodeType":864},{},[]," shifted decisively toward credential-based initial access starting in early 2023, with Microsoft ",{"data":44410,"content":44412,"nodeType":883},{"uri":44411},"https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/",[44413],{"data":44414,"marks":44415,"value":44416,"nodeType":864},{},[],"documenting",{"data":44418,"marks":44419,"value":44420,"nodeType":864},{},[]," large-scale password spray campaigns targeting thousands of organizations, ",{"data":44422,"content":44424,"nodeType":883},{"uri":44423},"https://www.bleepingcomputer.com/news/security/iranian-hackers-breach-defense-orgs-in-password-spray-attacks/",[44425],{"data":44426,"marks":44427,"value":44428,"nodeType":864},{},[],"Golden SAML",{"data":44430,"marks":44431,"value":44432,"nodeType":864},{},[]," attacks for persistent cloud access, and the use of ",{"data":44434,"content":44436,"nodeType":883},{"uri":44435},"https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/",[44437],{"data":44438,"marks":44439,"value":44440,"nodeType":864},{},[],"fraudulent Azure subscriptions",{"data":44442,"marks":44443,"value":44444,"nodeType":864},{},[]," for C2 infrastructure.",{"data":44446,"content":44447,"nodeType":945},{},[44448],{"data":44449,"content":44450,"nodeType":860},{},[44451,44456,44459,44467,44471,44479],{"data":44452,"marks":44453,"value":44455,"nodeType":864},{},[44454],{"type":899},"APT42",{"data":44457,"marks":44458,"value":3731,"nodeType":864},{},[],{"data":44460,"content":44462,"nodeType":883},{"uri":44461},"https://cloud.google.com/blog/topics/threat-intelligence/untangling-iran-apt42-operations",[44463],{"data":44464,"marks":44465,"value":44466,"nodeType":864},{},[],"assessed by Mandiant to operate on behalf of the IRGC-IO, ",{"data":44468,"marks":44469,"value":44470,"nodeType":864},{},[],"has made credential harvesting and MFA bypass its core competency, operating almost entirely within cloud environments post-compromise and ",{"data":44472,"content":44474,"nodeType":883},{"uri":44473},"https://cloud.google.com/blog/topics/threat-intelligence/apt42-charms-cons-compromises",[44475],{"data":44476,"marks":44477,"value":44478,"nodeType":864},{},[],"registering its own Microsoft Authenticator",{"data":44480,"marks":44481,"value":44482,"nodeType":864},{},[]," on compromised accounts for persistent access.",{"data":44484,"content":44485,"nodeType":945},{},[44486],{"data":44487,"content":44488,"nodeType":860},{},[44489,44494,44498,44506],{"data":44490,"marks":44491,"value":44493,"nodeType":864},{},[44492],{"type":899},"APT35",{"data":44495,"marks":44496,"value":44497,"nodeType":864},{},[]," (aka Imperial Kitten/Tortoiseshell) was observed ",{"data":44499,"content":44501,"nodeType":883},{"uri":44500},"https://www.crowdstrike.com/explore/2026-global-threat-report?utm_medium=org",[44502],{"data":44503,"marks":44504,"value":44505,"nodeType":864},{},[],"targeting cloud identities in November 2025",{"data":44507,"marks":44508,"value":44509,"nodeType":864},{},[],", deploying the Evilginx2 AitM toolkit against Microsoft 365 users in Israel.",{"data":44511,"content":44512,"nodeType":945},{},[44513],{"data":44514,"content":44515,"nodeType":860},{},[44516,44521,44525,44532],{"data":44517,"marks":44518,"value":44520,"nodeType":864},{},[44519],{"type":899},"CrustyKrill",{"data":44522,"marks":44523,"value":44524,"nodeType":864},{},[]," (TA455/Smoke Sandstorm) ",{"data":44526,"content":44527,"nodeType":883},{"uri":44500},[44528],{"data":44529,"marks":44530,"value":44531,"nodeType":864},{},[],"uses fake Google Meet and Microsoft Teams pages",{"data":44533,"marks":44534,"value":44535,"nodeType":864},{},[]," with a live operator intercepting 2FA codes in real time, alongside Azure Web Apps for C2.",{"data":44537,"content":44538,"nodeType":860},{},[44539,44543,44551],{"data":44540,"marks":44541,"value":44542,"nodeType":864},{},[],"A ",{"data":44544,"content":44546,"nodeType":883},{"uri":44545},"https://media.defense.gov/2024/Oct/16/2003565317/-1/-1/0/CSA-IRAN-CYBER-BRUTE-FORCE-CRITICAL-INFRASTRUCTURE-ORGS.PDF",[44547],{"data":44548,"marks":44549,"value":44550,"nodeType":864},{},[],"joint advisory from six nations",{"data":44552,"marks":44553,"value":44554,"nodeType":864},{},[]," (FBI, CISA, NSA, CSE, AFP, ASD, advisory AA24-290A, October 2024) confirmed the pattern at the government level, documenting Iranian actors using brute force, password spraying, and MFA push bombing to compromise critical infrastructure accounts since October 2023, and assessing that the actors sell this access on cybercriminal forums.",{"data":44556,"content":44557,"nodeType":1312},{},[44558],{"data":44559,"marks":44560,"value":44562,"nodeType":864},{},[44561],{"type":899},"MOIS groups are changing their approach too",{"data":44564,"content":44565,"nodeType":860},{},[44566],{"data":44567,"marks":44568,"value":44569,"nodeType":864},{},[],"On the MOIS side, the documented TTP baseline has historically centred on custom malware, network-level persistence, and exploitation of on-premises infrastructure. But identity compromise, particularly credential theft, has been a consistent thread across broader MOIS groups too:",{"data":44571,"content":44572,"nodeType":941},{},[44573,44612,44639,44690],{"data":44574,"content":44575,"nodeType":945},{},[44576],{"data":44577,"content":44578,"nodeType":860},{},[44579,44584,44588,44596,44600,44608],{"data":44580,"marks":44581,"value":44583,"nodeType":864},{},[44582],{"type":899},"APT34 (OilRig) ",{"data":44585,"marks":44586,"value":44587,"nodeType":864},{},[],"built its reputation on DNS tunnelling and custom backdoors, but its initial access methods include spearphishing and fake VPN portals for credential harvesting. Its 2024 campaigns introduced ",{"data":44589,"content":44591,"nodeType":883},{"uri":44590},"https://www.trendmicro.com/en_us/research/24/j/earth-simnavaz-cyberattacks.html",[44592],{"data":44593,"marks":44594,"value":44595,"nodeType":864},{},[],"password filter DLLs",{"data":44597,"marks":44598,"value":44599,"nodeType":864},{},[]," registered at the domain controller level to intercept plaintext credentials during password change events, with the ",{"data":44601,"content":44603,"nodeType":883},{"uri":44602},"https://www.bleepingcomputer.com/news/security/oilrig-hackers-now-exploit-windows-flaw-to-elevate-privileges/",[44604],{"data":44605,"marks":44606,"value":44607,"nodeType":864},{},[],"STEALHOOK backdoor",{"data":44609,"marks":44610,"value":44611,"nodeType":864},{},[]," exfiltrating stolen domain credentials via compromised Exchange servers. Cloud-based downloaders leveraging OneDrive and Microsoft Graph API were active against Israeli targets from 2022 to 2024.",{"data":44613,"content":44614,"nodeType":945},{},[44615],{"data":44616,"content":44617,"nodeType":860},{},[44618,44623,44627,44635],{"data":44619,"marks":44620,"value":44622,"nodeType":864},{},[44621],{"type":899},"APT39 (Chafer) ",{"data":44624,"marks":44625,"value":44626,"nodeType":864},{},[],"operated through the ",{"data":44628,"content":44630,"nodeType":883},{"uri":44629},"https://home.treasury.gov/news/press-releases/sm1127",[44631],{"data":44632,"marks":44633,"value":44634,"nodeType":864},{},[],"sanctioned front company Rana Intelligence Computing",{"data":44636,"marks":44637,"value":44638,"nodeType":864},{},[],", focuses on surveillance and tracking of individuals, using credential harvesting through spoofed airline and telecom domains across 30+ countries.",{"data":44640,"content":44641,"nodeType":945},{},[44642],{"data":44643,"content":44644,"nodeType":860},{},[44645,44650,44654,44662,44666,44674,44678,44686],{"data":44646,"marks":44647,"value":44649,"nodeType":864},{},[44648],{"type":899},"MuddyWater",{"data":44651,"marks":44652,"value":44653,"nodeType":864},{},[],", confirmed by a ",{"data":44655,"content":44657,"nodeType":883},{"uri":44656},"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a",[44658],{"data":44659,"marks":44660,"value":44661,"nodeType":864},{},[],"joint CISA/FBI/NSA/NCSC advisory",{"data":44663,"marks":44664,"value":44665,"nodeType":864},{},[]," as a subordinate element of MOIS, functions as an initial access broker within the ecosystem. Its operations rely on spearphishing and abuse of legitimate RMM tools, but the group has developed ",{"data":44667,"content":44669,"nodeType":883},{"uri":44668},"https://thehackernews.com/2025/12/iran-linked-hackers-hits-israeli_2.html",[44670],{"data":44671,"marks":44672,"value":44673,"nodeType":864},{},[],"dedicated credential stealers",{"data":44675,"marks":44676,"value":44677,"nodeType":864},{},[]," including CE-Notes (which bypasses Chrome's app-bound encryption), Blub (a multi-browser credential extractor), and LP-Notes (fake Windows Security dialogs to capture system credentials). A parallel campaign documented by ",{"data":44679,"content":44681,"nodeType":883},{"uri":44680},"https://www.group-ib.com/blog/muddywater-espionage/",[44682],{"data":44683,"marks":44684,"value":44685,"nodeType":864},{},[],"Group-IB",{"data":44687,"marks":44688,"value":44689,"nodeType":864},{},[]," found the group deploying a custom Chromium credential stealer alongside its Phoenix backdoor.",{"data":44691,"content":44692,"nodeType":945},{},[44693],{"data":44694,"content":44695,"nodeType":860},{},[44696,44701],{"data":44697,"marks":44698,"value":44700,"nodeType":864},{},[44699],{"type":899},"Lyceum (Hexane)",{"data":44702,"marks":44703,"value":44704,"nodeType":864},{},[]," overlaps operationally with APT34 and uses password spraying and brute-force attacks for initial access, and notably probed Albanian government infrastructure ahead of Handala destructive attacks in 2022, illustrating the collaborative model across MOIS groups.",{"data":44706,"content":44707,"nodeType":860},{},[44708,44712,44720],{"data":44709,"marks":44710,"value":44711,"nodeType":864},{},[],"Check Point has also ",{"data":44713,"content":44715,"nodeType":883},{"uri":44714},"https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connection/",[44716],{"data":44717,"marks":44718,"value":44719,"nodeType":864},{},[],"documented",{"data":44721,"marks":44722,"value":44723,"nodeType":864},{},[]," a broader pattern of MOIS actors engaging directly with the criminal ecosystem, including Handala's adoption of the Rhadamanthys commercial infostealer and Iranian-affiliated operators working through the Qilin ransomware-as-a-service infrastructure.",{"data":44725,"content":44729,"nodeType":996},{"target":44726},{"sys":44727},{"id":44728,"type":1001,"linkType":1002},"2SFtROFuPZ4SPTL87Vpjr9",[],{"data":44731,"content":44732,"nodeType":1005},{},[],{"data":44734,"content":44735,"nodeType":1009},{},[44736],{"data":44737,"marks":44738,"value":44740,"nodeType":864},{},[44739],{"type":899},"The problem with over-indexing on TTPs",{"data":44742,"content":44743,"nodeType":860},{},[44744],{"data":44745,"marks":44746,"value":44747,"nodeType":864},{},[],"Threat intelligence has real value. Attributing campaigns to named groups, mapping their techniques to MITRE ATT&CK, and generating detection rules gives defenders a meaningful starting point. The problem is treating a specific actor's historical TTP catalogue as the primary basis for detection logic, rather than combining it with the broader trends in attacker behaviour visible across the entire landscape.",{"data":44749,"content":44750,"nodeType":860},{},[44751],{"data":44752,"marks":44753,"value":44754,"nodeType":864},{},[],"Operators are creative and pragmatic. If the path of least resistance is a compromised admin credential and a legitimate MDM feature, no serious attacker is going to deploy custom wiper malware instead because that's what they used last time.",{"data":44756,"content":44757,"nodeType":860},{},[44758],{"data":44759,"marks":44760,"value":44761,"nodeType":864},{},[],"If your threat model says you're a plausible target for an Iranian threat group, and the trend data tells you that identity compromise is the most common initial access method across all actors, the rational response is to evaluate your controls aligned to identity-based initial access, not just deploy signatures for BiBi Wiper. When the specific actor profile crowds out the general trend data, you end up building defences against the last attack and leaving yourself exposed to the shift that every actor is going through.",{"data":44763,"content":44764,"nodeType":1005},{},[],{"data":44766,"content":44767,"nodeType":1009},{},[44768],{"data":44769,"marks":44770,"value":44772,"nodeType":864},{},[44771],{"type":899},"Evaluating the security guidance",{"data":44774,"content":44775,"nodeType":860},{},[44776,44780,44788,44792,44800,44804,44809],{"data":44777,"marks":44778,"value":44779,"nodeType":864},{},[],"In the wake of the breach, industry guidance has settled around enforcing phishing-resistant MFA on privileged accounts, implementing just-in-time privilege activation via ",{"data":44781,"content":44783,"nodeType":883},{"uri":44782},"https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure",[44784],{"data":44785,"marks":44786,"value":44787,"nodeType":864},{},[],"PIM",{"data":44789,"marks":44790,"value":44791,"nodeType":864},{},[],", enabling ",{"data":44793,"content":44795,"nodeType":883},{"uri":44794},"https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval",[44796],{"data":44797,"marks":44798,"value":44799,"nodeType":864},{},[],"Multi Admin Approval ",{"data":44801,"marks":44802,"value":44803,"nodeType":864},{},[],"for high-risk Intune operations, configuring anomaly alerting on bulk device actions, and segregating administrative identities from everyday user accounts. This is all sound advice, but these recommendations are designed to limit what an attacker can do ",{"data":44805,"marks":44806,"value":44808,"nodeType":864},{},[44807],{"type":2246},"after",{"data":44810,"marks":44811,"value":44812,"nodeType":864},{},[]," an account has already been compromised — introducing friction, but not blocking them entirely.",{"data":44814,"content":44815,"nodeType":860},{},[44816,44820,44828,44832,44840],{"data":44817,"marks":44818,"value":44819,"nodeType":864},{},[],"The detection challenges compound this. Entra ID sign-in logs and ",{"data":44821,"content":44823,"nodeType":883},{"uri":44822},"https://www.a6n.co.uk/2025/11/tracking-device-wipes-in-microsoft.html",[44824],{"data":44825,"marks":44826,"value":44827,"nodeType":864},{},[],"Intune audit logs exist in separate systems",{"data":44829,"marks":44830,"value":44831,"nodeType":864},{},[]," with separate correlation IDs. Tracing a sign-in to a subsequent device action requires deliberate log integration that many organizations haven't implemented. The ",{"data":44833,"content":44835,"nodeType":883},{"uri":44834},"https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/monitor-audit-logs",[44836],{"data":44837,"marks":44838,"value":44839,"nodeType":864},{},[],"logs do record",{"data":44841,"marks":44842,"value":44843,"nodeType":864},{},[]," \"wipe ManagedDevice\" events, but may not be linked to real-time alerting. And the underlying action, Intune's Remote Wipe, is a legitimate feature used routinely in enterprise IT. Again, the attack could have succeeded even with these in place.",{"data":44845,"content":44846,"nodeType":860},{},[44847],{"data":44848,"marks":44849,"value":44850,"nodeType":864},{},[],"In a world where a compromised account can be rapidly exploited, it's vital to focus on improving detection and prevention as early as possible in the kill chain — combating initial access techniques themselves.",{"data":44852,"content":44856,"nodeType":996},{"target":44853},{"sys":44854},{"id":44855,"type":1001,"linkType":1002},"4H3AzW7q4QBv7pJawSqQBJ",[],{"data":44858,"content":44859,"nodeType":1005},{},[],{"data":44861,"content":44862,"nodeType":1009},{},[44863],{"data":44864,"marks":44865,"value":29267,"nodeType":864},{},[44866],{"type":899},{"data":44868,"content":44869,"nodeType":860},{},[44870],{"data":44871,"marks":44872,"value":44873,"nodeType":864},{},[],"The Stryker attack reflects what attackers everywhere — from financially motivated criminal groups to more destructive nation-state operators — are already doing. Identity-based initial access, abuse of legitimate tools and services, and living-off-the-land execution are the current standard operating procedure.",{"data":44875,"content":44876,"nodeType":860},{},[44877],{"data":44878,"marks":44879,"value":44880,"nodeType":864},{},[],"Even with a perfectly hardened environment, most public breaches today involve attackers hijacking SSO mechanisms to move into connected applications, exfiltrating data for resale or extortion, and in some cases leveraging cloud services and admin platforms to deploy ransomware (the Scattered Spider playbook of dropping ransomware via VMware management portal being a well-documented example).",{"data":44882,"content":44883,"nodeType":860},{},[44884],{"data":44885,"marks":44886,"value":44887,"nodeType":864},{},[],"The majority of attackers will have no interest in destructively wiping an Intune environment — that's difficult to monetize. But the techniques that enabled the Stryker wipe are the same as those that enable financially motivated breaches at scale, pointing to a challenge that extends well beyond Iran-nexus threat actors and MDM hardening.",{"data":44889,"content":44890,"nodeType":1005},{},[],{"data":44892,"content":44893,"nodeType":1009},{},[44894],{"data":44895,"marks":44896,"value":44898,"nodeType":864},{},[44897],{"type":899},"About Push Security",{"data":44900,"content":44901,"nodeType":860},{},[44902],{"data":44903,"marks":44904,"value":44905,"nodeType":864},{},[],"Push Security's browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":44907,"content":44908,"nodeType":860},{},[44909,44912,44918,44921,44927,44930,44936],{"data":44910,"marks":44911,"value":16863,"nodeType":864},{},[],{"data":44913,"content":44914,"nodeType":883},{"uri":16866},[44915],{"data":44916,"marks":44917,"value":16871,"nodeType":864},{},[],{"data":44919,"marks":44920,"value":3731,"nodeType":864},{},[],{"data":44922,"content":44923,"nodeType":883},{"uri":16877},[44924],{"data":44925,"marks":44926,"value":16883,"nodeType":864},{},[],{"data":44928,"marks":44929,"value":16887,"nodeType":864},{},[],{"data":44931,"content":44932,"nodeType":883},{"uri":1700},[44933],{"data":44934,"marks":44935,"value":16894,"nodeType":864},{},[],{"data":44937,"marks":44938,"value":2924,"nodeType":864},{},[],"The Stryker breach didn't match the playbook. That shouldn't be a surprise.","Analysing the Stryker breach in line with recent changes to the Iran-nexus cyber playbook.","2026-03-19T00:00:00.000Z","stryker-handala-report",{"items":44944},[44945,44947],{"sys":44946,"name":13779},{"id":13778},{"sys":44948,"name":342},{"id":13775},{"items":44950},[44951],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":44952},{"url":2740},"blog/the-cisos-data-problem-and-how-browser-telemetry-can-help",{"json":44955},{"data":44956,"content":44957,"nodeType":856},{},[44958],{"data":44959,"content":44960,"nodeType":860},{},[44961],{"data":44962,"marks":44963,"value":44964,"nodeType":864},{},[],"For most security teams, quantifying cyber risk means borrowing someone else's numbers. For the identity attack surface that now dominates modern attack campaigns, high-fidelity browser telemetry changes that.",{"id":29612,"publishedAt":44966},"2026-08-12T11:52:56.247Z",{"items":44968},[44969,44971],{"sys":44970,"name":2729},{"id":2728},{"sys":44972,"name":342},{"id":13775},{"items":44974},[44975,44977,44979,44981,44983,44985,44987,44989,44991,44993,44995,44997,44999,45001,45003,45005,45007,45009,45011,45013,45015,45017,45019],{"sys":44976,"name":297,"slug":298,"tier":31},{"id":294},{"sys":44978,"name":413,"slug":414,"tier":31},{"id":410},{"sys":44980,"name":279,"slug":280,"tier":31},{"id":276},{"sys":44982,"name":519,"slug":520,"tier":31},{"id":516},{"sys":44984,"name":235,"slug":236,"tier":31},{"id":232},{"sys":44986,"name":342,"slug":343,"tier":31},{"id":339},{"sys":44988,"name":580,"slug":581,"tier":45},{"id":577},{"sys":44990,"name":484,"slug":485,"tier":45},{"id":481},{"sys":44992,"name":315,"slug":316,"tier":45},{"id":312},{"sys":44994,"name":502,"slug":503,"tier":45},{"id":499},{"sys":44996,"name":457,"slug":458,"tier":45},{"id":454},{"sys":44998,"name":395,"slug":396,"tier":45},{"id":392},{"sys":45000,"name":288,"slug":289,"tier":45},{"id":285},{"sys":45002,"name":324,"slug":325,"tier":45},{"id":321},{"sys":45004,"name":360,"slug":361,"tier":45},{"id":357},{"sys":45006,"name":475,"slug":476,"tier":45},{"id":472},{"sys":45008,"name":440,"slug":441,"tier":45},{"id":437},{"sys":45010,"name":261,"slug":262,"tier":45},{"id":258},{"sys":45012,"name":571,"slug":572,"tier":45},{"id":568},{"sys":45014,"name":589,"slug":590,"tier":45},{"id":586},{"sys":45016,"name":633,"slug":634,"tier":45},{"id":630},{"sys":45018,"name":528,"slug":529,"tier":45},{"id":525},{"sys":45020,"name":422,"slug":423,"tier":45},{"id":419},"0uIXQfHGqG5ggB63oTQMHHDsYjEefxJ1h3UuxIYOezk",{"id":45023,"title":24223,"authorsCollection":45024,"content":45029,"extension":228,"faqItemsCollection":45761,"faqTitle":59,"featured":19,"hashTags":59,"meta":45763,"metaTitle":45764,"ogImage":59,"postType":5726,"publishedDate":24225,"relatedBlogPostsCollection":45765,"slug":24226,"stem":49163,"subtitle":59,"summary":49164,"synopsis":24224,"sys":49175,"tagsCollection":49177,"topicsCollection":49183,"__hash__":49217},"blog/blog/introducing-the-browser-and-identity-attacks-matrix.json",{"items":45025},[45026],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":45027,"profilePicture":45028},[15231],{"url":2740},{"json":45030,"links":45738},{"data":45031,"content":45032,"nodeType":856},{},[45033,45048,45063,45078,45083,45086,45093,45099,45105,45111,45117,45124,45127,45134,45140,45146,45152,45157,45164,45179,45185,45191,45204,45211,45235,45248,45254,45278,45285,45309,45315,45322,45337,45343,45349,45354,45360,45367,45382,45388,45404,45410,45413,45420,45426,45501,45507,45520,45523,45548,45563,45569,45575,45578,45585,45600,45606,45612,45627,45630,45637,45643,45673,45679,45694,45709,45714,45717,45723],{"data":45034,"content":45035,"nodeType":860},{},[45036,45039,45045],{"data":45037,"marks":45038,"value":23408,"nodeType":864},{},[],{"data":45040,"content":45041,"nodeType":883},{"uri":23411},[45042],{"data":45043,"marks":45044,"value":23416,"nodeType":864},{},[],{"data":45046,"marks":45047,"value":23420,"nodeType":864},{},[],{"data":45049,"content":45050,"nodeType":860},{},[45051,45054,45060],{"data":45052,"marks":45053,"value":23427,"nodeType":864},{},[],{"data":45055,"content":45056,"nodeType":883},{"uri":23430},[45057],{"data":45058,"marks":45059,"value":23435,"nodeType":864},{},[],{"data":45061,"marks":45062,"value":23439,"nodeType":864},{},[],{"data":45064,"content":45065,"nodeType":860},{},[45066,45069,45075],{"data":45067,"marks":45068,"value":23446,"nodeType":864},{},[],{"data":45070,"content":45071,"nodeType":883},{"uri":11562},[45072],{"data":45073,"marks":45074,"value":11754,"nodeType":864},{},[],{"data":45076,"marks":45077,"value":23456,"nodeType":864},{},[],{"data":45079,"content":45082,"nodeType":996},{"target":45080},{"sys":45081},{"id":23461,"type":1001,"linkType":1002},[],{"data":45084,"content":45085,"nodeType":1005},{},[],{"data":45087,"content":45088,"nodeType":1009},{},[45089],{"data":45090,"marks":45091,"value":23473,"nodeType":864},{},[45092],{"type":899},{"data":45094,"content":45095,"nodeType":860},{},[45096],{"data":45097,"marks":45098,"value":23480,"nodeType":864},{},[],{"data":45100,"content":45101,"nodeType":860},{},[45102],{"data":45103,"marks":45104,"value":23487,"nodeType":864},{},[],{"data":45106,"content":45107,"nodeType":860},{},[45108],{"data":45109,"marks":45110,"value":23494,"nodeType":864},{},[],{"data":45112,"content":45113,"nodeType":860},{},[45114],{"data":45115,"marks":45116,"value":23501,"nodeType":864},{},[],{"data":45118,"content":45119,"nodeType":860},{},[45120],{"data":45121,"marks":45122,"value":23509,"nodeType":864},{},[45123],{"type":899},{"data":45125,"content":45126,"nodeType":1005},{},[],{"data":45128,"content":45129,"nodeType":1009},{},[45130],{"data":45131,"marks":45132,"value":23520,"nodeType":864},{},[45133],{"type":899},{"data":45135,"content":45136,"nodeType":860},{},[45137],{"data":45138,"marks":45139,"value":23527,"nodeType":864},{},[],{"data":45141,"content":45142,"nodeType":860},{},[45143],{"data":45144,"marks":45145,"value":23534,"nodeType":864},{},[],{"data":45147,"content":45148,"nodeType":860},{},[45149],{"data":45150,"marks":45151,"value":23541,"nodeType":864},{},[],{"data":45153,"content":45156,"nodeType":996},{"target":45154},{"sys":45155},{"id":23546,"type":1001,"linkType":1002},[],{"data":45158,"content":45159,"nodeType":1312},{},[45160],{"data":45161,"marks":45162,"value":23555,"nodeType":864},{},[45163],{"type":899},{"data":45165,"content":45166,"nodeType":860},{},[45167,45170,45176],{"data":45168,"marks":45169,"value":23562,"nodeType":864},{},[],{"data":45171,"content":45172,"nodeType":883},{"uri":18939},[45173],{"data":45174,"marks":45175,"value":23569,"nodeType":864},{},[],{"data":45177,"marks":45178,"value":23573,"nodeType":864},{},[],{"data":45180,"content":45181,"nodeType":860},{},[45182],{"data":45183,"marks":45184,"value":23580,"nodeType":864},{},[],{"data":45186,"content":45187,"nodeType":860},{},[45188],{"data":45189,"marks":45190,"value":23587,"nodeType":864},{},[],{"data":45192,"content":45193,"nodeType":860},{},[45194,45197,45201],{"data":45195,"marks":45196,"value":23594,"nodeType":864},{},[],{"data":45198,"marks":45199,"value":23599,"nodeType":864},{},[45200],{"type":899},{"data":45202,"marks":45203,"value":23603,"nodeType":864},{},[],{"data":45205,"content":45206,"nodeType":1312},{},[45207],{"data":45208,"marks":45209,"value":23611,"nodeType":864},{},[45210],{"type":899},{"data":45212,"content":45213,"nodeType":860},{},[45214,45217,45223,45226,45232],{"data":45215,"marks":45216,"value":23618,"nodeType":864},{},[],{"data":45218,"content":45219,"nodeType":883},{"uri":13427},[45220],{"data":45221,"marks":45222,"value":23625,"nodeType":864},{},[],{"data":45224,"marks":45225,"value":23629,"nodeType":864},{},[],{"data":45227,"content":45228,"nodeType":883},{"uri":3237},[45229],{"data":45230,"marks":45231,"value":23636,"nodeType":864},{},[],{"data":45233,"marks":45234,"value":23640,"nodeType":864},{},[],{"data":45236,"content":45237,"nodeType":860},{},[45238,45241,45245],{"data":45239,"marks":45240,"value":23647,"nodeType":864},{},[],{"data":45242,"marks":45243,"value":23652,"nodeType":864},{},[45244],{"type":899},{"data":45246,"marks":45247,"value":23656,"nodeType":864},{},[],{"data":45249,"content":45250,"nodeType":860},{},[45251],{"data":45252,"marks":45253,"value":23663,"nodeType":864},{},[],{"data":45255,"content":45256,"nodeType":860},{},[45257,45260,45266,45269,45275],{"data":45258,"marks":45259,"value":23670,"nodeType":864},{},[],{"data":45261,"content":45262,"nodeType":883},{"uri":11738},[45263],{"data":45264,"marks":45265,"value":19059,"nodeType":864},{},[],{"data":45267,"marks":45268,"value":23680,"nodeType":864},{},[],{"data":45270,"content":45271,"nodeType":883},{"uri":11726},[45272],{"data":45273,"marks":45274,"value":11731,"nodeType":864},{},[],{"data":45276,"marks":45277,"value":23690,"nodeType":864},{},[],{"data":45279,"content":45280,"nodeType":1312},{},[45281],{"data":45282,"marks":45283,"value":23698,"nodeType":864},{},[45284],{"type":899},{"data":45286,"content":45287,"nodeType":860},{},[45288,45291,45297,45300,45306],{"data":45289,"marks":45290,"value":23705,"nodeType":864},{},[],{"data":45292,"content":45293,"nodeType":883},{"uri":23708},[45294],{"data":45295,"marks":45296,"value":23713,"nodeType":864},{},[],{"data":45298,"marks":45299,"value":23717,"nodeType":864},{},[],{"data":45301,"content":45302,"nodeType":883},{"uri":6940},[45303],{"data":45304,"marks":45305,"value":23724,"nodeType":864},{},[],{"data":45307,"marks":45308,"value":23728,"nodeType":864},{},[],{"data":45310,"content":45311,"nodeType":860},{},[45312],{"data":45313,"marks":45314,"value":23735,"nodeType":864},{},[],{"data":45316,"content":45317,"nodeType":1312},{},[45318],{"data":45319,"marks":45320,"value":23743,"nodeType":864},{},[45321],{"type":899},{"data":45323,"content":45324,"nodeType":860},{},[45325,45328,45334],{"data":45326,"marks":45327,"value":23750,"nodeType":864},{},[],{"data":45329,"content":45330,"nodeType":883},{"uri":3259},[45331],{"data":45332,"marks":45333,"value":23757,"nodeType":864},{},[],{"data":45335,"marks":45336,"value":23761,"nodeType":864},{},[],{"data":45338,"content":45339,"nodeType":860},{},[45340],{"data":45341,"marks":45342,"value":23768,"nodeType":864},{},[],{"data":45344,"content":45345,"nodeType":860},{},[45346],{"data":45347,"marks":45348,"value":23775,"nodeType":864},{},[],{"data":45350,"content":45353,"nodeType":996},{"target":45351},{"sys":45352},{"id":23780,"type":1001,"linkType":1002},[],{"data":45355,"content":45356,"nodeType":860},{},[45357],{"data":45358,"marks":45359,"value":23788,"nodeType":864},{},[],{"data":45361,"content":45362,"nodeType":1312},{},[45363],{"data":45364,"marks":45365,"value":23796,"nodeType":864},{},[45366],{"type":899},{"data":45368,"content":45369,"nodeType":860},{},[45370,45373,45379],{"data":45371,"marks":45372,"value":23803,"nodeType":864},{},[],{"data":45374,"content":45375,"nodeType":883},{"uri":2411},[45376],{"data":45377,"marks":45378,"value":23810,"nodeType":864},{},[],{"data":45380,"marks":45381,"value":23814,"nodeType":864},{},[],{"data":45383,"content":45384,"nodeType":860},{},[45385],{"data":45386,"marks":45387,"value":23821,"nodeType":864},{},[],{"data":45389,"content":45390,"nodeType":860},{},[45391,45394,45401],{"data":45392,"marks":45393,"value":23828,"nodeType":864},{},[],{"data":45395,"content":45396,"nodeType":883},{"uri":2411},[45397],{"data":45398,"marks":45399,"value":23836,"nodeType":864},{},[45400],{"type":1455},{"data":45402,"marks":45403,"value":23840,"nodeType":864},{},[],{"data":45405,"content":45406,"nodeType":860},{},[45407],{"data":45408,"marks":45409,"value":23847,"nodeType":864},{},[],{"data":45411,"content":45412,"nodeType":1005},{},[],{"data":45414,"content":45415,"nodeType":1009},{},[45416],{"data":45417,"marks":45418,"value":23858,"nodeType":864},{},[45419],{"type":899},{"data":45421,"content":45422,"nodeType":860},{},[45423],{"data":45424,"marks":45425,"value":23865,"nodeType":864},{},[],{"data":45427,"content":45428,"nodeType":941},{},[45429,45447,45465,45483],{"data":45430,"content":45431,"nodeType":945},{},[45432],{"data":45433,"content":45434,"nodeType":860},{},[45435,45438,45444],{"data":45436,"marks":45437,"value":23878,"nodeType":864},{},[],{"data":45439,"content":45440,"nodeType":883},{"uri":16015},[45441],{"data":45442,"marks":45443,"value":16018,"nodeType":864},{},[],{"data":45445,"marks":45446,"value":23888,"nodeType":864},{},[],{"data":45448,"content":45449,"nodeType":945},{},[45450],{"data":45451,"content":45452,"nodeType":860},{},[45453,45456,45462],{"data":45454,"marks":45455,"value":23898,"nodeType":864},{},[],{"data":45457,"content":45458,"nodeType":883},{"uri":23901},[45459],{"data":45460,"marks":45461,"value":23906,"nodeType":864},{},[],{"data":45463,"marks":45464,"value":23910,"nodeType":864},{},[],{"data":45466,"content":45467,"nodeType":945},{},[45468],{"data":45469,"content":45470,"nodeType":860},{},[45471,45474,45480],{"data":45472,"marks":45473,"value":23878,"nodeType":864},{},[],{"data":45475,"content":45476,"nodeType":883},{"uri":11726},[45477],{"data":45478,"marks":45479,"value":23926,"nodeType":864},{},[],{"data":45481,"marks":45482,"value":23930,"nodeType":864},{},[],{"data":45484,"content":45485,"nodeType":945},{},[45486],{"data":45487,"content":45488,"nodeType":860},{},[45489,45492,45498],{"data":45490,"marks":45491,"value":2761,"nodeType":864},{},[],{"data":45493,"content":45494,"nodeType":883},{"uri":23942},[45495],{"data":45496,"marks":45497,"value":3756,"nodeType":864},{},[],{"data":45499,"marks":45500,"value":23950,"nodeType":864},{},[],{"data":45502,"content":45503,"nodeType":860},{},[45504],{"data":45505,"marks":45506,"value":23957,"nodeType":864},{},[],{"data":45508,"content":45509,"nodeType":860},{},[45510,45513,45517],{"data":45511,"marks":45512,"value":23964,"nodeType":864},{},[],{"data":45514,"marks":45515,"value":23969,"nodeType":864},{},[45516],{"type":899},{"data":45518,"marks":45519,"value":23973,"nodeType":864},{},[],{"data":45521,"content":45522,"nodeType":1005},{},[],{"data":45524,"content":45525,"nodeType":1009},{},[45526,45530,45535,45539,45544],{"data":45527,"marks":45528,"value":23984,"nodeType":864},{},[45529],{"type":899},{"data":45531,"marks":45532,"value":23990,"nodeType":864},{},[45533,45534],{"type":2246},{"type":899},{"data":45536,"marks":45537,"value":23995,"nodeType":864},{},[45538],{"type":899},{"data":45540,"marks":45541,"value":24001,"nodeType":864},{},[45542,45543],{"type":2246},{"type":899},{"data":45545,"marks":45546,"value":24006,"nodeType":864},{},[45547],{"type":899},{"data":45549,"content":45550,"nodeType":860},{},[45551,45554,45560],{"data":45552,"marks":45553,"value":24013,"nodeType":864},{},[],{"data":45555,"content":45556,"nodeType":883},{"uri":18859},[45557],{"data":45558,"marks":45559,"value":24020,"nodeType":864},{},[],{"data":45561,"marks":45562,"value":24024,"nodeType":864},{},[],{"data":45564,"content":45565,"nodeType":860},{},[45566],{"data":45567,"marks":45568,"value":24031,"nodeType":864},{},[],{"data":45570,"content":45571,"nodeType":860},{},[45572],{"data":45573,"marks":45574,"value":24038,"nodeType":864},{},[],{"data":45576,"content":45577,"nodeType":1005},{},[],{"data":45579,"content":45580,"nodeType":1009},{},[45581],{"data":45582,"marks":45583,"value":24049,"nodeType":864},{},[45584],{"type":899},{"data":45586,"content":45587,"nodeType":860},{},[45588,45591,45597],{"data":45589,"marks":45590,"value":24056,"nodeType":864},{},[],{"data":45592,"content":45593,"nodeType":883},{"uri":24059},[45594],{"data":45595,"marks":45596,"value":22093,"nodeType":864},{},[],{"data":45598,"marks":45599,"value":24067,"nodeType":864},{},[],{"data":45601,"content":45602,"nodeType":860},{},[45603],{"data":45604,"marks":45605,"value":24074,"nodeType":864},{},[],{"data":45607,"content":45608,"nodeType":860},{},[45609],{"data":45610,"marks":45611,"value":24081,"nodeType":864},{},[],{"data":45613,"content":45614,"nodeType":860},{},[45615,45618,45624],{"data":45616,"marks":45617,"value":24088,"nodeType":864},{},[],{"data":45619,"content":45620,"nodeType":883},{"uri":24091},[45621],{"data":45622,"marks":45623,"value":22093,"nodeType":864},{},[],{"data":45625,"marks":45626,"value":2924,"nodeType":864},{},[],{"data":45628,"content":45629,"nodeType":1005},{},[],{"data":45631,"content":45632,"nodeType":1009},{},[45633],{"data":45634,"marks":45635,"value":24109,"nodeType":864},{},[45636],{"type":899},{"data":45638,"content":45639,"nodeType":860},{},[45640],{"data":45641,"marks":45642,"value":24116,"nodeType":864},{},[],{"data":45644,"content":45645,"nodeType":941},{},[45646,45655,45664],{"data":45647,"content":45648,"nodeType":945},{},[45649],{"data":45650,"content":45651,"nodeType":860},{},[45652],{"data":45653,"marks":45654,"value":24129,"nodeType":864},{},[],{"data":45656,"content":45657,"nodeType":945},{},[45658],{"data":45659,"content":45660,"nodeType":860},{},[45661],{"data":45662,"marks":45663,"value":24139,"nodeType":864},{},[],{"data":45665,"content":45666,"nodeType":945},{},[45667],{"data":45668,"content":45669,"nodeType":860},{},[45670],{"data":45671,"marks":45672,"value":24149,"nodeType":864},{},[],{"data":45674,"content":45675,"nodeType":860},{},[45676],{"data":45677,"marks":45678,"value":24156,"nodeType":864},{},[],{"data":45680,"content":45681,"nodeType":860},{},[45682,45685,45691],{"data":45683,"marks":45684,"value":24163,"nodeType":864},{},[],{"data":45686,"content":45687,"nodeType":883},{"uri":11562},[45688],{"data":45689,"marks":45690,"value":24170,"nodeType":864},{},[],{"data":45692,"marks":45693,"value":2924,"nodeType":864},{},[],{"data":45695,"content":45696,"nodeType":860},{},[45697,45700,45706],{"data":45698,"marks":45699,"value":24180,"nodeType":864},{},[],{"data":45701,"content":45702,"nodeType":883},{"uri":11536},[45703],{"data":45704,"marks":45705,"value":24187,"nodeType":864},{},[],{"data":45707,"marks":45708,"value":24191,"nodeType":864},{},[],{"data":45710,"content":45713,"nodeType":996},{"target":45711},{"sys":45712},{"id":24196,"type":1001,"linkType":1002},[],{"data":45715,"content":45716,"nodeType":1005},{},[],{"data":45718,"content":45719,"nodeType":860},{},[45720],{"data":45721,"marks":45722,"value":24207,"nodeType":864},{},[],{"data":45724,"content":45725,"nodeType":860},{},[45726,45729,45735],{"data":45727,"marks":45728,"value":2707,"nodeType":864},{},[],{"data":45730,"content":45731,"nodeType":883},{"uri":1700},[45732],{"data":45733,"marks":45734,"value":2715,"nodeType":864},{},[],{"data":45736,"marks":45737,"value":2719,"nodeType":864},{},[],{"entries":45739},{"hyperlink":45740,"inline":45741,"block":45742},[],[],[45743,45747,45749,45757],{"sys":45744,"__typename":1724,"title":45745,"caption":59,"layoutMode":59,"file":45746},{"id":23461},"Browser & Identity Attacks Matrix Screenshot",{"url":19297,"width":19298,"height":19299},{"sys":45748,"__typename":1717,"type":1718,"ctaText":36837,"buttonLabel":36838,"buttonColour":1721,"buttonUrl":11536},{"id":23546},{"sys":45750,"__typename":1724,"title":45751,"caption":45752,"layoutMode":59,"file":45753},{"id":23780},"Device code phishing kit example","Device code phishing kit example.",{"url":45754,"width":45755,"height":45756},"https://images.ctfassets.net/y1cdw1ablpvd/2zbjCCqXRMTvaOr6Xpx2BJ/ccb3000b043b3bbc11a6d2315e66f6f1/Copy_of_Device_code_login_completion.gif",1280,720,{"sys":45758,"__typename":1717,"type":1718,"ctaText":45759,"buttonLabel":45760,"buttonColour":1721,"buttonUrl":11562},{"id":24196},"Check out the new-look Browser & Identity Attacks Matrix","See it Here",{"items":45762},[],{},"Stop browser attacks with our MITRE-inspired matrix",{"items":45766},[45767,46600,48515],{"__typename":2059,"sys":45768,"content":45769,"title":29597,"synopsis":29598,"hashTags":59,"publishedDate":24225,"slug":29599,"tagsCollection":46590,"authorsCollection":46596},{"id":28636},{"json":45770},{"data":45771,"content":45772,"nodeType":856},{},[45773,45795,45819,45852,45885,45890,45900,45903,45910,45952,45958,45977,45982,45985,45992,46016,46022,46029,46034,46037,46044,46050,46065,46071,46104,46110,46113,46120,46135,46177,46180,46187,46202,46217,46224,46230,46240,46250,46260,46270,46285,46292,46298,46301,46307,46313,46328,46331,46338,46353,46584],{"data":45774,"content":45775,"nodeType":860},{},[45776,45779,45785,45788,45792],{"data":45777,"marks":45778,"value":28647,"nodeType":864},{},[],{"data":45780,"content":45781,"nodeType":883},{"uri":16015},[45782],{"data":45783,"marks":45784,"value":16018,"nodeType":864},{},[],{"data":45786,"marks":45787,"value":28657,"nodeType":864},{},[],{"data":45789,"marks":45790,"value":28662,"nodeType":864},{},[45791],{"type":899},{"data":45793,"marks":45794,"value":28666,"nodeType":864},{},[],{"data":45796,"content":45797,"nodeType":860},{},[45798,45801,45807,45810,45816],{"data":45799,"marks":45800,"value":28673,"nodeType":864},{},[],{"data":45802,"content":45803,"nodeType":883},{"uri":28676},[45804],{"data":45805,"marks":45806,"value":28681,"nodeType":864},{},[],{"data":45808,"marks":45809,"value":28685,"nodeType":864},{},[],{"data":45811,"content":45812,"nodeType":883},{"uri":28688},[45813],{"data":45814,"marks":45815,"value":28693,"nodeType":864},{},[],{"data":45817,"marks":45818,"value":28697,"nodeType":864},{},[],{"data":45820,"content":45821,"nodeType":860},{},[45822,45825,45831,45834,45840,45843,45849],{"data":45823,"marks":45824,"value":28704,"nodeType":864},{},[],{"data":45826,"content":45827,"nodeType":883},{"uri":28707},[45828],{"data":45829,"marks":45830,"value":28712,"nodeType":864},{},[],{"data":45832,"marks":45833,"value":28716,"nodeType":864},{},[],{"data":45835,"content":45836,"nodeType":883},{"uri":28719},[45837],{"data":45838,"marks":45839,"value":28724,"nodeType":864},{},[],{"data":45841,"marks":45842,"value":28728,"nodeType":864},{},[],{"data":45844,"content":45845,"nodeType":883},{"uri":16553},[45846],{"data":45847,"marks":45848,"value":28735,"nodeType":864},{},[],{"data":45850,"marks":45851,"value":28739,"nodeType":864},{},[],{"data":45853,"content":45854,"nodeType":860},{},[45855,45858,45864,45867,45873,45876,45882],{"data":45856,"marks":45857,"value":28746,"nodeType":864},{},[],{"data":45859,"content":45860,"nodeType":883},{"uri":28749},[45861],{"data":45862,"marks":45863,"value":28754,"nodeType":864},{},[],{"data":45865,"marks":45866,"value":28758,"nodeType":864},{},[],{"data":45868,"content":45869,"nodeType":883},{"uri":28761},[45870],{"data":45871,"marks":45872,"value":28766,"nodeType":864},{},[],{"data":45874,"marks":45875,"value":28770,"nodeType":864},{},[],{"data":45877,"content":45878,"nodeType":883},{"uri":28773},[45879],{"data":45880,"marks":45881,"value":28778,"nodeType":864},{},[],{"data":45883,"marks":45884,"value":28782,"nodeType":864},{},[],{"data":45886,"content":45889,"nodeType":996},{"target":45887},{"sys":45888},{"id":28787,"type":1001,"linkType":1002},[],{"data":45891,"content":45892,"nodeType":860},{},[45893,45897],{"data":45894,"marks":45895,"value":28796,"nodeType":864},{},[45896],{"type":899},{"data":45898,"marks":45899,"value":28800,"nodeType":864},{},[],{"data":45901,"content":45902,"nodeType":1005},{},[],{"data":45904,"content":45905,"nodeType":1009},{},[45906],{"data":45907,"marks":45908,"value":28811,"nodeType":864},{},[45909],{"type":899},{"data":45911,"content":45912,"nodeType":860},{},[45913,45916,45922,45925,45931,45934,45940,45943,45949],{"data":45914,"marks":45915,"value":28818,"nodeType":864},{},[],{"data":45917,"content":45918,"nodeType":883},{"uri":28821},[45919],{"data":45920,"marks":45921,"value":28826,"nodeType":864},{},[],{"data":45923,"marks":45924,"value":11735,"nodeType":864},{},[],{"data":45926,"content":45927,"nodeType":883},{"uri":28832},[45928],{"data":45929,"marks":45930,"value":28837,"nodeType":864},{},[],{"data":45932,"marks":45933,"value":28841,"nodeType":864},{},[],{"data":45935,"content":45936,"nodeType":883},{"uri":28719},[45937],{"data":45938,"marks":45939,"value":28848,"nodeType":864},{},[],{"data":45941,"marks":45942,"value":28852,"nodeType":864},{},[],{"data":45944,"content":45945,"nodeType":883},{"uri":12879},[45946],{"data":45947,"marks":45948,"value":28859,"nodeType":864},{},[],{"data":45950,"marks":45951,"value":2924,"nodeType":864},{},[],{"data":45953,"content":45954,"nodeType":860},{},[45955],{"data":45956,"marks":45957,"value":28869,"nodeType":864},{},[],{"data":45959,"content":45960,"nodeType":860},{},[45961,45964,45970,45973],{"data":45962,"marks":45963,"value":28876,"nodeType":864},{},[],{"data":45965,"content":45966,"nodeType":883},{"uri":12879},[45967],{"data":45968,"marks":45969,"value":28883,"nodeType":864},{},[],{"data":45971,"marks":45972,"value":28887,"nodeType":864},{},[],{"data":45974,"marks":45975,"value":28892,"nodeType":864},{},[45976],{"type":899},{"data":45978,"content":45981,"nodeType":996},{"target":45979},{"sys":45980},{"id":28897,"type":1001,"linkType":1002},[],{"data":45983,"content":45984,"nodeType":1005},{},[],{"data":45986,"content":45987,"nodeType":1009},{},[45988],{"data":45989,"marks":45990,"value":28909,"nodeType":864},{},[45991],{"type":899},{"data":45993,"content":45994,"nodeType":860},{},[45995,45998,46004,46007,46013],{"data":45996,"marks":45997,"value":2761,"nodeType":864},{},[],{"data":45999,"content":46000,"nodeType":883},{"uri":23901},[46001],{"data":46002,"marks":46003,"value":28922,"nodeType":864},{},[],{"data":46005,"marks":46006,"value":28926,"nodeType":864},{},[],{"data":46008,"content":46009,"nodeType":883},{"uri":16553},[46010],{"data":46011,"marks":46012,"value":28933,"nodeType":864},{},[],{"data":46014,"marks":46015,"value":28937,"nodeType":864},{},[],{"data":46017,"content":46018,"nodeType":860},{},[46019],{"data":46020,"marks":46021,"value":28944,"nodeType":864},{},[],{"data":46023,"content":46024,"nodeType":860},{},[46025],{"data":46026,"marks":46027,"value":28952,"nodeType":864},{},[46028],{"type":899},{"data":46030,"content":46033,"nodeType":996},{"target":46031},{"sys":46032},{"id":28957,"type":1001,"linkType":1002},[],{"data":46035,"content":46036,"nodeType":1005},{},[],{"data":46038,"content":46039,"nodeType":1009},{},[46040],{"data":46041,"marks":46042,"value":28969,"nodeType":864},{},[46043],{"type":899},{"data":46045,"content":46046,"nodeType":860},{},[46047],{"data":46048,"marks":46049,"value":28976,"nodeType":864},{},[],{"data":46051,"content":46052,"nodeType":860},{},[46053,46056,46062],{"data":46054,"marks":46055,"value":2761,"nodeType":864},{},[],{"data":46057,"content":46058,"nodeType":883},{"uri":28985},[46059],{"data":46060,"marks":46061,"value":28990,"nodeType":864},{},[],{"data":46063,"marks":46064,"value":28994,"nodeType":864},{},[],{"data":46066,"content":46067,"nodeType":860},{},[46068],{"data":46069,"marks":46070,"value":29001,"nodeType":864},{},[],{"data":46072,"content":46073,"nodeType":860},{},[46074,46077,46083,46086,46092,46095,46101],{"data":46075,"marks":46076,"value":29008,"nodeType":864},{},[],{"data":46078,"content":46079,"nodeType":883},{"uri":29011},[46080],{"data":46081,"marks":46082,"value":29016,"nodeType":864},{},[],{"data":46084,"marks":46085,"value":29020,"nodeType":864},{},[],{"data":46087,"content":46088,"nodeType":883},{"uri":29023},[46089],{"data":46090,"marks":46091,"value":29028,"nodeType":864},{},[],{"data":46093,"marks":46094,"value":29032,"nodeType":864},{},[],{"data":46096,"content":46097,"nodeType":883},{"uri":4103},[46098],{"data":46099,"marks":46100,"value":16114,"nodeType":864},{},[],{"data":46102,"marks":46103,"value":29042,"nodeType":864},{},[],{"data":46105,"content":46106,"nodeType":860},{},[46107],{"data":46108,"marks":46109,"value":29049,"nodeType":864},{},[],{"data":46111,"content":46112,"nodeType":1005},{},[],{"data":46114,"content":46115,"nodeType":1009},{},[46116],{"data":46117,"marks":46118,"value":29060,"nodeType":864},{},[46119],{"type":899},{"data":46121,"content":46122,"nodeType":860},{},[46123,46126,46132],{"data":46124,"marks":46125,"value":29067,"nodeType":864},{},[],{"data":46127,"content":46128,"nodeType":883},{"uri":29070},[46129],{"data":46130,"marks":46131,"value":29075,"nodeType":864},{},[],{"data":46133,"marks":46134,"value":29079,"nodeType":864},{},[],{"data":46136,"content":46137,"nodeType":860},{},[46138,46141,46147,46150,46156,46159,46165,46168,46174],{"data":46139,"marks":46140,"value":29086,"nodeType":864},{},[],{"data":46142,"content":46143,"nodeType":883},{"uri":29089},[46144],{"data":46145,"marks":46146,"value":29094,"nodeType":864},{},[],{"data":46148,"marks":46149,"value":29098,"nodeType":864},{},[],{"data":46151,"content":46152,"nodeType":883},{"uri":29101},[46153],{"data":46154,"marks":46155,"value":29106,"nodeType":864},{},[],{"data":46157,"marks":46158,"value":29110,"nodeType":864},{},[],{"data":46160,"content":46161,"nodeType":883},{"uri":29113},[46162],{"data":46163,"marks":46164,"value":29118,"nodeType":864},{},[],{"data":46166,"marks":46167,"value":29122,"nodeType":864},{},[],{"data":46169,"content":46170,"nodeType":883},{"uri":29125},[46171],{"data":46172,"marks":46173,"value":29130,"nodeType":864},{},[],{"data":46175,"marks":46176,"value":29134,"nodeType":864},{},[],{"data":46178,"content":46179,"nodeType":1005},{},[],{"data":46181,"content":46182,"nodeType":1009},{},[46183],{"data":46184,"marks":46185,"value":29145,"nodeType":864},{},[46186],{"type":899},{"data":46188,"content":46189,"nodeType":860},{},[46190,46193,46199],{"data":46191,"marks":46192,"value":29152,"nodeType":864},{},[],{"data":46194,"content":46195,"nodeType":883},{"uri":3259},[46196],{"data":46197,"marks":46198,"value":29159,"nodeType":864},{},[],{"data":46200,"marks":46201,"value":29163,"nodeType":864},{},[],{"data":46203,"content":46204,"nodeType":860},{},[46205,46208,46214],{"data":46206,"marks":46207,"value":29170,"nodeType":864},{},[],{"data":46209,"content":46210,"nodeType":883},{"uri":29173},[46211],{"data":46212,"marks":46213,"value":315,"nodeType":864},{},[],{"data":46215,"marks":46216,"value":29181,"nodeType":864},{},[],{"data":46218,"content":46219,"nodeType":1312},{},[46220],{"data":46221,"marks":46222,"value":7533,"nodeType":864},{},[46223],{"type":899},{"data":46225,"content":46226,"nodeType":860},{},[46227],{"data":46228,"marks":46229,"value":29195,"nodeType":864},{},[],{"data":46231,"content":46232,"nodeType":860},{},[46233,46237],{"data":46234,"marks":46235,"value":29203,"nodeType":864},{},[46236],{"type":899},{"data":46238,"marks":46239,"value":29207,"nodeType":864},{},[],{"data":46241,"content":46242,"nodeType":860},{},[46243,46247],{"data":46244,"marks":46245,"value":29215,"nodeType":864},{},[46246],{"type":899},{"data":46248,"marks":46249,"value":29219,"nodeType":864},{},[],{"data":46251,"content":46252,"nodeType":860},{},[46253,46257],{"data":46254,"marks":46255,"value":29227,"nodeType":864},{},[46256],{"type":899},{"data":46258,"marks":46259,"value":29231,"nodeType":864},{},[],{"data":46261,"content":46262,"nodeType":860},{},[46263,46267],{"data":46264,"marks":46265,"value":29239,"nodeType":864},{},[46266],{"type":899},{"data":46268,"marks":46269,"value":29243,"nodeType":864},{},[],{"data":46271,"content":46272,"nodeType":860},{},[46273,46276,46282],{"data":46274,"marks":46275,"value":21,"nodeType":864},{},[],{"data":46277,"content":46278,"nodeType":883},{"uri":24926},[46279],{"data":46280,"marks":46281,"value":29256,"nodeType":864},{},[],{"data":46283,"marks":46284,"value":21,"nodeType":864},{},[],{"data":46286,"content":46287,"nodeType":1312},{},[46288],{"data":46289,"marks":46290,"value":29267,"nodeType":864},{},[46291],{"type":899},{"data":46293,"content":46294,"nodeType":860},{},[46295],{"data":46296,"marks":46297,"value":29274,"nodeType":864},{},[],{"data":46299,"content":46300,"nodeType":1005},{},[],{"data":46302,"content":46303,"nodeType":860},{},[46304],{"data":46305,"marks":46306,"value":4855,"nodeType":864},{},[],{"data":46308,"content":46309,"nodeType":860},{},[46310],{"data":46311,"marks":46312,"value":1689,"nodeType":864},{},[],{"data":46314,"content":46315,"nodeType":860},{},[46316,46319,46325],{"data":46317,"marks":46318,"value":21,"nodeType":864},{},[],{"data":46320,"content":46321,"nodeType":883},{"uri":14401},[46322],{"data":46323,"marks":46324,"value":1703,"nodeType":864},{},[],{"data":46326,"marks":46327,"value":21,"nodeType":864},{},[],{"data":46329,"content":46330,"nodeType":1005},{},[],{"data":46332,"content":46333,"nodeType":1009},{},[46334],{"data":46335,"marks":46336,"value":29315,"nodeType":864},{},[46337],{"type":899},{"data":46339,"content":46340,"nodeType":860},{},[46341,46344,46350],{"data":46342,"marks":46343,"value":29322,"nodeType":864},{},[],{"data":46345,"content":46346,"nodeType":883},{"uri":16015},[46347],{"data":46348,"marks":46349,"value":29329,"nodeType":864},{},[],{"data":46351,"marks":46352,"value":29333,"nodeType":864},{},[],{"data":46354,"content":46355,"nodeType":4845},{},[46356,46399,46455,46498,46541],{"data":46357,"content":46358,"nodeType":4581},{},[46359,46369,46379,46389],{"data":46360,"content":46361,"nodeType":4569},{},[46362],{"data":46363,"content":46364,"nodeType":860},{},[46365],{"data":46366,"marks":46367,"value":29350,"nodeType":864},{},[46368],{"type":899},{"data":46370,"content":46371,"nodeType":4569},{},[46372],{"data":46373,"content":46374,"nodeType":860},{},[46375],{"data":46376,"marks":46377,"value":29361,"nodeType":864},{},[46378],{"type":899},{"data":46380,"content":46381,"nodeType":4569},{},[46382],{"data":46383,"content":46384,"nodeType":860},{},[46385],{"data":46386,"marks":46387,"value":29372,"nodeType":864},{},[46388],{"type":899},{"data":46390,"content":46391,"nodeType":4569},{},[46392],{"data":46393,"content":46394,"nodeType":860},{},[46395],{"data":46396,"marks":46397,"value":29383,"nodeType":864},{},[46398],{"type":899},{"data":46400,"content":46401,"nodeType":4581},{},[46402,46422,46431,46440],{"data":46403,"content":46404,"nodeType":4569},{},[46405],{"data":46406,"content":46407,"nodeType":860},{},[46408,46412,46415,46419],{"data":46409,"marks":46410,"value":29397,"nodeType":864},{},[46411],{"type":899},{"data":46413,"marks":46414,"value":29401,"nodeType":864},{},[],{"data":46416,"marks":46417,"value":29406,"nodeType":864},{},[46418],{"type":899},{"data":46420,"marks":46421,"value":29410,"nodeType":864},{},[],{"data":46423,"content":46424,"nodeType":4569},{},[46425],{"data":46426,"content":46427,"nodeType":860},{},[46428],{"data":46429,"marks":46430,"value":29420,"nodeType":864},{},[],{"data":46432,"content":46433,"nodeType":4569},{},[46434],{"data":46435,"content":46436,"nodeType":860},{},[46437],{"data":46438,"marks":46439,"value":29430,"nodeType":864},{},[],{"data":46441,"content":46442,"nodeType":4569},{},[46443,46449],{"data":46444,"content":46445,"nodeType":860},{},[46446],{"data":46447,"marks":46448,"value":29440,"nodeType":864},{},[],{"data":46450,"content":46451,"nodeType":860},{},[46452],{"data":46453,"marks":46454,"value":29447,"nodeType":864},{},[],{"data":46456,"content":46457,"nodeType":4581},{},[46458,46471,46480,46489],{"data":46459,"content":46460,"nodeType":4569},{},[46461],{"data":46462,"content":46463,"nodeType":860},{},[46464,46468],{"data":46465,"marks":46466,"value":29461,"nodeType":864},{},[46467],{"type":899},{"data":46469,"marks":46470,"value":29465,"nodeType":864},{},[],{"data":46472,"content":46473,"nodeType":4569},{},[46474],{"data":46475,"content":46476,"nodeType":860},{},[46477],{"data":46478,"marks":46479,"value":29475,"nodeType":864},{},[],{"data":46481,"content":46482,"nodeType":4569},{},[46483],{"data":46484,"content":46485,"nodeType":860},{},[46486],{"data":46487,"marks":46488,"value":29485,"nodeType":864},{},[],{"data":46490,"content":46491,"nodeType":4569},{},[46492],{"data":46493,"content":46494,"nodeType":860},{},[46495],{"data":46496,"marks":46497,"value":29495,"nodeType":864},{},[],{"data":46499,"content":46500,"nodeType":4581},{},[46501,46514,46523,46532],{"data":46502,"content":46503,"nodeType":4569},{},[46504],{"data":46505,"content":46506,"nodeType":860},{},[46507,46511],{"data":46508,"marks":46509,"value":29509,"nodeType":864},{},[46510],{"type":899},{"data":46512,"marks":46513,"value":29513,"nodeType":864},{},[],{"data":46515,"content":46516,"nodeType":4569},{},[46517],{"data":46518,"content":46519,"nodeType":860},{},[46520],{"data":46521,"marks":46522,"value":29523,"nodeType":864},{},[],{"data":46524,"content":46525,"nodeType":4569},{},[46526],{"data":46527,"content":46528,"nodeType":860},{},[46529],{"data":46530,"marks":46531,"value":29533,"nodeType":864},{},[],{"data":46533,"content":46534,"nodeType":4569},{},[46535],{"data":46536,"content":46537,"nodeType":860},{},[46538],{"data":46539,"marks":46540,"value":29543,"nodeType":864},{},[],{"data":46542,"content":46543,"nodeType":4581},{},[46544,46557,46566,46575],{"data":46545,"content":46546,"nodeType":4569},{},[46547],{"data":46548,"content":46549,"nodeType":860},{},[46550,46554],{"data":46551,"marks":46552,"value":29557,"nodeType":864},{},[46553],{"type":899},{"data":46555,"marks":46556,"value":29561,"nodeType":864},{},[],{"data":46558,"content":46559,"nodeType":4569},{},[46560],{"data":46561,"content":46562,"nodeType":860},{},[46563],{"data":46564,"marks":46565,"value":29420,"nodeType":864},{},[],{"data":46567,"content":46568,"nodeType":4569},{},[46569],{"data":46570,"content":46571,"nodeType":860},{},[46572],{"data":46573,"marks":46574,"value":29580,"nodeType":864},{},[],{"data":46576,"content":46577,"nodeType":4569},{},[46578],{"data":46579,"content":46580,"nodeType":860},{},[46581],{"data":46582,"marks":46583,"value":29590,"nodeType":864},{},[],{"data":46585,"content":46586,"nodeType":860},{},[46587],{"data":46588,"marks":46589,"value":21,"nodeType":864},{},[],{"items":46591},[46592,46594],{"sys":46593,"name":13779},{"id":13778},{"sys":46595,"name":342},{"id":13775},{"items":46597},[46598],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":46599},{"url":2740},{"__typename":2059,"sys":46601,"content":46603,"title":48498,"synopsis":48499,"hashTags":59,"publishedDate":48500,"slug":48501,"tagsCollection":48502,"authorsCollection":48508},{"id":46602},"2tz0zEJCarJBkceOYk4zVg",{"json":46604},{"data":46605,"content":46606,"nodeType":856},{},[46607,46614,46643,46654,46661,46667,46679,46685,46688,46696,46703,46766,46773,46779,46782,46790,46797,46803,46811,46818,46944,46950,46956,46962,46968,46976,46983,46990,47053,47060,47066,47072,47080,47087,47094,47102,47109,47142,47149,47155,47162,47210,47217,47225,47232,47238,47245,47252,47258,47265,47298,47305,47311,47314,47322,47329,47336,47343,47348,47355,47362,47368,47375,47381,47388,47394,47401,47408,47411,47419,47435,47442,47461,47704,47711,47742,47977,47984,47991,48192,48199,48384,48387,48395,48402,48409,48421,48424,48431,48448,48465,48472,48475,48482],{"data":46608,"content":46609,"nodeType":860},{},[46610],{"data":46611,"marks":46612,"value":46613,"nodeType":864},{},[],"When Push blocks an attack in the browser, we take the opportunity to do some more digging to see what else we can find. One recent detection led us down the rabbit hole — and right into a criminal phishing panel. ",{"data":46615,"content":46616,"nodeType":860},{},[46617,46621,46627,46631,46639],{"data":46618,"marks":46619,"value":46620,"nodeType":864},{},[],"Real-time operated phishing panels have been used extensively in recent months, in vishing + phishing attacks attributed to first ",{"data":46622,"content":46623,"nodeType":883},{"uri":23901},[46624],{"data":46625,"marks":46626,"value":4087,"nodeType":864},{},[],{"data":46628,"marks":46629,"value":46630,"nodeType":864},{},[],", and more recently the ",{"data":46632,"content":46634,"nodeType":883},{"uri":46633},"https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/",[46635],{"data":46636,"marks":46637,"value":46638,"nodeType":864},{},[],"BlackFile",{"data":46640,"marks":46641,"value":46642,"nodeType":864},{},[]," hacking group, with a significant overlap in techniques and tooling. ",{"data":46644,"content":46645,"nodeType":860},{},[46646,46651],{"data":46647,"marks":46648,"value":46650,"nodeType":864},{},[46649],{"type":899},"We’ve directly accessed active deployments of the operator panels driving these campaigns, observed what happens in real-time when a victim is targeted, and analyzed multiple variants and forks of the tooling. ",{"data":46652,"marks":46653,"value":1171,"nodeType":864},{},[],{"data":46655,"content":46656,"nodeType":860},{},[46657],{"data":46658,"marks":46659,"value":46660,"nodeType":864},{},[],"We identified four primary infrastructure clusters, with each deployment having its own panel implementation. While the panels share common heritage, the operators deploying them appear to be separate groups with different infrastructure preferences and operational patterns.",{"data":46662,"content":46666,"nodeType":996},{"target":46663},{"sys":46664},{"id":46665,"type":1001,"linkType":1002},"5BQOpzjSbobLx8OkvXl6os",[],{"data":46668,"content":46669,"nodeType":860},{},[46670,46674],{"data":46671,"marks":46672,"value":46673,"nodeType":864},{},[],"The existence of these independently branded forks indicates that the tooling has entered a phase of wider distribution — operators who obtained the original panel source are now customizing and reshipping it for their own purposes. As a result, the tooling is now most likely accessible to a broad population of financially motivated threat actors. ",{"data":46675,"marks":46676,"value":46678,"nodeType":864},{},[46677],{"type":899},"In total, we’ve identified over 400 domains linked to the attacks, giving an indication of the scale. ",{"data":46680,"content":46684,"nodeType":996},{"target":46681},{"sys":46682},{"id":46683,"type":1001,"linkType":1002},"2Z1LUdYXVONWO9nnJTkWsJ",[],{"data":46686,"content":46687,"nodeType":1005},{},[],{"data":46689,"content":46690,"nodeType":1009},{},[46691],{"data":46692,"marks":46693,"value":46695,"nodeType":864},{},[46694],{"type":899},"Background",{"data":46697,"content":46698,"nodeType":860},{},[46699],{"data":46700,"marks":46701,"value":46702,"nodeType":864},{},[],"Since at least August 2025, attackers have been running hybrid social engineering campaigns targeting hundreds of organizations across financial services, technology, cryptocurrency, healthcare, hospitality, and private aviation. ",{"data":46704,"content":46705,"nodeType":941},{},[46706,46721,46736,46751],{"data":46707,"content":46708,"nodeType":945},{},[46709],{"data":46710,"content":46711,"nodeType":860},{},[46712,46717],{"data":46713,"marks":46714,"value":46716,"nodeType":864},{},[46715],{"type":899},"August 2025: ",{"data":46718,"marks":46719,"value":46720,"nodeType":864},{},[],"Tooling made available, used in crypto-focused attacks",{"data":46722,"content":46723,"nodeType":945},{},[46724],{"data":46725,"content":46726,"nodeType":860},{},[46727,46732],{"data":46728,"marks":46729,"value":46731,"nodeType":864},{},[46730],{"type":899},"November 2025:",{"data":46733,"marks":46734,"value":46735,"nodeType":864},{},[]," Major attacks on enterprise identity platforms begin",{"data":46737,"content":46738,"nodeType":945},{},[46739],{"data":46740,"content":46741,"nodeType":860},{},[46742,46747],{"data":46743,"marks":46744,"value":46746,"nodeType":864},{},[46745],{"type":899},"January 2026: ",{"data":46748,"marks":46749,"value":46750,"nodeType":864},{},[],"Public breaches reported",{"data":46752,"content":46753,"nodeType":945},{},[46754],{"data":46755,"content":46756,"nodeType":860},{},[46757,46762],{"data":46758,"marks":46759,"value":46761,"nodeType":864},{},[46760],{"type":899},"March 2026: ",{"data":46763,"marks":46764,"value":46765,"nodeType":864},{},[],"Activity spikes again",{"data":46767,"content":46768,"nodeType":860},{},[46769],{"data":46770,"marks":46771,"value":46772,"nodeType":864},{},[],"The attacks combine voice phishing with MFA-bypassing adversary-in-the-middle (AiTM) phishing mechanisms that allow the attacker to steal authenticated sessions for target applications — typically enterprise identity providers and cryptocurrency exchanges. Once an identity provider account is compromised, the attackers pivot across connected SaaS platforms — SharePoint, Salesforce, DocuSign, Slack — exfiltrates data, and attempts to extort the victim organization. ",{"data":46774,"content":46778,"nodeType":996},{"target":46775},{"sys":46776},{"id":46777,"type":1001,"linkType":1002},"2X2YXMpozrbRQhegk7yF1k",[],{"data":46780,"content":46781,"nodeType":1005},{},[],{"data":46783,"content":46784,"nodeType":1009},{},[46785],{"data":46786,"marks":46787,"value":46789,"nodeType":864},{},[46788],{"type":899},"Inside the panels: what Push found",{"data":46791,"content":46792,"nodeType":860},{},[46793],{"data":46794,"marks":46795,"value":46796,"nodeType":864},{},[],"Push detected an active Okta phishing site with TTPs aligned to the tooling used by SLH and affiliated groups. Through analysis of the phishing infrastructure, we gained direct access to Doko’s Panel and variants, and were able to observe how these attacks unfold from the operator's perspective — including real victim submission logs from the current week confirming ongoing active operations.",{"data":46798,"content":46802,"nodeType":996},{"target":46799},{"sys":46800},{"id":46801,"type":1001,"linkType":1002},"5ND0etPs5xN7ejz24l71jy",[],{"data":46804,"content":46805,"nodeType":1312},{},[46806],{"data":46807,"marks":46808,"value":46810,"nodeType":864},{},[46809],{"type":899},"How the attack works",{"data":46812,"content":46813,"nodeType":860},{},[46814],{"data":46815,"marks":46816,"value":46817,"nodeType":864},{},[],"The general sequence of steps is the same across the panels:",{"data":46819,"content":46820,"nodeType":941},{},[46821,46836,46851,46875,46890,46905,46929],{"data":46822,"content":46823,"nodeType":945},{},[46824],{"data":46825,"content":46826,"nodeType":860},{},[46827,46832],{"data":46828,"marks":46829,"value":46831,"nodeType":864},{},[46830],{"type":899},"The operator calls the target",{"data":46833,"marks":46834,"value":46835,"nodeType":864},{},[]," spoofing the organization's IT helpdesk number, often referencing real employee names or internal ticket numbers to establish trust. The target is directed to a phishing domain — usually following a combosquatting pattern like my\u003Ctarget>internal[.]com or \u003Ctarget>sso[.]com — under the pretext of a mandatory security update, passkey enrollment, or support ticket resolution. ",{"data":46837,"content":46838,"nodeType":945},{},[46839],{"data":46840,"content":46841,"nodeType":860},{},[46842,46847],{"data":46843,"marks":46844,"value":46846,"nodeType":864},{},[46845],{"type":899},"The victim lands on the phishing domain",{"data":46848,"marks":46849,"value":46850,"nodeType":864},{},[]," and is presented with a loading spinner — the anti-bot gate that prevents unauthorized access to the phishing pages.",{"data":46852,"content":46853,"nodeType":945},{},[46854],{"data":46855,"content":46856,"nodeType":860},{},[46857,46862,46866,46871],{"data":46858,"marks":46859,"value":46861,"nodeType":864},{},[46860],{"type":899},"The operator accepts the visitor",{"data":46863,"marks":46864,"value":46865,"nodeType":864},{},[]," from the admin panel and ",{"data":46867,"marks":46868,"value":46870,"nodeType":864},{},[46869],{"type":899},"the victim is redirected",{"data":46872,"marks":46873,"value":46874,"nodeType":864},{},[]," to the cloned login page (e.g. Google, Microsoft, Okta).",{"data":46876,"content":46877,"nodeType":945},{},[46878],{"data":46879,"content":46880,"nodeType":860},{},[46881,46886],{"data":46882,"marks":46883,"value":46885,"nodeType":864},{},[46884],{"type":899},"The victim enters their email address and password",{"data":46887,"marks":46888,"value":46889,"nodeType":864},{},[],", which is forwarded to the operator's Telegram channel. The victim sees a processing spinner on the branded login form.",{"data":46891,"content":46892,"nodeType":945},{},[46893],{"data":46894,"content":46895,"nodeType":860},{},[46896,46901],{"data":46897,"marks":46898,"value":46900,"nodeType":864},{},[46899],{"type":899},"The operator relays the credentials",{"data":46902,"marks":46903,"value":46904,"nodeType":864},{},[]," to the real identity provider. If they're valid, the attack proceeds. If they're invalid, the operator can redirect the victim back to the credential entry pages. Assuming MFA is required, the operator issues a redirect to an appropriate MFA capture page — \"Submit SMS OTP,\" \"Submit Gauth OTP,\" or \"Approve [XX] Prompt,\" depending on what the legitimate IdP is presenting.",{"data":46906,"content":46907,"nodeType":945},{},[46908],{"data":46909,"content":46910,"nodeType":860},{},[46911,46916,46920,46925],{"data":46912,"marks":46913,"value":46915,"nodeType":864},{},[46914],{"type":899},"The victim submits their OTP or approves the push notification ",{"data":46917,"marks":46918,"value":46919,"nodeType":864},{},[],"and",{"data":46921,"marks":46922,"value":46924,"nodeType":864},{},[46923],{"type":899}," the operator relays the OTP",{"data":46926,"marks":46927,"value":46928,"nodeType":864},{},[]," in their own login session, completes authentication, and captures the session. ",{"data":46930,"content":46931,"nodeType":945},{},[46932],{"data":46933,"content":46934,"nodeType":860},{},[46935,46940],{"data":46936,"marks":46937,"value":46939,"nodeType":864},{},[46938],{"type":899},"The victim is redirected to a benign page",{"data":46941,"marks":46942,"value":46943,"nodeType":864},{},[]," (e.g., Google Drive) or to a support ticket closure screen displaying a fabricated ticket number.",{"data":46945,"content":46949,"nodeType":996},{"target":46946},{"sys":46947},{"id":46948,"type":1001,"linkType":1002},"1o0wm3EOd7zSl5MddsNxgL",[],{"data":46951,"content":46955,"nodeType":996},{"target":46952},{"sys":46953},{"id":46954,"type":1001,"linkType":1002},"7w7SQEn3aITpcgXLMThhbS",[],{"data":46957,"content":46958,"nodeType":860},{},[46959],{"data":46960,"marks":46961,"value":21,"nodeType":864},{},[],{"data":46963,"content":46967,"nodeType":996},{"target":46964},{"sys":46965},{"id":46966,"type":1001,"linkType":1002},"PJJabY1ZfoCfl8XQ6PMj2",[],{"data":46969,"content":46970,"nodeType":1312},{},[46971],{"data":46972,"marks":46973,"value":46975,"nodeType":864},{},[46974],{"type":899},"Doko’s Panel",{"data":46977,"content":46978,"nodeType":860},{},[46979],{"data":46980,"marks":46981,"value":46982,"nodeType":864},{},[],"Let’s take a closer look at the panels themselves. We'll start with the default version of Doko's Panel since it’s the most established. It provides a multi-functional framework targeting users of Google, Microsoft Entra, Okta, and popular cryptocurrency exchanges including Abra, Coinbase, Gemini, and Kraken. Its core functionality resides in a client-side JavaScript file (client.js) that establishes the real-time feedback loop between the victim's browser and the operator's C2.",{"data":46984,"content":46985,"nodeType":860},{},[46986],{"data":46987,"marks":46988,"value":46989,"nodeType":864},{},[],"The technical indicators that characterize Doko's Panel in its standard form include:",{"data":46991,"content":46992,"nodeType":941},{},[46993,47008,47023,47038],{"data":46994,"content":46995,"nodeType":945},{},[46996],{"data":46997,"content":46998,"nodeType":860},{},[46999,47004],{"data":47000,"marks":47001,"value":47003,"nodeType":864},{},[47002],{"type":899},"client.js",{"data":47005,"marks":47006,"value":47007,"nodeType":864},{},[]," containing a pingServer() function that sends a JSON POST request to /backend.php every second with the structure { action: 'ping', token, window_id, page, os, browser }. If the response contains a redirect key, the victim's browser navigates to that path. ",{"data":47009,"content":47010,"nodeType":945},{},[47011],{"data":47012,"content":47013,"nodeType":860},{},[47014,47019],{"data":47015,"marks":47016,"value":47018,"nodeType":864},{},[47017],{"type":899},"sendTelegramMessage()",{"data":47020,"marks":47021,"value":47022,"nodeType":864},{},[]," (aliased to sendtg()), a function for relaying real-time credential submissions and session updates to the operator's Telegram channel.",{"data":47024,"content":47025,"nodeType":945},{},[47026],{"data":47027,"content":47028,"nodeType":860},{},[47029,47034],{"data":47030,"marks":47031,"value":47033,"nodeType":864},{},[47032],{"type":899},"backend.php",{"data":47035,"marks":47036,"value":47037,"nodeType":864},{},[]," as the primary server-side handler for both victim ping actions and admin panel operations (retrieving connected victim information, sending redirect instructions).",{"data":47039,"content":47040,"nodeType":945},{},[47041],{"data":47042,"content":47043,"nodeType":860},{},[47044,47049],{"data":47045,"marks":47046,"value":47048,"nodeType":864},{},[47047],{"type":899},"j.php",{"data":47050,"marks":47051,"value":47052,"nodeType":864},{},[]," as the endpoint for sending Telegram messages, relaying captured credentials and session logs.",{"data":47054,"content":47055,"nodeType":860},{},[47056],{"data":47057,"marks":47058,"value":47059,"nodeType":864},{},[],"Push found that deployments of Doko's Panel had minimal security by default — anyone was able to view the admin panel and manage visitors' connections without authentication.",{"data":47061,"content":47065,"nodeType":996},{"target":47062},{"sys":47063},{"id":47064,"type":1001,"linkType":1002},"3glwGSGHdCpf3DLqNmQqN8",[],{"data":47067,"content":47071,"nodeType":996},{"target":47068},{"sys":47069},{"id":47070,"type":1001,"linkType":1002},"20ymWIXMkmJlw7XYb93c9o",[],{"data":47073,"content":47074,"nodeType":1312},{},[47075],{"data":47076,"marks":47077,"value":47079,"nodeType":864},{},[47078],{"type":899},"Panel proliferation and remixes",{"data":47081,"content":47082,"nodeType":860},{},[47083],{"data":47084,"marks":47085,"value":47086,"nodeType":864},{},[],"Access to Doko's Panel has clearly proliferated beyond its original developers, resulting in remixes and variants being distributed across the ecosystem. Push identified a variant titled \"Lord Mensius's Panel\" targeting Koinly (a cryptocurrency tax platform), and another titled \"$$$\" using a template impersonating the Australian Tax Office, also targeting cryptocurrency tax filing. ",{"data":47088,"content":47089,"nodeType":860},{},[47090],{"data":47091,"marks":47092,"value":47093,"nodeType":864},{},[],"The existence of these independently branded forks indicates that the tooling has entered a phase of wider distribution — operators who obtained the original panel source are now customizing and reshipping it for their own purposes. As a result, the tooling is now accessible to a broad population of financially motivated threat actors. ",{"data":47095,"content":47096,"nodeType":1312},{},[47097],{"data":47098,"marks":47099,"value":47101,"nodeType":864},{},[47100],{"type":899},"heartbeat/check_redirect variant",{"data":47103,"content":47104,"nodeType":860},{},[47105],{"data":47106,"marks":47107,"value":47108,"nodeType":864},{},[],"In addition to Doko’s Panel and its forks, the site initially detected by Push used a modified variant of Doko's Panel with a different C2 protocol. Rather than the standard ping action, this variant sent two types of regular requests from client.js to the backend:",{"data":47110,"content":47111,"nodeType":941},{},[47112,47127],{"data":47113,"content":47114,"nodeType":945},{},[47115],{"data":47116,"content":47117,"nodeType":860},{},[47118,47123],{"data":47119,"marks":47120,"value":47122,"nodeType":864},{},[47121],{"type":899},"Heartbeat",{"data":47124,"marks":47125,"value":47126,"nodeType":864},{},[]," — POST to backend.php with action=heartbeat along with page, token, and window_id.",{"data":47128,"content":47129,"nodeType":945},{},[47130],{"data":47131,"content":47132,"nodeType":860},{},[47133,47138],{"data":47134,"marks":47135,"value":47137,"nodeType":864},{},[47136],{"type":899},"Check Redirect",{"data":47139,"marks":47140,"value":47141,"nodeType":864},{},[]," — GET to backend.php with parameters action=check_redirect along with token and window_id.",{"data":47143,"content":47144,"nodeType":860},{},[47145],{"data":47146,"marks":47147,"value":47148,"nodeType":864},{},[],"A redirect instruction in response to either request causes the victim's browser to navigate to the specified page. The variant compounds this with a separate inline script embedded in the landing gate HTML — in addition to client.js — that schedules its own sendHeartbeat() and checkRedirect() functions on regular intervals. ",{"data":47150,"content":47154,"nodeType":996},{"target":47151},{"sys":47152},{"id":47153,"type":1001,"linkType":1002},"6zRc9ublZvEQCxcWtMBSnF",[],{"data":47156,"content":47157,"nodeType":860},{},[47158],{"data":47159,"marks":47160,"value":47161,"nodeType":864},{},[],"Additional technical differentiators for this variant include:",{"data":47163,"content":47164,"nodeType":941},{},[47165,47180,47195],{"data":47166,"content":47167,"nodeType":945},{},[47168],{"data":47169,"content":47170,"nodeType":860},{},[47171,47176],{"data":47172,"marks":47173,"value":47175,"nodeType":864},{},[47174],{"type":899},"UUID generation",{"data":47177,"marks":47178,"value":47179,"nodeType":864},{},[]," using Math.random() to replace x in the template xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx, rather than the original Doko's Panel method of constructing a template from [1e7]+-1e3+-4e3+-8e3+-1e11 and replacing [018].",{"data":47181,"content":47182,"nodeType":945},{},[47183],{"data":47184,"content":47185,"nodeType":860},{},[47186,47191],{"data":47187,"marks":47188,"value":47190,"nodeType":864},{},[47189],{"type":899},"No central Telegram sending function",{"data":47192,"marks":47193,"value":47194,"nodeType":864},{},[],", though j.php still exists and is called from inline scripts on individual phishing pages.",{"data":47196,"content":47197,"nodeType":945},{},[47198],{"data":47199,"content":47200,"nodeType":860},{},[47201,47206],{"data":47202,"marks":47203,"value":47205,"nodeType":864},{},[47204],{"type":899},"No use of FNV-1a",{"data":47207,"marks":47208,"value":47209,"nodeType":864},{},[]," to hash-generate the window ID.",{"data":47211,"content":47212,"nodeType":860},{},[47213],{"data":47214,"marks":47215,"value":47216,"nodeType":864},{},[],"Push also found sub-variants hosting Okta phishing pages with additional modifications: a minified client.js script, and a renamed backend endpoint (api_FyekIDWY.php replacing backend.php).",{"data":47218,"content":47219,"nodeType":1312},{},[47220],{"data":47221,"marks":47222,"value":47224,"nodeType":864},{},[47223],{"type":899},"Revamped admin panel",{"data":47226,"content":47227,"nodeType":860},{},[47228],{"data":47229,"marks":47230,"value":47231,"nodeType":864},{},[],"Push also found examples of a significantly revamped admin panel, including a version from April 2026 specifically targeting Microsoft as an enterprise identity provider. ",{"data":47233,"content":47237,"nodeType":996},{"target":47234},{"sys":47235},{"id":47236,"type":1001,"linkType":1002},"3ufb4cotpg0f7yoIQJnND0",[],{"data":47239,"content":47240,"nodeType":860},{},[47241],{"data":47242,"marks":47243,"value":47244,"nodeType":864},{},[],"This panel featured a more sophisticated operator interface with an updated look, quick action buttons, and sound notifications.",{"data":47246,"content":47247,"nodeType":860},{},[47248],{"data":47249,"marks":47250,"value":47251,"nodeType":864},{},[],"In addition to the standard compromise flow for acquiring email, password, and OTP, this panel provided operator actions for sending Microsoft Teams call instructions to the victim — a Meeting ID and Passcode rendered on a branded page. This capability likely enables further interaction through a channel that supports screensharing, extending the attacker's reach beyond credential theft into live session manipulation. It also has the potential to make the scenario more believable for the victim.",{"data":47253,"content":47257,"nodeType":996},{"target":47254},{"sys":47255},{"id":47256,"type":1001,"linkType":1002},"4pg65d1SvTJA3xm6AsxZBp",[],{"data":47259,"content":47260,"nodeType":860},{},[47261],{"data":47262,"marks":47263,"value":47264,"nodeType":864},{},[],"Other capabilities were referenced in the panel's source code but did not appear active in the observed deployment:",{"data":47266,"content":47267,"nodeType":941},{},[47268,47283],{"data":47269,"content":47270,"nodeType":945},{},[47271],{"data":47272,"content":47273,"nodeType":860},{},[47274,47279],{"data":47275,"marks":47276,"value":47278,"nodeType":864},{},[47277],{"type":899},"Additional MFA approval pages",{"data":47280,"marks":47281,"value":47282,"nodeType":864},{},[]," for Duo and Okta, with the operator providing a code to display to the victim.",{"data":47284,"content":47285,"nodeType":945},{},[47286],{"data":47287,"content":47288,"nodeType":860},{},[47289,47294],{"data":47290,"marks":47291,"value":47293,"nodeType":864},{},[47292],{"type":899},"A code execution prompt",{"data":47295,"marks":47296,"value":47297,"nodeType":864},{},[]," to instruct the victim to run a command — the placeholder example being mshta to execute a remote HTA file, suggesting a potential bridge from identity compromise into malware delivery.",{"data":47299,"content":47300,"nodeType":860},{},[47301],{"data":47302,"marks":47303,"value":47304,"nodeType":864},{},[],"The admin panel also included settings for restricting access to specific geographic locations and device types, allowing operators to refine their campaign targeting and also avoid detection from unusual devices (often an indicator that the visitor is not a real human and is actually a security tool or bot).",{"data":47306,"content":47310,"nodeType":996},{"target":47307},{"sys":47308},{"id":47309,"type":1001,"linkType":1002},"1hebGtxbkyuejWXczwx5n6",[],{"data":47312,"content":47313,"nodeType":1005},{},[],{"data":47315,"content":47316,"nodeType":1009},{},[47317],{"data":47318,"marks":47319,"value":47321,"nodeType":864},{},[47320],{"type":899},"LLM-generated tells: vibe-coded phishing infrastructure",{"data":47323,"content":47324,"nodeType":860},{},[47325],{"data":47326,"marks":47327,"value":47328,"nodeType":864},{},[],"Evidence of extensive LLM use is extremely prevalent in attacks detected by Push, from LLM-generated phishing kits and tools to vibe-coded cloned pages. Attackers have also been observed leveraging AI–assisted capabilities in SaaS platforms to automate and scale-up their campaigns from an infrastructure and operations perspective. ",{"data":47330,"content":47331,"nodeType":860},{},[47332],{"data":47333,"marks":47334,"value":47335,"nodeType":864},{},[],"The ‘heartbeat’ variant in particular has significant tells of heavy use of LLMs to modify the phishing panel for the operator’s needs. The fact that these are so blatant increases the belief that these tools are being vibe-coded by relatively inexperienced developers with limited regard for operational security.",{"data":47337,"content":47338,"nodeType":860},{},[47339],{"data":47340,"marks":47341,"value":47342,"nodeType":864},{},[],"Some versions of client.js begin with verbose header comments that no human developer would write:",{"data":47344,"content":47347,"nodeType":996},{"target":47345},{"sys":47346},{"id":13395,"type":1001,"linkType":1002},[],{"data":47349,"content":47350,"nodeType":860},{},[47351],{"data":47352,"marks":47353,"value":47354,"nodeType":864},{},[],"The \"NOTES FOR NEXT SESSION\" header is particularly telling — it's a pattern generated by LLMs that maintain context between chat sessions, not a convention any human developer would adopt in production code, let alone in a phishing kit where operational security should discourage self-documenting infrastructure.",{"data":47356,"content":47357,"nodeType":860},{},[47358],{"data":47359,"marks":47360,"value":47361,"nodeType":864},{},[],"The admin panel HTML contains similarly over-documented opening comments:",{"data":47363,"content":47367,"nodeType":996},{"target":47364},{"sys":47365},{"id":47366,"type":1001,"linkType":1002},"60snRhz0RIsvLI6OU9RDOk",[],{"data":47369,"content":47370,"nodeType":860},{},[47371],{"data":47372,"marks":47373,"value":47374,"nodeType":864},{},[],"One of the Okta cloned login pages observed by Push contained the following comments suggesting the use of an LLM to create the clone:",{"data":47376,"content":47380,"nodeType":996},{"target":47377},{"sys":47378},{"id":47379,"type":1001,"linkType":1002},"1WCd5LQ6cfPf1IsNAhPSIT",[],{"data":47382,"content":47383,"nodeType":860},{},[47384],{"data":47385,"marks":47386,"value":47387,"nodeType":864},{},[],"The cloned Microsoft login pages displayed previously contain terser comments, but still typical of useless comments that are included by an LLM rather than a human author, especially a malware/phishing author:",{"data":47389,"content":47393,"nodeType":996},{"target":47390},{"sys":47391},{"id":47392,"type":1001,"linkType":1002},"6WN59mkiscNmAt8dmOR81c",[],{"data":47395,"content":47396,"nodeType":860},{},[47397],{"data":47398,"marks":47399,"value":47400,"nodeType":864},{},[],"The broken duplication in the heartbeat variant — where an inline script and client.js independently schedule the same backend requests using slightly different data formats — is consistent with an operator pasting requirements into an LLM and accepting the output without understanding the existing codebase well enough to recognize the redundancy.",{"data":47402,"content":47403,"nodeType":860},{},[47404],{"data":47405,"marks":47406,"value":47407,"nodeType":864},{},[],"Clearly, the barrier to entry for building (or forking) and operating a real-time vishing phishing panel is lower than the effectiveness of the tooling might suggest.",{"data":47409,"content":47410,"nodeType":1005},{},[],{"data":47412,"content":47413,"nodeType":1009},{},[47414],{"data":47415,"marks":47416,"value":47418,"nodeType":864},{},[47417],{"type":899},"Infrastructure clustering and attribution",{"data":47420,"content":47421,"nodeType":860},{},[47422,47426,47431],{"data":47423,"marks":47424,"value":47425,"nodeType":864},{},[],"Through analysis of phishing domains, hosting infrastructure, and technical indicators in the panel source code, ",{"data":47427,"marks":47428,"value":47430,"nodeType":864},{},[47429],{"type":899},"we’re highlighting four distinct infrastructure clusters associated with this tooling. ",{"data":47432,"marks":47433,"value":47434,"nodeType":864},{},[],"While the panels share common heritage, the operators deploying them appear to be separate groups with different infrastructure preferences and operational patterns.",{"data":47436,"content":47437,"nodeType":1312},{},[47438],{"data":47439,"marks":47440,"value":47441,"nodeType":864},{},[],"Cluster A",{"data":47443,"content":47444,"nodeType":860},{},[47445,47449,47457],{"data":47446,"marks":47447,"value":47448,"nodeType":864},{},[],"The indicators for Cluster A overlap with ",{"data":47450,"content":47451,"nodeType":883},{"uri":28821},[47452],{"data":47453,"marks":47454,"value":47456,"nodeType":864},{},[47455],{"type":1455},"Mandiant’s reporting on UNC6661",{"data":47458,"marks":47459,"value":47460,"nodeType":864},{},[],". Mandiant also attributes the extortion activity following UNC6661 intrusions to UNC6240, aka ShinyHunters.",{"data":47462,"content":47463,"nodeType":4845},{},[47464,47488,47517,47540,47591,47635,47658,47681],{"data":47465,"content":47466,"nodeType":4581},{},[47467,47478],{"data":47468,"content":47469,"nodeType":4569},{},[47470],{"data":47471,"content":47472,"nodeType":860},{},[47473],{"data":47474,"marks":47475,"value":47477,"nodeType":864},{},[47476],{"type":899},"Tool",{"data":47479,"content":47480,"nodeType":4569},{},[47481],{"data":47482,"content":47483,"nodeType":860},{},[47484],{"data":47485,"marks":47486,"value":46975,"nodeType":864},{},[47487],{"type":899},{"data":47489,"content":47490,"nodeType":4581},{},[47491,47500],{"data":47492,"content":47493,"nodeType":4569},{},[47494],{"data":47495,"content":47496,"nodeType":860},{},[47497],{"data":47498,"marks":47499,"value":47003,"nodeType":864},{},[],{"data":47501,"content":47502,"nodeType":4569},{},[47503,47510],{"data":47504,"content":47505,"nodeType":860},{},[47506],{"data":47507,"marks":47508,"value":47509,"nodeType":864},{},[],"8a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44c",{"data":47511,"content":47512,"nodeType":860},{},[47513],{"data":47514,"marks":47515,"value":47516,"nodeType":864},{},[],"f574b6e6b3a968cda5f51bec2c090d8eb095fbcfc383314f94bc15676a0d6692",{"data":47518,"content":47519,"nodeType":4581},{},[47520,47530],{"data":47521,"content":47522,"nodeType":4569},{},[47523],{"data":47524,"content":47525,"nodeType":860},{},[47526],{"data":47527,"marks":47528,"value":47529,"nodeType":864},{},[],"Timeframe",{"data":47531,"content":47532,"nodeType":4569},{},[47533],{"data":47534,"content":47535,"nodeType":860},{},[47536],{"data":47537,"marks":47538,"value":47539,"nodeType":864},{},[],"November 2025 - present (April 2026)",{"data":47541,"content":47542,"nodeType":4581},{},[47543,47553],{"data":47544,"content":47545,"nodeType":4569},{},[47546],{"data":47547,"content":47548,"nodeType":860},{},[47549],{"data":47550,"marks":47551,"value":47552,"nodeType":864},{},[],"Domain Patterns",{"data":47554,"content":47555,"nodeType":4569},{},[47556,47563,47570,47577,47584],{"data":47557,"content":47558,"nodeType":860},{},[47559],{"data":47560,"marks":47561,"value":47562,"nodeType":864},{},[],"\u003Ctarget>internal.com\n\u003Ctarget>sso.com",{"data":47564,"content":47565,"nodeType":860},{},[47566],{"data":47567,"marks":47568,"value":47569,"nodeType":864},{},[],"my\u003Ctarget>.com",{"data":47571,"content":47572,"nodeType":860},{},[47573],{"data":47574,"marks":47575,"value":47576,"nodeType":864},{},[],"my\u003Ctarget>internal.com",{"data":47578,"content":47579,"nodeType":860},{},[47580],{"data":47581,"marks":47582,"value":47583,"nodeType":864},{},[],"my\u003Ctarget>manager.com",{"data":47585,"content":47586,"nodeType":860},{},[47587],{"data":47588,"marks":47589,"value":47590,"nodeType":864},{},[],"my\u003Ctarget>sso.com",{"data":47592,"content":47593,"nodeType":4581},{},[47594,47604],{"data":47595,"content":47596,"nodeType":4569},{},[47597],{"data":47598,"content":47599,"nodeType":860},{},[47600],{"data":47601,"marks":47602,"value":47603,"nodeType":864},{},[],"Examples",{"data":47605,"content":47606,"nodeType":4569},{},[47607,47614,47621,47628],{"data":47608,"content":47609,"nodeType":860},{},[47610],{"data":47611,"marks":47612,"value":47613,"nodeType":864},{},[],"mydropboxinternal.com (November 2025)",{"data":47615,"content":47616,"nodeType":860},{},[47617],{"data":47618,"marks":47619,"value":47620,"nodeType":864},{},[],"myxerointernal.com (December 2025)",{"data":47622,"content":47623,"nodeType":860},{},[47624],{"data":47625,"marks":47626,"value":47627,"nodeType":864},{},[],"amazoninternal.com (March 2026)",{"data":47629,"content":47630,"nodeType":860},{},[47631],{"data":47632,"marks":47633,"value":47634,"nodeType":864},{},[],"mydisneysso.com (March 2026)",{"data":47636,"content":47637,"nodeType":4581},{},[47638,47648],{"data":47639,"content":47640,"nodeType":4569},{},[47641],{"data":47642,"content":47643,"nodeType":860},{},[47644],{"data":47645,"marks":47646,"value":47647,"nodeType":864},{},[],"Registrar",{"data":47649,"content":47650,"nodeType":4569},{},[47651],{"data":47652,"content":47653,"nodeType":860},{},[47654],{"data":47655,"marks":47656,"value":47657,"nodeType":864},{},[],"NiceNIC",{"data":47659,"content":47660,"nodeType":4581},{},[47661,47671],{"data":47662,"content":47663,"nodeType":4569},{},[47664],{"data":47665,"content":47666,"nodeType":860},{},[47667],{"data":47668,"marks":47669,"value":47670,"nodeType":864},{},[],"Name Servers",{"data":47672,"content":47673,"nodeType":4569},{},[47674],{"data":47675,"content":47676,"nodeType":860},{},[47677],{"data":47678,"marks":47679,"value":47680,"nodeType":864},{},[],"1984.is FreeDNS",{"data":47682,"content":47683,"nodeType":4581},{},[47684,47694],{"data":47685,"content":47686,"nodeType":4569},{},[47687],{"data":47688,"content":47689,"nodeType":860},{},[47690],{"data":47691,"marks":47692,"value":47693,"nodeType":864},{},[],"Hosting Provider",{"data":47695,"content":47696,"nodeType":4569},{},[47697],{"data":47698,"content":47699,"nodeType":860},{},[47700],{"data":47701,"marks":47702,"value":47703,"nodeType":864},{},[],"Mevspace (AS201814)",{"data":47705,"content":47706,"nodeType":1312},{},[47707],{"data":47708,"marks":47709,"value":47710,"nodeType":864},{},[],"Cluster B",{"data":47712,"content":47713,"nodeType":860},{},[47714,47718,47726,47729,47738],{"data":47715,"marks":47716,"value":47717,"nodeType":864},{},[],"The indicators for Cluster B overlap with ",{"data":47719,"content":47720,"nodeType":883},{"uri":28821},[47721],{"data":47722,"marks":47723,"value":47725,"nodeType":864},{},[47724],{"type":1455},"Mandiant’s reporting on UNC6671",{"data":47727,"marks":47728,"value":1774,"nodeType":864},{},[],{"data":47730,"content":47732,"nodeType":883},{"uri":47731},"https://rhisac.org/threat-intelligence/extortion-in-the-enterprise-defending-against-blackfile-attacks/",[47733],{"data":47734,"marks":47735,"value":47737,"nodeType":864},{},[47736],{"type":1455},"Other external reporting",{"data":47739,"marks":47740,"value":47741,"nodeType":864},{},[]," has linked this group to BlackFile-branded extortion and leaks.",{"data":47743,"content":47744,"nodeType":4845},{},[47745,47768,47811,47833,47868,47911,47933,47955],{"data":47746,"content":47747,"nodeType":4581},{},[47748,47758],{"data":47749,"content":47750,"nodeType":4569},{},[47751],{"data":47752,"content":47753,"nodeType":860},{},[47754],{"data":47755,"marks":47756,"value":47477,"nodeType":864},{},[47757],{"type":899},{"data":47759,"content":47760,"nodeType":4569},{},[47761],{"data":47762,"content":47763,"nodeType":860},{},[47764],{"data":47765,"marks":47766,"value":47101,"nodeType":864},{},[47767],{"type":899},{"data":47769,"content":47770,"nodeType":4581},{},[47771,47780],{"data":47772,"content":47773,"nodeType":4569},{},[47774],{"data":47775,"content":47776,"nodeType":860},{},[47777],{"data":47778,"marks":47779,"value":47003,"nodeType":864},{},[],{"data":47781,"content":47782,"nodeType":4569},{},[47783,47790,47797,47804],{"data":47784,"content":47785,"nodeType":860},{},[47786],{"data":47787,"marks":47788,"value":47789,"nodeType":864},{},[],"c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26",{"data":47791,"content":47792,"nodeType":860},{},[47793],{"data":47794,"marks":47795,"value":47796,"nodeType":864},{},[],"d178dc7108fa9344dae28e350e810352e9e874563496dc7876ee628b11b0eabb",{"data":47798,"content":47799,"nodeType":860},{},[47800],{"data":47801,"marks":47802,"value":47803,"nodeType":864},{},[],"9c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21",{"data":47805,"content":47806,"nodeType":860},{},[47807],{"data":47808,"marks":47809,"value":47810,"nodeType":864},{},[],"e8128b33259f7ea4313c942689ba0ba557f17b1474f2e621c62a5b77674fab86",{"data":47812,"content":47813,"nodeType":4581},{},[47814,47823],{"data":47815,"content":47816,"nodeType":4569},{},[47817],{"data":47818,"content":47819,"nodeType":860},{},[47820],{"data":47821,"marks":47822,"value":47529,"nodeType":864},{},[],{"data":47824,"content":47825,"nodeType":4569},{},[47826],{"data":47827,"content":47828,"nodeType":860},{},[47829],{"data":47830,"marks":47831,"value":47832,"nodeType":864},{},[],"January 2026",{"data":47834,"content":47835,"nodeType":4581},{},[47836,47845],{"data":47837,"content":47838,"nodeType":4569},{},[47839],{"data":47840,"content":47841,"nodeType":860},{},[47842],{"data":47843,"marks":47844,"value":47552,"nodeType":864},{},[],{"data":47846,"content":47847,"nodeType":4569},{},[47848,47855,47862],{"data":47849,"content":47850,"nodeType":860},{},[47851],{"data":47852,"marks":47853,"value":47854,"nodeType":864},{},[],"\u003Ctarget>internal.com",{"data":47856,"content":47857,"nodeType":860},{},[47858],{"data":47859,"marks":47860,"value":47861,"nodeType":864},{},[],"\u003Ctarget>sso.com",{"data":47863,"content":47864,"nodeType":860},{},[47865],{"data":47866,"marks":47867,"value":47590,"nodeType":864},{},[],{"data":47869,"content":47870,"nodeType":4581},{},[47871,47880],{"data":47872,"content":47873,"nodeType":4569},{},[47874],{"data":47875,"content":47876,"nodeType":860},{},[47877],{"data":47878,"marks":47879,"value":47603,"nodeType":864},{},[],{"data":47881,"content":47882,"nodeType":4569},{},[47883,47890,47897,47904],{"data":47884,"content":47885,"nodeType":860},{},[47886],{"data":47887,"marks":47888,"value":47889,"nodeType":864},{},[],"epicgamessso[.]com (December 2025)",{"data":47891,"content":47892,"nodeType":860},{},[47893],{"data":47894,"marks":47895,"value":47896,"nodeType":864},{},[],"myadyeninternal[.]com (January 2026)",{"data":47898,"content":47899,"nodeType":860},{},[47900],{"data":47901,"marks":47902,"value":47903,"nodeType":864},{},[],"mysonossso[.]com (January 2026)",{"data":47905,"content":47906,"nodeType":860},{},[47907],{"data":47908,"marks":47909,"value":47910,"nodeType":864},{},[],"sonosinternal[.]com (January 2026)",{"data":47912,"content":47913,"nodeType":4581},{},[47914,47923],{"data":47915,"content":47916,"nodeType":4569},{},[47917],{"data":47918,"content":47919,"nodeType":860},{},[47920],{"data":47921,"marks":47922,"value":47647,"nodeType":864},{},[],{"data":47924,"content":47925,"nodeType":4569},{},[47926],{"data":47927,"content":47928,"nodeType":860},{},[47929],{"data":47930,"marks":47931,"value":47932,"nodeType":864},{},[],"Tucows",{"data":47934,"content":47935,"nodeType":4581},{},[47936,47945],{"data":47937,"content":47938,"nodeType":4569},{},[47939],{"data":47940,"content":47941,"nodeType":860},{},[47942],{"data":47943,"marks":47944,"value":47670,"nodeType":864},{},[],{"data":47946,"content":47947,"nodeType":4569},{},[47948],{"data":47949,"content":47950,"nodeType":860},{},[47951],{"data":47952,"marks":47953,"value":47954,"nodeType":864},{},[],"Njalla",{"data":47956,"content":47957,"nodeType":4581},{},[47958,47967],{"data":47959,"content":47960,"nodeType":4569},{},[47961],{"data":47962,"content":47963,"nodeType":860},{},[47964],{"data":47965,"marks":47966,"value":47693,"nodeType":864},{},[],{"data":47968,"content":47969,"nodeType":4569},{},[47970],{"data":47971,"content":47972,"nodeType":860},{},[47973],{"data":47974,"marks":47975,"value":47976,"nodeType":864},{},[],"Njalla (AS39287)",{"data":47978,"content":47979,"nodeType":1312},{},[47980],{"data":47981,"marks":47982,"value":47983,"nodeType":864},{},[],"Cluster C",{"data":47985,"content":47986,"nodeType":860},{},[47987],{"data":47988,"marks":47989,"value":47990,"nodeType":864},{},[],"Cluster C is likely an evolution of Cluster B. Some evidence has been observed tying the backend hosting to Njalla behind the Cloudflare CDN further solidifying the link. The shift to Cloudflare Turnstile protection and subdomain-based targeting represents an operational refinement — moving away from the distinctive [target]internal[.]com pattern that had become a well-known campaign indicator.",{"data":47992,"content":47993,"nodeType":4845},{},[47994,48018,48040,48062,48084,48127,48148,48170],{"data":47995,"content":47996,"nodeType":4581},{},[47997,48007],{"data":47998,"content":47999,"nodeType":4569},{},[48000],{"data":48001,"content":48002,"nodeType":860},{},[48003],{"data":48004,"marks":48005,"value":47477,"nodeType":864},{},[48006],{"type":899},{"data":48008,"content":48009,"nodeType":4569},{},[48010],{"data":48011,"content":48012,"nodeType":860},{},[48013],{"data":48014,"marks":48015,"value":48017,"nodeType":864},{},[48016],{"type":899},"heartbeat/check_redirect variant protected with Cloudflare turnstile",{"data":48019,"content":48020,"nodeType":4581},{},[48021,48030],{"data":48022,"content":48023,"nodeType":4569},{},[48024],{"data":48025,"content":48026,"nodeType":860},{},[48027],{"data":48028,"marks":48029,"value":47003,"nodeType":864},{},[],{"data":48031,"content":48032,"nodeType":4569},{},[48033],{"data":48034,"content":48035,"nodeType":860},{},[48036],{"data":48037,"marks":48038,"value":48039,"nodeType":864},{},[],"cb1d409278b2247af23e7b00ac779b232baaf4ce5f63fdf5ebc3920a38cc6102",{"data":48041,"content":48042,"nodeType":4581},{},[48043,48052],{"data":48044,"content":48045,"nodeType":4569},{},[48046],{"data":48047,"content":48048,"nodeType":860},{},[48049],{"data":48050,"marks":48051,"value":47529,"nodeType":864},{},[],{"data":48053,"content":48054,"nodeType":4569},{},[48055],{"data":48056,"content":48057,"nodeType":860},{},[48058],{"data":48059,"marks":48060,"value":48061,"nodeType":864},{},[],"March 2026 - present (April 2026)",{"data":48063,"content":48064,"nodeType":4581},{},[48065,48074],{"data":48066,"content":48067,"nodeType":4569},{},[48068],{"data":48069,"content":48070,"nodeType":860},{},[48071],{"data":48072,"marks":48073,"value":47552,"nodeType":864},{},[],{"data":48075,"content":48076,"nodeType":4569},{},[48077],{"data":48078,"content":48079,"nodeType":860},{},[48080],{"data":48081,"marks":48082,"value":48083,"nodeType":864},{},[],"\u003Ctarget> subdomain with generic “sso”, “passkey”, “enroll”, “okta” theme root domain",{"data":48085,"content":48086,"nodeType":4581},{},[48087,48096],{"data":48088,"content":48089,"nodeType":4569},{},[48090],{"data":48091,"content":48092,"nodeType":860},{},[48093],{"data":48094,"marks":48095,"value":47603,"nodeType":864},{},[],{"data":48097,"content":48098,"nodeType":4569},{},[48099,48106,48113,48120],{"data":48100,"content":48101,"nodeType":860},{},[48102],{"data":48103,"marks":48104,"value":48105,"nodeType":864},{},[],"\u003Ctarget>.passkeysetup.com (March 2026)",{"data":48107,"content":48108,"nodeType":860},{},[48109],{"data":48110,"marks":48111,"value":48112,"nodeType":864},{},[],"\u003Ctarget>.enrollms.com (March 2026)",{"data":48114,"content":48115,"nodeType":860},{},[48116],{"data":48117,"marks":48118,"value":48119,"nodeType":864},{},[],"\u003Ctarget>.keyokta.com (April 2026)",{"data":48121,"content":48122,"nodeType":860},{},[48123],{"data":48124,"marks":48125,"value":48126,"nodeType":864},{},[],"\u003Ctarget>.passkeywork.com (April 2026)",{"data":48128,"content":48129,"nodeType":4581},{},[48130,48139],{"data":48131,"content":48132,"nodeType":4569},{},[48133],{"data":48134,"content":48135,"nodeType":860},{},[48136],{"data":48137,"marks":48138,"value":47647,"nodeType":864},{},[],{"data":48140,"content":48141,"nodeType":4569},{},[48142],{"data":48143,"content":48144,"nodeType":860},{},[48145],{"data":48146,"marks":48147,"value":47932,"nodeType":864},{},[],{"data":48149,"content":48150,"nodeType":4581},{},[48151,48160],{"data":48152,"content":48153,"nodeType":4569},{},[48154],{"data":48155,"content":48156,"nodeType":860},{},[48157],{"data":48158,"marks":48159,"value":47670,"nodeType":864},{},[],{"data":48161,"content":48162,"nodeType":4569},{},[48163],{"data":48164,"content":48165,"nodeType":860},{},[48166],{"data":48167,"marks":48168,"value":48169,"nodeType":864},{},[],"Cloudflare",{"data":48171,"content":48172,"nodeType":4581},{},[48173,48182],{"data":48174,"content":48175,"nodeType":4569},{},[48176],{"data":48177,"content":48178,"nodeType":860},{},[48179],{"data":48180,"marks":48181,"value":47693,"nodeType":864},{},[],{"data":48183,"content":48184,"nodeType":4569},{},[48185],{"data":48186,"content":48187,"nodeType":860},{},[48188],{"data":48189,"marks":48190,"value":48191,"nodeType":864},{},[],"Cloudflare (AS13335)",{"data":48193,"content":48194,"nodeType":1312},{},[48195],{"data":48196,"marks":48197,"value":48198,"nodeType":864},{},[],"Cluster D",{"data":48200,"content":48201,"nodeType":4845},{},[48202,48226,48248,48270,48292,48321,48342,48363],{"data":48203,"content":48204,"nodeType":4581},{},[48205,48215],{"data":48206,"content":48207,"nodeType":4569},{},[48208],{"data":48209,"content":48210,"nodeType":860},{},[48211],{"data":48212,"marks":48213,"value":47477,"nodeType":864},{},[48214],{"type":899},{"data":48216,"content":48217,"nodeType":4569},{},[48218],{"data":48219,"content":48220,"nodeType":860},{},[48221],{"data":48222,"marks":48223,"value":48225,"nodeType":864},{},[48224],{"type":899},"heartbeat/check_redirect variant (minified)",{"data":48227,"content":48228,"nodeType":4581},{},[48229,48238],{"data":48230,"content":48231,"nodeType":4569},{},[48232],{"data":48233,"content":48234,"nodeType":860},{},[48235],{"data":48236,"marks":48237,"value":47003,"nodeType":864},{},[],{"data":48239,"content":48240,"nodeType":4569},{},[48241],{"data":48242,"content":48243,"nodeType":860},{},[48244],{"data":48245,"marks":48246,"value":48247,"nodeType":864},{},[],"9d65dd34384b441505e6b67647153c02d5c367bb53da36ce36a392e70b37940a",{"data":48249,"content":48250,"nodeType":4581},{},[48251,48260],{"data":48252,"content":48253,"nodeType":4569},{},[48254],{"data":48255,"content":48256,"nodeType":860},{},[48257],{"data":48258,"marks":48259,"value":47529,"nodeType":864},{},[],{"data":48261,"content":48262,"nodeType":4569},{},[48263],{"data":48264,"content":48265,"nodeType":860},{},[48266],{"data":48267,"marks":48268,"value":48269,"nodeType":864},{},[],"April 2026 (low volume)",{"data":48271,"content":48272,"nodeType":4581},{},[48273,48282],{"data":48274,"content":48275,"nodeType":4569},{},[48276],{"data":48277,"content":48278,"nodeType":860},{},[48279],{"data":48280,"marks":48281,"value":47552,"nodeType":864},{},[],{"data":48283,"content":48284,"nodeType":4569},{},[48285],{"data":48286,"content":48287,"nodeType":860},{},[48288],{"data":48289,"marks":48290,"value":48291,"nodeType":864},{},[],"\u003Ctarget> subdomain with generic “passkey”, “portal”, “okta” theme root domain",{"data":48293,"content":48294,"nodeType":4581},{},[48295,48304],{"data":48296,"content":48297,"nodeType":4569},{},[48298],{"data":48299,"content":48300,"nodeType":860},{},[48301],{"data":48302,"marks":48303,"value":47603,"nodeType":864},{},[],{"data":48305,"content":48306,"nodeType":4569},{},[48307,48314],{"data":48308,"content":48309,"nodeType":860},{},[48310],{"data":48311,"marks":48312,"value":48313,"nodeType":864},{},[],"\u003Ctarget>.passkeyportalsetup.com",{"data":48315,"content":48316,"nodeType":860},{},[48317],{"data":48318,"marks":48319,"value":48320,"nodeType":864},{},[],"\u003Ctarget>.addoktapasskey.com",{"data":48322,"content":48323,"nodeType":4581},{},[48324,48333],{"data":48325,"content":48326,"nodeType":4569},{},[48327],{"data":48328,"content":48329,"nodeType":860},{},[48330],{"data":48331,"marks":48332,"value":47647,"nodeType":864},{},[],{"data":48334,"content":48335,"nodeType":4569},{},[48336],{"data":48337,"content":48338,"nodeType":860},{},[48339],{"data":48340,"marks":48341,"value":47657,"nodeType":864},{},[],{"data":48343,"content":48344,"nodeType":4581},{},[48345,48354],{"data":48346,"content":48347,"nodeType":4569},{},[48348],{"data":48349,"content":48350,"nodeType":860},{},[48351],{"data":48352,"marks":48353,"value":47670,"nodeType":864},{},[],{"data":48355,"content":48356,"nodeType":4569},{},[48357],{"data":48358,"content":48359,"nodeType":860},{},[48360],{"data":48361,"marks":48362,"value":48169,"nodeType":864},{},[],{"data":48364,"content":48365,"nodeType":4581},{},[48366,48375],{"data":48367,"content":48368,"nodeType":4569},{},[48369],{"data":48370,"content":48371,"nodeType":860},{},[48372],{"data":48373,"marks":48374,"value":47693,"nodeType":864},{},[],{"data":48376,"content":48377,"nodeType":4569},{},[48378],{"data":48379,"content":48380,"nodeType":860},{},[48381],{"data":48382,"marks":48383,"value":48191,"nodeType":864},{},[],{"data":48385,"content":48386,"nodeType":1005},{},[],{"data":48388,"content":48389,"nodeType":1009},{},[48390],{"data":48391,"marks":48392,"value":48394,"nodeType":864},{},[48393],{"type":899},"Detection considerations",{"data":48396,"content":48397,"nodeType":860},{},[48398],{"data":48399,"marks":48400,"value":48401,"nodeType":864},{},[],"For Push, the detection approach to these panels is fundamentally the same as for any other phishing kit — behavioral analysis of the rendered page in the browser, regardless of the C2 protocol running underneath. ",{"data":48403,"content":48404,"nodeType":860},{},[48405],{"data":48406,"marks":48407,"value":48408,"nodeType":864},{},[],"The main operational difference is on the operator end, where the human-in-the-loop interaction replaces fully automated credential harvesting. This has implications for defenders relying on proactive infrastructure scanning: the gated landing pages, anti-bot checks, and operator-approval requirements mean the malicious content is only served to active targets, making it significantly harder for automated scanners to discover and flag these domains before they're used against a victim.",{"data":48410,"content":48411,"nodeType":860},{},[48412,48417],{"data":48413,"marks":48414,"value":48416,"nodeType":864},{},[48415],{"type":899},"The phone call as delivery vector eliminates the email-based detection surface that most organizations rely on as their primary phishing defense. ",{"data":48418,"marks":48419,"value":48420,"nodeType":864},{},[],"Operator-gated payload delivery further reduces the likelihood that these sites will be flagged as malicious and added to known-bad detection lists (and in any case, it’s trivial for attackers to spin up new ones). This reinforces the need for browser-based detection at the point the user interacts with the page, analyzing it in real time for malicious content without relying on static IoCs. ",{"data":48422,"content":48423,"nodeType":1005},{},[],{"data":48425,"content":48426,"nodeType":1009},{},[48427],{"data":48428,"marks":48429,"value":14420,"nodeType":864},{},[48430],{"type":899},{"data":48432,"content":48433,"nodeType":860},{},[48434,48438,48444],{"data":48435,"marks":48436,"value":48437,"nodeType":864},{},[],"Short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":48439,"content":48440,"nodeType":883},{"uri":14430},[48441],{"data":48442,"marks":48443,"value":14435,"nodeType":864},{},[],{"data":48445,"marks":48446,"value":48447,"nodeType":864},{},[]," in the attack chain, often dynamically serving different URLs to site visitors. ",{"data":48449,"content":48450,"nodeType":860},{},[48451,48454,48462],{"data":48452,"marks":48453,"value":21,"nodeType":864},{},[],{"data":48455,"content":48457,"nodeType":883},{"uri":48456},"https://www.virustotal.com/gui/collection/0f745e9da6ef7664444594a7ee930cfe5a9d8bd6c2f039dcde818599b8926610",[48458],{"data":48459,"marks":48460,"value":48461,"nodeType":864},{},[],"The full list of IoCs is on VirusTotal here. ",{"data":48463,"marks":48464,"value":21,"nodeType":864},{},[],{"data":48466,"content":48467,"nodeType":860},{},[48468],{"data":48469,"marks":48470,"value":14377,"nodeType":864},{},[48471],{"type":899},{"data":48473,"content":48474,"nodeType":1005},{},[],{"data":48476,"content":48477,"nodeType":1009},{},[48478],{"data":48479,"marks":48480,"value":3578,"nodeType":864},{},[48481],{"type":899},{"data":48483,"content":48484,"nodeType":860},{},[48485,48489,48495],{"data":48486,"marks":48487,"value":48488,"nodeType":864},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.\n\nSecurity teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.\n\nBook a ",{"data":48490,"content":48491,"nodeType":883},{"uri":1700},[48492],{"data":48493,"marks":48494,"value":2715,"nodeType":864},{},[],{"data":48496,"marks":48497,"value":2719,"nodeType":864},{},[],"We infiltrated a criminal phishing panel: here’s what we found","We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Here’s what we found.","2026-05-07T00:00:00.000Z","inside-criminal-phishing-panel",{"items":48503},[48504,48506],{"sys":48505,"name":13779},{"id":13778},{"sys":48507,"name":342},{"id":13775},{"items":48509},[48510],{"fullName":48511,"firstName":48512,"jobTitle":2738,"profilePicture":48513},"Push Security Research Team","Research",{"url":48514},"https://images.ctfassets.net/y1cdw1ablpvd/7LpkwyXbOZ8WCVTAXzULmC/bfa3634c78ee9dfbee6606ba5519918b/push-round.png",{"__typename":2059,"sys":48516,"content":48517,"title":16898,"synopsis":16899,"hashTags":59,"publishedDate":16900,"slug":16901,"tagsCollection":49153,"authorsCollection":49159},{"id":16149},{"json":48518},{"data":48519,"content":48520,"nodeType":856},{},[48521,48544,48570,48576,48581,48584,48591,48597,48602,48617,48623,48630,48646,48659,48665,48671,48674,48681,48687,48693,48748,48754,48761,48771,48777,48783,48788,48795,48801,48807,48813,48819,48824,48831,48837,48908,48913,48916,48923,48929,48942,48948,48954,48959,48975,48978,48985,48991,48996,49012,49018,49024,49029,49032,49039,49045,49051,49056,49062,49067,49072,49092,49097,49107,49113,49119],{"data":48522,"content":48523,"nodeType":860},{},[48524,48527,48534,48537,48541],{"data":48525,"marks":48526,"value":16160,"nodeType":864},{},[],{"data":48528,"content":48529,"nodeType":883},{"uri":16015},[48530],{"data":48531,"marks":48532,"value":16168,"nodeType":864},{},[48533],{"type":1455},{"data":48535,"marks":48536,"value":16172,"nodeType":864},{},[],{"data":48538,"marks":48539,"value":16177,"nodeType":864},{},[48540],{"type":899},{"data":48542,"marks":48543,"value":11546,"nodeType":864},{},[],{"data":48545,"content":48546,"nodeType":860},{},[48547,48550,48557,48560,48567],{"data":48548,"marks":48549,"value":16187,"nodeType":864},{},[],{"data":48551,"content":48552,"nodeType":883},{"uri":16190},[48553],{"data":48554,"marks":48555,"value":16196,"nodeType":864},{},[48556],{"type":1455},{"data":48558,"marks":48559,"value":16200,"nodeType":864},{},[],{"data":48561,"content":48562,"nodeType":883},{"uri":16203},[48563],{"data":48564,"marks":48565,"value":16209,"nodeType":864},{},[48566],{"type":1455},{"data":48568,"marks":48569,"value":16213,"nodeType":864},{},[],{"data":48571,"content":48572,"nodeType":860},{},[48573],{"data":48574,"marks":48575,"value":16220,"nodeType":864},{},[],{"data":48577,"content":48580,"nodeType":996},{"target":48578},{"sys":48579},{"id":16225,"type":1001,"linkType":1002},[],{"data":48582,"content":48583,"nodeType":1005},{},[],{"data":48585,"content":48586,"nodeType":1009},{},[48587],{"data":48588,"marks":48589,"value":16237,"nodeType":864},{},[48590],{"type":899},{"data":48592,"content":48593,"nodeType":860},{},[48594],{"data":48595,"marks":48596,"value":16244,"nodeType":864},{},[],{"data":48598,"content":48601,"nodeType":996},{"target":48599},{"sys":48600},{"id":16249,"type":1001,"linkType":1002},[],{"data":48603,"content":48604,"nodeType":860},{},[48605,48608,48614],{"data":48606,"marks":48607,"value":16257,"nodeType":864},{},[],{"data":48609,"content":48610,"nodeType":883},{"uri":16260},[48611],{"data":48612,"marks":48613,"value":16265,"nodeType":864},{},[],{"data":48615,"marks":48616,"value":16269,"nodeType":864},{},[],{"data":48618,"content":48619,"nodeType":860},{},[48620],{"data":48621,"marks":48622,"value":16276,"nodeType":864},{},[],{"data":48624,"content":48625,"nodeType":1312},{},[48626],{"data":48627,"marks":48628,"value":16284,"nodeType":864},{},[48629],{"type":899},{"data":48631,"content":48632,"nodeType":860},{},[48633,48636,48643],{"data":48634,"marks":48635,"value":16291,"nodeType":864},{},[],{"data":48637,"content":48638,"nodeType":883},{"uri":16294},[48639],{"data":48640,"marks":48641,"value":16300,"nodeType":864},{},[48642],{"type":1455},{"data":48644,"marks":48645,"value":16304,"nodeType":864},{},[],{"data":48647,"content":48648,"nodeType":860},{},[48649,48652,48656],{"data":48650,"marks":48651,"value":16311,"nodeType":864},{},[],{"data":48653,"marks":48654,"value":16316,"nodeType":864},{},[48655],{"type":2246},{"data":48657,"marks":48658,"value":16320,"nodeType":864},{},[],{"data":48660,"content":48661,"nodeType":860},{},[48662],{"data":48663,"marks":48664,"value":16327,"nodeType":864},{},[],{"data":48666,"content":48667,"nodeType":860},{},[48668],{"data":48669,"marks":48670,"value":16334,"nodeType":864},{},[],{"data":48672,"content":48673,"nodeType":1005},{},[],{"data":48675,"content":48676,"nodeType":1009},{},[48677],{"data":48678,"marks":48679,"value":16345,"nodeType":864},{},[48680],{"type":899},{"data":48682,"content":48683,"nodeType":860},{},[48684],{"data":48685,"marks":48686,"value":16352,"nodeType":864},{},[],{"data":48688,"content":48689,"nodeType":860},{},[48690],{"data":48691,"marks":48692,"value":16359,"nodeType":864},{},[],{"data":48694,"content":48695,"nodeType":941},{},[48696,48709,48722,48735],{"data":48697,"content":48698,"nodeType":945},{},[48699],{"data":48700,"content":48701,"nodeType":860},{},[48702,48706],{"data":48703,"marks":48704,"value":16373,"nodeType":864},{},[48705],{"type":899},{"data":48707,"marks":48708,"value":16377,"nodeType":864},{},[],{"data":48710,"content":48711,"nodeType":945},{},[48712],{"data":48713,"content":48714,"nodeType":860},{},[48715,48719],{"data":48716,"marks":48717,"value":16388,"nodeType":864},{},[48718],{"type":899},{"data":48720,"marks":48721,"value":16392,"nodeType":864},{},[],{"data":48723,"content":48724,"nodeType":945},{},[48725],{"data":48726,"content":48727,"nodeType":860},{},[48728,48732],{"data":48729,"marks":48730,"value":16403,"nodeType":864},{},[48731],{"type":899},{"data":48733,"marks":48734,"value":16407,"nodeType":864},{},[],{"data":48736,"content":48737,"nodeType":945},{},[48738],{"data":48739,"content":48740,"nodeType":860},{},[48741,48745],{"data":48742,"marks":48743,"value":16418,"nodeType":864},{},[48744],{"type":899},{"data":48746,"marks":48747,"value":16422,"nodeType":864},{},[],{"data":48749,"content":48750,"nodeType":860},{},[48751],{"data":48752,"marks":48753,"value":16429,"nodeType":864},{},[],{"data":48755,"content":48756,"nodeType":1312},{},[48757],{"data":48758,"marks":48759,"value":16437,"nodeType":864},{},[48760],{"type":899},{"data":48762,"content":48763,"nodeType":860},{},[48764,48768],{"data":48765,"marks":48766,"value":16445,"nodeType":864},{},[48767],{"type":899},{"data":48769,"marks":48770,"value":16449,"nodeType":864},{},[],{"data":48772,"content":48773,"nodeType":860},{},[48774],{"data":48775,"marks":48776,"value":16456,"nodeType":864},{},[],{"data":48778,"content":48779,"nodeType":860},{},[48780],{"data":48781,"marks":48782,"value":16463,"nodeType":864},{},[],{"data":48784,"content":48787,"nodeType":996},{"target":48785},{"sys":48786},{"id":16468,"type":1001,"linkType":1002},[],{"data":48789,"content":48790,"nodeType":1312},{},[48791],{"data":48792,"marks":48793,"value":16477,"nodeType":864},{},[48794],{"type":899},{"data":48796,"content":48797,"nodeType":860},{},[48798],{"data":48799,"marks":48800,"value":16484,"nodeType":864},{},[],{"data":48802,"content":48803,"nodeType":860},{},[48804],{"data":48805,"marks":48806,"value":16491,"nodeType":864},{},[],{"data":48808,"content":48809,"nodeType":860},{},[48810],{"data":48811,"marks":48812,"value":16498,"nodeType":864},{},[],{"data":48814,"content":48815,"nodeType":860},{},[48816],{"data":48817,"marks":48818,"value":16505,"nodeType":864},{},[],{"data":48820,"content":48823,"nodeType":996},{"target":48821},{"sys":48822},{"id":16510,"type":1001,"linkType":1002},[],{"data":48825,"content":48826,"nodeType":1312},{},[48827],{"data":48828,"marks":48829,"value":16519,"nodeType":864},{},[48830],{"type":899},{"data":48832,"content":48833,"nodeType":860},{},[48834],{"data":48835,"marks":48836,"value":16526,"nodeType":864},{},[],{"data":48838,"content":48839,"nodeType":941},{},[48840,48879],{"data":48841,"content":48842,"nodeType":945},{},[48843],{"data":48844,"content":48845,"nodeType":860},{},[48846,48849,48856,48859,48866,48869,48876],{"data":48847,"marks":48848,"value":16539,"nodeType":864},{},[],{"data":48850,"content":48851,"nodeType":883},{"uri":16015},[48852],{"data":48853,"marks":48854,"value":16018,"nodeType":864},{},[48855],{"type":1455},{"data":48857,"marks":48858,"value":16550,"nodeType":864},{},[],{"data":48860,"content":48861,"nodeType":883},{"uri":16553},[48862],{"data":48863,"marks":48864,"value":16559,"nodeType":864},{},[48865],{"type":1455},{"data":48867,"marks":48868,"value":16563,"nodeType":864},{},[],{"data":48870,"content":48871,"nodeType":883},{"uri":16566},[48872],{"data":48873,"marks":48874,"value":16572,"nodeType":864},{},[48875],{"type":1455},{"data":48877,"marks":48878,"value":16576,"nodeType":864},{},[],{"data":48880,"content":48881,"nodeType":945},{},[48882],{"data":48883,"content":48884,"nodeType":860},{},[48885,48888,48895,48898,48905],{"data":48886,"marks":48887,"value":16586,"nodeType":864},{},[],{"data":48889,"content":48890,"nodeType":883},{"uri":16027},[48891],{"data":48892,"marks":48893,"value":16030,"nodeType":864},{},[48894],{"type":1455},{"data":48896,"marks":48897,"value":16597,"nodeType":864},{},[],{"data":48899,"content":48900,"nodeType":883},{"uri":16600},[48901],{"data":48902,"marks":48903,"value":16606,"nodeType":864},{},[48904],{"type":1455},{"data":48906,"marks":48907,"value":16610,"nodeType":864},{},[],{"data":48909,"content":48912,"nodeType":996},{"target":48910},{"sys":48911},{"id":16615,"type":1001,"linkType":1002},[],{"data":48914,"content":48915,"nodeType":1005},{},[],{"data":48917,"content":48918,"nodeType":1009},{},[48919],{"data":48920,"marks":48921,"value":16627,"nodeType":864},{},[48922],{"type":899},{"data":48924,"content":48925,"nodeType":860},{},[48926],{"data":48927,"marks":48928,"value":16634,"nodeType":864},{},[],{"data":48930,"content":48931,"nodeType":860},{},[48932,48935,48939],{"data":48933,"marks":48934,"value":16641,"nodeType":864},{},[],{"data":48936,"marks":48937,"value":16646,"nodeType":864},{},[48938],{"type":899},{"data":48940,"marks":48941,"value":16650,"nodeType":864},{},[],{"data":48943,"content":48944,"nodeType":860},{},[48945],{"data":48946,"marks":48947,"value":16657,"nodeType":864},{},[],{"data":48949,"content":48950,"nodeType":860},{},[48951],{"data":48952,"marks":48953,"value":16664,"nodeType":864},{},[],{"data":48955,"content":48958,"nodeType":996},{"target":48956},{"sys":48957},{"id":16669,"type":1001,"linkType":1002},[],{"data":48960,"content":48961,"nodeType":860},{},[48962,48965,48972],{"data":48963,"marks":48964,"value":16677,"nodeType":864},{},[],{"data":48966,"content":48967,"nodeType":883},{"uri":11738},[48968],{"data":48969,"marks":48970,"value":16685,"nodeType":864},{},[48971],{"type":1455},{"data":48973,"marks":48974,"value":16689,"nodeType":864},{},[],{"data":48976,"content":48977,"nodeType":1005},{},[],{"data":48979,"content":48980,"nodeType":1009},{},[48981],{"data":48982,"marks":48983,"value":2578,"nodeType":864},{},[48984],{"type":899},{"data":48986,"content":48987,"nodeType":860},{},[48988],{"data":48989,"marks":48990,"value":16706,"nodeType":864},{},[],{"data":48992,"content":48995,"nodeType":996},{"target":48993},{"sys":48994},{"id":16711,"type":1001,"linkType":1002},[],{"data":48997,"content":48998,"nodeType":860},{},[48999,49002,49009],{"data":49000,"marks":49001,"value":16719,"nodeType":864},{},[],{"data":49003,"content":49004,"nodeType":883},{"uri":11825},[49005],{"data":49006,"marks":49007,"value":16727,"nodeType":864},{},[49008],{"type":1455},{"data":49010,"marks":49011,"value":11546,"nodeType":864},{},[],{"data":49013,"content":49014,"nodeType":860},{},[49015],{"data":49016,"marks":49017,"value":16737,"nodeType":864},{},[],{"data":49019,"content":49020,"nodeType":860},{},[49021],{"data":49022,"marks":49023,"value":16744,"nodeType":864},{},[],{"data":49025,"content":49028,"nodeType":996},{"target":49026},{"sys":49027},{"id":16749,"type":1001,"linkType":1002},[],{"data":49030,"content":49031,"nodeType":1005},{},[],{"data":49033,"content":49034,"nodeType":1009},{},[49035],{"data":49036,"marks":49037,"value":7533,"nodeType":864},{},[49038],{"type":899},{"data":49040,"content":49041,"nodeType":860},{},[49042],{"data":49043,"marks":49044,"value":16767,"nodeType":864},{},[],{"data":49046,"content":49047,"nodeType":860},{},[49048],{"data":49049,"marks":49050,"value":16774,"nodeType":864},{},[],{"data":49052,"content":49055,"nodeType":996},{"target":49053},{"sys":49054},{"id":16779,"type":1001,"linkType":1002},[],{"data":49057,"content":49058,"nodeType":860},{},[49059],{"data":49060,"marks":49061,"value":16787,"nodeType":864},{},[],{"data":49063,"content":49066,"nodeType":996},{"target":49064},{"sys":49065},{"id":16792,"type":1001,"linkType":1002},[],{"data":49068,"content":49071,"nodeType":996},{"target":49069},{"sys":49070},{"id":16798,"type":1001,"linkType":1002},[],{"data":49073,"content":49074,"nodeType":860},{},[49075,49078,49082,49085,49089],{"data":49076,"marks":49077,"value":16806,"nodeType":864},{},[],{"data":49079,"marks":49080,"value":16811,"nodeType":864},{},[49081],{"type":899},{"data":49083,"marks":49084,"value":16815,"nodeType":864},{},[],{"data":49086,"marks":49087,"value":16820,"nodeType":864},{},[49088],{"type":899},{"data":49090,"marks":49091,"value":16824,"nodeType":864},{},[],{"data":49093,"content":49096,"nodeType":996},{"target":49094},{"sys":49095},{"id":16829,"type":1001,"linkType":1002},[],{"data":49098,"content":49099,"nodeType":1312},{},[49100,49103],{"data":49101,"marks":49102,"value":16837,"nodeType":864},{},[],{"data":49104,"marks":49105,"value":16842,"nodeType":864},{},[49106],{"type":899},{"data":49108,"content":49109,"nodeType":860},{},[49110],{"data":49111,"marks":49112,"value":16849,"nodeType":864},{},[],{"data":49114,"content":49115,"nodeType":860},{},[49116],{"data":49117,"marks":49118,"value":16856,"nodeType":864},{},[],{"data":49120,"content":49121,"nodeType":860},{},[49122,49125,49131,49134,49141,49144,49150],{"data":49123,"marks":49124,"value":16863,"nodeType":864},{},[],{"data":49126,"content":49127,"nodeType":883},{"uri":16866},[49128],{"data":49129,"marks":49130,"value":16871,"nodeType":864},{},[],{"data":49132,"marks":49133,"value":3731,"nodeType":864},{},[],{"data":49135,"content":49136,"nodeType":883},{"uri":16877},[49137],{"data":49138,"marks":49139,"value":16883,"nodeType":864},{},[49140],{"type":1455},{"data":49142,"marks":49143,"value":16887,"nodeType":864},{},[],{"data":49145,"content":49146,"nodeType":883},{"uri":1700},[49147],{"data":49148,"marks":49149,"value":16894,"nodeType":864},{},[],{"data":49151,"marks":49152,"value":2924,"nodeType":864},{},[],{"items":49154},[49155,49157],{"sys":49156,"name":13779},{"id":13778},{"sys":49158,"name":342},{"id":13775},{"items":49160},[49161],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":49162},{"url":2740},"blog/introducing-the-browser-and-identity-attacks-matrix",{"json":49165},{"data":49166,"content":49167,"nodeType":856},{},[49168],{"data":49169,"content":49170,"nodeType":860},{},[49171],{"data":49172,"marks":49173,"value":49174,"nodeType":864},{},[],"We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what you can expect to see more of in future.",{"id":23397,"publishedAt":49176},"2026-08-12T11:52:57.689Z",{"items":49178},[49179,49181],{"sys":49180,"name":13779},{"id":13778},{"sys":49182,"name":342},{"id":13775},{"items":49184},[49185,49187,49189,49191,49193,49195,49197,49199,49201,49203,49205,49207,49209,49211,49213,49215],{"sys":49186,"name":279,"slug":280,"tier":31},{"id":276},{"sys":49188,"name":413,"slug":414,"tier":31},{"id":410},{"sys":49190,"name":519,"slug":520,"tier":31},{"id":516},{"sys":49192,"name":642,"slug":643,"tier":31},{"id":639},{"sys":49194,"name":616,"slug":617,"tier":31},{"id":613},{"sys":49196,"name":261,"slug":262,"tier":45},{"id":258},{"sys":49198,"name":315,"slug":316,"tier":45},{"id":312},{"sys":49200,"name":360,"slug":361,"tier":45},{"id":357},{"sys":49202,"name":475,"slug":476,"tier":45},{"id":472},{"sys":49204,"name":511,"slug":512,"tier":45},{"id":508},{"sys":49206,"name":333,"slug":334,"tier":45},{"id":330},{"sys":49208,"name":422,"slug":423,"tier":45},{"id":419},{"sys":49210,"name":288,"slug":289,"tier":45},{"id":285},{"sys":49212,"name":484,"slug":485,"tier":45},{"id":481},{"sys":49214,"name":571,"slug":572,"tier":45},{"id":568},{"sys":49216,"name":448,"slug":449,"tier":45},{"id":445},"KeN5z465lyvbRDueJHHQu-xfDgeExBn9dQTgjMadkKc",{"id":49219,"title":49220,"authorsCollection":49221,"content":49226,"extension":228,"faqItemsCollection":50168,"faqTitle":59,"featured":6,"hashTags":59,"meta":50170,"metaTitle":50171,"ogImage":59,"postType":5726,"publishedDate":50172,"relatedBlogPostsCollection":50173,"slug":53433,"stem":53434,"subtitle":59,"summary":53435,"synopsis":53446,"sys":53447,"tagsCollection":53450,"topicsCollection":53456,"__hash__":53476},"blog/blog/why-browser-extension-risk-scoring-wont-predict-your-next-breach.json","Why relying on browser extension risk scoring is an antipattern that won’t predict your next breach",{"items":49222},[49223],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":49224,"profilePicture":49225},[15231],{"url":2740},{"json":49227,"links":50071},{"data":49228,"content":49229,"nodeType":856},{},[49230,49236,49272,49279,49286,49289,49297,49304,49312,49351,49368,49371,49379,49386,49393,49400,49416,49430,49437,49453,49460,49476,49497,49517,49573,49585,49605,49611,49618,49625,49632,49639,49662,49668,49675,49682,49689,49701,49726,49729,49737,49744,49751,49758,49777,49783,49806,49813,49820,49944,49950,49957,49964,49967,49975,49982,50001,50008,50016,50019,50038],{"data":49231,"content":49235,"nodeType":996},{"target":49232},{"sys":49233},{"id":49234,"type":1001,"linkType":1002},"4Lk4sATAlk2wPcevG0cJCu",[],{"data":49237,"content":49238,"nodeType":860},{},[49239,49242,49249,49252,49258,49261,49268],{"data":49240,"marks":49241,"value":3939,"nodeType":864},{},[],{"data":49243,"content":49244,"nodeType":883},{"uri":3942},[49245],{"data":49246,"marks":49247,"value":3948,"nodeType":864},{},[49248],{"type":1455},{"data":49250,"marks":49251,"value":3731,"nodeType":864},{},[],{"data":49253,"content":49254,"nodeType":883},{"uri":3954},[49255],{"data":49256,"marks":49257,"value":3959,"nodeType":864},{},[],{"data":49259,"marks":49260,"value":3731,"nodeType":864},{},[],{"data":49262,"content":49263,"nodeType":883},{"uri":3965},[49264],{"data":49265,"marks":49266,"value":3970,"nodeType":864},{},[49267],{"type":1455},{"data":49269,"marks":49270,"value":49271,"nodeType":864},{},[],", among many others). ",{"data":49273,"content":49274,"nodeType":860},{},[49275],{"data":49276,"marks":49277,"value":49278,"nodeType":864},{},[],"But as the industry scrambles to respond, there's a tendency to treat browser extension management as an entirely new paradigm that requires a new approach, particularly risk scoring systems that attempt to rate each extension on a spectrum from safe to dangerous.",{"data":49280,"content":49281,"nodeType":860},{},[49282],{"data":49283,"marks":49284,"value":49285,"nodeType":864},{},[],"We think this framing misses the point, and that it's leading security teams toward a strategy that won't protect them from the attacks that actually cause damage.",{"data":49287,"content":49288,"nodeType":1005},{},[],{"data":49290,"content":49291,"nodeType":1009},{},[49292],{"data":49293,"marks":49294,"value":49296,"nodeType":864},{},[49295],{"type":899},"The practical problem: \"just remove the high-risk ones\" doesn't work",{"data":49298,"content":49299,"nodeType":860},{},[49300],{"data":49301,"marks":49302,"value":49303,"nodeType":864},{},[],"The strategy we see most often is some version of \"identify and remove the highest-risk extensions.\" On the surface this seems reasonable — you can't address everything, so you prioritize. The problem is that it doesn't materially reduce your exposure to the attacks that are actually happening.",{"data":49305,"content":49306,"nodeType":860},{},[49307],{"data":49308,"marks":49309,"value":49311,"nodeType":864},{},[49310],{"type":899},"Browser extension attacks almost always follow one of two patterns: ",{"data":49313,"content":49314,"nodeType":941},{},[49315,49325],{"data":49316,"content":49317,"nodeType":945},{},[49318],{"data":49319,"content":49320,"nodeType":860},{},[49321],{"data":49322,"marks":49323,"value":49324,"nodeType":864},{},[],"A legitimate developer is compromised through consent phishing, session theft, or AiTM phishing, and a malicious update is pushed to the existing user base. Cyberhaven is a good example of this — a developer got consent phished with a specific app that granted the attacker access to the extension store.",{"data":49326,"content":49327,"nodeType":945},{},[49328],{"data":49329,"content":49330,"nodeType":860},{},[49331,49335,49347],{"data":49332,"marks":49333,"value":49334,"nodeType":864},{},[],"An attacker builds or acquires a clean extension, operates it legitimately until it accumulates a sufficient user base, then deploys a malicious update. GitLab's threat intelligence team documented a cluster of",{"data":49336,"content":49338,"nodeType":883},{"uri":49337},"https://gitlab-com.gitlab.io/gl-security/security-tech-notes/threat-intelligence-tech-notes/malicious-browser-extensions-feb-2025/",[49339,49342],{"data":49340,"marks":49341,"value":1171,"nodeType":864},{},[],{"data":49343,"marks":49344,"value":49346,"nodeType":864},{},[49345],{"type":1455},"16 extensions impacting 3.2 million users",{"data":49348,"marks":49349,"value":49350,"nodeType":864},{},[]," where access had been acquired from original developers rather than via compromise.",{"data":49352,"content":49353,"nodeType":860},{},[49354,49359,49363],{"data":49355,"marks":49356,"value":49358,"nodeType":864},{},[49357],{"type":899},"This means that real-world extension breaches aren't coming from extensions that looked risky beforehand.",{"data":49360,"marks":49361,"value":49362,"nodeType":864},{},[]," If your strategy is \"identify and remove the highest-risk extensions,\" you're optimizing for the wrong thing — because even extensions that score as moderate or low risk by every conventional measure still have the permissions and access needed for a full compromise. ",{"data":49364,"marks":49365,"value":49367,"nodeType":864},{},[49366],{"type":899},"If you skim off the top 10% “riskiest” extensions, 90% of the extensions in your environment could still become a breach vector. ",{"data":49369,"content":49370,"nodeType":1005},{},[],{"data":49372,"content":49373,"nodeType":1009},{},[49374],{"data":49375,"marks":49376,"value":49378,"nodeType":864},{},[49377],{"type":899},"What risk scoring is designed to measure — and why it can’t predict future compromise",{"data":49380,"content":49381,"nodeType":860},{},[49382],{"data":49383,"marks":49384,"value":49385,"nodeType":864},{},[],"Most extension risk scoring systems evaluate some combination of permissions, install count, user ratings, code analysis, developer reputation, and web store trust signals. Nice-to-have data points, but with a common limitation: they describe the extension as it is today, not what it will become after the next update. That makes them poor predictors of the thing that actually causes breaches — a previously-clean extension being weaponized through a supply chain compromise.",{"data":49387,"content":49388,"nodeType":860},{},[49389],{"data":49390,"marks":49391,"value":49392,"nodeType":864},{},[],"It's worth examining why each signal falls short as a predictor specifically of future compromise, because the failure modes are different and well-documented.",{"data":49394,"content":49395,"nodeType":1312},{},[49396],{"data":49397,"marks":49398,"value":49399,"nodeType":864},{},[],"Permissions",{"data":49401,"content":49402,"nodeType":860},{},[49403,49407,49412],{"data":49404,"marks":49405,"value":49406,"nodeType":864},{},[],"Permissions are the most meaningful input to a risk score, because they determine what an extension is ",{"data":49408,"marks":49409,"value":49411,"nodeType":864},{},[49410],{"type":2246},"capable",{"data":49413,"marks":49414,"value":49415,"nodeType":864},{},[]," of doing if it turns malicious. An extension with access to cookies, scripting, and broad host permissions can steal session tokens, log keystrokes, and exfiltrate data from any site the user visits. This is the data that actually answers the question \"what could this extension do to us if it went bad?\"",{"data":49417,"content":49418,"nodeType":860},{},[49419,49423,49427],{"data":49420,"marks":49421,"value":49422,"nodeType":864},{},[],"The problem is that these permissions are extraordinarily common. We analyzed a sample of 20,000 unique extensions deployed across Push customers and found that ",{"data":49424,"marks":49425,"value":3997,"nodeType":864},{},[49426],{"type":899},{"data":49428,"marks":49429,"value":11546,"nodeType":864},{},[],{"data":49431,"content":49432,"nodeType":860},{},[49433],{"data":49434,"marks":49435,"value":49436,"nodeType":864},{},[],"These figures also understate the real exposure. One of the most straightforward attack techniques involves injecting content scripts into web pages to hook request functions and extract cookies. The user-facing warning Chrome shows for this capability — \"Read and change all your data on the websites you visit\" — is the same generic string shown for ad blockers, password managers, and translation tools. ",{"data":49438,"content":49439,"nodeType":860},{},[49440,49444,49449],{"data":49441,"marks":49442,"value":49443,"nodeType":864},{},[],"You can't practically remove everything that ",{"data":49445,"marks":49446,"value":49448,"nodeType":864},{},[49447],{"type":2246},"could",{"data":49450,"marks":49451,"value":49452,"nodeType":864},{},[]," be dangerous, because that includes most of the extensions people actually use for work. And if you set the threshold lower to keep the list manageable, you're excluding extensions that have the same permissions and pose the same theoretical risk.",{"data":49454,"content":49455,"nodeType":1312},{},[49456],{"data":49457,"marks":49458,"value":49459,"nodeType":864},{},[],"Install counts, ratings, developer reputation, and web store badges",{"data":49461,"content":49462,"nodeType":860},{},[49463,49467,49472],{"data":49464,"marks":49465,"value":49466,"nodeType":864},{},[],"These signals share a common failure mode, so it's worth addressing them together: they all describe the extension's ",{"data":49468,"marks":49469,"value":49471,"nodeType":864},{},[49470],{"type":2246},"reputation",{"data":49473,"marks":49474,"value":49475,"nodeType":864},{},[]," at a point in time, and attackers have both the means and the incentive to ensure that reputation looks clean.",{"data":49477,"content":49478,"nodeType":860},{},[49479,49484,49488,49493],{"data":49480,"marks":49481,"value":49483,"nodeType":864},{},[49482],{"type":899},"Install count ",{"data":49485,"marks":49486,"value":49487,"nodeType":864},{},[],"is sometimes used as a proxy for trustworthiness, on the assumption that widely-adopted extensions are more likely to be legitimate. In practice, high install count is often a ",{"data":49489,"marks":49490,"value":49492,"nodeType":864},{},[49491],{"type":2246},"precondition",{"data":49494,"marks":49495,"value":49496,"nodeType":864},{},[]," for the attack rather than a signal against it. ",{"data":49498,"content":49499,"nodeType":860},{},[49500,49504,49513],{"data":49501,"marks":49502,"value":49503,"nodeType":864},{},[],"Attackers who acquire or build extensions are specifically waiting for the install base to grow before weaponizing — what researchers are calling the \"",{"data":49505,"content":49507,"nodeType":883},{"uri":49506},"https://www.malwarebytes.com/blog/news/2025/12/sleeper-browser-extensions-woke-up-as-spyware-on-4-million-devices",[49508],{"data":49509,"marks":49510,"value":49512,"nodeType":864},{},[49511],{"type":1455},"sleeper agent",{"data":49514,"marks":49515,"value":49516,"nodeType":864},{},[],"\" strategy. Install counts can also be easily inflated with bots, meaning that using them as a positive risk signal actively rewards the attackers who are best at gaming the system.",{"data":49518,"content":49519,"nodeType":941},{},[49520,49541,49563],{"data":49521,"content":49522,"nodeType":945},{},[49523],{"data":49524,"content":49525,"nodeType":860},{},[49526,49529,49537],{"data":49527,"marks":49528,"value":2761,"nodeType":864},{},[],{"data":49530,"content":49531,"nodeType":883},{"uri":3954},[49532],{"data":49533,"marks":49534,"value":49536,"nodeType":864},{},[49535],{"type":1455},"DarkSpectre campaign",{"data":49538,"marks":49539,"value":49540,"nodeType":864},{},[]," accumulated over 8.8 million compromised browsers across extensions that held \"verified\" status and healthy install counts throughout a seven-year operational period. ",{"data":49542,"content":49543,"nodeType":945},{},[49544],{"data":49545,"content":49546,"nodeType":860},{},[49547,49550,49559],{"data":49548,"marks":49549,"value":2761,"nodeType":864},{},[],{"data":49551,"content":49553,"nodeType":883},{"uri":49552},"https://www.ox.security/blog/malicious-chrome-extensions-steal-chatgpt-deepseek-conversations/",[49554],{"data":49555,"marks":49556,"value":49558,"nodeType":864},{},[49557],{"type":1455},"AITOPIA",{"data":49560,"marks":49561,"value":49562,"nodeType":864},{},[]," impersonation extensions had over 900,000 combined installs and a Google \"Featured\" badge. ",{"data":49564,"content":49565,"nodeType":945},{},[49566],{"data":49567,"content":49568,"nodeType":860},{},[49569],{"data":49570,"marks":49571,"value":49572,"nodeType":864},{},[],"Cyberhaven had approximately 400,000 users at the time of compromise. ",{"data":49574,"content":49575,"nodeType":860},{},[49576,49581],{"data":49577,"marks":49578,"value":49580,"nodeType":864},{},[49579],{"type":899},"User ratings",{"data":49582,"marks":49583,"value":49584,"nodeType":864},{},[]," suffer from the same problems. Attackers use bot networks to generate positive reviews, and even genuinely clean extensions will carry good ratings right up until they're compromised. By the time users start leaving negative reviews the attack has already run its course.",{"data":49586,"content":49587,"nodeType":860},{},[49588,49593,49596,49601],{"data":49589,"marks":49590,"value":49592,"nodeType":864},{},[49591],{"type":899},"Developer reputation and \"Featured\" and \"Verified\"",{"data":49594,"marks":49595,"value":1171,"nodeType":864},{},[],{"data":49597,"marks":49598,"value":49600,"nodeType":864},{},[49599],{"type":899},"badges",{"data":49602,"marks":49603,"value":49604,"nodeType":864},{},[]," fail for a related but slightly different reason: the attack typically doesn't come from a known-bad developer. It comes from a reputable developer whose account has been compromised, or from an extension that has changed hands. ",{"data":49606,"content":49610,"nodeType":996},{"target":49607},{"sys":49608},{"id":49609,"type":1001,"linkType":1002},"d1C5wKxUnKFwfhf4OBQAq",[],{"data":49612,"content":49613,"nodeType":860},{},[49614],{"data":49615,"marks":49616,"value":49617,"nodeType":864},{},[],"The net result across all of these signals is that the extensions most likely to appear in breach headlines — established tools with large user bases, good ratings, verified badges, and reputable developers — are precisely the ones that risk scoring would rate as low-risk.",{"data":49619,"content":49620,"nodeType":1312},{},[49621],{"data":49622,"marks":49623,"value":49624,"nodeType":864},{},[],"Code analysis",{"data":49626,"content":49627,"nodeType":860},{},[49628],{"data":49629,"marks":49630,"value":49631,"nodeType":864},{},[],"Static analysis of extension code is the approach that sounds most rigorous, and it's the basis for Chrome Web Store's own review process. Google operates a hybrid system combining automated analysis and manual review, with manual review typically reserved for submissions that trigger specific signals such as sensitive permissions or large code volumes.",{"data":49633,"content":49634,"nodeType":860},{},[49635],{"data":49636,"marks":49637,"value":49638,"nodeType":864},{},[],"But attackers have developed reliable techniques to pass these checks, and the specific evasion methods used in major campaigns illustrate why static analysis consistently falls short. ",{"data":49640,"content":49641,"nodeType":941},{},[49642,49652],{"data":49643,"content":49644,"nodeType":945},{},[49645],{"data":49646,"content":49647,"nodeType":860},{},[49648],{"data":49649,"marks":49650,"value":49651,"nodeType":864},{},[],"The Cyberhaven compromise used dynamically loaded content fetched from a remote server via service workers, with the C2 infrastructure delivering different malicious configurations to different end-users — meaning that even if a scanner fetched the remote payload, it might receive a benign configuration depending on the target profile.",{"data":49653,"content":49654,"nodeType":945},{},[49655],{"data":49656,"content":49657,"nodeType":860},{},[49658],{"data":49659,"marks":49660,"value":49661,"nodeType":864},{},[],"The GhostPoster campaign (part of the broader DarkSpectre operation) took evasion further still: the extension waited 48 hours between configuration check-ins and only loaded a malicious payload 10% of the time. No sandbox is running for 48 hours, and a 10% activation rate means that nine out of ten analysis runs would see nothing at all.",{"data":49663,"content":49667,"nodeType":996},{"target":49664},{"sys":49665},{"id":49666,"type":1001,"linkType":1002},"6jy6jvYcHTXO2uMd7kx647",[],{"data":49669,"content":49670,"nodeType":860},{},[49671],{"data":49672,"marks":49673,"value":49674,"nodeType":864},{},[],"It's also worth noting that Chrome Web Store policy explicitly disallows code obfuscation, precisely because it makes review impossible. The fact that attackers have found ways to hide malicious behavior without technically obfuscating their code speaks to the fundamental asymmetry at play: the attacker controls when and how malicious functionality appears, and static analysis can only evaluate what's present at the time of review.",{"data":49676,"content":49677,"nodeType":1312},{},[49678],{"data":49679,"marks":49680,"value":49681,"nodeType":864},{},[],"But extension scores combine all of these things …",{"data":49683,"content":49684,"nodeType":860},{},[49685],{"data":49686,"marks":49687,"value":49688,"nodeType":864},{},[],"The obvious counterargument is that no serious risk scoring system relies on any single signal in isolation — the value is supposed to come from combining permissions, install count, ratings, code analysis, and developer reputation into a composite score that's more predictive than any individual input. In theory, this sounds like the right approach: weak signals aggregated together should produce a stronger signal.",{"data":49690,"content":49691,"nodeType":860},{},[49692,49697],{"data":49693,"marks":49694,"value":49696,"nodeType":864},{},[49695],{"type":899},"In practice, combining signals that are individually unable to predict supply chain compromise doesn't produce a signal that can. ",{"data":49698,"marks":49699,"value":49700,"nodeType":864},{},[],"Aggregating a set of backward-looking indicators doesn't make the aggregate forward-looking; it just gives you a more detailed description of the present state, which is the state before the attack has happened. No weighting or combination of install count, code behavior, and developer reputation would have flagged Cyberhaven, or DarkSpectre, or Trust Wallet before the malicious update shipped, because at that point every input to the composite score was returning a legitimate value.",{"data":49702,"content":49703,"nodeType":860},{},[49704,49708,49713,49717,49722],{"data":49705,"marks":49706,"value":49707,"nodeType":864},{},[],"Meanwhile, the indicators that ",{"data":49709,"marks":49710,"value":49712,"nodeType":864},{},[49711],{"type":2246},"do",{"data":49714,"marks":49715,"value":49716,"nodeType":864},{},[]," predict real-world compromise — an extension changing ownership, a developer account being phished, an update introducing behavior that wasn't present in prior versions, or an extension being explicitly confirmed as malicious through threat intelligence — aren't predictive risk score inputs. ",{"data":49718,"marks":49719,"value":49721,"nodeType":864},{},[49720],{"type":899},"They're discrete events that require monitoring and an immediate response, not a recalculated number on a dashboard. ",{"data":49723,"marks":49724,"value":49725,"nodeType":864},{},[],"This is an important distinction: the signals that matter are changes over time, not static attributes at a point in time, and they call for a detection-and-response workflow rather than a periodic risk review.",{"data":49727,"content":49728,"nodeType":1005},{},[],{"data":49730,"content":49731,"nodeType":1009},{},[49732],{"data":49733,"marks":49734,"value":49736,"nodeType":864},{},[49735],{"type":899},"What works instead",{"data":49738,"content":49739,"nodeType":860},{},[49740],{"data":49741,"marks":49742,"value":49743,"nodeType":864},{},[],"If the goal is to reduce your exposure to extension-based supply chain compromise rather than to generate a ranked list of risk, the approach is operationally straightforward — even if it requires more discipline than deploying a scoring dashboard.",{"data":49745,"content":49746,"nodeType":1312},{},[49747],{"data":49748,"marks":49749,"value":49750,"nodeType":864},{},[],"Reduce your attack surface through allowlisting",{"data":49752,"content":49753,"nodeType":860},{},[49754],{"data":49755,"marks":49756,"value":49757,"nodeType":864},{},[],"Build a complete inventory of every extension running across your environment — what's installed, how it got there (managed deployment, manual install, sideloaded, developer mode), what permissions it has, who's using it, and whether it serves a legitimate work purpose. Then create a strict allowlist of vetted and approved extensions and block everything else.",{"data":49759,"content":49760,"nodeType":860},{},[49761,49765,49773],{"data":49762,"marks":49763,"value":49764,"nodeType":864},{},[],"This is the same default-deny approach that's been best practice for firewall policy and endpoint allowlisting for decades. ",{"data":49766,"content":49767,"nodeType":883},{"uri":11825},[49768],{"data":49769,"marks":49770,"value":49772,"nodeType":864},{},[49771],{"type":1455},"In Push, it works like building a firewall rule",{"data":49774,"marks":49775,"value":49776,"nodeType":864},{},[],": a global block rule at the bottom that disables all browser extensions, with explicit exceptions above it for approved tools. Users who attempt to install unapproved extensions see a block screen.",{"data":49778,"content":49782,"nodeType":996},{"target":49779},{"sys":49780},{"id":49781,"type":1001,"linkType":1002},"97dDukjKsRsAptpHV1kpn",[],{"data":49784,"content":49785,"nodeType":860},{},[49786,49791,49797,49802],{"data":49787,"marks":49788,"value":49790,"nodeType":864},{},[49789],{"type":899},"The key insight is that every extension you don't ",{"data":49792,"marks":49793,"value":49796,"nodeType":864},{},[49794,49795],{"type":899},{"type":2246},"really ",{"data":49798,"marks":49799,"value":49801,"nodeType":864},{},[49800],{"type":899},"need, but haven't blocked, is attack surface that exists for no business reason. ",{"data":49803,"marks":49804,"value":49805,"nodeType":864},{},[],"Most organizations are surprised by how many of the extensions in their environment are unused, forgotten, or have readily available alternatives. Reducing the population of installed extensions to only the ones that serve a genuine work purpose is the single most effective thing you can do — and it doesn't require a risk score to accomplish.",{"data":49807,"content":49808,"nodeType":1312},{},[49809],{"data":49810,"marks":49811,"value":49812,"nodeType":864},{},[],"Monitor for changes that indicate weaponization",{"data":49814,"content":49815,"nodeType":860},{},[49816],{"data":49817,"marks":49818,"value":49819,"nodeType":864},{},[],"Once you have a controlled baseline, the risk shifts from unmanaged installations (those are blocked) to changes in the extensions you've already approved. These are the signals that map to real-world attack patterns and serve as leading indicators of weaponization:",{"data":49821,"content":49822,"nodeType":941},{},[49823,49867,49882,49897,49912],{"data":49824,"content":49825,"nodeType":945},{},[49826],{"data":49827,"content":49828,"nodeType":860},{},[49829,49834,49838,49847,49852,49856,49864],{"data":49830,"marks":49831,"value":49833,"nodeType":864},{},[49832],{"type":899},"Ownership changes",{"data":49835,"marks":49836,"value":49837,"nodeType":864},{},[]," — an extension changing hands is one of the most reliable precursors to supply chain compromise, as demonstrated by the ",{"data":49839,"content":49841,"nodeType":883},{"uri":49840},"https://thehackernews.com/2026/03/chrome-extension-turns-malicious-after.html",[49842],{"data":49843,"marks":49844,"value":49846,"nodeType":864},{},[49845],{"type":1455},"QuickLens and ShotBird attack",{"data":49848,"marks":49849,"value":49851,"nodeType":864},{},[49850],{"type":1455},"s",{"data":49853,"marks":49854,"value":49855,"nodeType":864},{},[]," and the acquired-extension clusters documented by ",{"data":49857,"content":49858,"nodeType":883},{"uri":49337},[49859],{"data":49860,"marks":49861,"value":49863,"nodeType":864},{},[49862],{"type":1455},"GitLab",{"data":49865,"marks":49866,"value":2924,"nodeType":864},{},[],{"data":49868,"content":49869,"nodeType":945},{},[49870],{"data":49871,"content":49872,"nodeType":860},{},[49873,49878],{"data":49874,"marks":49875,"value":49877,"nodeType":864},{},[49876],{"type":899},"Developer contact information changes",{"data":49879,"marks":49880,"value":49881,"nodeType":864},{},[]," — often an early indicator that an extension has been sold or that a developer account has been taken over.",{"data":49883,"content":49884,"nodeType":945},{},[49885],{"data":49886,"content":49887,"nodeType":860},{},[49888,49893],{"data":49889,"marks":49890,"value":49892,"nodeType":864},{},[49891],{"type":899},"Permission escalations in updates",{"data":49894,"marks":49895,"value":49896,"nodeType":864},{},[]," — a previously-scoped extension suddenly requesting broad host permissions or cookie access.",{"data":49898,"content":49899,"nodeType":945},{},[49900],{"data":49901,"content":49902,"nodeType":860},{},[49903,49908],{"data":49904,"marks":49905,"value":49907,"nodeType":864},{},[49906],{"type":899},"Delisting from the web store",{"data":49909,"marks":49910,"value":49911,"nodeType":864},{},[]," — can indicate that the store's review process has caught something, or that the developer has abandoned the extension.",{"data":49913,"content":49914,"nodeType":945},{},[49915],{"data":49916,"content":49917,"nodeType":860},{},[49918,49923,49927,49935,49940],{"data":49919,"marks":49920,"value":49922,"nodeType":864},{},[49921],{"type":899},"Known malicious classification",{"data":49924,"marks":49925,"value":49926,"nodeType":864},{},[]," — when an extension is confirmed as weaponized or linked to an active campaign through threat intelligence. (",{"data":49928,"content":49929,"nodeType":883},{"uri":11825},[49930],{"data":49931,"marks":49932,"value":49934,"nodeType":864},{},[49933],{"type":1455},"Push blocks known-bad extensions automaticall",{"data":49936,"marks":49937,"value":49939,"nodeType":864},{},[49938],{"type":1455},"y",{"data":49941,"marks":49942,"value":49943,"nodeType":864},{},[],").",{"data":49945,"content":49949,"nodeType":996},{"target":49946},{"sys":49947},{"id":49948,"type":1001,"linkType":1002},"4PWyOD92E549plkeNH1DxO",[],{"data":49951,"content":49952,"nodeType":860},{},[49953],{"data":49954,"marks":49955,"value":49956,"nodeType":864},{},[],"To make this concrete: Push emits structured events via webhook whenever extension metadata changes that captures all of the variables above. These these can be fed directly into your SIEM or SOAR workflows, making it easy for security teams to detect when a meaningful change occurs. An ownership change on its own warrants investigation; an ownership change paired with a new version and added permissions warrants an immediate block pending review.",{"data":49958,"content":49959,"nodeType":860},{},[49960],{"data":49961,"marks":49962,"value":49963,"nodeType":864},{},[],"Push detects these changes in real time and can automatically block an extension when a meaningful risk indicator fires, before the damage propagates. This is fundamentally different from a periodic risk score: rather than attempting to predict which extensions might go bad based on static attributes, Push monitors for the specific events that precede or accompany weaponization in the attacks we've actually observed.",{"data":49965,"content":49966,"nodeType":1005},{},[],{"data":49968,"content":49969,"nodeType":1009},{},[49970],{"data":49971,"marks":49972,"value":49974,"nodeType":864},{},[49973],{"type":899},"The bottom line",{"data":49976,"content":49977,"nodeType":860},{},[49978],{"data":49979,"marks":49980,"value":49981,"nodeType":864},{},[],"Traditional extension risk scores — based on permissions, store metadata, code analysis, and developer reputation — are poor predictors of which extensions will actually compromise you. The extensions involved in the major breaches of the past 18 months consistently scored as normal or low-risk right up until the moment they were weaponized. If your extension management strategy is built around \"identify the riskiest extensions and remove them,\" the extension that gets you is the one that wasn't on the list.",{"data":49983,"content":49984,"nodeType":860},{},[49985,49989,49997],{"data":49986,"marks":49987,"value":49988,"nodeType":864},{},[],"Browser extensions are software. They're third-party code running with significant privilege inside the browser, capable of reading and modifying page content, accessing cookies and session tokens, and interacting with virtually every web application your employees use. Like any other software dependency — ",{"data":49990,"content":49991,"nodeType":883},{"uri":4103},[49992],{"data":49993,"marks":49994,"value":49996,"nodeType":864},{},[49995],{"type":1455},"OAuth integrations",{"data":49998,"marks":49999,"value":50000,"nodeType":864},{},[]," being another relevant recent example in public breaches — each one expands your attack surface. ",{"data":50002,"content":50003,"nodeType":860},{},[50004],{"data":50005,"marks":50006,"value":50007,"nodeType":864},{},[],"The principles behind managing browser extensions need to be the same as any other software — default-deny, build an allowlist, monitor and maintain that allowlist. This might trigger some PTSD for security teams, but it shouldn’t. On the endpoint, application allowlisting has always been operationally painful — diverse workflows, unpredictable application needs, and the overhead of vetting every binary made it impractical for most organizations outside of high-security environments. In the browser, it’s not that serious. You’re not going to brick an endpoint by blocking a third-party browser extension. ",{"data":50009,"content":50010,"nodeType":860},{},[50011],{"data":50012,"marks":50013,"value":50015,"nodeType":864},{},[50014],{"type":899},"The browser is one of the few environments where an allowlisting approach is both technically feasible and operationally lightweight: use it to your advantage. ",{"data":50017,"content":50018,"nodeType":1005},{},[],{"data":50020,"content":50021,"nodeType":860},{},[50022,50026,50034],{"data":50023,"marks":50024,"value":50025,"nodeType":864},{},[],"Push detects and blocks malicious browser extensions, and gives security teams the controls to ",{"data":50027,"content":50028,"nodeType":883},{"uri":11825},[50029],{"data":50030,"marks":50031,"value":50033,"nodeType":864},{},[50032],{"type":1455},"enforce an extension allowlist and monitor for risky changes",{"data":50035,"marks":50036,"value":50037,"nodeType":864},{},[]," across every browser in the environment. Combined with protection against AiTM phishing, ClickFix attacks, session hijacking, and stolen credentials — plus proactive hardening for ghost logins, SSO coverage gaps, MFA gaps, and vulnerable passwords — Push provides browser-native visibility and control where it matters most.",{"data":50039,"content":50040,"nodeType":860},{},[50041,50044,50050,50053,50059,50062,50068],{"data":50042,"marks":50043,"value":16863,"nodeType":864},{},[],{"data":50045,"content":50046,"nodeType":883},{"uri":16866},[50047],{"data":50048,"marks":50049,"value":16871,"nodeType":864},{},[],{"data":50051,"marks":50052,"value":3731,"nodeType":864},{},[],{"data":50054,"content":50055,"nodeType":883},{"uri":16877},[50056],{"data":50057,"marks":50058,"value":16883,"nodeType":864},{},[],{"data":50060,"marks":50061,"value":16887,"nodeType":864},{},[],{"data":50063,"content":50064,"nodeType":883},{"uri":1700},[50065],{"data":50066,"marks":50067,"value":16894,"nodeType":864},{},[],{"data":50069,"marks":50070,"value":2924,"nodeType":864},{},[],{"entries":50072},{"hyperlink":50073,"inline":50074,"block":50075},[],[],[50076,50101,50127,50153,50161],{"sys":50077,"__typename":1740,"content":50078,"name":50100,"title":59},{"id":49234},{"json":50079},{"data":50080,"content":50081,"nodeType":856},{},[50082,50093],{"data":50083,"content":50084,"nodeType":860},{},[50085,50089],{"data":50086,"marks":50087,"value":39602,"nodeType":864},{},[50088],{"type":899},{"data":50090,"marks":50091,"value":50092,"nodeType":864},{},[]," Traditional extension risk scores — based on data like permissions, store metadata, code analysis, and developer reputation — are poor predictors of which extensions will actually lead to a compromise. The extensions behind every major breach of the past 18 months scored as normal or low-risk beforehand. ",{"data":50094,"content":50095,"nodeType":860},{},[50096],{"data":50097,"marks":50098,"value":50099,"nodeType":864},{},[],"If your strategy is \"remove the highest-risk extensions,\" you're optimizing for the wrong question. The more effective approach is to implement an allowlist, block the rest, and monitor the approved set for the changes — like ownership transfers and permission escalations — that actually precede real-world attacks. ","Browser extension risk scoring IB1",{"sys":50102,"__typename":1740,"content":50103,"name":50126,"title":59},{"id":49609},{"json":50104},{"nodeType":856,"data":50105,"content":50106},{},[50107],{"nodeType":860,"data":50108,"content":50109},{},[50110,50114,50122],{"nodeType":864,"value":50111,"marks":50112,"data":50113},"Extensions compromised in the broader campaign impacting Cyberhaven had been legitimate, well-maintained tools with strong developer reputations before the developer accounts were phished. Likewise, the ",[],{},{"nodeType":883,"data":50115,"content":50116},{"uri":49840},[50117],{"nodeType":864,"value":50118,"marks":50119,"data":50121},"QuickLens and ShotBird ownership transfer attacks",[50120],{"type":1455},{},{"nodeType":864,"value":50123,"marks":50124,"data":50125}," in March 2026 involved extensions acquired through a legitimate marketplace, with malicious code introduced after the sale. Developer reputation at time of installation told you nothing about the developer at time of attack. ",[],{},"Browser extension risk scoring IB2",{"sys":50128,"__typename":1740,"content":50129,"name":50152,"title":59},{"id":49666},{"json":50130},{"nodeType":856,"data":50131,"content":50132},{},[50133],{"nodeType":860,"data":50134,"content":50135},{},[50136,50140,50148],{"nodeType":864,"value":50137,"marks":50138,"data":50139},"These are not outlier techniques. Across the major campaigns documented since late 2024 — including the 108-extension campaign ",[],{},{"nodeType":883,"data":50141,"content":50143},{"uri":50142},"https://thehackernews.com/2026/04/108-malicious-chrome-extensions-steal.html",[50144],{"nodeType":864,"value":50145,"marks":50146,"data":50147},"discovered in April 2026 ",[],{},{"nodeType":864,"value":50149,"marks":50150,"data":50151},"— some combination of dynamically loaded payloads, conditional execution, time-delayed activation, and base64-encoded endpoints has been present in virtually every case. If these techniques are bypassing Google's own review infrastructure, which has both the scale and the incentive to detect them, they will bypass third-party code analysis tools as well.",[],{},"Browser extension risk scoring IB3",{"sys":50154,"__typename":1724,"title":50155,"caption":50156,"layoutMode":59,"file":50157},{"id":49781},"This extension is not approved for business use","Employees will see a customizable block screen when trying to use extensions that are not approved.",{"url":50158,"width":50159,"height":50160},"https://images.ctfassets.net/y1cdw1ablpvd/2hFpE2X60adttS6vAtyUIO/963e14eb2899163f583e7342db3f0650/image5.png",1440,744,{"sys":50162,"__typename":1724,"title":50163,"caption":50163,"layoutMode":59,"file":50164},{"id":49948},"Push automatically blocks known-bad browser extensions.",{"url":50165,"width":50166,"height":50167},"https://images.ctfassets.net/y1cdw1ablpvd/31TgJEkYVua0s5ecwgQPmM/efb0a7048f9ecc9eacf2e29b7b2233bc/image1.png",1433,810,{"items":50169},[],{},"Why browser extension risk scoring won’t predict a breach","2026-04-29T00:00:00.000Z",{"items":50174},[50175,50823,52073],{"__typename":2059,"sys":50176,"content":50177,"title":16898,"synopsis":16899,"hashTags":59,"publishedDate":16900,"slug":16901,"tagsCollection":50813,"authorsCollection":50819},{"id":16149},{"json":50178},{"data":50179,"content":50180,"nodeType":856},{},[50181,50204,50230,50236,50241,50244,50251,50257,50262,50277,50283,50290,50306,50319,50325,50331,50334,50341,50347,50353,50408,50414,50421,50431,50437,50443,50448,50455,50461,50467,50473,50479,50484,50491,50497,50568,50573,50576,50583,50589,50602,50608,50614,50619,50635,50638,50645,50651,50656,50672,50678,50684,50689,50692,50699,50705,50711,50716,50722,50727,50732,50752,50757,50767,50773,50779],{"data":50182,"content":50183,"nodeType":860},{},[50184,50187,50194,50197,50201],{"data":50185,"marks":50186,"value":16160,"nodeType":864},{},[],{"data":50188,"content":50189,"nodeType":883},{"uri":16015},[50190],{"data":50191,"marks":50192,"value":16168,"nodeType":864},{},[50193],{"type":1455},{"data":50195,"marks":50196,"value":16172,"nodeType":864},{},[],{"data":50198,"marks":50199,"value":16177,"nodeType":864},{},[50200],{"type":899},{"data":50202,"marks":50203,"value":11546,"nodeType":864},{},[],{"data":50205,"content":50206,"nodeType":860},{},[50207,50210,50217,50220,50227],{"data":50208,"marks":50209,"value":16187,"nodeType":864},{},[],{"data":50211,"content":50212,"nodeType":883},{"uri":16190},[50213],{"data":50214,"marks":50215,"value":16196,"nodeType":864},{},[50216],{"type":1455},{"data":50218,"marks":50219,"value":16200,"nodeType":864},{},[],{"data":50221,"content":50222,"nodeType":883},{"uri":16203},[50223],{"data":50224,"marks":50225,"value":16209,"nodeType":864},{},[50226],{"type":1455},{"data":50228,"marks":50229,"value":16213,"nodeType":864},{},[],{"data":50231,"content":50232,"nodeType":860},{},[50233],{"data":50234,"marks":50235,"value":16220,"nodeType":864},{},[],{"data":50237,"content":50240,"nodeType":996},{"target":50238},{"sys":50239},{"id":16225,"type":1001,"linkType":1002},[],{"data":50242,"content":50243,"nodeType":1005},{},[],{"data":50245,"content":50246,"nodeType":1009},{},[50247],{"data":50248,"marks":50249,"value":16237,"nodeType":864},{},[50250],{"type":899},{"data":50252,"content":50253,"nodeType":860},{},[50254],{"data":50255,"marks":50256,"value":16244,"nodeType":864},{},[],{"data":50258,"content":50261,"nodeType":996},{"target":50259},{"sys":50260},{"id":16249,"type":1001,"linkType":1002},[],{"data":50263,"content":50264,"nodeType":860},{},[50265,50268,50274],{"data":50266,"marks":50267,"value":16257,"nodeType":864},{},[],{"data":50269,"content":50270,"nodeType":883},{"uri":16260},[50271],{"data":50272,"marks":50273,"value":16265,"nodeType":864},{},[],{"data":50275,"marks":50276,"value":16269,"nodeType":864},{},[],{"data":50278,"content":50279,"nodeType":860},{},[50280],{"data":50281,"marks":50282,"value":16276,"nodeType":864},{},[],{"data":50284,"content":50285,"nodeType":1312},{},[50286],{"data":50287,"marks":50288,"value":16284,"nodeType":864},{},[50289],{"type":899},{"data":50291,"content":50292,"nodeType":860},{},[50293,50296,50303],{"data":50294,"marks":50295,"value":16291,"nodeType":864},{},[],{"data":50297,"content":50298,"nodeType":883},{"uri":16294},[50299],{"data":50300,"marks":50301,"value":16300,"nodeType":864},{},[50302],{"type":1455},{"data":50304,"marks":50305,"value":16304,"nodeType":864},{},[],{"data":50307,"content":50308,"nodeType":860},{},[50309,50312,50316],{"data":50310,"marks":50311,"value":16311,"nodeType":864},{},[],{"data":50313,"marks":50314,"value":16316,"nodeType":864},{},[50315],{"type":2246},{"data":50317,"marks":50318,"value":16320,"nodeType":864},{},[],{"data":50320,"content":50321,"nodeType":860},{},[50322],{"data":50323,"marks":50324,"value":16327,"nodeType":864},{},[],{"data":50326,"content":50327,"nodeType":860},{},[50328],{"data":50329,"marks":50330,"value":16334,"nodeType":864},{},[],{"data":50332,"content":50333,"nodeType":1005},{},[],{"data":50335,"content":50336,"nodeType":1009},{},[50337],{"data":50338,"marks":50339,"value":16345,"nodeType":864},{},[50340],{"type":899},{"data":50342,"content":50343,"nodeType":860},{},[50344],{"data":50345,"marks":50346,"value":16352,"nodeType":864},{},[],{"data":50348,"content":50349,"nodeType":860},{},[50350],{"data":50351,"marks":50352,"value":16359,"nodeType":864},{},[],{"data":50354,"content":50355,"nodeType":941},{},[50356,50369,50382,50395],{"data":50357,"content":50358,"nodeType":945},{},[50359],{"data":50360,"content":50361,"nodeType":860},{},[50362,50366],{"data":50363,"marks":50364,"value":16373,"nodeType":864},{},[50365],{"type":899},{"data":50367,"marks":50368,"value":16377,"nodeType":864},{},[],{"data":50370,"content":50371,"nodeType":945},{},[50372],{"data":50373,"content":50374,"nodeType":860},{},[50375,50379],{"data":50376,"marks":50377,"value":16388,"nodeType":864},{},[50378],{"type":899},{"data":50380,"marks":50381,"value":16392,"nodeType":864},{},[],{"data":50383,"content":50384,"nodeType":945},{},[50385],{"data":50386,"content":50387,"nodeType":860},{},[50388,50392],{"data":50389,"marks":50390,"value":16403,"nodeType":864},{},[50391],{"type":899},{"data":50393,"marks":50394,"value":16407,"nodeType":864},{},[],{"data":50396,"content":50397,"nodeType":945},{},[50398],{"data":50399,"content":50400,"nodeType":860},{},[50401,50405],{"data":50402,"marks":50403,"value":16418,"nodeType":864},{},[50404],{"type":899},{"data":50406,"marks":50407,"value":16422,"nodeType":864},{},[],{"data":50409,"content":50410,"nodeType":860},{},[50411],{"data":50412,"marks":50413,"value":16429,"nodeType":864},{},[],{"data":50415,"content":50416,"nodeType":1312},{},[50417],{"data":50418,"marks":50419,"value":16437,"nodeType":864},{},[50420],{"type":899},{"data":50422,"content":50423,"nodeType":860},{},[50424,50428],{"data":50425,"marks":50426,"value":16445,"nodeType":864},{},[50427],{"type":899},{"data":50429,"marks":50430,"value":16449,"nodeType":864},{},[],{"data":50432,"content":50433,"nodeType":860},{},[50434],{"data":50435,"marks":50436,"value":16456,"nodeType":864},{},[],{"data":50438,"content":50439,"nodeType":860},{},[50440],{"data":50441,"marks":50442,"value":16463,"nodeType":864},{},[],{"data":50444,"content":50447,"nodeType":996},{"target":50445},{"sys":50446},{"id":16468,"type":1001,"linkType":1002},[],{"data":50449,"content":50450,"nodeType":1312},{},[50451],{"data":50452,"marks":50453,"value":16477,"nodeType":864},{},[50454],{"type":899},{"data":50456,"content":50457,"nodeType":860},{},[50458],{"data":50459,"marks":50460,"value":16484,"nodeType":864},{},[],{"data":50462,"content":50463,"nodeType":860},{},[50464],{"data":50465,"marks":50466,"value":16491,"nodeType":864},{},[],{"data":50468,"content":50469,"nodeType":860},{},[50470],{"data":50471,"marks":50472,"value":16498,"nodeType":864},{},[],{"data":50474,"content":50475,"nodeType":860},{},[50476],{"data":50477,"marks":50478,"value":16505,"nodeType":864},{},[],{"data":50480,"content":50483,"nodeType":996},{"target":50481},{"sys":50482},{"id":16510,"type":1001,"linkType":1002},[],{"data":50485,"content":50486,"nodeType":1312},{},[50487],{"data":50488,"marks":50489,"value":16519,"nodeType":864},{},[50490],{"type":899},{"data":50492,"content":50493,"nodeType":860},{},[50494],{"data":50495,"marks":50496,"value":16526,"nodeType":864},{},[],{"data":50498,"content":50499,"nodeType":941},{},[50500,50539],{"data":50501,"content":50502,"nodeType":945},{},[50503],{"data":50504,"content":50505,"nodeType":860},{},[50506,50509,50516,50519,50526,50529,50536],{"data":50507,"marks":50508,"value":16539,"nodeType":864},{},[],{"data":50510,"content":50511,"nodeType":883},{"uri":16015},[50512],{"data":50513,"marks":50514,"value":16018,"nodeType":864},{},[50515],{"type":1455},{"data":50517,"marks":50518,"value":16550,"nodeType":864},{},[],{"data":50520,"content":50521,"nodeType":883},{"uri":16553},[50522],{"data":50523,"marks":50524,"value":16559,"nodeType":864},{},[50525],{"type":1455},{"data":50527,"marks":50528,"value":16563,"nodeType":864},{},[],{"data":50530,"content":50531,"nodeType":883},{"uri":16566},[50532],{"data":50533,"marks":50534,"value":16572,"nodeType":864},{},[50535],{"type":1455},{"data":50537,"marks":50538,"value":16576,"nodeType":864},{},[],{"data":50540,"content":50541,"nodeType":945},{},[50542],{"data":50543,"content":50544,"nodeType":860},{},[50545,50548,50555,50558,50565],{"data":50546,"marks":50547,"value":16586,"nodeType":864},{},[],{"data":50549,"content":50550,"nodeType":883},{"uri":16027},[50551],{"data":50552,"marks":50553,"value":16030,"nodeType":864},{},[50554],{"type":1455},{"data":50556,"marks":50557,"value":16597,"nodeType":864},{},[],{"data":50559,"content":50560,"nodeType":883},{"uri":16600},[50561],{"data":50562,"marks":50563,"value":16606,"nodeType":864},{},[50564],{"type":1455},{"data":50566,"marks":50567,"value":16610,"nodeType":864},{},[],{"data":50569,"content":50572,"nodeType":996},{"target":50570},{"sys":50571},{"id":16615,"type":1001,"linkType":1002},[],{"data":50574,"content":50575,"nodeType":1005},{},[],{"data":50577,"content":50578,"nodeType":1009},{},[50579],{"data":50580,"marks":50581,"value":16627,"nodeType":864},{},[50582],{"type":899},{"data":50584,"content":50585,"nodeType":860},{},[50586],{"data":50587,"marks":50588,"value":16634,"nodeType":864},{},[],{"data":50590,"content":50591,"nodeType":860},{},[50592,50595,50599],{"data":50593,"marks":50594,"value":16641,"nodeType":864},{},[],{"data":50596,"marks":50597,"value":16646,"nodeType":864},{},[50598],{"type":899},{"data":50600,"marks":50601,"value":16650,"nodeType":864},{},[],{"data":50603,"content":50604,"nodeType":860},{},[50605],{"data":50606,"marks":50607,"value":16657,"nodeType":864},{},[],{"data":50609,"content":50610,"nodeType":860},{},[50611],{"data":50612,"marks":50613,"value":16664,"nodeType":864},{},[],{"data":50615,"content":50618,"nodeType":996},{"target":50616},{"sys":50617},{"id":16669,"type":1001,"linkType":1002},[],{"data":50620,"content":50621,"nodeType":860},{},[50622,50625,50632],{"data":50623,"marks":50624,"value":16677,"nodeType":864},{},[],{"data":50626,"content":50627,"nodeType":883},{"uri":11738},[50628],{"data":50629,"marks":50630,"value":16685,"nodeType":864},{},[50631],{"type":1455},{"data":50633,"marks":50634,"value":16689,"nodeType":864},{},[],{"data":50636,"content":50637,"nodeType":1005},{},[],{"data":50639,"content":50640,"nodeType":1009},{},[50641],{"data":50642,"marks":50643,"value":2578,"nodeType":864},{},[50644],{"type":899},{"data":50646,"content":50647,"nodeType":860},{},[50648],{"data":50649,"marks":50650,"value":16706,"nodeType":864},{},[],{"data":50652,"content":50655,"nodeType":996},{"target":50653},{"sys":50654},{"id":16711,"type":1001,"linkType":1002},[],{"data":50657,"content":50658,"nodeType":860},{},[50659,50662,50669],{"data":50660,"marks":50661,"value":16719,"nodeType":864},{},[],{"data":50663,"content":50664,"nodeType":883},{"uri":11825},[50665],{"data":50666,"marks":50667,"value":16727,"nodeType":864},{},[50668],{"type":1455},{"data":50670,"marks":50671,"value":11546,"nodeType":864},{},[],{"data":50673,"content":50674,"nodeType":860},{},[50675],{"data":50676,"marks":50677,"value":16737,"nodeType":864},{},[],{"data":50679,"content":50680,"nodeType":860},{},[50681],{"data":50682,"marks":50683,"value":16744,"nodeType":864},{},[],{"data":50685,"content":50688,"nodeType":996},{"target":50686},{"sys":50687},{"id":16749,"type":1001,"linkType":1002},[],{"data":50690,"content":50691,"nodeType":1005},{},[],{"data":50693,"content":50694,"nodeType":1009},{},[50695],{"data":50696,"marks":50697,"value":7533,"nodeType":864},{},[50698],{"type":899},{"data":50700,"content":50701,"nodeType":860},{},[50702],{"data":50703,"marks":50704,"value":16767,"nodeType":864},{},[],{"data":50706,"content":50707,"nodeType":860},{},[50708],{"data":50709,"marks":50710,"value":16774,"nodeType":864},{},[],{"data":50712,"content":50715,"nodeType":996},{"target":50713},{"sys":50714},{"id":16779,"type":1001,"linkType":1002},[],{"data":50717,"content":50718,"nodeType":860},{},[50719],{"data":50720,"marks":50721,"value":16787,"nodeType":864},{},[],{"data":50723,"content":50726,"nodeType":996},{"target":50724},{"sys":50725},{"id":16792,"type":1001,"linkType":1002},[],{"data":50728,"content":50731,"nodeType":996},{"target":50729},{"sys":50730},{"id":16798,"type":1001,"linkType":1002},[],{"data":50733,"content":50734,"nodeType":860},{},[50735,50738,50742,50745,50749],{"data":50736,"marks":50737,"value":16806,"nodeType":864},{},[],{"data":50739,"marks":50740,"value":16811,"nodeType":864},{},[50741],{"type":899},{"data":50743,"marks":50744,"value":16815,"nodeType":864},{},[],{"data":50746,"marks":50747,"value":16820,"nodeType":864},{},[50748],{"type":899},{"data":50750,"marks":50751,"value":16824,"nodeType":864},{},[],{"data":50753,"content":50756,"nodeType":996},{"target":50754},{"sys":50755},{"id":16829,"type":1001,"linkType":1002},[],{"data":50758,"content":50759,"nodeType":1312},{},[50760,50763],{"data":50761,"marks":50762,"value":16837,"nodeType":864},{},[],{"data":50764,"marks":50765,"value":16842,"nodeType":864},{},[50766],{"type":899},{"data":50768,"content":50769,"nodeType":860},{},[50770],{"data":50771,"marks":50772,"value":16849,"nodeType":864},{},[],{"data":50774,"content":50775,"nodeType":860},{},[50776],{"data":50777,"marks":50778,"value":16856,"nodeType":864},{},[],{"data":50780,"content":50781,"nodeType":860},{},[50782,50785,50791,50794,50801,50804,50810],{"data":50783,"marks":50784,"value":16863,"nodeType":864},{},[],{"data":50786,"content":50787,"nodeType":883},{"uri":16866},[50788],{"data":50789,"marks":50790,"value":16871,"nodeType":864},{},[],{"data":50792,"marks":50793,"value":3731,"nodeType":864},{},[],{"data":50795,"content":50796,"nodeType":883},{"uri":16877},[50797],{"data":50798,"marks":50799,"value":16883,"nodeType":864},{},[50800],{"type":1455},{"data":50802,"marks":50803,"value":16887,"nodeType":864},{},[],{"data":50805,"content":50806,"nodeType":883},{"uri":1700},[50807],{"data":50808,"marks":50809,"value":16894,"nodeType":864},{},[],{"data":50811,"marks":50812,"value":2924,"nodeType":864},{},[],{"items":50814},[50815,50817],{"sys":50816,"name":13779},{"id":13778},{"sys":50818,"name":342},{"id":13775},{"items":50820},[50821],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":50822},{"url":2740},{"__typename":2059,"sys":50824,"content":50826,"title":52055,"synopsis":52056,"hashTags":59,"publishedDate":52057,"slug":52058,"tagsCollection":52059,"authorsCollection":52065},{"id":50825},"6sprbTRpfnTJsP3mGR2gKa",{"json":50827},{"data":50828,"content":50829,"nodeType":856},{},[50830,50837,50840,50847,50854,50887,50894,50897,50904,50924,50957,50964,50971,50974,50981,50988,50995,51018,51025,51032,51035,51042,51049,51056,51063,51070,51077,51084,51091,51098,51105,51138,51145,51152,51155,51162,51169,51175,51182,51215,51222,51225,51232,51239,51246,51269,51276,51283,51290,51297,51304,51311,51318,51325,51358,51401,51408,51415,51422,51429,51436,51443,51450,51498,51504,51524,51531,51564,51571,51577,51580,51587,51594,51601,51608,51615,51622,51629,51636,51643,51646,51653,51660,51667,51674,51694,51701,51708,51741,51748,51755,51762,51769,51776,51842,51845,51852,51859,51902,51905,51912,51919,51939,51946,51953,51960,51963,51970,51977,51984,52004,52011,52018,52025,52032,52039],{"data":50831,"content":50832,"nodeType":860},{},[50833],{"data":50834,"marks":50835,"value":50836,"nodeType":864},{},[],"Inline with what was targeted in this campaign, our focus here is on the extension deployment process. All browser vendors stand to benefit from greater security in this area — we hope that sharing what we’ve learned is useful, and look forward to comments and feedback so we can collectively reduce the scope for attacks on browser extensions in the future. ",{"data":50838,"content":50839,"nodeType":1005},{},[],{"data":50841,"content":50842,"nodeType":1009},{},[50843],{"data":50844,"marks":50845,"value":50846,"nodeType":864},{},[],"TL;DR",{"data":50848,"content":50849,"nodeType":860},{},[50850],{"data":50851,"marks":50852,"value":50853,"nodeType":864},{},[],"In this blog, we’ll start with some background and walk through the “why” before discussing the key improvements that we feel are needed. But if you don’t care about the why or just want to cut to the chase, the key parts of defending against these attacks are:",{"data":50855,"content":50856,"nodeType":941},{},[50857,50867,50877],{"data":50858,"content":50859,"nodeType":945},{},[50860],{"data":50861,"content":50862,"nodeType":860},{},[50863],{"data":50864,"marks":50865,"value":50866,"nodeType":864},{},[],"Disable always-on access for all users to the browser extension store developer portals — you need to automate deployments through CI/CD to enable this.",{"data":50868,"content":50869,"nodeType":945},{},[50870],{"data":50871,"content":50872,"nodeType":860},{},[50873],{"data":50874,"marks":50875,"value":50876,"nodeType":864},{},[],"Implement a multiparty approval process for extension deployments.",{"data":50878,"content":50879,"nodeType":945},{},[50880],{"data":50881,"content":50882,"nodeType":860},{},[50883],{"data":50884,"marks":50885,"value":50886,"nodeType":864},{},[],"Secure your admin identities.",{"data":50888,"content":50889,"nodeType":860},{},[50890],{"data":50891,"marks":50892,"value":50893,"nodeType":864},{},[],"For details of how to do this practically, skip ahead to the “Recommended security architecture” section.",{"data":50895,"content":50896,"nodeType":1005},{},[],{"data":50898,"content":50899,"nodeType":1009},{},[50900],{"data":50901,"marks":50902,"value":50903,"nodeType":864},{},[],"Background: The Cyberhaven incident",{"data":50905,"content":50906,"nodeType":860},{},[50907,50911,50920],{"data":50908,"marks":50909,"value":50910,"nodeType":864},{},[],"In December 2024, a campaign targeting browser extension developers was launched, and succeeded in compromising at least ",{"data":50912,"content":50914,"nodeType":883},{"uri":50913},"https://www.bleepingcomputer.com/news/security/new-details-reveal-how-hackers-hijacked-35-google-chrome-extensions/",[50915],{"data":50916,"marks":50917,"value":50919,"nodeType":864},{},[50918],{"type":1455},"35 Google Chrome extensions",{"data":50921,"marks":50922,"value":50923,"nodeType":864},{},[],". Cyberhaven’s extension was the most notable of these, and the campaign has inherited their name.",{"data":50925,"content":50926,"nodeType":860},{},[50927,50931,50940,50944,50953],{"data":50928,"marks":50929,"value":50930,"nodeType":864},{},[],"The campaign targeted extension devs through the support email address listed on the extension stores, but notably, the ",{"data":50932,"content":50934,"nodeType":883},{"uri":50933},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/consent_phishing/description.md",[50935],{"data":50936,"marks":50937,"value":50939,"nodeType":864},{},[50938],{"type":1455},"consent phishing attack technique",{"data":50941,"marks":50942,"value":50943,"nodeType":864},{},[]," was used. While not a new technique, it has rarely been seen — especially given how powerful it is. Rather than a traditional credential and MFA phishing attacks which harvest credentials (or session tokens to bypass MFA), with consent phishing the attacker's goal is to trick the victim into granting them an OAuth token to perform actions on their behalf. In this case the permission or scope used by the attacker granted that token the ability to upload and publish new versions of the victim’s extension to the Chrome Web Store — which in this case included some backdoor code that executed commands that were dynamically configured by the attacker. For more in-depth information, see the ",{"data":50945,"content":50947,"nodeType":883},{"uri":50946},"https://secureannex.com/blog/cyberhaven-extension-compromise/",[50948],{"data":50949,"marks":50950,"value":50952,"nodeType":864},{},[50951],{"type":1455},"excellent analysis",{"data":50954,"marks":50955,"value":50956,"nodeType":864},{},[]," by the Secure Annex team.",{"data":50958,"content":50959,"nodeType":860},{},[50960],{"data":50961,"marks":50962,"value":50963,"nodeType":864},{},[],"Because of the dynamic nature of the commands sent to backdoored extensions, it’s difficult to be sure what the impact was — but whatever the case was in this specific incident, it’s perhaps more useful to understand what the impact to users might be so we can work to mitigate future attacks.",{"data":50965,"content":50966,"nodeType":860},{},[50967],{"data":50968,"marks":50969,"value":50970,"nodeType":864},{},[],"The simple fact is that for most common extensions that operate across multiple sites (like ad-blockers etc.), using fairly typical permissions, a backdoor would likely be able to reach credentials and session tokens. This would mean an attacker could use a backdoored extension to get access to a user’s accounts on various websites. This poses a very high impact to users, and something that all extension developers should be focused on preventing. ",{"data":50972,"content":50973,"nodeType":1005},{},[],{"data":50975,"content":50976,"nodeType":1009},{},[50977],{"data":50978,"marks":50979,"value":50980,"nodeType":864},{},[],"How do we stop the next iteration of this attack?",{"data":50982,"content":50983,"nodeType":860},{},[50984],{"data":50985,"marks":50986,"value":50987,"nodeType":864},{},[],"Given the value of the data, the relative ease with which this attack was performed (vs. for example something like a browser 0-day), and the success of the attack, it seems very likely this type of attack will happen again. As we saw in 2024, the success of the attacks on Snowflake customers gave rise to a huge increase in infostealer attacks. Attackers are quick to identify areas of potential opportunity and capitalize on them.",{"data":50989,"content":50990,"nodeType":860},{},[50991],{"data":50992,"marks":50993,"value":50994,"nodeType":864},{},[],"As an extension user, you should be mainly worried about one of two scenarios;",{"data":50996,"content":50997,"nodeType":941},{},[50998,51008],{"data":50999,"content":51000,"nodeType":945},{},[51001],{"data":51002,"content":51003,"nodeType":860},{},[51004],{"data":51005,"marks":51006,"value":51007,"nodeType":864},{},[],"The developer of the extension adds malicious code to an extension, they publish the update to the app store, your browser automatically updates, and malicious code runs in your browser",{"data":51009,"content":51010,"nodeType":945},{},[51011],{"data":51012,"content":51013,"nodeType":860},{},[51014],{"data":51015,"marks":51016,"value":51017,"nodeType":864},{},[],"The developer of your extension is attacked, and the attacker gains access to publish an updated version of the extension to the app store, and uses this to push an update that includes their backdoor, your browser automatically updates, and malicious code runs in your browser",{"data":51019,"content":51020,"nodeType":860},{},[51021],{"data":51022,"marks":51023,"value":51024,"nodeType":864},{},[],"However, since we’re writing this for honest extension developers, and these attacks targeted the second scenario, that’s what we’ll be focussing on. ",{"data":51026,"content":51027,"nodeType":860},{},[51028],{"data":51029,"marks":51030,"value":51031,"nodeType":864},{},[],"The challenge then is to make sure that only legitimate developers can push updates to the extension store. Easy to say, harder to do in the real world.",{"data":51033,"content":51034,"nodeType":1005},{},[],{"data":51036,"content":51037,"nodeType":1009},{},[51038],{"data":51039,"marks":51040,"value":51041,"nodeType":864},{},[],"Primer on extension stores and the publication process",{"data":51043,"content":51044,"nodeType":860},{},[51045],{"data":51046,"marks":51047,"value":51048,"nodeType":864},{},[],"As a light intro for folks that aren’t extension developers but are still interested, here’s a very brief description of this process. It’s not critical to understand the inner workings and differences between the stores to follow this blog, but it is very interesting (in my opinion). ",{"data":51050,"content":51051,"nodeType":860},{},[51052],{"data":51053,"marks":51054,"value":51055,"nodeType":864},{},[],"At Push we publish to three main extension stores; Chrome Web Store (this lets us cover all the Chromium-based browsers including Edge and Arc), Firefox Add-ons, and the Apple Store, so these are the stores we’re covering here.",{"data":51057,"content":51058,"nodeType":860},{},[51059],{"data":51060,"marks":51061,"value":51062,"nodeType":864},{},[],"The generic process is the same for all stores. To publish an update, you first build (or package, really) your extension source, upload it to your tenant/team/org in the store, and publish it. The publishing step triggers a manual review process in the Chrome and Apple stores, and once complete, the new version appears on the extension stores. In Firefox it goes straight out immediately.",{"data":51064,"content":51065,"nodeType":860},{},[51066],{"data":51067,"marks":51068,"value":51069,"nodeType":864},{},[],"A note on the reviews; if you aren’t adding new permissions (something we haven’t seen attackers do because it triggers a new interactive approval for the end-user when the extension is updated — something an attacker wants to avoid to evade detection) then our experience is that the the manual review process is typically fairly cursory. This is likely why the checks implemented at the store level failed to discover malicious updates in these cases.",{"data":51071,"content":51072,"nodeType":860},{},[51073],{"data":51074,"marks":51075,"value":51076,"nodeType":864},{},[],"While it’s possible to do this process completely manually, developers often automate builds and include some of the deployment steps above in the build automation process — I’ll use the term CI/CD to refer to this build and deployment process in the rest of this piece. All three stores provide API keys (albeit in different ways) to enable this process.",{"data":51078,"content":51079,"nodeType":860},{},[51080],{"data":51081,"marks":51082,"value":51083,"nodeType":864},{},[],"I’ll leave it there for now, but again see the “Extension store differences” section in the Appendix for more detail.",{"data":51085,"content":51086,"nodeType":1312},{},[51087],{"data":51088,"marks":51089,"value":51090,"nodeType":864},{},[],"So what's the problem with the stores?",{"data":51092,"content":51093,"nodeType":860},{},[51094],{"data":51095,"marks":51096,"value":51097,"nodeType":864},{},[],"Ok, so far it sounds like the stores are all pretty standardised, so what's the actual problem here? Why did these attacks succeed?",{"data":51099,"content":51100,"nodeType":860},{},[51101],{"data":51102,"marks":51103,"value":51104,"nodeType":864},{},[],"There are a few notable control gaps relating to the extension stores which made this attack possible, and could have mitigated it were they in place. ",{"data":51106,"content":51107,"nodeType":941},{},[51108,51118,51128],{"data":51109,"content":51110,"nodeType":945},{},[51111],{"data":51112,"content":51113,"nodeType":860},{},[51114],{"data":51115,"marks":51116,"value":51117,"nodeType":864},{},[],"Despite the massive risk related to publishing a malicious extension, none of the mainstream stores provide a mechanism to implement a multiparty approval process, increasing the number of successful phishing attempts required. ",{"data":51119,"content":51120,"nodeType":945},{},[51121],{"data":51122,"content":51123,"nodeType":860},{},[51124],{"data":51125,"marks":51126,"value":51127,"nodeType":864},{},[],"Due to the lack of granular permissions in the Chrome store, any dev with access to the store could be phished. A slightly more granular permission model — for example the ability to have one developer with the permission to upload an extension (but not publish it), and another with the ability to publish an uploaded extension (but not upload a new package) — could have addressed this. ",{"data":51129,"content":51130,"nodeType":945},{},[51131],{"data":51132,"content":51133,"nodeType":860},{},[51134],{"data":51135,"marks":51136,"value":51137,"nodeType":864},{},[],"No log stream that could be easily ingested by a SIEM tool is provided, making it much harder to detect and respond. ",{"data":51139,"content":51140,"nodeType":860},{},[51141],{"data":51142,"marks":51143,"value":51144,"nodeType":864},{},[],"But alas, we’re not here to complain about the stores — that’s a different blog post — we’re here to solve problems today!",{"data":51146,"content":51147,"nodeType":860},{},[51148],{"data":51149,"marks":51150,"value":51151,"nodeType":864},{},[],"I mentioned before that a multiparty approval process is key. But to understand why, it’s useful to think about this in terms of how this system will be attacked. Threat or attack models are typical approaches to doing this.",{"data":51153,"content":51154,"nodeType":1005},{},[],{"data":51156,"content":51157,"nodeType":1009},{},[51158],{"data":51159,"marks":51160,"value":51161,"nodeType":864},{},[],"Attack model for publishing a malicious extension",{"data":51163,"content":51164,"nodeType":860},{},[51165],{"data":51166,"marks":51167,"value":51168,"nodeType":864},{},[],"The main attack paths enabling an attacker to publish a malicious extension are outlined below. ",{"data":51170,"content":51174,"nodeType":996},{"target":51171},{"sys":51172},{"id":51173,"type":1001,"linkType":1002},"2RQTz9QmPxOxAvy4EtXIQZ",[],{"data":51176,"content":51177,"nodeType":860},{},[51178],{"data":51179,"marks":51180,"value":51181,"nodeType":864},{},[],"You don’t need to follow all the minutia of these attack paths, but some things to note about these attack paths are that they all target single points of failure (a single identity, a single endpoint), primarily through Social Engineering attacks:",{"data":51183,"content":51184,"nodeType":941},{},[51185,51195,51205],{"data":51186,"content":51187,"nodeType":945},{},[51188],{"data":51189,"content":51190,"nodeType":860},{},[51191],{"data":51192,"marks":51193,"value":51194,"nodeType":864},{},[],"A single user with access to the store needs to fall for a social engineering attack for this to work (as happened in this case). ",{"data":51196,"content":51197,"nodeType":945},{},[51198],{"data":51199,"content":51200,"nodeType":860},{},[51201],{"data":51202,"marks":51203,"value":51204,"nodeType":864},{},[],"Many paths can be completed with an identity or endpoint attack, and in most cases a single identity or endpoint is sufficient.",{"data":51206,"content":51207,"nodeType":945},{},[51208],{"data":51209,"content":51210,"nodeType":860},{},[51211],{"data":51212,"marks":51213,"value":51214,"nodeType":864},{},[],"Attacks against code repos and CI/CD flows are parallel paths, you need to trust those systems already.",{"data":51216,"content":51217,"nodeType":860},{},[51218],{"data":51219,"marks":51220,"value":51221,"nodeType":864},{},[],"So in designing a security architecture, we want to do as much to reduce single points of failure, and make social engineering ineffective (even when it succeeds).",{"data":51223,"content":51224,"nodeType":1005},{},[],{"data":51226,"content":51227,"nodeType":1009},{},[51228],{"data":51229,"marks":51230,"value":51231,"nodeType":864},{},[],"Recommended security architecture",{"data":51233,"content":51234,"nodeType":860},{},[51235],{"data":51236,"marks":51237,"value":51238,"nodeType":864},{},[],"You could literally write a book on everything it takes to secure identities, endpoints and code repositories in general, and we’ll certainly mention some of the identity controls we think are effective later on. One thing to note here is that whatever you implement, the attack that succeeds in the real-word today is vastly more likely to involve an element of social engineering vs. for example a vulnerability exploit. This is not just my opinion (solid as I like to think that is), but also well supported by threat reports like the Verizon DBIR, with 68% of attacks involving ‘the human element’ in the 2024 edition. ",{"data":51240,"content":51241,"nodeType":860},{},[51242],{"data":51243,"marks":51244,"value":51245,"nodeType":864},{},[],"In tackling attacks that involve social engineering, there are two main workable options:",{"data":51247,"content":51248,"nodeType":941},{},[51249,51259],{"data":51250,"content":51251,"nodeType":945},{},[51252],{"data":51253,"content":51254,"nodeType":860},{},[51255],{"data":51256,"marks":51257,"value":51258,"nodeType":864},{},[],"Remove the user’s ability to give the attacker what they need.",{"data":51260,"content":51261,"nodeType":945},{},[51262],{"data":51263,"content":51264,"nodeType":860},{},[51265],{"data":51266,"marks":51267,"value":51268,"nodeType":864},{},[],"Assume that at least some users will fall for the attack, and make it as hard as possible for the attacker.",{"data":51270,"content":51271,"nodeType":860},{},[51272],{"data":51273,"marks":51274,"value":51275,"nodeType":864},{},[],"You may note I didn’t include security or awareness training in the above — essentially because I’ve never seen it be effective enough to be relied on, which is not to say it’s not very useful (especially if it’s well targeted and relevant — like unpacking what happened to Cyberhaven with your whole extension developer team would be!), just that technical controls are generally more reliable.",{"data":51277,"content":51278,"nodeType":860},{},[51279],{"data":51280,"marks":51281,"value":51282,"nodeType":864},{},[],"Anyway, back to what I think makes the cornerstones of a solution.",{"data":51284,"content":51285,"nodeType":1312},{},[51286],{"data":51287,"marks":51288,"value":51289,"nodeType":864},{},[],"Remove BAU access to extension stores",{"data":51291,"content":51292,"nodeType":860},{},[51293],{"data":51294,"marks":51295,"value":51296,"nodeType":864},{},[],"If developers don’t have access to extension stores, they cannot be manipulated into giving attackers access to API keys, they cannot grant attackers authorization to access the store on their behalf, and if the identities are compromised they cannot be used to access the store.",{"data":51298,"content":51299,"nodeType":860},{},[51300],{"data":51301,"marks":51302,"value":51303,"nodeType":864},{},[],"The key to achieving this is to lean fully into completely automated CI/CD processes for normal extension updates. This means that after you’ve configured the CI/CD flows, no developer needs access to the extension stores to do their normal work (publishing new versions of the extension).",{"data":51305,"content":51306,"nodeType":860},{},[51307],{"data":51308,"marks":51309,"value":51310,"nodeType":864},{},[],"Unfortunately, you will still need to access the web console manually for some tasks like updating branding, updating extension descriptions, and proving justification for new permissions (Chrome and Apple only). For our team, these tasks are infrequent enough that they can be handled using break-glass accounts.",{"data":51312,"content":51313,"nodeType":860},{},[51314],{"data":51315,"marks":51316,"value":51317,"nodeType":864},{},[],"A side note here: it might seem that you are just moving the risk around, from the extension store to the code repo & CI/CD system, but you are really already dependent on the security of these systems, so this is just removing the direct access to the extension store from the attack surface. You also have far greater flexibility and control in the CI/CD system as we’ll see in the “Implement multiparty approval in CI/CD” section below.",{"data":51319,"content":51320,"nodeType":1312},{},[51321],{"data":51322,"marks":51323,"value":51324,"nodeType":864},{},[],"Break-glass store admin accounts",{"data":51326,"content":51327,"nodeType":860},{},[51328,51332,51341,51345,51354],{"data":51329,"marks":51330,"value":51331,"nodeType":864},{},[],"In practice you might implement this by issuing developers that need access to the extension stores a second SSO identity that is dedicated to this. You could have a ",{"data":51333,"content":51335,"nodeType":883},{"uri":51334},"mailto:john@amce.com",[51336],{"data":51337,"marks":51338,"value":51340,"nodeType":864},{},[51339],{"type":1455},"john@acme.com",{"data":51342,"marks":51343,"value":51344,"nodeType":864},{},[]," Google account to do normal development work, and a ",{"data":51346,"content":51348,"nodeType":883},{"uri":51347},"mailto:john.admin@acme.com",[51349],{"data":51350,"marks":51351,"value":51353,"nodeType":864},{},[51352],{"type":1455},"john.admin@acme.com",{"data":51355,"marks":51356,"value":51357,"nodeType":864},{},[]," Google account to access the extension stores. You could also:",{"data":51359,"content":51360,"nodeType":941},{},[51361,51371,51381,51391],{"data":51362,"content":51363,"nodeType":945},{},[51364],{"data":51365,"content":51366,"nodeType":860},{},[51367],{"data":51368,"marks":51369,"value":51370,"nodeType":864},{},[],"Make the .admin accounts disabled by default in Google, and enable one of them at a time as and when needed (this should be very rare).",{"data":51372,"content":51373,"nodeType":945},{},[51374],{"data":51375,"content":51376,"nodeType":860},{},[51377],{"data":51378,"marks":51379,"value":51380,"nodeType":864},{},[],"Put the .admin accounts in a separate OU in GWS, and configure that OU so that those accounts are not allowed to authorize any OAuth integrations.",{"data":51382,"content":51383,"nodeType":945},{},[51384],{"data":51385,"content":51386,"nodeType":860},{},[51387],{"data":51388,"marks":51389,"value":51390,"nodeType":864},{},[],"Ensure that all the .admin accounts use hardware backed passkeys that don’t sync anywhere (we like Yubikeys) and disable password logins.",{"data":51392,"content":51393,"nodeType":945},{},[51394],{"data":51395,"content":51396,"nodeType":860},{},[51397],{"data":51398,"marks":51399,"value":51400,"nodeType":864},{},[],"For bonus points, make sure .admin accounts can only be used on a separate dedicated endpoint (e.g. a locked-down Chromebook).",{"data":51402,"content":51403,"nodeType":860},{},[51404],{"data":51405,"marks":51406,"value":51407,"nodeType":864},{},[],"In this way you can have a setup where an attacker would have to successfully target a developer using a hardware-backed identity during the few minutes a year their account is active, and do so without using consent phishing attacks (because all OAuth integrations are disabled for your break-glass accounts). This is a majorly tall order for the attacker.",{"data":51409,"content":51410,"nodeType":1312},{},[51411],{"data":51412,"marks":51413,"value":51414,"nodeType":864},{},[],"Implement multiparty approval in CI/CD",{"data":51416,"content":51417,"nodeType":860},{},[51418],{"data":51419,"marks":51420,"value":51421,"nodeType":864},{},[],"If nobody has active BAU access to extension stores for more than very brief periods, the attacker’s next best option is to target the process that developers are using to publish, i.e. committing code to the repository and waiting for the CI/CD system to publish the extension automatically.",{"data":51423,"content":51424,"nodeType":860},{},[51425],{"data":51426,"marks":51427,"value":51428,"nodeType":864},{},[],"In practice this means the attacker would need to attack the identity (account) the employee uses to access the code repository (assuming a typical cloud hosted system like GitHub here), or sneak code in through an endpoint attack. Overwhelmingly, these attacks are likely to include an element of social engineering — whether that’s phishing credentials or session tokens, or tricking the user into downloading malware, perhaps through a malicious dependency or vscode extension.",{"data":51430,"content":51431,"nodeType":860},{},[51432],{"data":51433,"marks":51434,"value":51435,"nodeType":864},{},[],"We can make the attacker’s life exponentially harder by requiring that they successfully attack two developers, at the same time, before anyone notices. Quick intuition might make it seem like we’re only doubling the difficulty, but other red-teamers with experience doing this will agree that it’s often very easy to target a random user in a large population quickly (one employee in a large corporate), but a single user in a much smaller team (say an extension dev team) might take repeated attacks. When you need to target multiple users in a small team, in a single attack, and maintain the breach concurrently while taking actions (e.g. committing malicious code hoping no-one notices) it becomes much more likely that the alarm will be raised. ",{"data":51437,"content":51438,"nodeType":1312},{},[51439],{"data":51440,"marks":51441,"value":51442,"nodeType":864},{},[],"How to implement multiparty approval through CI/CD",{"data":51444,"content":51445,"nodeType":860},{},[51446],{"data":51447,"marks":51448,"value":51449,"nodeType":864},{},[],"There are probably dozens of ways to skin this cat, but I’ll share one way of doing this that works with mainstream tools and developer processes — using protected git branches.",{"data":51451,"content":51452,"nodeType":941},{},[51453,51468,51483],{"data":51454,"content":51455,"nodeType":945},{},[51456],{"data":51457,"content":51458,"nodeType":860},{},[51459,51464],{"data":51460,"marks":51461,"value":51463,"nodeType":864},{},[51462],{"type":899},"Step 1: ",{"data":51465,"marks":51466,"value":51467,"nodeType":864},{},[],"Setup multiple branches, these might be dev/stg/prd, or development/prerelease/release, and trigger automated build and deploy to the stores using CI/CD with PR merges to the prd/release branches. ",{"data":51469,"content":51470,"nodeType":945},{},[51471],{"data":51472,"content":51473,"nodeType":860},{},[51474,51479],{"data":51475,"marks":51476,"value":51478,"nodeType":864},{},[51477],{"type":899},"Step 2: ",{"data":51480,"marks":51481,"value":51482,"nodeType":864},{},[],"Use branch protection rules that require a second (or even third) named or group of developers to review and approve the PR merge. This achieves multiparty approval.",{"data":51484,"content":51485,"nodeType":945},{},[51486],{"data":51487,"content":51488,"nodeType":860},{},[51489,51494],{"data":51490,"marks":51491,"value":51493,"nodeType":864},{},[51492],{"type":899},"Step 3:",{"data":51495,"marks":51496,"value":51497,"nodeType":864},{},[]," Configure fully automated builds and deployments as part of your CI/CD flows. While this is possible for all three stores, some of the stores do make you jump through a few hoops. Take a look at the steps required to automate a publish to the Apple Store:",{"data":51499,"content":51503,"nodeType":996},{"target":51500},{"sys":51501},{"id":51502,"type":1001,"linkType":1002},"4b9fc1ZUj4HdKl6Iv7Yx8T",[],{"data":51505,"content":51506,"nodeType":860},{},[51507,51511,51520],{"data":51508,"marks":51509,"value":51510,"nodeType":864},{},[],"Since we’ve done the work of figuring this out once already, we extracted the critical steps into a ",{"data":51512,"content":51514,"nodeType":883},{"uri":51513},"https://github.com/pushsecurity/extension-security-guide",[51515],{"data":51516,"marks":51517,"value":51519,"nodeType":864},{},[51518],{"type":1455},"companion Github repo",{"data":51521,"marks":51522,"value":51523,"nodeType":864},{},[]," to make this a bit easier to implement.",{"data":51525,"content":51526,"nodeType":860},{},[51527],{"data":51528,"marks":51529,"value":51530,"nodeType":864},{},[],"As we’ve described it so far, this is a fairly basic implementation, and there are several other controls you might consider to harden this process, including:",{"data":51532,"content":51533,"nodeType":941},{},[51534,51544,51554],{"data":51535,"content":51536,"nodeType":945},{},[51537],{"data":51538,"content":51539,"nodeType":860},{},[51540],{"data":51541,"marks":51542,"value":51543,"nodeType":864},{},[],"Make sure you use a secrets protection system to store Web Store API keys in the CI/CD (it’s no use if the attacker can read the API keys from a config file in your code).",{"data":51545,"content":51546,"nodeType":945},{},[51547],{"data":51548,"content":51549,"nodeType":860},{},[51550],{"data":51551,"marks":51552,"value":51553,"nodeType":864},{},[],"Ensure that developers don’t have access to change branch protection rules, or access CI/CD secrets (otherwise one compromised developer account can undo all this good work — let DevOps or other admin users that are not extension developers handle this admin).",{"data":51555,"content":51556,"nodeType":945},{},[51557],{"data":51558,"content":51559,"nodeType":860},{},[51560],{"data":51561,"marks":51562,"value":51563,"nodeType":864},{},[],"Enforce hardware-backed signed commits as a condition for PR merges (this makes it very very difficult to get bad code into the repo without also compromising your dev team’s Yubikeys)",{"data":51565,"content":51566,"nodeType":860},{},[51567],{"data":51568,"marks":51569,"value":51570,"nodeType":864},{},[],"Now you have strong hardware-backed multiparty authenticated deployments to the stores, and should end up with something that looks a bit like this:",{"data":51572,"content":51576,"nodeType":996},{"target":51573},{"sys":51574},{"id":51575,"type":1001,"linkType":1002},"6tWdfgYKyH2i2Zai05BxzB",[],{"data":51578,"content":51579,"nodeType":1005},{},[],{"data":51581,"content":51582,"nodeType":1009},{},[51583],{"data":51584,"marks":51585,"value":51586,"nodeType":864},{},[],"The next best attack path — IdP admin compromise",{"data":51588,"content":51589,"nodeType":860},{},[51590],{"data":51591,"marks":51592,"value":51593,"nodeType":864},{},[],"Once developers don’t have direct access to the stores, and you have multiparty approvals to get code into CI/CD, the next best attack paths are to target other single-points-of-failure — most likely the administrators. ",{"data":51595,"content":51596,"nodeType":860},{},[51597],{"data":51598,"marks":51599,"value":51600,"nodeType":864},{},[],"This might be the IdP (Google Workspace, Entra, Okta, etc.) admins, which can then be used to provision access to the stores, or simply recover one or more of the developer or break-glass accounts. Or it might target the code repo or CI/CD (GitHub in our example) admins which have access to API keys and can change branch protection rules.",{"data":51602,"content":51603,"nodeType":860},{},[51604],{"data":51605,"marks":51606,"value":51607,"nodeType":864},{},[],"Managing privileged identities like these admin accounts is a constant challenge, but continuing what is perhaps the central thread of this blog, identity attacks (likely through social engineering) are going to be the first port of call for an attacker.",{"data":51609,"content":51610,"nodeType":1312},{},[51611],{"data":51612,"marks":51613,"value":51614,"nodeType":864},{},[],"Recommendations for hardening admin identities",{"data":51616,"content":51617,"nodeType":860},{},[51618],{"data":51619,"marks":51620,"value":51621,"nodeType":864},{},[],"If there’s one thing we know here at Push, it’s identity security — but I’ll fight the urge to go into too much depth with generic recommendations, and focus on where there are opportunities specific to this scope.",{"data":51623,"content":51624,"nodeType":860},{},[51625],{"data":51626,"marks":51627,"value":51628,"nodeType":864},{},[],"One of the most critical aspects of securing these admin accounts is making sure that they are phishing resistant. Where possible, you should be using phishing resistant MFA methods. Typically this means some kind of domain bound security key using the WebAuthn protocol — a passkey using your fingerprint reader is good, something like Yubikey is great. I think this is pretty well understood, but where it goes wrong most often is when backup methods and alternative login methods exist. For example, you might be using an Google OIDC login secured with a Yubikey to access the Firefox store, but not realize that this account also has a password to set that doesn’t have MFA, or has phish-able MFA like SMS or an app-code set.",{"data":51630,"content":51631,"nodeType":860},{},[51632],{"data":51633,"marks":51634,"value":51635,"nodeType":864},{},[],"Attackers are increasingly using attacks that downgrade MFA methods (so the attacker will request the least secure active MFA method when phishing you, rather than the strong method you might use day-to-day), and this is completely automated in modern MFA-bypass phishing kits.",{"data":51637,"content":51638,"nodeType":860},{},[51639],{"data":51640,"marks":51641,"value":51642,"nodeType":864},{},[],"Warning, product plug coming 🙂 — what we do at Push is help you identify issues like these at scale, across all admin, break-glass, dev, and normal user accounts. We also block credential phishing by detecting when users try to enter their SSO credentials on the wrong page, detecting session theft, and can even monitor when credentials stolen via infostealers show up on underground forums.",{"data":51644,"content":51645,"nodeType":1005},{},[],{"data":51647,"content":51648,"nodeType":1009},{},[51649],{"data":51650,"marks":51651,"value":51652,"nodeType":864},{},[],"Going even further to harden extension deployment",{"data":51654,"content":51655,"nodeType":860},{},[51656],{"data":51657,"marks":51658,"value":51659,"nodeType":864},{},[],"This blog is already getting way too long, but there are a lot of other controls that can really help harden extension deployment — if there is interest I might go into detail in a future blog post, but for now let me just mention some of them.",{"data":51661,"content":51662,"nodeType":1312},{},[51663],{"data":51664,"marks":51665,"value":51666,"nodeType":864},{},[],"Multiparty approvals for Google",{"data":51668,"content":51669,"nodeType":860},{},[51670],{"data":51671,"marks":51672,"value":51673,"nodeType":864},{},[],"If you’re going to do multiparty approvals for extension deployments, then enabling this for admin actions that protect that infrastructure seems like a no-brainer.",{"data":51675,"content":51676,"nodeType":860},{},[51677,51681,51690],{"data":51678,"marks":51679,"value":51680,"nodeType":864},{},[],"Google allows you to enable ",{"data":51682,"content":51684,"nodeType":883},{"uri":51683},"https://support.google.com/a/answer/13790448?hl=en",[51685],{"data":51686,"marks":51687,"value":51689,"nodeType":864},{},[51688],{"type":1455},"multiparty approval for sensitive actions",{"data":51691,"marks":51692,"value":51693,"nodeType":864},{},[]," in Google Workspace. We wish it was a bit more granular, and covered more configurable actions — but it’s an awesome start, nice work Google!",{"data":51695,"content":51696,"nodeType":1312},{},[51697],{"data":51698,"marks":51699,"value":51700,"nodeType":864},{},[],"Admin workstations",{"data":51702,"content":51703,"nodeType":860},{},[51704],{"data":51705,"marks":51706,"value":51707,"nodeType":864},{},[],"When we used to do red-team exercises, one of the most challenging controls to work around was when the admin accounts we were targeting were only used on dedicated admin workstations. Ideally those workstations would do nothing except admin tasks, and the accounts would be locked down, so in this case that might mean:",{"data":51709,"content":51710,"nodeType":941},{},[51711,51721,51731],{"data":51712,"content":51713,"nodeType":945},{},[51714],{"data":51715,"content":51716,"nodeType":860},{},[51717],{"data":51718,"marks":51719,"value":51720,"nodeType":864},{},[],"No email access",{"data":51722,"content":51723,"nodeType":945},{},[51724],{"data":51725,"content":51726,"nodeType":860},{},[51727],{"data":51728,"marks":51729,"value":51730,"nodeType":864},{},[],"No extensions",{"data":51732,"content":51733,"nodeType":945},{},[51734],{"data":51735,"content":51736,"nodeType":860},{},[51737],{"data":51738,"marks":51739,"value":51740,"nodeType":864},{},[],"No OAuth apps",{"data":51742,"content":51743,"nodeType":860},{},[51744],{"data":51745,"marks":51746,"value":51747,"nodeType":864},{},[],"This becomes incredibly challenging to attack — but it does come with some obvious painful UX impact for admins, so I don’t think this is a no-brainer for everyone.",{"data":51749,"content":51750,"nodeType":1312},{},[51751],{"data":51752,"marks":51753,"value":51754,"nodeType":864},{},[],"Isolate support emails",{"data":51756,"content":51757,"nodeType":860},{},[51758],{"data":51759,"marks":51760,"value":51761,"nodeType":864},{},[],"Sending your support emails to extension developers creates a direct path to start social engineering — something attackers used to great effect in this campaign. If your developers are not also your frontline support team, consider ringfencing developers from that public support email group so attackers have to at least do some reconnaissance work to identify the developers to target.",{"data":51763,"content":51764,"nodeType":1312},{},[51765],{"data":51766,"marks":51767,"value":51768,"nodeType":864},{},[],"Detection and response",{"data":51770,"content":51771,"nodeType":860},{},[51772],{"data":51773,"marks":51774,"value":51775,"nodeType":864},{},[],"As always there are a myriad of things that can be monitored. We think high value would be doing things like:",{"data":51777,"content":51778,"nodeType":941},{},[51779,51822,51832],{"data":51780,"content":51781,"nodeType":945},{},[51782,51789],{"data":51783,"content":51784,"nodeType":860},{},[51785],{"data":51786,"marks":51787,"value":51788,"nodeType":864},{},[],"Checking whether new versions of your extension appearing in the store is directly related or caused by the CI/CD process, and:",{"data":51790,"content":51791,"nodeType":941},{},[51792,51802,51812],{"data":51793,"content":51794,"nodeType":945},{},[51795],{"data":51796,"content":51797,"nodeType":860},{},[51798],{"data":51799,"marks":51800,"value":51801,"nodeType":864},{},[],"Alert if there is no direct link here.",{"data":51803,"content":51804,"nodeType":945},{},[51805],{"data":51806,"content":51807,"nodeType":860},{},[51808],{"data":51809,"marks":51810,"value":51811,"nodeType":864},{},[],"You can configure email alerts to trigger this automated check.",{"data":51813,"content":51814,"nodeType":945},{},[51815],{"data":51816,"content":51817,"nodeType":860},{},[51818],{"data":51819,"marks":51820,"value":51821,"nodeType":864},{},[],"You could consider immediate automated roll-back to a previous version of the extension if it wasn’t published via the CI/CD system.",{"data":51823,"content":51824,"nodeType":945},{},[51825],{"data":51826,"content":51827,"nodeType":860},{},[51828],{"data":51829,"marks":51830,"value":51831,"nodeType":864},{},[],"Any activity on break-glass accounts — these accounts should only be used after they are activated by admins to complete a specific task, so this is an obvious alert to configure.",{"data":51833,"content":51834,"nodeType":945},{},[51835],{"data":51836,"content":51837,"nodeType":860},{},[51838],{"data":51839,"marks":51840,"value":51841,"nodeType":864},{},[],"Unusual activity on service accounts — this is a bit of work to profile, but very valuable.",{"data":51843,"content":51844,"nodeType":1005},{},[],{"data":51846,"content":51847,"nodeType":1009},{},[51848],{"data":51849,"marks":51850,"value":51851,"nodeType":864},{},[],"Our request to extension stores",{"data":51853,"content":51854,"nodeType":860},{},[51855],{"data":51856,"marks":51857,"value":51858,"nodeType":864},{},[],"I’ll use this opportunity to make an open request to the browser extension stores for a couple of features that I think would really benefit the entire ecosystem:",{"data":51860,"content":51861,"nodeType":941},{},[51862,51872,51882,51892],{"data":51863,"content":51864,"nodeType":945},{},[51865],{"data":51866,"content":51867,"nodeType":860},{},[51868],{"data":51869,"marks":51870,"value":51871,"nodeType":864},{},[],"Add the ability to configure an explicit multiparty approval process (and show the public which extensions have enabled these controls!).",{"data":51873,"content":51874,"nodeType":945},{},[51875],{"data":51876,"content":51877,"nodeType":860},{},[51878],{"data":51879,"marks":51880,"value":51881,"nodeType":864},{},[],"More granular permissions or roles (e.g. only edit descriptions, only only upload, only publish, only accept new terms).",{"data":51883,"content":51884,"nodeType":945},{},[51885],{"data":51886,"content":51887,"nodeType":860},{},[51888],{"data":51889,"marks":51890,"value":51891,"nodeType":864},{},[],"Better logs and monitoring – making it easier to ingest events related to your extension via the store into a SIEM would make alerts much easier to configure.",{"data":51893,"content":51894,"nodeType":945},{},[51895],{"data":51896,"content":51897,"nodeType":860},{},[51898],{"data":51899,"marks":51900,"value":51901,"nodeType":864},{},[],"Enforce stronger default identity security controls (even if only for risky or popular extensions) — we enforce MFA by default for GitHub repositories now, it’s about time that we require MFA to access an extension store as well.",{"data":51903,"content":51904,"nodeType":1005},{},[],{"data":51906,"content":51907,"nodeType":1009},{},[51908],{"data":51909,"marks":51910,"value":51911,"nodeType":864},{},[],"Conclusion",{"data":51913,"content":51914,"nodeType":860},{},[51915],{"data":51916,"marks":51917,"value":51918,"nodeType":864},{},[],"We’ve seen in the past that the successful use of new techniques seem to inspire other attackers and lead to many similar attacks, so the smart money is on this happening again.",{"data":51920,"content":51921,"nodeType":860},{},[51922,51926,51935],{"data":51923,"marks":51924,"value":51925,"nodeType":864},{},[],"There is lots to work needed to secure this process, and hopefully this blog has provided a starting point. We’d love to hear from you — let’s start ",{"data":51927,"content":51929,"nodeType":883},{"uri":51928},"https://github.com/pushsecurity/extension-security-guide/discussions",[51930],{"data":51931,"marks":51932,"value":51934,"nodeType":864},{},[51933],{"type":1455},"sharing some ideas",{"data":51936,"marks":51937,"value":51938,"nodeType":864},{},[]," around hardening this process even more!",{"data":51940,"content":51941,"nodeType":860},{},[51942],{"data":51943,"marks":51944,"value":51945,"nodeType":864},{},[],"If you're a customer rather than an extension developer, this guide hopefully gives you a sense of the supply chain attacks that are likely to happen in the future. Asking your vendors which steps they’ve taken to prevent these attacks might be a sensible addition to your vendor risk assessment process (when the product includes a browser extension). ",{"data":51947,"content":51948,"nodeType":860},{},[51949],{"data":51950,"marks":51951,"value":51952,"nodeType":864},{},[],"This kind of due diligence is viable where the developer is a vendor you have a commercial relationship with, but is a non-starter when it’s an extension that’s offered for free by well meaning open source developers. In these cases a sensible response might be to require approvals for new browser extensions, a technical risk review based on (at least) the permissions the extension is asking for, and managed browser policies to control and further limit what some or all extensions can do. For example, you may decide to block access for extensions to your IdP’s domains to protect your SSO accounts. ",{"data":51954,"content":51955,"nodeType":860},{},[51956],{"data":51957,"marks":51958,"value":51959,"nodeType":864},{},[],"We’ll be releasing guidance on how to manage third party extensions used in your organization in the near future — subscribe to our mailing list to be notified when we do.",{"data":51961,"content":51962,"nodeType":1005},{},[],{"data":51964,"content":51965,"nodeType":1009},{},[51966],{"data":51967,"marks":51968,"value":51969,"nodeType":864},{},[],"Appendix: Extension store differences",{"data":51971,"content":51972,"nodeType":860},{},[51973],{"data":51974,"marks":51975,"value":51976,"nodeType":864},{},[],"We covered the general process of publishing extensions to the different stores in the “Primer on extension stores and the publication process” section above, now let’s talk about the differences between the stores. Let’s start with how they provision for automated deployments.",{"data":51978,"content":51979,"nodeType":1312},{},[51980],{"data":51981,"marks":51982,"value":51983,"nodeType":864},{},[],"Automation keys",{"data":51985,"content":51986,"nodeType":860},{},[51987,51991,52000],{"data":51988,"marks":51989,"value":51990,"nodeType":864},{},[],"The Chrome Web Store allows automation through an OAuth app. As described in ",{"data":51992,"content":51994,"nodeType":883},{"uri":51993},"https://developer.chrome.com/docs/webstore/using-api",[51995],{"data":51996,"marks":51997,"value":51999,"nodeType":864},{},[51998],{"type":1455},"their documentation",{"data":52001,"marks":52002,"value":52003,"nodeType":864},{},[],", the process is for a developer to create a custom OAuth app (a client on OAuth speak), then a user with access to the store authorizes the OAuth app to access the chrome store on their behalf using the https://www.googleapis.com/auth/chromewebstore scope. ",{"data":52005,"content":52006,"nodeType":860},{},[52007],{"data":52008,"marks":52009,"value":52010,"nodeType":864},{},[],"If this sounds familiar, that’s because this is exactly what attackers tricked developers into doing using their own OAuth app in the Cyberhave campaign. In the normal flow, the developer then uses a service key linked to the OAuth app in their CI/CD flow to automate the deployment process.",{"data":52012,"content":52013,"nodeType":860},{},[52014],{"data":52015,"marks":52016,"value":52017,"nodeType":864},{},[],"The situation is a bit simpler for Firefox and Apple, which both work by developers just creating simple static API keys, though Apple does allow you to create personal API keys linked to a single account (and that account’s permissions).",{"data":52019,"content":52020,"nodeType":1312},{},[52021],{"data":52022,"marks":52023,"value":52024,"nodeType":864},{},[],"Accessing the store",{"data":52026,"content":52027,"nodeType":860},{},[52028],{"data":52029,"marks":52030,"value":52031,"nodeType":864},{},[],"In a business environment, using SSO to access apps is extremely useful as it simplifies the provisioning and security-ops work of maintaining secure identities — and often provides more secure authentication methods (e.g. hardware backed WebAuthn MFA) than the target app does (as is the case for the web stores). It also simplifies and centralizes the ability to log and monitor the use of these accounts. I can’t recommend the use of strong SSO authentication enough in cases like this where ensuring you have the right controls in place is paramount.",{"data":52033,"content":52034,"nodeType":860},{},[52035],{"data":52036,"marks":52037,"value":52038,"nodeType":864},{},[],"Fortunately all the stores provide SSO login methods. For the Chrome store, users login (only) using Google SSO accounts — and if they are part of a Google Workspace, access can be provisioned through membership to a group. Firefox allows access using a username and password, but also offers OIDC SSO logins through Google or Apple accounts. If you make use of Managed Apple IDs, Apple offers OIDC SSO authentication as well. ",{"data":52040,"content":52041,"nodeType":860},{},[52042,52046,52051],{"data":52043,"marks":52044,"value":52045,"nodeType":864},{},[],"For Chrome and Firefox there is no real concept of roles (or nothing really useful), and ",{"data":52047,"marks":52048,"value":52050,"nodeType":864},{},[52049],{"type":1455},"you should assume any user with access to a team in your account has the ability to publish extension updates",{"data":52052,"marks":52053,"value":52054,"nodeType":864},{},[],". Apple offers more granular roles and permissions - and there are low privileged roles that can’t publish updates.","Guide to secure browser extension deployment","How extension developers can improve their security controls to prevent extension compromise.","2025-01-14T00:00:00.000Z","guide-to-secure-browser-extension-deployment",{"items":52060},[52061,52063],{"sys":52062,"name":297},{"id":2732},{"sys":52064,"name":342},{"id":13775},{"items":52066},[52067],{"fullName":52068,"firstName":52069,"jobTitle":52070,"profilePicture":52071},"Jacques Louw","Jacques","Co-founder / CRO",{"url":52072},"https://images.ctfassets.net/y1cdw1ablpvd/39m8bektV23lnCRcEq0G8h/2a08f6276a50744f1a4b499b273f6bb2/Push_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-21.jpg",{"__typename":2059,"sys":52074,"content":52076,"title":53419,"synopsis":53420,"hashTags":59,"publishedDate":53421,"slug":53422,"tagsCollection":53423,"authorsCollection":53429},{"id":52075},"wI3paLVDlEKdaRI5qMYFc",{"json":52077},{"data":52078,"content":52079,"nodeType":856},{},[52080,52087,52110,52117,52123,52130,52137,52144,52150,52153,52161,52168,52174,52180,52196,52396,52408,52416,52423,52430,52437,52457,52463,52470,52473,52481,52488,52521,52528,52544,52565,52600,52606,52613,52632,52639,52646,52649,52657,52664,52757,52764,52771,52779,52786,52793,52800,52805,52813,52820,52827,52834,52840,52847,52855,52873,52881,52888,52894,52897,52905,52912,52919,53030,53036,53043,53050,53057,53064,53071,53079,53086,53093,53117,53123,53139,53154,53169,53175,53183,53190,53198,53205,53208,53216,53223,53255,53261,53283,53290,53293,53301,53308,53324,53330,53337,53344,53347,53354,53372,53379],{"data":52081,"content":52082,"nodeType":860},{},[52083],{"data":52084,"marks":52085,"value":52086,"nodeType":864},{},[],"Here are two things that can’t both be true:",{"data":52088,"content":52089,"nodeType":941},{},[52090,52100],{"data":52091,"content":52092,"nodeType":945},{},[52093],{"data":52094,"content":52095,"nodeType":860},{},[52096],{"data":52097,"marks":52098,"value":52099,"nodeType":864},{},[],"Users are the weakest link in security. They just need to stop clicking on things.",{"data":52101,"content":52102,"nodeType":945},{},[52103],{"data":52104,"content":52105,"nodeType":860},{},[52106],{"data":52107,"marks":52108,"value":52109,"nodeType":864},{},[],"The internet is a giant clicking-on-things machine.",{"data":52111,"content":52112,"nodeType":860},{},[52113],{"data":52114,"marks":52115,"value":52116,"nodeType":864},{},[],"In particular, when we look at the TTPs of modern browser-based attacks that target employees, it’s obvious where this disconnect has real consequences. ",{"data":52118,"content":52122,"nodeType":996},{"target":52119},{"sys":52120},{"id":52121,"type":1001,"linkType":1002},"2x3blnHzZYcJ8c439C4NqI",[],{"data":52124,"content":52125,"nodeType":860},{},[52126],{"data":52127,"marks":52128,"value":52129,"nodeType":864},{},[],"Here’s why: Security tooling hasn’t kept up with adversary advances, and normal human behaviors are being expressly targeted via the browser to achieve compromise of accounts and endpoints. If you list the pitfalls facing the common end-user encountering these kinds of attack methods, the picture becomes even more stark.",{"data":52131,"content":52132,"nodeType":860},{},[52133],{"data":52134,"marks":52135,"value":52136,"nodeType":864},{},[],"To solve these problems, you need security tooling that sits in line with the user where they’re already working: In the browser. In this Push product guide, we’ll cover how you can use Push to provide point-in-time guidance — everything from block pages to informational banners — to protect users from modern browser-based TTPs and to guide them to remediate common vulnerabilities that can lead to account takeover.",{"data":52138,"content":52139,"nodeType":860},{},[52140],{"data":52141,"marks":52142,"value":52143,"nodeType":864},{},[],"We’ve also recently introduced custom branding and styling options for user-facing block pages and banners so you can provide a cohesive and trustworthy experience across your security ecosystem.",{"data":52145,"content":52149,"nodeType":996},{"target":52146},{"sys":52147},{"id":52148,"type":1001,"linkType":1002},"7fwCnr9bz76rWWCL6EReOT",[],{"data":52151,"content":52152,"nodeType":1005},{},[],{"data":52154,"content":52155,"nodeType":1009},{},[52156],{"data":52157,"marks":52158,"value":52160,"nodeType":864},{},[52159],{"type":899},"Why you can’t train users to recognize modern browser-based attack methods",{"data":52162,"content":52163,"nodeType":860},{},[52164],{"data":52165,"marks":52166,"value":52167,"nodeType":864},{},[],"User awareness training can help you build your workforce’s basic security baseline. But it’s not a reliable remedy for modern browser-based TTPs. When you look at the creative methods attackers are using — and rapidly improving on — it’s obvious why.",{"data":52169,"content":52173,"nodeType":996},{"target":52170},{"sys":52171},{"id":52172,"type":1001,"linkType":1002},"eHla7GPCH5eTpdfEqW5Zo",[],{"data":52175,"content":52179,"nodeType":996},{"target":52176},{"sys":52177},{"id":52178,"type":1001,"linkType":1002},"29vUtbEUam8fhbwnQdINRJ",[],{"data":52181,"content":52182,"nodeType":860},{},[52183,52187,52192],{"data":52184,"marks":52185,"value":52186,"nodeType":864},{},[],"To avoid account or endpoint compromise while going about your daily work as a user, you would need to accomplish these ",{"data":52188,"marks":52189,"value":52191,"nodeType":864},{},[52190],{"type":2246},"extremely 100% achievable activities",{"data":52193,"marks":52194,"value":52195,"nodeType":864},{},[],", including:",{"data":52197,"content":52198,"nodeType":4845},{},[52199,52224,52264,52287,52321,52353],{"data":52200,"content":52201,"nodeType":4581},{},[52202,52213],{"data":52203,"content":52204,"nodeType":14464},{},[52205],{"data":52206,"content":52207,"nodeType":860},{},[52208],{"data":52209,"marks":52210,"value":52212,"nodeType":864},{},[52211],{"type":899},"Scenario",{"data":52214,"content":52215,"nodeType":14464},{},[52216],{"data":52217,"content":52218,"nodeType":860},{},[52219],{"data":52220,"marks":52221,"value":52223,"nodeType":864},{},[52222],{"type":899},"Threat",{"data":52225,"content":52226,"nodeType":4581},{},[52227,52250],{"data":52228,"content":52229,"nodeType":4569},{},[52230],{"data":52231,"content":52232,"nodeType":860},{},[52233,52237,52246],{"data":52234,"marks":52235,"value":52236,"nodeType":864},{},[],"While using search engines, never click on a ",{"data":52238,"content":52241,"nodeType":39736},{"target":52239},{"sys":52240},{"id":39958,"type":1001,"linkType":1002},[52242],{"data":52243,"marks":52244,"value":52245,"nodeType":864},{},[],"malicious link",{"data":52247,"marks":52248,"value":52249,"nodeType":864},{},[]," in sponsored or organic results (it's often the first link you see, too).",{"data":52251,"content":52252,"nodeType":4569},{},[52253],{"data":52254,"content":52255,"nodeType":860},{},[52256,52260],{"data":52257,"marks":52258,"value":52259,"nodeType":864},{},[],"M",{"data":52261,"marks":52262,"value":52263,"nodeType":864},{},[],"alvertising, SEO poisoning, compromised legitimate webpages, vibecoded phishing webpages.",{"data":52265,"content":52266,"nodeType":4581},{},[52267,52277],{"data":52268,"content":52269,"nodeType":4569},{},[52270],{"data":52271,"content":52272,"nodeType":860},{},[52273],{"data":52274,"marks":52275,"value":52276,"nodeType":864},{},[],"Know when to trust an email coming from an app you use every day, and when it could be malicious (it looks the same).",{"data":52278,"content":52279,"nodeType":4569},{},[52280],{"data":52281,"content":52282,"nodeType":860},{},[52283],{"data":52284,"marks":52285,"value":52286,"nodeType":864},{},[],"Using SaaS services to distribute malicious links using trusted sites (also a handy way of evading email controls).",{"data":52288,"content":52289,"nodeType":4581},{},[52290,52311],{"data":52291,"content":52292,"nodeType":4569},{},[52293],{"data":52294,"content":52295,"nodeType":860},{},[52296,52300,52308],{"data":52297,"marks":52298,"value":52299,"nodeType":864},{},[],"When reading a LinkedIn DM from a colleague, anticipate that they might have been hacked and have sent you a malicious link. (Yes, this was a ",{"data":52301,"content":52303,"nodeType":883},{"uri":52302},"https://pushsecurity.com/blog/how-push-stopped-a-high-risk-linkedin-spear-phishing-attack/",[52304],{"data":52305,"marks":52306,"value":52307,"nodeType":864},{},[],"real scenario",{"data":52309,"marks":52310,"value":14316,"nodeType":864},{},[],{"data":52312,"content":52313,"nodeType":4569},{},[52314],{"data":52315,"content":52316,"nodeType":860},{},[52317],{"data":52318,"marks":52319,"value":52320,"nodeType":864},{},[],"Abuse of social media, IM platforms, and other apps where you can be directly contacted by users external to your organization. ",{"data":52322,"content":52323,"nodeType":4581},{},[52324,52334],{"data":52325,"content":52326,"nodeType":4569},{},[52327],{"data":52328,"content":52329,"nodeType":860},{},[52330],{"data":52331,"marks":52332,"value":52333,"nodeType":864},{},[],"When logging in to an app, never follow benign-seeming but actually malicious instructions to enter a code onto a legitimate page to complete your login.",{"data":52335,"content":52336,"nodeType":4569},{},[52337],{"data":52338,"content":52339,"nodeType":860},{},[52340,52344,52350],{"data":52341,"marks":52342,"value":52343,"nodeType":864},{},[],"AiTM phishing, OAuth consent phishing, ",{"data":52345,"content":52346,"nodeType":883},{"uri":3259},[52347],{"data":52348,"marks":52349,"value":18962,"nodeType":864},{},[],{"data":52351,"marks":52352,"value":2924,"nodeType":864},{},[],{"data":52354,"content":52355,"nodeType":4581},{},[52356,52366],{"data":52357,"content":52358,"nodeType":4569},{},[52359],{"data":52360,"content":52361,"nodeType":860},{},[52362],{"data":52363,"marks":52364,"value":52365,"nodeType":864},{},[],"Know which instructions to follow and which are malicious when verifying that you're human on a CAPTCHA-style page.",{"data":52367,"content":52368,"nodeType":4569},{},[52369],{"data":52370,"content":52371,"nodeType":860},{},[52372,52375,52382,52386,52392],{"data":52373,"marks":52374,"value":21,"nodeType":864},{},[],{"data":52376,"content":52378,"nodeType":883},{"uri":52377},"https://pushsecurity.com/blog/the-most-advanced-clickfix-yet/",[52379],{"data":52380,"marks":52381,"value":315,"nodeType":864},{},[],{"data":52383,"marks":52384,"value":52385,"nodeType":864},{},[],"-style attacks that trick the user into running a malicious script or command, or ",{"data":52387,"content":52388,"nodeType":883},{"uri":11726},[52389],{"data":52390,"marks":52391,"value":11731,"nodeType":864},{},[],{"data":52393,"marks":52394,"value":52395,"nodeType":864},{},[]," (which is even sneakier and simply involves copying a URL).",{"data":52397,"content":52398,"nodeType":860},{},[52399,52403],{"data":52400,"marks":52401,"value":52402,"nodeType":864},{},[],"And we're barely scratching the surface here. ",{"data":52404,"marks":52405,"value":52407,"nodeType":864},{},[52406],{"type":899},"Easy, right?",{"data":52409,"content":52410,"nodeType":1312},{},[52411],{"data":52412,"marks":52413,"value":52415,"nodeType":864},{},[52414],{"type":899},"Can't we block users from interacting with bad content? ",{"data":52417,"content":52418,"nodeType":860},{},[52419],{"data":52420,"marks":52421,"value":52422,"nodeType":864},{},[],"So if you can’t train your way out of these problems, what about locking down and blocking your way out of the problem?",{"data":52424,"content":52425,"nodeType":860},{},[52426],{"data":52427,"marks":52428,"value":52429,"nodeType":864},{},[],"This, too, simply isn’t really feasible. ",{"data":52431,"content":52432,"nodeType":860},{},[52433],{"data":52434,"marks":52435,"value":52436,"nodeType":864},{},[],"Modern cloud-first adversaries routinely rotate domains on malicious pages; use trusted services like SharePoint, Adobe, Google Sites, Cloudflare, and Atlassian to deliver lures; target end-users across multiple channels, including social media, forums, chat platforms, Google search results, email, and webpages; and use legitimate security tools like bot protection to bypass detection by other legitimate security tools, such as web content scanning and analysis solutions.",{"data":52438,"content":52439,"nodeType":860},{},[52440,52444,52448,52453],{"data":52441,"marks":52442,"value":52443,"nodeType":864},{},[],"To safely navigate the internet today, y",{"data":52445,"marks":52446,"value":52447,"nodeType":864},{},[],"ou need to be able to spot malicious pages and content ",{"data":52449,"marks":52450,"value":52452,"nodeType":864},{},[52451],{"type":899},"the first time they're seen in the wild",{"data":52454,"marks":52455,"value":52456,"nodeType":864},{},[],". If you're relying on indicators of known bad, you're always a step behind, leaving users exposed.",{"data":52458,"content":52462,"nodeType":996},{"target":52459},{"sys":52460},{"id":52461,"type":1001,"linkType":1002},"3ZfqOLRdJZJIc78rj9E9JZ",[],{"data":52464,"content":52465,"nodeType":860},{},[52466],{"data":52467,"marks":52468,"value":52469,"nodeType":864},{},[],"To protect users while they work online, you need a purpose-built security tool that can respond in real time to modern TTPs and guide users securely — without introducing extra work or a lot of friction. Push can help with that.",{"data":52471,"content":52472,"nodeType":1005},{},[],{"data":52474,"content":52475,"nodeType":1009},{},[52476],{"data":52477,"marks":52478,"value":52480,"nodeType":864},{},[52479],{"type":899},"Why in-browser controls?",{"data":52482,"content":52483,"nodeType":860},{},[52484],{"data":52485,"marks":52486,"value":52487,"nodeType":864},{},[],"Simply put, using in-browser security controls gets you the closest to the user and their work in order to protect them from modern browser-based threats. Adding in-browser controls also solves two tricky problems for security teams: ",{"data":52489,"content":52490,"nodeType":941},{},[52491,52506],{"data":52492,"content":52493,"nodeType":945},{},[52494],{"data":52495,"content":52496,"nodeType":860},{},[52497,52502],{"data":52498,"marks":52499,"value":52501,"nodeType":864},{},[52500],{"type":899},"Filling the gap between solution layers",{"data":52503,"marks":52504,"value":52505,"nodeType":864},{},[]," in order to detect and block attack methods like Adversary-in-the-Middle phishing, malicious browser extensions, and ClickFix-style social engineering attacks that other tools miss.",{"data":52507,"content":52508,"nodeType":945},{},[52509],{"data":52510,"content":52511,"nodeType":860},{},[52512,52517],{"data":52513,"marks":52514,"value":52516,"nodeType":864},{},[52515],{"type":899},"Providing just-in-time security enforcement",{"data":52518,"marks":52519,"value":52520,"nodeType":864},{},[]," to end-users when it’s the right moment to act on that guidance, reducing your attack surface across your online apps, browser extensions, and accounts, and ensuring your app usage policies are followed.",{"data":52522,"content":52523,"nodeType":1312},{},[52524],{"data":52525,"marks":52526,"value":52527,"nodeType":864},{},[],"Fill the gap between solution layers",{"data":52529,"content":52530,"nodeType":860},{},[52531,52535,52540],{"data":52532,"marks":52533,"value":52534,"nodeType":864},{},[],"Most existing security solutions operate just ",{"data":52536,"marks":52537,"value":52539,"nodeType":864},{},[52538],{"type":2246},"outside",{"data":52541,"marks":52542,"value":52543,"nodeType":864},{},[]," the context of a user interacting with a webpage. This leaves blind spots that attackers are exploiting between layers of security tooling.",{"data":52545,"content":52546,"nodeType":860},{},[52547,52551,52561],{"data":52548,"marks":52549,"value":52550,"nodeType":864},{},[],"For example, network proxies see HTTP requests, URLs, and page headers, but not the ",{"data":52552,"content":52556,"nodeType":39736},{"target":52553},{"sys":52554},{"id":52555,"type":1001,"linkType":1002},"5caCcGCqMMPm5KlwUv0sbz",[52557],{"data":52558,"marks":52559,"value":52560,"nodeType":864},{},[],"structural elements",{"data":52562,"marks":52563,"value":52564,"nodeType":864},{},[]," of the DOM or on-page user interactions that are key to fingerprinting the behavior of AiTM phishing kits or ClickFix-style social engineering attacks. ",{"data":52566,"content":52567,"nodeType":860},{},[52568,52572,52582,52586,52596],{"data":52569,"marks":52570,"value":52571,"nodeType":864},{},[],"Similarly, ",{"data":52573,"content":52577,"nodeType":39736},{"target":52574},{"sys":52575},{"id":52576,"type":1001,"linkType":1002},"6YWYKGESlyUKQxvhKmBzeH",[52578],{"data":52579,"marks":52580,"value":52581,"nodeType":864},{},[],"EDR tools",{"data":52583,"marks":52584,"value":52585,"nodeType":864},{},[]," only see the bad thing when it hits the endpoint, and many ",{"data":52587,"content":52591,"nodeType":39736},{"target":52588},{"sys":52589},{"id":52590,"type":1001,"linkType":1002},"2k2aDK5dyQKlQBrk66pMXE",[52592],{"data":52593,"marks":52594,"value":52595,"nodeType":864},{},[],"cloud security tools",{"data":52597,"marks":52598,"value":52599,"nodeType":864},{},[]," rely on complex policy configurations across a core set of apps to provide security protection — leaving a gap in detection and response capabilities outside their purview.",{"data":52601,"content":52605,"nodeType":996},{"target":52602},{"sys":52603},{"id":52604,"type":1001,"linkType":1002},"50NyBpr96dKspvTzJTBOlC",[],{"data":52607,"content":52608,"nodeType":1312},{},[52609],{"data":52610,"marks":52611,"value":52612,"nodeType":864},{},[],"Provide just-in-time security enforcement",{"data":52614,"content":52615,"nodeType":860},{},[52616,52620,52628],{"data":52617,"marks":52618,"value":52619,"nodeType":864},{},[],"As some of our customers like to say, Push provides security teams with a ",{"data":52621,"content":52623,"nodeType":883},{"uri":52622},"/customer-stories/upvest",[52624],{"data":52625,"marks":52626,"value":52627,"nodeType":864},{},[],"“seat on the user’s side”",{"data":52629,"marks":52630,"value":52631,"nodeType":864},{},[]," of the equation so you can enforce security best practices.",{"data":52633,"content":52634,"nodeType":860},{},[52635],{"data":52636,"marks":52637,"value":52638,"nodeType":864},{},[],"Having that seat on the user’s side also helps you deliver guidance in the right context for it to be followed: When the user is engaged in doing the behavior you want to influence (or prevent). The right information, at the right time, in the right format — not a belated reminder through a different channel that’s easy to ignore.",{"data":52640,"content":52641,"nodeType":860},{},[52642],{"data":52643,"marks":52644,"value":52645,"nodeType":864},{},[],"With those outcomes in mind, let’s look at some specific solutions from the Push platform.",{"data":52647,"content":52648,"nodeType":1005},{},[],{"data":52650,"content":52651,"nodeType":1009},{},[52652],{"data":52653,"marks":52654,"value":52656,"nodeType":864},{},[52655],{"type":899},"How Push helps you protect users from browser-based ATO, ClickFix, and similar attacks",{"data":52658,"content":52659,"nodeType":860},{},[52660],{"data":52661,"marks":52662,"value":52663,"nodeType":864},{},[],"The Push platform provides out-of-the-box detections for browser-based attacks, including:",{"data":52665,"content":52666,"nodeType":941},{},[52667,52690,52713,52734],{"data":52668,"content":52669,"nodeType":945},{},[52670],{"data":52671,"content":52672,"nodeType":860},{},[52673,52676,52686],{"data":52674,"marks":52675,"value":21,"nodeType":864},{},[],{"data":52677,"content":52681,"nodeType":39736},{"target":52678},{"sys":52679},{"id":52680,"type":1001,"linkType":1002},"7KRnTSnJAbbiho69gNyN0B",[52682],{"data":52683,"marks":52684,"value":52685,"nodeType":864},{},[],"AiTM phishing kits",{"data":52687,"marks":52688,"value":52689,"nodeType":864},{},[]," that can bypass MFA",{"data":52691,"content":52692,"nodeType":945},{},[52693],{"data":52694,"content":52695,"nodeType":860},{},[52696,52699,52709],{"data":52697,"marks":52698,"value":21,"nodeType":864},{},[],{"data":52700,"content":52704,"nodeType":39736},{"target":52701},{"sys":52702},{"id":52703,"type":1001,"linkType":1002},"jN3GN5ddMJZiDtl0fgUVd",[52705],{"data":52706,"marks":52707,"value":52708,"nodeType":864},{},[],"Cloned login pages",{"data":52710,"marks":52711,"value":52712,"nodeType":864},{},[]," designed to steal user credentials",{"data":52714,"content":52715,"nodeType":945},{},[52716],{"data":52717,"content":52718,"nodeType":860},{},[52719,52722,52731],{"data":52720,"marks":52721,"value":21,"nodeType":864},{},[],{"data":52723,"content":52727,"nodeType":39736},{"target":52724},{"sys":52725},{"id":52726,"type":1001,"linkType":1002},"5NyiWgjMDwk16XZ0S681JK",[52728],{"data":52729,"marks":52730,"value":699,"nodeType":864},{},[],{"data":52732,"marks":52733,"value":21,"nodeType":864},{},[],{"data":52735,"content":52736,"nodeType":945},{},[52737],{"data":52738,"content":52739,"nodeType":860},{},[52740,52743,52753],{"data":52741,"marks":52742,"value":21,"nodeType":864},{},[],{"data":52744,"content":52748,"nodeType":39736},{"target":52745},{"sys":52746},{"id":52747,"type":1001,"linkType":1002},"7jygmadjoz0asAHv7e5PuK",[52749],{"data":52750,"marks":52751,"value":52752,"nodeType":864},{},[],"Malicious copy and paste attacks",{"data":52754,"marks":52755,"value":52756,"nodeType":864},{},[]," like ClickFix, FileFix, and similar",{"data":52758,"content":52759,"nodeType":860},{},[52760],{"data":52761,"marks":52762,"value":52763,"nodeType":864},{},[],"For each of these attack vectors, Push delivers detection events and associated metadata for quick triage by the security team, as well as employee-facing warn or block screens, based on your selected configuration.",{"data":52765,"content":52766,"nodeType":860},{},[52767],{"data":52768,"marks":52769,"value":52770,"nodeType":864},{},[],"Here’s a snapshot of the capabilities of these controls and what end-users will experience.",{"data":52772,"content":52773,"nodeType":1312},{},[52774],{"data":52775,"marks":52776,"value":52778,"nodeType":864},{},[52777],{"type":899},"The scenario:",{"data":52780,"content":52781,"nodeType":860},{},[52782],{"data":52783,"marks":52784,"value":52785,"nodeType":864},{},[],"When a user encounters a malicious page — whether that’s an AiTM phishing tool running on a webpage, or a ClickFix-style attack — or attempts to install a malicious extension, Push immediately steps in. ",{"data":52787,"content":52788,"nodeType":860},{},[52789],{"data":52790,"marks":52791,"value":52792,"nodeType":864},{},[],"Push can prevent users from entering their credentials on phishing pages, including cloned login pages, or from pasting malicious clipboard contents that can run malware on their device. Push can also prevent users from installing known-bad browser extensions. ",{"data":52794,"content":52795,"nodeType":860},{},[52796],{"data":52797,"marks":52798,"value":52799,"nodeType":864},{},[],"In each of these scenarios, Push admins get detailed detection information they can use to triage the incident.",{"data":52801,"content":52804,"nodeType":996},{"target":52802},{"sys":52803},{"id":40048,"type":1001,"linkType":1002},[],{"data":52806,"content":52807,"nodeType":1312},{},[52808],{"data":52809,"marks":52810,"value":52812,"nodeType":864},{},[52811],{"type":899},"How it works:",{"data":52814,"content":52815,"nodeType":860},{},[52816],{"data":52817,"marks":52818,"value":52819,"nodeType":864},{},[],"Rather than relying on known-bad intelligence like domains or URLs, Push performs a behavioral and structural analysis of malicious pages in real time.",{"data":52821,"content":52822,"nodeType":860},{},[52823],{"data":52824,"marks":52825,"value":52826,"nodeType":864},{},[],"That means a phishing page never has to appear in a threat intelligence feed in order to be detected and blocked.",{"data":52828,"content":52829,"nodeType":860},{},[52830],{"data":52831,"marks":52832,"value":52833,"nodeType":864},{},[],"Similarly, for malicious copy and paste attacks like ClickFix, Push analyzes the content copied to the clipboard but also evaluates the context of the page to reduce false positives. In blocking mode, Push’s control for ClickFix-style attacks replaces the malicious clipboard contents with safe text — preventing potential endpoint compromise before it can occur.",{"data":52835,"content":52839,"nodeType":996},{"target":52836},{"sys":52837},{"id":52838,"type":1001,"linkType":1002},"3OkejjEjV9xflBc5ouOVFn",[],{"data":52841,"content":52842,"nodeType":860},{},[52843],{"data":52844,"marks":52845,"value":52846,"nodeType":864},{},[],"Finally, for identifying malicious browser extensions, Push takes a slightly different approach — combining both behavioral detections and curated intelligence of known-bad extensions from our own research and from trusted industry sources. We’ve found this combination provides the highest-fidelity way to identify malicious extensions without relying on approaches like analyzing extension permissions, which often isn’t actionable. ",{"data":52848,"content":52849,"nodeType":1312},{},[52850],{"data":52851,"marks":52852,"value":52854,"nodeType":864},{},[52853],{"type":899},"Your security team gets:",{"data":52856,"content":52857,"nodeType":860},{},[52858,52862,52870],{"data":52859,"marks":52860,"value":52861,"nodeType":864},{},[],"Readymade detection and alerting, combined with detailed telemetry. Detections and their associated metadata can be consumed via ",{"data":52863,"content":52865,"nodeType":883},{"uri":52864},"/help/audience/administrators/docs/getting-started/#api-and-webhooks",[52866],{"data":52867,"marks":52868,"value":52869,"nodeType":864},{},[],"Push’s REST API and webhooks",{"data":52871,"marks":52872,"value":1774,"nodeType":864},{},[],{"data":52874,"content":52875,"nodeType":1312},{},[52876],{"data":52877,"marks":52878,"value":52880,"nodeType":864},{},[52879],{"type":899},"Your end-users see:",{"data":52882,"content":52883,"nodeType":860},{},[52884],{"data":52885,"marks":52886,"value":52887,"nodeType":864},{},[],"An immediate block screen in your company colors and brand style, providing a highly memorable, contextual moment of learning — and reassuring them that an incident has been prevented.",{"data":52889,"content":52893,"nodeType":996},{"target":52890},{"sys":52891},{"id":52892,"type":1001,"linkType":1002},"4QfjDDfKjohKr1qqDLRT0m",[],{"data":52895,"content":52896,"nodeType":1005},{},[],{"data":52898,"content":52899,"nodeType":1009},{},[52900],{"data":52901,"marks":52902,"value":52904,"nodeType":864},{},[52903],{"type":899},"How Push helps you remediate account vulnerabilities at scale",{"data":52906,"content":52907,"nodeType":860},{},[52908],{"data":52909,"marks":52910,"value":52911,"nodeType":864},{},[],"Just-in-time security enforcement works best when it’s trustworthy and contextual — without making a lot more work for your team. Push also provides readymade controls for remediating common account vulnerabilities that contribute to your attack surface online, helping you harden existing accounts and reduce behaviors that introduce new risks.",{"data":52913,"content":52914,"nodeType":860},{},[52915],{"data":52916,"marks":52917,"value":52918,"nodeType":864},{},[],"With Push, you can:",{"data":52920,"content":52921,"nodeType":941},{},[52922,52945,52983,53007],{"data":52923,"content":52924,"nodeType":945},{},[52925],{"data":52926,"content":52927,"nodeType":860},{},[52928,52931,52941],{"data":52929,"marks":52930,"value":21,"nodeType":864},{},[],{"data":52932,"content":52936,"nodeType":39736},{"target":52933},{"sys":52934},{"id":52935,"type":1001,"linkType":1002},"6FYHbkcRUrtznPo7RarRsz",[52937],{"data":52938,"marks":52939,"value":52940,"nodeType":864},{},[],"Prevent the phishing or reuse of high-value passwords",{"data":52942,"marks":52943,"value":52944,"nodeType":864},{},[],", like your IdP, AWS, or code repository passwords.",{"data":52946,"content":52947,"nodeType":945},{},[52948],{"data":52949,"content":52950,"nodeType":860},{},[52951,52955,52965,52969,52979],{"data":52952,"marks":52953,"value":52954,"nodeType":864},{},[],"Remediate ",{"data":52956,"content":52960,"nodeType":39736},{"target":52957},{"sys":52958},{"id":52959,"type":1001,"linkType":1002},"2WAc5HflKonFN7Jc53ROgj",[52961],{"data":52962,"marks":52963,"value":52964,"nodeType":864},{},[],"missing MFA",{"data":52966,"marks":52967,"value":52968,"nodeType":864},{},[]," or ",{"data":52970,"content":52974,"nodeType":39736},{"target":52971},{"sys":52972},{"id":52973,"type":1001,"linkType":1002},"2dAP36chda6ZDGKzw0Itfs",[52975],{"data":52976,"marks":52977,"value":52978,"nodeType":864},{},[],"insecure passwords",{"data":52980,"marks":52981,"value":52982,"nodeType":864},{},[]," on any work app, even those not managed by your SSO solution.",{"data":52984,"content":52985,"nodeType":945},{},[52986],{"data":52987,"content":52988,"nodeType":860},{},[52989,52993,53003],{"data":52990,"marks":52991,"value":52992,"nodeType":864},{},[],"Use ",{"data":52994,"content":52998,"nodeType":39736},{"target":52995},{"sys":52996},{"id":52997,"type":1001,"linkType":1002},"2ZpKnuljaUH0jzVaae4SMN",[52999],{"data":53000,"marks":53001,"value":53002,"nodeType":864},{},[],"in-browser banners",{"data":53004,"marks":53005,"value":53006,"nodeType":864},{},[]," to add guardrails to app usage, including blocking unapproved SaaS or collecting a business reason to access an app before approving it.",{"data":53008,"content":53009,"nodeType":945},{},[53010],{"data":53011,"content":53012,"nodeType":860},{},[53013,53016,53026],{"data":53014,"marks":53015,"value":21,"nodeType":864},{},[],{"data":53017,"content":53021,"nodeType":39736},{"target":53018},{"sys":53019},{"id":53020,"type":1001,"linkType":1002},"3ibVBa6u0XfcXXDVtON5th",[53022],{"data":53023,"marks":53024,"value":53025,"nodeType":864},{},[],"Block unwanted or unapproved browser extensions",{"data":53027,"marks":53028,"value":53029,"nodeType":864},{},[]," from being installed, or disable them if they’ve been installed previously.",{"data":53031,"content":53032,"nodeType":860},{},[53033],{"data":53034,"marks":53035,"value":52770,"nodeType":864},{},[],{"data":53037,"content":53038,"nodeType":1312},{},[53039],{"data":53040,"marks":53041,"value":52778,"nodeType":864},{},[53042],{"type":899},{"data":53044,"content":53045,"nodeType":860},{},[53046],{"data":53047,"marks":53048,"value":53049,"nodeType":864},{},[],"Push uses in-browser controls to intervene when a user is missing MFA; reusing a high-value password; using an insecure password; attempting to log in to an unapproved app; or attempting to install a blocked extension. ",{"data":53051,"content":53052,"nodeType":860},{},[53053],{"data":53054,"marks":53055,"value":53056,"nodeType":864},{},[],"Push can block users from reusing passwords set as “protected” (meaning they can’t be reused on any other page or app) or from using unapproved apps or extensions. Push can guide users to update their password or register for MFA on accounts where they lack it. Push can also provide any other specific security or policy guidance to employees via banners that appear on apps in your environment, including GenAI apps. ",{"data":53058,"content":53059,"nodeType":860},{},[53060],{"data":53061,"marks":53062,"value":53063,"nodeType":864},{},[],"For all of these scenarios, you can tune Push controls to your preferred mode (informing vs. blocking, for example) and select which employees, employee groups, and apps or accounts to focus on.",{"data":53065,"content":53066,"nodeType":860},{},[53067],{"data":53068,"marks":53069,"value":53070,"nodeType":864},{},[],"You can also customize the message that employees see, to match your organizational culture and policies.",{"data":53072,"content":53073,"nodeType":1312},{},[53074],{"data":53075,"marks":53076,"value":53078,"nodeType":864},{},[53077],{"type":899},"How it works: ",{"data":53080,"content":53081,"nodeType":860},{},[53082],{"data":53083,"marks":53084,"value":53085,"nodeType":864},{},[],"The Push browser agent observes real-time user behavior and securely analyzes users’ account vulnerabilities in order to identify risks and execute your preconfigured controls. ",{"data":53087,"content":53088,"nodeType":860},{},[53089],{"data":53090,"marks":53091,"value":53092,"nodeType":864},{},[],"To identify MFA status, Push uses the app’s own API to query the logged-in user’s registered MFA methods. To analyze password security, Push creates a salted, truncated hash that is stored locally in the user’s browser and then used for comparison to find reused passwords, leaked passwords, and shared passwords. ",{"data":53094,"content":53095,"nodeType":860},{},[53096,53100,53105,53108,53113],{"data":53097,"marks":53098,"value":53099,"nodeType":864},{},[],"Using the ",{"data":53101,"marks":53102,"value":53104,"nodeType":864},{},[53103],{"type":899},"MFA enforcement",{"data":53106,"marks":53107,"value":902,"nodeType":864},{},[],{"data":53109,"marks":53110,"value":53112,"nodeType":864},{},[53111],{"type":899},"Strong password enforcement",{"data":53114,"marks":53115,"value":53116,"nodeType":864},{},[]," controls, you can then automatically display a banner to users with those account vulnerabilities, guiding them to fix the issue.",{"data":53118,"content":53122,"nodeType":996},{"target":53119},{"sys":53120},{"id":53121,"type":1001,"linkType":1002},"7Ka4CumZk9it6GsdlNHREA",[],{"data":53124,"content":53125,"nodeType":860},{},[53126,53130,53135],{"data":53127,"marks":53128,"value":53129,"nodeType":864},{},[],"Using Push’s ",{"data":53131,"marks":53132,"value":53134,"nodeType":864},{},[53133],{"type":899},"Password protection",{"data":53136,"marks":53137,"value":53138,"nodeType":864},{},[]," control, you can select apps where you want to essentially “pin” the high-value password to only that app and prevent its reuse (or phishing) on any other domain. ",{"data":53140,"content":53141,"nodeType":860},{},[53142,53145,53150],{"data":53143,"marks":53144,"value":53129,"nodeType":864},{},[],{"data":53146,"marks":53147,"value":53149,"nodeType":864},{},[53148],{"type":899},"Browser extension blocking",{"data":53151,"marks":53152,"value":53153,"nodeType":864},{},[]," control, you can create a blocklist or allowlist of extensions and prevent users from installing or enabling blocked extensions.",{"data":53155,"content":53156,"nodeType":860},{},[53157,53161,53165],{"data":53158,"marks":53159,"value":53160,"nodeType":864},{},[],"Finally, using Push’s ",{"data":53162,"marks":53163,"value":1366,"nodeType":864},{},[53164],{"type":899},{"data":53166,"marks":53167,"value":53168,"nodeType":864},{},[]," feature, you can add custom messages in a range of modes — from informing to blocking — to apps in use across your business, or even specific URL patterns.",{"data":53170,"content":53174,"nodeType":996},{"target":53171},{"sys":53172},{"id":53173,"type":1001,"linkType":1002},"5Mq4PEzEhW8p1qLvS9aZMm",[],{"data":53176,"content":53177,"nodeType":1312},{},[53178],{"data":53179,"marks":53180,"value":53182,"nodeType":864},{},[53181],{"type":899},"Your security team gets: ",{"data":53184,"content":53185,"nodeType":860},{},[53186],{"data":53187,"marks":53188,"value":53189,"nodeType":864},{},[],"A flexible and highly configurable set of controls to solve account vulnerabilities at scale and to enforce your security controls around browser extensions and app usage.",{"data":53191,"content":53192,"nodeType":1312},{},[53193],{"data":53194,"marks":53195,"value":53197,"nodeType":864},{},[53196],{"type":899},"Your end-users see: ",{"data":53199,"content":53200,"nodeType":860},{},[53201],{"data":53202,"marks":53203,"value":53204,"nodeType":864},{},[],"Contextual, actionable guidance in the midst of their actual workflow, helping them fix the issue or guiding them to safety.",{"data":53206,"content":53207,"nodeType":1005},{},[],{"data":53209,"content":53210,"nodeType":1009},{},[53211],{"data":53212,"marks":53213,"value":53215,"nodeType":864},{},[53214],{"type":899},"Implementation tips",{"data":53217,"content":53218,"nodeType":860},{},[53219],{"data":53220,"marks":53221,"value":53222,"nodeType":864},{},[],"Push allows you to set the scope and mode of each control, making it simple to roll out. ",{"data":53224,"content":53225,"nodeType":860},{},[53226,53230,53234,53238,53242,53246,53251],{"data":53227,"marks":53228,"value":53229,"nodeType":864},{},[],"We recommend starting in ",{"data":53231,"marks":53232,"value":1334,"nodeType":864},{},[53233],{"type":899},{"data":53235,"marks":53236,"value":53237,"nodeType":864},{},[]," mode for controls that intervene in end-user activities. That way, you can perform testing with sample malicious sites or scenarios like reused protected passwords, tune out any benign true positives, and develop the messaging you want to use on warn or block pages. (For controls without an explicit monitor mode, like ",{"data":53239,"marks":53240,"value":53112,"nodeType":864},{},[53241],{"type":899},{"data":53243,"marks":53244,"value":53245,"nodeType":864},{},[],", you can still monitor for related events on the ",{"data":53247,"marks":53248,"value":53250,"nodeType":864},{},[53249],{"type":899},"Events",{"data":53252,"marks":53253,"value":53254,"nodeType":864},{},[]," page, such as account security findings, or by consuming webhooks into a downstream tool.)",{"data":53256,"content":53260,"nodeType":996},{"target":53257},{"sys":53258},{"id":53259,"type":1001,"linkType":1002},"7vk8DHv01cM1o2C0ZpAvZu",[],{"data":53262,"content":53263,"nodeType":860},{},[53264,53268,53272,53275,53279],{"data":53265,"marks":53266,"value":53267,"nodeType":864},{},[],"When you’re ready, set the mode to ",{"data":53269,"marks":53270,"value":1503,"nodeType":864},{},[53271],{"type":899},{"data":53273,"marks":53274,"value":52968,"nodeType":864},{},[],{"data":53276,"marks":53277,"value":1397,"nodeType":864},{},[53278],{"type":899},{"data":53280,"marks":53281,"value":53282,"nodeType":864},{},[]," and use the scope options to perform a phased rollout to your user population by adding additional user groups to the control until you have complete coverage of your population.",{"data":53284,"content":53285,"nodeType":860},{},[53286],{"data":53287,"marks":53288,"value":53289,"nodeType":864},{},[],"By consuming webhook events into your SIEM, you can integrate Push alerts into your existing security workflows, monitoring for new detections or tracking when account vulnerabilities are resolved.",{"data":53291,"content":53292,"nodeType":1005},{},[],{"data":53294,"content":53295,"nodeType":1009},{},[53296],{"data":53297,"marks":53298,"value":53300,"nodeType":864},{},[53299],{"type":899},"Enhancing user trust with custom branding",{"data":53302,"content":53303,"nodeType":860},{},[53304],{"data":53305,"marks":53306,"value":53307,"nodeType":864},{},[],"We recently released the option to customize the look and feel of all employee-facing banners and block pages. ",{"data":53309,"content":53310,"nodeType":860},{},[53311,53315,53320],{"data":53312,"marks":53313,"value":53314,"nodeType":864},{},[],"From the ",{"data":53316,"marks":53317,"value":53319,"nodeType":864},{},[53318],{"type":899},"Settings",{"data":53321,"marks":53322,"value":53323,"nodeType":864},{},[]," page in the Push admin console, you can upload your logo, add accent colors, and choose from light or dark backgrounds.",{"data":53325,"content":53329,"nodeType":996},{"target":53326},{"sys":53327},{"id":53328,"type":1001,"linkType":1002},"51lk1VRP20G7H4PAoRZANI",[],{"data":53331,"content":53332,"nodeType":860},{},[53333],{"data":53334,"marks":53335,"value":53336,"nodeType":864},{},[],"Custom branding increases the trustworthiness of these in-the-moment security guardrails so that users recognize them immediately and act on their guidance.",{"data":53338,"content":53339,"nodeType":860},{},[53340],{"data":53341,"marks":53342,"value":53343,"nodeType":864},{},[],"The result: Better compliance and lower friction for you and your employees.",{"data":53345,"content":53346,"nodeType":1005},{},[],{"data":53348,"content":53349,"nodeType":1009},{},[53350],{"data":53351,"marks":53352,"value":3578,"nodeType":864},{},[53353],{"type":899},{"data":53355,"content":53356,"nodeType":860},{},[53357,53361,53368],{"data":53358,"marks":53359,"value":53360,"nodeType":864},{},[],"Push Security’s browser-based security platform stops browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking — ",{"data":53362,"content":53363,"nodeType":883},{"uri":152},[53364],{"data":53365,"marks":53366,"value":53367,"nodeType":864},{},[],"modern attack techniques",{"data":53369,"marks":53370,"value":53371,"nodeType":864},{},[]," that are the leading cause of breaches today.",{"data":53373,"content":53374,"nodeType":860},{},[53375],{"data":53376,"marks":53377,"value":53378,"nodeType":864},{},[],"You don’t need to wait until it all goes wrong either. You can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":53380,"content":53381,"nodeType":860},{},[53382,53386,53394,53398,53406,53410,53416],{"data":53383,"marks":53384,"value":53385,"nodeType":864},{},[],"Want to learn more about Push? Check out our latest ",{"data":53387,"content":53389,"nodeType":883},{"uri":53388},"/resources/product-brochure",[53390],{"data":53391,"marks":53392,"value":53393,"nodeType":864},{},[],"product overview",{"data":53395,"marks":53396,"value":53397,"nodeType":864},{},[],", visit our ",{"data":53399,"content":53401,"nodeType":883},{"uri":53400},"/product-demo/",[53402],{"data":53403,"marks":53404,"value":53405,"nodeType":864},{},[],"demo library",{"data":53407,"marks":53408,"value":53409,"nodeType":864},{},[],", or book some time with one of our team for a ",{"data":53411,"content":53412,"nodeType":883},{"uri":40635},[53413],{"data":53414,"marks":53415,"value":2715,"nodeType":864},{},[],{"data":53417,"marks":53418,"value":2924,"nodeType":864},{},[],"Guide: How to use Push controls to protect your users from modern browser threats","How to use in-browser controls to stop browser-based attacks before compromise can occur","2026-04-08T00:00:00.000Z","guide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks",{"items":53424},[53425,53427],{"sys":53426,"name":13779},{"id":13778},{"sys":53428,"name":342},{"id":13775},{"items":53430},[53431],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":53432},{"url":853},"why-browser-extension-risk-scoring-wont-predict-your-next-breach","blog/why-browser-extension-risk-scoring-wont-predict-your-next-breach",{"json":53436},{"data":53437,"content":53438,"nodeType":856},{},[53439],{"data":53440,"content":53441,"nodeType":860},{},[53442],{"data":53443,"marks":53444,"value":53445,"nodeType":864},{},[],"Why typical browser extension risk scores are poor predictors of which extensions could actually lead to a compromise.","Why typical browser extension risk scores are poor predictors of which extensions will actually lead to a compromise.",{"id":53448,"publishedAt":53449},"6X3wP0WhtDk2l1jKH2fPIb","2026-08-12T12:01:03.703Z",{"items":53451},[53452,53454],{"sys":53453,"name":342},{"id":13775},{"sys":53455,"name":13779},{"id":13778},{"items":53457},[53458,53460,53462,53464,53466,53468,53470,53472,53474],{"sys":53459,"name":297,"slug":298,"tier":31},{"id":294},{"sys":53461,"name":279,"slug":280,"tier":31},{"id":276},{"sys":53463,"name":342,"slug":343,"tier":31},{"id":339},{"sys":53465,"name":288,"slug":289,"tier":45},{"id":285},{"sys":53467,"name":616,"slug":617,"tier":31},{"id":613},{"sys":53469,"name":571,"slug":572,"tier":45},{"id":568},{"sys":53471,"name":484,"slug":485,"tier":45},{"id":481},{"sys":53473,"name":324,"slug":325,"tier":45},{"id":321},{"sys":53475,"name":633,"slug":634,"tier":45},{"id":630},"q-AJwxFE1-Q49yPg6KXxf0M2eF0tk1BkAx8sMzXOC6E",{"id":53478,"title":16898,"authorsCollection":53479,"content":53484,"extension":228,"faqItemsCollection":54296,"faqTitle":59,"featured":6,"hashTags":59,"meta":54298,"metaTitle":54299,"ogImage":59,"postType":54300,"publishedDate":16900,"relatedBlogPostsCollection":54301,"slug":16901,"stem":59153,"subtitle":59,"summary":59154,"synopsis":16899,"sys":59165,"tagsCollection":59167,"topicsCollection":59173,"__hash__":59215},"blog/blog/unpacking-the-vercel-breach.json",{"items":53480},[53481],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":53482,"profilePicture":53483},[15231],{"url":2740},{"json":53485,"links":54120},{"data":53486,"content":53487,"nodeType":856},{},[53488,53511,53537,53543,53548,53551,53558,53564,53569,53584,53590,53597,53613,53626,53632,53638,53641,53648,53654,53660,53715,53721,53728,53738,53744,53750,53755,53762,53768,53774,53780,53786,53791,53798,53804,53875,53880,53883,53890,53896,53909,53915,53921,53926,53942,53945,53952,53958,53963,53979,53985,53991,53996,53999,54006,54012,54018,54023,54029,54034,54039,54059,54064,54074,54080,54086],{"data":53489,"content":53490,"nodeType":860},{},[53491,53494,53501,53504,53508],{"data":53492,"marks":53493,"value":16160,"nodeType":864},{},[],{"data":53495,"content":53496,"nodeType":883},{"uri":16015},[53497],{"data":53498,"marks":53499,"value":16168,"nodeType":864},{},[53500],{"type":1455},{"data":53502,"marks":53503,"value":16172,"nodeType":864},{},[],{"data":53505,"marks":53506,"value":16177,"nodeType":864},{},[53507],{"type":899},{"data":53509,"marks":53510,"value":11546,"nodeType":864},{},[],{"data":53512,"content":53513,"nodeType":860},{},[53514,53517,53524,53527,53534],{"data":53515,"marks":53516,"value":16187,"nodeType":864},{},[],{"data":53518,"content":53519,"nodeType":883},{"uri":16190},[53520],{"data":53521,"marks":53522,"value":16196,"nodeType":864},{},[53523],{"type":1455},{"data":53525,"marks":53526,"value":16200,"nodeType":864},{},[],{"data":53528,"content":53529,"nodeType":883},{"uri":16203},[53530],{"data":53531,"marks":53532,"value":16209,"nodeType":864},{},[53533],{"type":1455},{"data":53535,"marks":53536,"value":16213,"nodeType":864},{},[],{"data":53538,"content":53539,"nodeType":860},{},[53540],{"data":53541,"marks":53542,"value":16220,"nodeType":864},{},[],{"data":53544,"content":53547,"nodeType":996},{"target":53545},{"sys":53546},{"id":16225,"type":1001,"linkType":1002},[],{"data":53549,"content":53550,"nodeType":1005},{},[],{"data":53552,"content":53553,"nodeType":1009},{},[53554],{"data":53555,"marks":53556,"value":16237,"nodeType":864},{},[53557],{"type":899},{"data":53559,"content":53560,"nodeType":860},{},[53561],{"data":53562,"marks":53563,"value":16244,"nodeType":864},{},[],{"data":53565,"content":53568,"nodeType":996},{"target":53566},{"sys":53567},{"id":16249,"type":1001,"linkType":1002},[],{"data":53570,"content":53571,"nodeType":860},{},[53572,53575,53581],{"data":53573,"marks":53574,"value":16257,"nodeType":864},{},[],{"data":53576,"content":53577,"nodeType":883},{"uri":16260},[53578],{"data":53579,"marks":53580,"value":16265,"nodeType":864},{},[],{"data":53582,"marks":53583,"value":16269,"nodeType":864},{},[],{"data":53585,"content":53586,"nodeType":860},{},[53587],{"data":53588,"marks":53589,"value":16276,"nodeType":864},{},[],{"data":53591,"content":53592,"nodeType":1312},{},[53593],{"data":53594,"marks":53595,"value":16284,"nodeType":864},{},[53596],{"type":899},{"data":53598,"content":53599,"nodeType":860},{},[53600,53603,53610],{"data":53601,"marks":53602,"value":16291,"nodeType":864},{},[],{"data":53604,"content":53605,"nodeType":883},{"uri":16294},[53606],{"data":53607,"marks":53608,"value":16300,"nodeType":864},{},[53609],{"type":1455},{"data":53611,"marks":53612,"value":16304,"nodeType":864},{},[],{"data":53614,"content":53615,"nodeType":860},{},[53616,53619,53623],{"data":53617,"marks":53618,"value":16311,"nodeType":864},{},[],{"data":53620,"marks":53621,"value":16316,"nodeType":864},{},[53622],{"type":2246},{"data":53624,"marks":53625,"value":16320,"nodeType":864},{},[],{"data":53627,"content":53628,"nodeType":860},{},[53629],{"data":53630,"marks":53631,"value":16327,"nodeType":864},{},[],{"data":53633,"content":53634,"nodeType":860},{},[53635],{"data":53636,"marks":53637,"value":16334,"nodeType":864},{},[],{"data":53639,"content":53640,"nodeType":1005},{},[],{"data":53642,"content":53643,"nodeType":1009},{},[53644],{"data":53645,"marks":53646,"value":16345,"nodeType":864},{},[53647],{"type":899},{"data":53649,"content":53650,"nodeType":860},{},[53651],{"data":53652,"marks":53653,"value":16352,"nodeType":864},{},[],{"data":53655,"content":53656,"nodeType":860},{},[53657],{"data":53658,"marks":53659,"value":16359,"nodeType":864},{},[],{"data":53661,"content":53662,"nodeType":941},{},[53663,53676,53689,53702],{"data":53664,"content":53665,"nodeType":945},{},[53666],{"data":53667,"content":53668,"nodeType":860},{},[53669,53673],{"data":53670,"marks":53671,"value":16373,"nodeType":864},{},[53672],{"type":899},{"data":53674,"marks":53675,"value":16377,"nodeType":864},{},[],{"data":53677,"content":53678,"nodeType":945},{},[53679],{"data":53680,"content":53681,"nodeType":860},{},[53682,53686],{"data":53683,"marks":53684,"value":16388,"nodeType":864},{},[53685],{"type":899},{"data":53687,"marks":53688,"value":16392,"nodeType":864},{},[],{"data":53690,"content":53691,"nodeType":945},{},[53692],{"data":53693,"content":53694,"nodeType":860},{},[53695,53699],{"data":53696,"marks":53697,"value":16403,"nodeType":864},{},[53698],{"type":899},{"data":53700,"marks":53701,"value":16407,"nodeType":864},{},[],{"data":53703,"content":53704,"nodeType":945},{},[53705],{"data":53706,"content":53707,"nodeType":860},{},[53708,53712],{"data":53709,"marks":53710,"value":16418,"nodeType":864},{},[53711],{"type":899},{"data":53713,"marks":53714,"value":16422,"nodeType":864},{},[],{"data":53716,"content":53717,"nodeType":860},{},[53718],{"data":53719,"marks":53720,"value":16429,"nodeType":864},{},[],{"data":53722,"content":53723,"nodeType":1312},{},[53724],{"data":53725,"marks":53726,"value":16437,"nodeType":864},{},[53727],{"type":899},{"data":53729,"content":53730,"nodeType":860},{},[53731,53735],{"data":53732,"marks":53733,"value":16445,"nodeType":864},{},[53734],{"type":899},{"data":53736,"marks":53737,"value":16449,"nodeType":864},{},[],{"data":53739,"content":53740,"nodeType":860},{},[53741],{"data":53742,"marks":53743,"value":16456,"nodeType":864},{},[],{"data":53745,"content":53746,"nodeType":860},{},[53747],{"data":53748,"marks":53749,"value":16463,"nodeType":864},{},[],{"data":53751,"content":53754,"nodeType":996},{"target":53752},{"sys":53753},{"id":16468,"type":1001,"linkType":1002},[],{"data":53756,"content":53757,"nodeType":1312},{},[53758],{"data":53759,"marks":53760,"value":16477,"nodeType":864},{},[53761],{"type":899},{"data":53763,"content":53764,"nodeType":860},{},[53765],{"data":53766,"marks":53767,"value":16484,"nodeType":864},{},[],{"data":53769,"content":53770,"nodeType":860},{},[53771],{"data":53772,"marks":53773,"value":16491,"nodeType":864},{},[],{"data":53775,"content":53776,"nodeType":860},{},[53777],{"data":53778,"marks":53779,"value":16498,"nodeType":864},{},[],{"data":53781,"content":53782,"nodeType":860},{},[53783],{"data":53784,"marks":53785,"value":16505,"nodeType":864},{},[],{"data":53787,"content":53790,"nodeType":996},{"target":53788},{"sys":53789},{"id":16510,"type":1001,"linkType":1002},[],{"data":53792,"content":53793,"nodeType":1312},{},[53794],{"data":53795,"marks":53796,"value":16519,"nodeType":864},{},[53797],{"type":899},{"data":53799,"content":53800,"nodeType":860},{},[53801],{"data":53802,"marks":53803,"value":16526,"nodeType":864},{},[],{"data":53805,"content":53806,"nodeType":941},{},[53807,53846],{"data":53808,"content":53809,"nodeType":945},{},[53810],{"data":53811,"content":53812,"nodeType":860},{},[53813,53816,53823,53826,53833,53836,53843],{"data":53814,"marks":53815,"value":16539,"nodeType":864},{},[],{"data":53817,"content":53818,"nodeType":883},{"uri":16015},[53819],{"data":53820,"marks":53821,"value":16018,"nodeType":864},{},[53822],{"type":1455},{"data":53824,"marks":53825,"value":16550,"nodeType":864},{},[],{"data":53827,"content":53828,"nodeType":883},{"uri":16553},[53829],{"data":53830,"marks":53831,"value":16559,"nodeType":864},{},[53832],{"type":1455},{"data":53834,"marks":53835,"value":16563,"nodeType":864},{},[],{"data":53837,"content":53838,"nodeType":883},{"uri":16566},[53839],{"data":53840,"marks":53841,"value":16572,"nodeType":864},{},[53842],{"type":1455},{"data":53844,"marks":53845,"value":16576,"nodeType":864},{},[],{"data":53847,"content":53848,"nodeType":945},{},[53849],{"data":53850,"content":53851,"nodeType":860},{},[53852,53855,53862,53865,53872],{"data":53853,"marks":53854,"value":16586,"nodeType":864},{},[],{"data":53856,"content":53857,"nodeType":883},{"uri":16027},[53858],{"data":53859,"marks":53860,"value":16030,"nodeType":864},{},[53861],{"type":1455},{"data":53863,"marks":53864,"value":16597,"nodeType":864},{},[],{"data":53866,"content":53867,"nodeType":883},{"uri":16600},[53868],{"data":53869,"marks":53870,"value":16606,"nodeType":864},{},[53871],{"type":1455},{"data":53873,"marks":53874,"value":16610,"nodeType":864},{},[],{"data":53876,"content":53879,"nodeType":996},{"target":53877},{"sys":53878},{"id":16615,"type":1001,"linkType":1002},[],{"data":53881,"content":53882,"nodeType":1005},{},[],{"data":53884,"content":53885,"nodeType":1009},{},[53886],{"data":53887,"marks":53888,"value":16627,"nodeType":864},{},[53889],{"type":899},{"data":53891,"content":53892,"nodeType":860},{},[53893],{"data":53894,"marks":53895,"value":16634,"nodeType":864},{},[],{"data":53897,"content":53898,"nodeType":860},{},[53899,53902,53906],{"data":53900,"marks":53901,"value":16641,"nodeType":864},{},[],{"data":53903,"marks":53904,"value":16646,"nodeType":864},{},[53905],{"type":899},{"data":53907,"marks":53908,"value":16650,"nodeType":864},{},[],{"data":53910,"content":53911,"nodeType":860},{},[53912],{"data":53913,"marks":53914,"value":16657,"nodeType":864},{},[],{"data":53916,"content":53917,"nodeType":860},{},[53918],{"data":53919,"marks":53920,"value":16664,"nodeType":864},{},[],{"data":53922,"content":53925,"nodeType":996},{"target":53923},{"sys":53924},{"id":16669,"type":1001,"linkType":1002},[],{"data":53927,"content":53928,"nodeType":860},{},[53929,53932,53939],{"data":53930,"marks":53931,"value":16677,"nodeType":864},{},[],{"data":53933,"content":53934,"nodeType":883},{"uri":11738},[53935],{"data":53936,"marks":53937,"value":16685,"nodeType":864},{},[53938],{"type":1455},{"data":53940,"marks":53941,"value":16689,"nodeType":864},{},[],{"data":53943,"content":53944,"nodeType":1005},{},[],{"data":53946,"content":53947,"nodeType":1009},{},[53948],{"data":53949,"marks":53950,"value":2578,"nodeType":864},{},[53951],{"type":899},{"data":53953,"content":53954,"nodeType":860},{},[53955],{"data":53956,"marks":53957,"value":16706,"nodeType":864},{},[],{"data":53959,"content":53962,"nodeType":996},{"target":53960},{"sys":53961},{"id":16711,"type":1001,"linkType":1002},[],{"data":53964,"content":53965,"nodeType":860},{},[53966,53969,53976],{"data":53967,"marks":53968,"value":16719,"nodeType":864},{},[],{"data":53970,"content":53971,"nodeType":883},{"uri":11825},[53972],{"data":53973,"marks":53974,"value":16727,"nodeType":864},{},[53975],{"type":1455},{"data":53977,"marks":53978,"value":11546,"nodeType":864},{},[],{"data":53980,"content":53981,"nodeType":860},{},[53982],{"data":53983,"marks":53984,"value":16737,"nodeType":864},{},[],{"data":53986,"content":53987,"nodeType":860},{},[53988],{"data":53989,"marks":53990,"value":16744,"nodeType":864},{},[],{"data":53992,"content":53995,"nodeType":996},{"target":53993},{"sys":53994},{"id":16749,"type":1001,"linkType":1002},[],{"data":53997,"content":53998,"nodeType":1005},{},[],{"data":54000,"content":54001,"nodeType":1009},{},[54002],{"data":54003,"marks":54004,"value":7533,"nodeType":864},{},[54005],{"type":899},{"data":54007,"content":54008,"nodeType":860},{},[54009],{"data":54010,"marks":54011,"value":16767,"nodeType":864},{},[],{"data":54013,"content":54014,"nodeType":860},{},[54015],{"data":54016,"marks":54017,"value":16774,"nodeType":864},{},[],{"data":54019,"content":54022,"nodeType":996},{"target":54020},{"sys":54021},{"id":16779,"type":1001,"linkType":1002},[],{"data":54024,"content":54025,"nodeType":860},{},[54026],{"data":54027,"marks":54028,"value":16787,"nodeType":864},{},[],{"data":54030,"content":54033,"nodeType":996},{"target":54031},{"sys":54032},{"id":16792,"type":1001,"linkType":1002},[],{"data":54035,"content":54038,"nodeType":996},{"target":54036},{"sys":54037},{"id":16798,"type":1001,"linkType":1002},[],{"data":54040,"content":54041,"nodeType":860},{},[54042,54045,54049,54052,54056],{"data":54043,"marks":54044,"value":16806,"nodeType":864},{},[],{"data":54046,"marks":54047,"value":16811,"nodeType":864},{},[54048],{"type":899},{"data":54050,"marks":54051,"value":16815,"nodeType":864},{},[],{"data":54053,"marks":54054,"value":16820,"nodeType":864},{},[54055],{"type":899},{"data":54057,"marks":54058,"value":16824,"nodeType":864},{},[],{"data":54060,"content":54063,"nodeType":996},{"target":54061},{"sys":54062},{"id":16829,"type":1001,"linkType":1002},[],{"data":54065,"content":54066,"nodeType":1312},{},[54067,54070],{"data":54068,"marks":54069,"value":16837,"nodeType":864},{},[],{"data":54071,"marks":54072,"value":16842,"nodeType":864},{},[54073],{"type":899},{"data":54075,"content":54076,"nodeType":860},{},[54077],{"data":54078,"marks":54079,"value":16849,"nodeType":864},{},[],{"data":54081,"content":54082,"nodeType":860},{},[54083],{"data":54084,"marks":54085,"value":16856,"nodeType":864},{},[],{"data":54087,"content":54088,"nodeType":860},{},[54089,54092,54098,54101,54108,54111,54117],{"data":54090,"marks":54091,"value":16863,"nodeType":864},{},[],{"data":54093,"content":54094,"nodeType":883},{"uri":16866},[54095],{"data":54096,"marks":54097,"value":16871,"nodeType":864},{},[],{"data":54099,"marks":54100,"value":3731,"nodeType":864},{},[],{"data":54102,"content":54103,"nodeType":883},{"uri":16877},[54104],{"data":54105,"marks":54106,"value":16883,"nodeType":864},{},[54107],{"type":1455},{"data":54109,"marks":54110,"value":16887,"nodeType":864},{},[],{"data":54112,"content":54113,"nodeType":883},{"uri":1700},[54114],{"data":54115,"marks":54116,"value":16894,"nodeType":864},{},[],{"data":54118,"marks":54119,"value":2924,"nodeType":864},{},[],{"entries":54121},{"hyperlink":54122,"inline":54123,"block":54124},[],[],[54125,54133,54147,54155,54162,54187,54225,54244,54271,54277,54283,54290],{"sys":54126,"__typename":1724,"title":54127,"caption":54128,"layoutMode":59,"file":54129},{"id":16225},"Vercel breach summary","Overview of the breach and Vercel's response. ",{"url":54130,"width":54131,"height":54132},"https://images.ctfassets.net/y1cdw1ablpvd/63DxqlpuTD1qIjsSh2gXI2/f1da745b30082c52362c4eb875737548/Screenshot_2026-04-28_at_09.07.41.png",2912,912,{"sys":54134,"__typename":1740,"content":54135,"name":54146,"title":59},{"id":16249},{"json":54136},{"data":54137,"content":54138,"nodeType":856},{},[54139],{"data":54140,"content":54141,"nodeType":860},{},[54142],{"data":54143,"marks":54144,"value":54145,"nodeType":864},{},[],"An all-too-common tale in the modern enterprise is the SaaS app that was trialled by a single employee, lightly used, integrated with core app tenants, and forgotten about — adding an invisible node to the organization’s attack surface.","Vercel IB 4",{"sys":54148,"__typename":1724,"title":54149,"caption":54150,"layoutMode":59,"file":54151},{"id":16468},"Illustrative example of SaaS OAuth sprawl. AI apps are highlighted orange.","Illustrative example of SaaS OAuth sprawl, from primary enterprise cloud, to core apps, to wider SaaS. AI apps are highlighted orange.",{"url":54152,"width":54153,"height":54154},"https://images.ctfassets.net/y1cdw1ablpvd/6u0rnGPxUjcFSxdbsIcNz0/b093fbd09053a6a764b03af9ba56e5df/Screenshot_2026-04-23_at_20.41.29.png",2516,2086,{"sys":54156,"__typename":1724,"title":54157,"caption":54157,"layoutMode":59,"file":54158},{"id":16510},"A normal employee in a poorly governed org can expose as much or more data than a developer in a well-governed one.",{"url":54159,"width":54160,"height":54161},"https://images.ctfassets.net/y1cdw1ablpvd/R2st9zXI0vB5Mu9Co2pA1/dc1843bc5be5da60252c9c7ea7caf677/oauth-blast-radius-push_1__4_.png",2880,2040,{"sys":54163,"__typename":1740,"content":54164,"name":54186,"title":59},{"id":16615},{"json":54165},{"nodeType":856,"data":54166,"content":54167},{},[54168],{"nodeType":860,"data":54169,"content":54170},{},[54171,54175,54182],{"nodeType":864,"value":54172,"marks":54173,"data":54174},"Not only are attackers abusing existing (legitimate) OAuth connections as part of supply chain attacks, but they’re using OAuth-focused phishing as the front door to victim environments. Last year’s Salesforce campaign began with ",[],{},{"nodeType":883,"data":54176,"content":54177},{"uri":3259},[54178],{"nodeType":864,"value":18962,"marks":54179,"data":54181},[54180],{"type":1455},{},{"nodeType":864,"value":54183,"marks":54184,"data":54185},", where attackers tricked victims into registering an attacker-controlled app into their Salesforce tenant, granting full API access for mass data exfiltration.",[],{},"Vercel IB 1",{"sys":54188,"__typename":1740,"content":54189,"name":54224,"title":59},{"id":16669},{"json":54190},{"nodeType":856,"data":54191,"content":54192},{},[54193,54212],{"nodeType":860,"data":54194,"content":54195},{},[54196,54200,54208],{"nodeType":864,"value":54197,"marks":54198,"data":54199},"If you’re wondering how a personal device could result in corporate credential leakage, browser syncing (",[],{},{"nodeType":883,"data":54201,"content":54202},{"uri":16203},[54203],{"nodeType":864,"value":54204,"marks":54205,"data":54207},"where users sign into their personal account in a corporate browser",[54206],{"type":1455},{},{"nodeType":864,"value":54209,"marks":54210,"data":54211},") can lead to this exact scenario. And given Vercel’s potentially lacking controls around OAuth integrations in their Workspace, it’s also possible that browser syncing had not been identified as a security risk and disabled. ",[],{},{"nodeType":860,"data":54213,"content":54214},{},[54215,54219],{"nodeType":864,"value":54216,"marks":54217,"data":54218},"The 2025 Verizon DBIR reported that 54% of all ransomware attacks traced back to infostealer-enabled credential theft. ",[],{},{"nodeType":864,"value":54220,"marks":54221,"data":54223},"46% of systems with compromised corporate credentials were non-managed devices. ",[54222],{"type":899},{},"Vercel IB 2",{"sys":54226,"__typename":1740,"content":54227,"name":54243,"title":59},{"id":16711},{"json":54228},{"nodeType":856,"data":54229,"content":54230},{},[54231],{"nodeType":860,"data":54232,"content":54233},{},[54234,54239],{"nodeType":864,"value":54235,"marks":54236,"data":54238},"OAuth App:",[54237],{"type":899},{},{"nodeType":864,"value":54240,"marks":54241,"data":54242}," 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com",[],{},"Vercel IB 5",{"sys":54245,"__typename":1740,"content":54246,"name":54270,"title":59},{"id":16749},{"json":54247},{"nodeType":856,"data":54248,"content":54249},{},[54250],{"nodeType":860,"data":54251,"content":54252},{},[54253,54257,54266],{"nodeType":864,"value":54254,"marks":54255,"data":54256},"Since the breach was initially reported, ",[],{},{"nodeType":883,"data":54258,"content":54260},{"uri":54259},"https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html",[54261],{"nodeType":864,"value":54262,"marks":54263,"data":54265},"it has also emerged that",[54264],{"type":1455},{},{"nodeType":864,"value":54267,"marks":54268,"data":54269}," Context.ai’s browser extension has also been pulled from the Chrome store. It’s unclear whether attackers were able to publish a malicious extension update too, whether the extension was removed at Context.ai’s request (because the app has been deprecated), or Google pulled it down as a precaution in light of the incident. ",[],{},"Vercel IB 3",{"sys":54272,"__typename":1724,"title":54273,"caption":54273,"layoutMode":59,"file":54274},{"id":16779},"Inspect apps and identities to uncover and remediate vulnerabilities.",{"url":54275,"width":1736,"height":54276},"https://images.ctfassets.net/y1cdw1ablpvd/4rfQX7ICFP2tiio0Ra9r0f/ef6cdc27bc3dde03127105189523e405/image5.png",1074,{"sys":54278,"__typename":1724,"title":54279,"caption":54279,"layoutMode":59,"file":54280},{"id":16792},"Analyse OAuth integrations, including permissions, user count, and other useful metadata. ",{"url":54281,"width":1736,"height":54282},"https://images.ctfassets.net/y1cdw1ablpvd/6srKhXfs62Ql2vIUc0QszJ/58ae9672ed3e79bfef1fb65a6cd7450a/image3.png",1091,{"sys":54284,"__typename":1724,"title":54285,"caption":54285,"layoutMode":59,"file":54286},{"id":16798},"Easily delete unwanted integrations. ",{"url":54287,"width":54288,"height":54289},"https://images.ctfassets.net/y1cdw1ablpvd/8BTe7GRIl7aLnwcmkRQkb/eb26d8d0ecb0165d4ab3c4d4a3ac6111/image1.png",567,213,{"sys":54291,"__typename":1724,"title":54292,"caption":54293,"layoutMode":59,"file":54294},{"id":16829},"Block OAuth connection attempts as they transit the browser using Push.","Block OAuth connection attempts as they transit the browser using Push. Example shows blocking Claude connectors. ",{"url":54295,"width":45755,"height":45756},"https://images.ctfassets.net/y1cdw1ablpvd/4TIl7F28Qd1Mk5M4vrFUF7/1b983ddc567ea7130cc76c3397d8fb69/OAuth_blocking.gif",{"items":54297},[],{},"Unpacking the Vercel breach: Shadow AI and OAuth sprawl","breach-analysis",{"items":54302},[54303,57020,57979],{"__typename":2059,"sys":54304,"content":54305,"title":22297,"synopsis":22298,"hashTags":59,"publishedDate":22299,"slug":361,"tagsCollection":57010,"authorsCollection":57016},{"id":19308},{"json":54306},{"data":54307,"content":54308,"nodeType":856},{},[54309,54314,54330,54346,54352,54357,54363,54369,54372,54379,54384,54450,54466,54471,54477,54573,54578,54581,54588,54594,54599,54602,54609,54645,54650,54656,54662,54668,54674,54690,54695,54700,54705,54710,54715,54720,54725,54731,54961,54964,54971,55098,55103,55106,55113,55144,55271,55276,55279,55286,55425,55430,55433,55440,55445,55579,55584,55589,55592,55599,55738,55743,55746,55753,55893,55898,55901,55908,55999,56004,56007,56014,56105,56110,56113,56120,56125,56252,56257,56260,56267,56314,56319,56322,56329,56462,56467,56470,56477,56604,56609,56612,56619,56629,56635,56640,56645,56651,56668,56681,56686,56689,56696,56703,56720,56737,56742,56748,56754,56761,56767,56773,56779,56786,56792,56837,56842,56845,56852,56858,56864,56901,56906,56912,56915,56922,56928,56934,56950,56955,56961,56968,56974],{"data":54310,"content":54313,"nodeType":996},{"target":54311},{"sys":54312},{"id":19317,"type":1001,"linkType":1002},[],{"data":54315,"content":54316,"nodeType":860},{},[54317,54320,54327],{"data":54318,"marks":54319,"value":19325,"nodeType":864},{},[],{"data":54321,"content":54322,"nodeType":883},{"uri":19328},[54323],{"data":54324,"marks":54325,"value":19334,"nodeType":864},{},[54326],{"type":1455},{"data":54328,"marks":54329,"value":19338,"nodeType":864},{},[],{"data":54331,"content":54332,"nodeType":860},{},[54333,54336,54343],{"data":54334,"marks":54335,"value":21,"nodeType":864},{},[],{"data":54337,"content":54338,"nodeType":883},{"uri":19347},[54339],{"data":54340,"marks":54341,"value":360,"nodeType":864},{},[54342],{"type":1455},{"data":54344,"marks":54345,"value":19356,"nodeType":864},{},[],{"data":54347,"content":54348,"nodeType":860},{},[54349],{"data":54350,"marks":54351,"value":19363,"nodeType":864},{},[],{"data":54353,"content":54356,"nodeType":996},{"target":54354},{"sys":54355},{"id":19368,"type":1001,"linkType":1002},[],{"data":54358,"content":54359,"nodeType":860},{},[54360],{"data":54361,"marks":54362,"value":19376,"nodeType":864},{},[],{"data":54364,"content":54365,"nodeType":860},{},[54366],{"data":54367,"marks":54368,"value":19383,"nodeType":864},{},[],{"data":54370,"content":54371,"nodeType":1005},{},[],{"data":54373,"content":54374,"nodeType":1009},{},[54375],{"data":54376,"marks":54377,"value":19394,"nodeType":864},{},[54378],{"type":899},{"data":54380,"content":54383,"nodeType":996},{"target":54381},{"sys":54382},{"id":19399,"type":1001,"linkType":1002},[],{"data":54385,"content":54386,"nodeType":860},{},[54387,54390,54397,54400,54407,54410,54417,54420,54427,54430,54437,54440,54447],{"data":54388,"marks":54389,"value":19407,"nodeType":864},{},[],{"data":54391,"content":54392,"nodeType":883},{"uri":19410},[54393],{"data":54394,"marks":54395,"value":19416,"nodeType":864},{},[54396],{"type":1455},{"data":54398,"marks":54399,"value":19420,"nodeType":864},{},[],{"data":54401,"content":54402,"nodeType":883},{"uri":19423},[54403],{"data":54404,"marks":54405,"value":19429,"nodeType":864},{},[54406],{"type":1455},{"data":54408,"marks":54409,"value":19433,"nodeType":864},{},[],{"data":54411,"content":54412,"nodeType":883},{"uri":19436},[54413],{"data":54414,"marks":54415,"value":19442,"nodeType":864},{},[54416],{"type":1455},{"data":54418,"marks":54419,"value":19446,"nodeType":864},{},[],{"data":54421,"content":54422,"nodeType":883},{"uri":19449},[54423],{"data":54424,"marks":54425,"value":19455,"nodeType":864},{},[54426],{"type":1455},{"data":54428,"marks":54429,"value":19459,"nodeType":864},{},[],{"data":54431,"content":54432,"nodeType":883},{"uri":19462},[54433],{"data":54434,"marks":54435,"value":19468,"nodeType":864},{},[54436],{"type":1455},{"data":54438,"marks":54439,"value":902,"nodeType":864},{},[],{"data":54441,"content":54442,"nodeType":883},{"uri":19474},[54443],{"data":54444,"marks":54445,"value":19480,"nodeType":864},{},[54446],{"type":1455},{"data":54448,"marks":54449,"value":19484,"nodeType":864},{},[],{"data":54451,"content":54452,"nodeType":860},{},[54453,54456,54463],{"data":54454,"marks":54455,"value":19491,"nodeType":864},{},[],{"data":54457,"content":54458,"nodeType":883},{"uri":19494},[54459],{"data":54460,"marks":54461,"value":19500,"nodeType":864},{},[54462],{"type":1455},{"data":54464,"marks":54465,"value":19504,"nodeType":864},{},[],{"data":54467,"content":54470,"nodeType":996},{"target":54468},{"sys":54469},{"id":19509,"type":1001,"linkType":1002},[],{"data":54472,"content":54473,"nodeType":860},{},[54474],{"data":54475,"marks":54476,"value":19517,"nodeType":864},{},[],{"data":54478,"content":54479,"nodeType":941},{},[54480,54507,54525],{"data":54481,"content":54482,"nodeType":945},{},[54483],{"data":54484,"content":54485,"nodeType":860},{},[54486,54489,54495,54498,54504],{"data":54487,"marks":54488,"value":19530,"nodeType":864},{},[],{"data":54490,"content":54491,"nodeType":883},{"uri":19533},[54492],{"data":54493,"marks":54494,"value":19538,"nodeType":864},{},[],{"data":54496,"marks":54497,"value":902,"nodeType":864},{},[],{"data":54499,"content":54500,"nodeType":883},{"uri":19544},[54501],{"data":54502,"marks":54503,"value":19549,"nodeType":864},{},[],{"data":54505,"marks":54506,"value":19553,"nodeType":864},{},[],{"data":54508,"content":54509,"nodeType":945},{},[54510],{"data":54511,"content":54512,"nodeType":860},{},[54513,54516,54522],{"data":54514,"marks":54515,"value":19563,"nodeType":864},{},[],{"data":54517,"content":54518,"nodeType":883},{"uri":16015},[54519],{"data":54520,"marks":54521,"value":16018,"nodeType":864},{},[],{"data":54523,"marks":54524,"value":19573,"nodeType":864},{},[],{"data":54526,"content":54527,"nodeType":945},{},[54528],{"data":54529,"content":54530,"nodeType":860},{},[54531,54534,54540,54543,54550,54553,54560,54563,54570],{"data":54532,"marks":54533,"value":19583,"nodeType":864},{},[],{"data":54535,"content":54536,"nodeType":883},{"uri":19586},[54537],{"data":54538,"marks":54539,"value":19591,"nodeType":864},{},[],{"data":54541,"marks":54542,"value":19595,"nodeType":864},{},[],{"data":54544,"content":54545,"nodeType":883},{"uri":19598},[54546],{"data":54547,"marks":54548,"value":19604,"nodeType":864},{},[54549],{"type":1455},{"data":54551,"marks":54552,"value":2232,"nodeType":864},{},[],{"data":54554,"content":54555,"nodeType":883},{"uri":19610},[54556],{"data":54557,"marks":54558,"value":19616,"nodeType":864},{},[54559],{"type":1455},{"data":54561,"marks":54562,"value":19620,"nodeType":864},{},[],{"data":54564,"content":54565,"nodeType":883},{"uri":7018},[54566],{"data":54567,"marks":54568,"value":19628,"nodeType":864},{},[54569],{"type":1455},{"data":54571,"marks":54572,"value":19632,"nodeType":864},{},[],{"data":54574,"content":54577,"nodeType":996},{"target":54575},{"sys":54576},{"id":19637,"type":1001,"linkType":1002},[],{"data":54579,"content":54580,"nodeType":1005},{},[],{"data":54582,"content":54583,"nodeType":1009},{},[54584],{"data":54585,"marks":54586,"value":19649,"nodeType":864},{},[54587],{"type":899},{"data":54589,"content":54590,"nodeType":860},{},[54591],{"data":54592,"marks":54593,"value":19656,"nodeType":864},{},[],{"data":54595,"content":54598,"nodeType":996},{"target":54596},{"sys":54597},{"id":19661,"type":1001,"linkType":1002},[],{"data":54600,"content":54601,"nodeType":1005},{},[],{"data":54603,"content":54604,"nodeType":1312},{},[54605],{"data":54606,"marks":54607,"value":19673,"nodeType":864},{},[54608],{"type":899},{"data":54610,"content":54611,"nodeType":860},{},[54612,54615,54622,54625,54632,54635,54642],{"data":54613,"marks":54614,"value":21,"nodeType":864},{},[],{"data":54616,"content":54617,"nodeType":883},{"uri":7018},[54618],{"data":54619,"marks":54620,"value":19628,"nodeType":864},{},[54621],{"type":1455},{"data":54623,"marks":54624,"value":3731,"nodeType":864},{},[],{"data":54626,"content":54627,"nodeType":883},{"uri":19692},[54628],{"data":54629,"marks":54630,"value":19698,"nodeType":864},{},[54631],{"type":1455},{"data":54633,"marks":54634,"value":19702,"nodeType":864},{},[],{"data":54636,"content":54637,"nodeType":883},{"uri":19610},[54638],{"data":54639,"marks":54640,"value":19710,"nodeType":864},{},[54641],{"type":1455},{"data":54643,"marks":54644,"value":19714,"nodeType":864},{},[],{"data":54646,"content":54649,"nodeType":996},{"target":54647},{"sys":54648},{"id":19719,"type":1001,"linkType":1002},[],{"data":54651,"content":54652,"nodeType":860},{},[54653],{"data":54654,"marks":54655,"value":19727,"nodeType":864},{},[],{"data":54657,"content":54658,"nodeType":860},{},[54659],{"data":54660,"marks":54661,"value":19734,"nodeType":864},{},[],{"data":54663,"content":54664,"nodeType":860},{},[54665],{"data":54666,"marks":54667,"value":19741,"nodeType":864},{},[],{"data":54669,"content":54670,"nodeType":860},{},[54671],{"data":54672,"marks":54673,"value":19748,"nodeType":864},{},[],{"data":54675,"content":54676,"nodeType":860},{},[54677,54680,54687],{"data":54678,"marks":54679,"value":19755,"nodeType":864},{},[],{"data":54681,"content":54682,"nodeType":883},{"uri":14307},[54683],{"data":54684,"marks":54685,"value":19763,"nodeType":864},{},[54686],{"type":1455},{"data":54688,"marks":54689,"value":19767,"nodeType":864},{},[],{"data":54691,"content":54694,"nodeType":996},{"target":54692},{"sys":54693},{"id":19772,"type":1001,"linkType":1002},[],{"data":54696,"content":54699,"nodeType":996},{"target":54697},{"sys":54698},{"id":19778,"type":1001,"linkType":1002},[],{"data":54701,"content":54704,"nodeType":996},{"target":54702},{"sys":54703},{"id":19784,"type":1001,"linkType":1002},[],{"data":54706,"content":54709,"nodeType":996},{"target":54707},{"sys":54708},{"id":19790,"type":1001,"linkType":1002},[],{"data":54711,"content":54714,"nodeType":996},{"target":54712},{"sys":54713},{"id":19796,"type":1001,"linkType":1002},[],{"data":54716,"content":54719,"nodeType":996},{"target":54717},{"sys":54718},{"id":19802,"type":1001,"linkType":1002},[],{"data":54721,"content":54724,"nodeType":996},{"target":54722},{"sys":54723},{"id":19808,"type":1001,"linkType":1002},[],{"data":54726,"content":54727,"nodeType":860},{},[54728],{"data":54729,"marks":54730,"value":21,"nodeType":864},{},[],{"data":54732,"content":54733,"nodeType":4845},{},[54734,54756,54827,54873,54895],{"data":54735,"content":54736,"nodeType":4581},{},[54737,54747],{"data":54738,"content":54739,"nodeType":4569},{},[54740],{"data":54741,"content":54742,"nodeType":860},{},[54743],{"data":54744,"marks":54745,"value":19832,"nodeType":864},{},[54746],{"type":899},{"data":54748,"content":54749,"nodeType":4569},{},[54750],{"data":54751,"content":54752,"nodeType":860},{},[54753],{"data":54754,"marks":54755,"value":19842,"nodeType":864},{},[],{"data":54757,"content":54758,"nodeType":4581},{},[54759,54769],{"data":54760,"content":54761,"nodeType":4569},{},[54762],{"data":54763,"content":54764,"nodeType":860},{},[54765],{"data":54766,"marks":54767,"value":19856,"nodeType":864},{},[54768],{"type":899},{"data":54770,"content":54771,"nodeType":4569},{},[54772,54796],{"data":54773,"content":54774,"nodeType":860},{},[54775,54779,54782,54786,54789,54793],{"data":54776,"marks":54777,"value":19867,"nodeType":864},{},[54778],{"type":899},{"data":54780,"marks":54781,"value":19871,"nodeType":864},{},[],{"data":54783,"marks":54784,"value":19876,"nodeType":864},{},[54785],{"type":899},{"data":54787,"marks":54788,"value":19880,"nodeType":864},{},[],{"data":54790,"marks":54791,"value":19885,"nodeType":864},{},[54792],{"type":899},{"data":54794,"marks":54795,"value":19889,"nodeType":864},{},[],{"data":54797,"content":54798,"nodeType":860},{},[54799,54803,54806,54810,54813,54817,54820,54824],{"data":54800,"marks":54801,"value":19897,"nodeType":864},{},[54802],{"type":899},{"data":54804,"marks":54805,"value":1171,"nodeType":864},{},[],{"data":54807,"marks":54808,"value":19905,"nodeType":864},{},[54809],{"type":899},{"data":54811,"marks":54812,"value":19909,"nodeType":864},{},[],{"data":54814,"marks":54815,"value":19876,"nodeType":864},{},[54816],{"type":899},{"data":54818,"marks":54819,"value":19917,"nodeType":864},{},[],{"data":54821,"marks":54822,"value":19885,"nodeType":864},{},[54823],{"type":899},{"data":54825,"marks":54826,"value":19925,"nodeType":864},{},[],{"data":54828,"content":54829,"nodeType":4581},{},[54830,54840],{"data":54831,"content":54832,"nodeType":4569},{},[54833],{"data":54834,"content":54835,"nodeType":860},{},[54836],{"data":54837,"marks":54838,"value":19939,"nodeType":864},{},[54839],{"type":899},{"data":54841,"content":54842,"nodeType":4569},{},[54843,54849,54855,54861,54867],{"data":54844,"content":54845,"nodeType":860},{},[54846],{"data":54847,"marks":54848,"value":19949,"nodeType":864},{},[],{"data":54850,"content":54851,"nodeType":860},{},[54852],{"data":54853,"marks":54854,"value":19956,"nodeType":864},{},[],{"data":54856,"content":54857,"nodeType":860},{},[54858],{"data":54859,"marks":54860,"value":19963,"nodeType":864},{},[],{"data":54862,"content":54863,"nodeType":860},{},[54864],{"data":54865,"marks":54866,"value":19970,"nodeType":864},{},[],{"data":54868,"content":54869,"nodeType":860},{},[54870],{"data":54871,"marks":54872,"value":19977,"nodeType":864},{},[],{"data":54874,"content":54875,"nodeType":4581},{},[54876,54886],{"data":54877,"content":54878,"nodeType":4569},{},[54879],{"data":54880,"content":54881,"nodeType":860},{},[54882],{"data":54883,"marks":54884,"value":19991,"nodeType":864},{},[54885],{"type":899},{"data":54887,"content":54888,"nodeType":4569},{},[54889],{"data":54890,"content":54891,"nodeType":860},{},[54892],{"data":54893,"marks":54894,"value":20001,"nodeType":864},{},[],{"data":54896,"content":54897,"nodeType":4581},{},[54898,54908],{"data":54899,"content":54900,"nodeType":4569},{},[54901],{"data":54902,"content":54903,"nodeType":860},{},[54904],{"data":54905,"marks":54906,"value":20015,"nodeType":864},{},[54907],{"type":899},{"data":54909,"content":54910,"nodeType":4569},{},[54911,54921,54931,54941,54951],{"data":54912,"content":54913,"nodeType":860},{},[54914,54918],{"data":54915,"marks":54916,"value":20026,"nodeType":864},{},[54917],{"type":899},{"data":54919,"marks":54920,"value":20030,"nodeType":864},{},[],{"data":54922,"content":54923,"nodeType":860},{},[54924,54928],{"data":54925,"marks":54926,"value":20038,"nodeType":864},{},[54927],{"type":899},{"data":54929,"marks":54930,"value":20042,"nodeType":864},{},[],{"data":54932,"content":54933,"nodeType":860},{},[54934,54938],{"data":54935,"marks":54936,"value":20050,"nodeType":864},{},[54937],{"type":899},{"data":54939,"marks":54940,"value":20054,"nodeType":864},{},[],{"data":54942,"content":54943,"nodeType":860},{},[54944,54948],{"data":54945,"marks":54946,"value":20062,"nodeType":864},{},[54947],{"type":899},{"data":54949,"marks":54950,"value":20066,"nodeType":864},{},[],{"data":54952,"content":54953,"nodeType":860},{},[54954,54958],{"data":54955,"marks":54956,"value":20074,"nodeType":864},{},[54957],{"type":899},{"data":54959,"marks":54960,"value":20078,"nodeType":864},{},[],{"data":54962,"content":54963,"nodeType":1005},{},[],{"data":54965,"content":54966,"nodeType":1312},{},[54967],{"data":54968,"marks":54969,"value":20089,"nodeType":864},{},[54970],{"type":899},{"data":54972,"content":54973,"nodeType":4845},{},[54974,54996,55032,55054,55076],{"data":54975,"content":54976,"nodeType":4581},{},[54977,54987],{"data":54978,"content":54979,"nodeType":4569},{},[54980],{"data":54981,"content":54982,"nodeType":860},{},[54983],{"data":54984,"marks":54985,"value":19832,"nodeType":864},{},[54986],{"type":899},{"data":54988,"content":54989,"nodeType":4569},{},[54990],{"data":54991,"content":54992,"nodeType":860},{},[54993],{"data":54994,"marks":54995,"value":20115,"nodeType":864},{},[],{"data":54997,"content":54998,"nodeType":4581},{},[54999,55009],{"data":55000,"content":55001,"nodeType":4569},{},[55002],{"data":55003,"content":55004,"nodeType":860},{},[55005],{"data":55006,"marks":55007,"value":19856,"nodeType":864},{},[55008],{"type":899},{"data":55010,"content":55011,"nodeType":4569},{},[55012,55022],{"data":55013,"content":55014,"nodeType":860},{},[55015,55019],{"data":55016,"marks":55017,"value":20139,"nodeType":864},{},[55018],{"type":899},{"data":55020,"marks":55021,"value":20143,"nodeType":864},{},[],{"data":55023,"content":55024,"nodeType":860},{},[55025,55029],{"data":55026,"marks":55027,"value":19897,"nodeType":864},{},[55028],{"type":899},{"data":55030,"marks":55031,"value":20154,"nodeType":864},{},[],{"data":55033,"content":55034,"nodeType":4581},{},[55035,55045],{"data":55036,"content":55037,"nodeType":4569},{},[55038],{"data":55039,"content":55040,"nodeType":860},{},[55041],{"data":55042,"marks":55043,"value":19939,"nodeType":864},{},[55044],{"type":899},{"data":55046,"content":55047,"nodeType":4569},{},[55048],{"data":55049,"content":55050,"nodeType":860},{},[55051],{"data":55052,"marks":55053,"value":20177,"nodeType":864},{},[],{"data":55055,"content":55056,"nodeType":4581},{},[55057,55067],{"data":55058,"content":55059,"nodeType":4569},{},[55060],{"data":55061,"content":55062,"nodeType":860},{},[55063],{"data":55064,"marks":55065,"value":19991,"nodeType":864},{},[55066],{"type":899},{"data":55068,"content":55069,"nodeType":4569},{},[55070],{"data":55071,"content":55072,"nodeType":860},{},[55073],{"data":55074,"marks":55075,"value":20200,"nodeType":864},{},[],{"data":55077,"content":55078,"nodeType":4581},{},[55079,55089],{"data":55080,"content":55081,"nodeType":4569},{},[55082],{"data":55083,"content":55084,"nodeType":860},{},[55085],{"data":55086,"marks":55087,"value":20214,"nodeType":864},{},[55088],{"type":899},{"data":55090,"content":55091,"nodeType":4569},{},[55092],{"data":55093,"content":55094,"nodeType":860},{},[55095],{"data":55096,"marks":55097,"value":20224,"nodeType":864},{},[],{"data":55099,"content":55102,"nodeType":996},{"target":55100},{"sys":55101},{"id":20229,"type":1001,"linkType":1002},[],{"data":55104,"content":55105,"nodeType":1005},{},[],{"data":55107,"content":55108,"nodeType":1312},{},[55109],{"data":55110,"marks":55111,"value":20241,"nodeType":864},{},[55112],{"type":899},{"data":55114,"content":55115,"nodeType":860},{},[55116,55119,55123,55126,55132,55135,55141],{"data":55117,"marks":55118,"value":20248,"nodeType":864},{},[],{"data":55120,"marks":55121,"value":20253,"nodeType":864},{},[55122],{"type":899},{"data":55124,"marks":55125,"value":20257,"nodeType":864},{},[],{"data":55127,"content":55128,"nodeType":883},{"uri":20260},[55129],{"data":55130,"marks":55131,"value":20265,"nodeType":864},{},[],{"data":55133,"marks":55134,"value":20269,"nodeType":864},{},[],{"data":55136,"content":55137,"nodeType":883},{"uri":20272},[55138],{"data":55139,"marks":55140,"value":20277,"nodeType":864},{},[],{"data":55142,"marks":55143,"value":20281,"nodeType":864},{},[],{"data":55145,"content":55146,"nodeType":4845},{},[55147,55169,55205,55227,55249],{"data":55148,"content":55149,"nodeType":4581},{},[55150,55160],{"data":55151,"content":55152,"nodeType":4569},{},[55153],{"data":55154,"content":55155,"nodeType":860},{},[55156],{"data":55157,"marks":55158,"value":19832,"nodeType":864},{},[55159],{"type":899},{"data":55161,"content":55162,"nodeType":4569},{},[55163],{"data":55164,"content":55165,"nodeType":860},{},[55166],{"data":55167,"marks":55168,"value":20307,"nodeType":864},{},[],{"data":55170,"content":55171,"nodeType":4581},{},[55172,55182],{"data":55173,"content":55174,"nodeType":4569},{},[55175],{"data":55176,"content":55177,"nodeType":860},{},[55178],{"data":55179,"marks":55180,"value":19856,"nodeType":864},{},[55181],{"type":899},{"data":55183,"content":55184,"nodeType":4569},{},[55185,55195],{"data":55186,"content":55187,"nodeType":860},{},[55188,55192],{"data":55189,"marks":55190,"value":20331,"nodeType":864},{},[55191],{"type":899},{"data":55193,"marks":55194,"value":20335,"nodeType":864},{},[],{"data":55196,"content":55197,"nodeType":860},{},[55198,55202],{"data":55199,"marks":55200,"value":19897,"nodeType":864},{},[55201],{"type":899},{"data":55203,"marks":55204,"value":20346,"nodeType":864},{},[],{"data":55206,"content":55207,"nodeType":4581},{},[55208,55218],{"data":55209,"content":55210,"nodeType":4569},{},[55211],{"data":55212,"content":55213,"nodeType":860},{},[55214],{"data":55215,"marks":55216,"value":19939,"nodeType":864},{},[55217],{"type":899},{"data":55219,"content":55220,"nodeType":4569},{},[55221],{"data":55222,"content":55223,"nodeType":860},{},[55224],{"data":55225,"marks":55226,"value":20369,"nodeType":864},{},[],{"data":55228,"content":55229,"nodeType":4581},{},[55230,55240],{"data":55231,"content":55232,"nodeType":4569},{},[55233],{"data":55234,"content":55235,"nodeType":860},{},[55236],{"data":55237,"marks":55238,"value":19991,"nodeType":864},{},[55239],{"type":899},{"data":55241,"content":55242,"nodeType":4569},{},[55243],{"data":55244,"content":55245,"nodeType":860},{},[55246],{"data":55247,"marks":55248,"value":20392,"nodeType":864},{},[],{"data":55250,"content":55251,"nodeType":4581},{},[55252,55262],{"data":55253,"content":55254,"nodeType":4569},{},[55255],{"data":55256,"content":55257,"nodeType":860},{},[55258],{"data":55259,"marks":55260,"value":20214,"nodeType":864},{},[55261],{"type":899},{"data":55263,"content":55264,"nodeType":4569},{},[55265],{"data":55266,"content":55267,"nodeType":860},{},[55268],{"data":55269,"marks":55270,"value":20415,"nodeType":864},{},[],{"data":55272,"content":55275,"nodeType":996},{"target":55273},{"sys":55274},{"id":20420,"type":1001,"linkType":1002},[],{"data":55277,"content":55278,"nodeType":1005},{},[],{"data":55280,"content":55281,"nodeType":1312},{},[55282],{"data":55283,"marks":55284,"value":20432,"nodeType":864},{},[55285],{"type":899},{"data":55287,"content":55288,"nodeType":4845},{},[55289,55311,55353,55381,55403],{"data":55290,"content":55291,"nodeType":4581},{},[55292,55302],{"data":55293,"content":55294,"nodeType":4569},{},[55295],{"data":55296,"content":55297,"nodeType":860},{},[55298],{"data":55299,"marks":55300,"value":19832,"nodeType":864},{},[55301],{"type":899},{"data":55303,"content":55304,"nodeType":4569},{},[55305],{"data":55306,"content":55307,"nodeType":860},{},[55308],{"data":55309,"marks":55310,"value":20458,"nodeType":864},{},[],{"data":55312,"content":55313,"nodeType":4581},{},[55314,55324],{"data":55315,"content":55316,"nodeType":4569},{},[55317],{"data":55318,"content":55319,"nodeType":860},{},[55320],{"data":55321,"marks":55322,"value":19856,"nodeType":864},{},[55323],{"type":899},{"data":55325,"content":55326,"nodeType":4569},{},[55327,55337,55343],{"data":55328,"content":55329,"nodeType":860},{},[55330,55334],{"data":55331,"marks":55332,"value":20331,"nodeType":864},{},[55333],{"type":899},{"data":55335,"marks":55336,"value":20485,"nodeType":864},{},[],{"data":55338,"content":55339,"nodeType":860},{},[55340],{"data":55341,"marks":55342,"value":20492,"nodeType":864},{},[],{"data":55344,"content":55345,"nodeType":860},{},[55346,55350],{"data":55347,"marks":55348,"value":19897,"nodeType":864},{},[55349],{"type":899},{"data":55351,"marks":55352,"value":20503,"nodeType":864},{},[],{"data":55354,"content":55355,"nodeType":4581},{},[55356,55366],{"data":55357,"content":55358,"nodeType":4569},{},[55359],{"data":55360,"content":55361,"nodeType":860},{},[55362],{"data":55363,"marks":55364,"value":19939,"nodeType":864},{},[55365],{"type":899},{"data":55367,"content":55368,"nodeType":4569},{},[55369,55375],{"data":55370,"content":55371,"nodeType":860},{},[55372],{"data":55373,"marks":55374,"value":20526,"nodeType":864},{},[],{"data":55376,"content":55377,"nodeType":860},{},[55378],{"data":55379,"marks":55380,"value":20533,"nodeType":864},{},[],{"data":55382,"content":55383,"nodeType":4581},{},[55384,55394],{"data":55385,"content":55386,"nodeType":4569},{},[55387],{"data":55388,"content":55389,"nodeType":860},{},[55390],{"data":55391,"marks":55392,"value":19991,"nodeType":864},{},[55393],{"type":899},{"data":55395,"content":55396,"nodeType":4569},{},[55397],{"data":55398,"content":55399,"nodeType":860},{},[55400],{"data":55401,"marks":55402,"value":20556,"nodeType":864},{},[],{"data":55404,"content":55405,"nodeType":4581},{},[55406,55416],{"data":55407,"content":55408,"nodeType":4569},{},[55409],{"data":55410,"content":55411,"nodeType":860},{},[55412],{"data":55413,"marks":55414,"value":20214,"nodeType":864},{},[55415],{"type":899},{"data":55417,"content":55418,"nodeType":4569},{},[55419],{"data":55420,"content":55421,"nodeType":860},{},[55422],{"data":55423,"marks":55424,"value":20579,"nodeType":864},{},[],{"data":55426,"content":55429,"nodeType":996},{"target":55427},{"sys":55428},{"id":20584,"type":1001,"linkType":1002},[],{"data":55431,"content":55432,"nodeType":1005},{},[],{"data":55434,"content":55435,"nodeType":1312},{},[55436],{"data":55437,"marks":55438,"value":20596,"nodeType":864},{},[55439],{"type":899},{"data":55441,"content":55444,"nodeType":996},{"target":55442},{"sys":55443},{"id":20601,"type":1001,"linkType":1002},[],{"data":55446,"content":55447,"nodeType":4845},{},[55448,55470,55513,55535,55557],{"data":55449,"content":55450,"nodeType":4581},{},[55451,55461],{"data":55452,"content":55453,"nodeType":4569},{},[55454],{"data":55455,"content":55456,"nodeType":860},{},[55457],{"data":55458,"marks":55459,"value":19832,"nodeType":864},{},[55460],{"type":899},{"data":55462,"content":55463,"nodeType":4569},{},[55464],{"data":55465,"content":55466,"nodeType":860},{},[55467],{"data":55468,"marks":55469,"value":20628,"nodeType":864},{},[],{"data":55471,"content":55472,"nodeType":4581},{},[55473,55483],{"data":55474,"content":55475,"nodeType":4569},{},[55476],{"data":55477,"content":55478,"nodeType":860},{},[55479],{"data":55480,"marks":55481,"value":19856,"nodeType":864},{},[55482],{"type":899},{"data":55484,"content":55485,"nodeType":4569},{},[55486,55496],{"data":55487,"content":55488,"nodeType":860},{},[55489,55493],{"data":55490,"marks":55491,"value":20331,"nodeType":864},{},[55492],{"type":899},{"data":55494,"marks":55495,"value":20655,"nodeType":864},{},[],{"data":55497,"content":55498,"nodeType":860},{},[55499,55503,55506,55510],{"data":55500,"marks":55501,"value":19897,"nodeType":864},{},[55502],{"type":899},{"data":55504,"marks":55505,"value":1171,"nodeType":864},{},[],{"data":55507,"marks":55508,"value":7160,"nodeType":864},{},[55509],{"type":899},{"data":55511,"marks":55512,"value":20673,"nodeType":864},{},[],{"data":55514,"content":55515,"nodeType":4581},{},[55516,55526],{"data":55517,"content":55518,"nodeType":4569},{},[55519],{"data":55520,"content":55521,"nodeType":860},{},[55522],{"data":55523,"marks":55524,"value":19939,"nodeType":864},{},[55525],{"type":899},{"data":55527,"content":55528,"nodeType":4569},{},[55529],{"data":55530,"content":55531,"nodeType":860},{},[55532],{"data":55533,"marks":55534,"value":20696,"nodeType":864},{},[],{"data":55536,"content":55537,"nodeType":4581},{},[55538,55548],{"data":55539,"content":55540,"nodeType":4569},{},[55541],{"data":55542,"content":55543,"nodeType":860},{},[55544],{"data":55545,"marks":55546,"value":19991,"nodeType":864},{},[55547],{"type":899},{"data":55549,"content":55550,"nodeType":4569},{},[55551],{"data":55552,"content":55553,"nodeType":860},{},[55554],{"data":55555,"marks":55556,"value":20719,"nodeType":864},{},[],{"data":55558,"content":55559,"nodeType":4581},{},[55560,55570],{"data":55561,"content":55562,"nodeType":4569},{},[55563],{"data":55564,"content":55565,"nodeType":860},{},[55566],{"data":55567,"marks":55568,"value":20214,"nodeType":864},{},[55569],{"type":899},{"data":55571,"content":55572,"nodeType":4569},{},[55573],{"data":55574,"content":55575,"nodeType":860},{},[55576],{"data":55577,"marks":55578,"value":20742,"nodeType":864},{},[],{"data":55580,"content":55583,"nodeType":996},{"target":55581},{"sys":55582},{"id":20747,"type":1001,"linkType":1002},[],{"data":55585,"content":55588,"nodeType":996},{"target":55586},{"sys":55587},{"id":20753,"type":1001,"linkType":1002},[],{"data":55590,"content":55591,"nodeType":1005},{},[],{"data":55593,"content":55594,"nodeType":1312},{},[55595],{"data":55596,"marks":55597,"value":20765,"nodeType":864},{},[55598],{"type":899},{"data":55600,"content":55601,"nodeType":4845},{},[55602,55624,55660,55694,55716],{"data":55603,"content":55604,"nodeType":4581},{},[55605,55615],{"data":55606,"content":55607,"nodeType":4569},{},[55608],{"data":55609,"content":55610,"nodeType":860},{},[55611],{"data":55612,"marks":55613,"value":19832,"nodeType":864},{},[55614],{"type":899},{"data":55616,"content":55617,"nodeType":4569},{},[55618],{"data":55619,"content":55620,"nodeType":860},{},[55621],{"data":55622,"marks":55623,"value":20791,"nodeType":864},{},[],{"data":55625,"content":55626,"nodeType":4581},{},[55627,55637],{"data":55628,"content":55629,"nodeType":4569},{},[55630],{"data":55631,"content":55632,"nodeType":860},{},[55633],{"data":55634,"marks":55635,"value":19856,"nodeType":864},{},[55636],{"type":899},{"data":55638,"content":55639,"nodeType":4569},{},[55640,55650],{"data":55641,"content":55642,"nodeType":860},{},[55643,55647],{"data":55644,"marks":55645,"value":20331,"nodeType":864},{},[55646],{"type":899},{"data":55648,"marks":55649,"value":20818,"nodeType":864},{},[],{"data":55651,"content":55652,"nodeType":860},{},[55653,55657],{"data":55654,"marks":55655,"value":19897,"nodeType":864},{},[55656],{"type":899},{"data":55658,"marks":55659,"value":20829,"nodeType":864},{},[],{"data":55661,"content":55662,"nodeType":4581},{},[55663,55673],{"data":55664,"content":55665,"nodeType":4569},{},[55666],{"data":55667,"content":55668,"nodeType":860},{},[55669],{"data":55670,"marks":55671,"value":19939,"nodeType":864},{},[55672],{"type":899},{"data":55674,"content":55675,"nodeType":4569},{},[55676,55682,55688],{"data":55677,"content":55678,"nodeType":860},{},[55679],{"data":55680,"marks":55681,"value":20852,"nodeType":864},{},[],{"data":55683,"content":55684,"nodeType":860},{},[55685],{"data":55686,"marks":55687,"value":20859,"nodeType":864},{},[],{"data":55689,"content":55690,"nodeType":860},{},[55691],{"data":55692,"marks":55693,"value":20866,"nodeType":864},{},[],{"data":55695,"content":55696,"nodeType":4581},{},[55697,55707],{"data":55698,"content":55699,"nodeType":4569},{},[55700],{"data":55701,"content":55702,"nodeType":860},{},[55703],{"data":55704,"marks":55705,"value":19991,"nodeType":864},{},[55706],{"type":899},{"data":55708,"content":55709,"nodeType":4569},{},[55710],{"data":55711,"content":55712,"nodeType":860},{},[55713],{"data":55714,"marks":55715,"value":20889,"nodeType":864},{},[],{"data":55717,"content":55718,"nodeType":4581},{},[55719,55729],{"data":55720,"content":55721,"nodeType":4569},{},[55722],{"data":55723,"content":55724,"nodeType":860},{},[55725],{"data":55726,"marks":55727,"value":20214,"nodeType":864},{},[55728],{"type":899},{"data":55730,"content":55731,"nodeType":4569},{},[55732],{"data":55733,"content":55734,"nodeType":860},{},[55735],{"data":55736,"marks":55737,"value":20912,"nodeType":864},{},[],{"data":55739,"content":55742,"nodeType":996},{"target":55740},{"sys":55741},{"id":20917,"type":1001,"linkType":1002},[],{"data":55744,"content":55745,"nodeType":1005},{},[],{"data":55747,"content":55748,"nodeType":1312},{},[55749],{"data":55750,"marks":55751,"value":20929,"nodeType":864},{},[55752],{"type":899},{"data":55754,"content":55755,"nodeType":4845},{},[55756,55778,55821,55849,55871],{"data":55757,"content":55758,"nodeType":4581},{},[55759,55769],{"data":55760,"content":55761,"nodeType":4569},{},[55762],{"data":55763,"content":55764,"nodeType":860},{},[55765],{"data":55766,"marks":55767,"value":19832,"nodeType":864},{},[55768],{"type":899},{"data":55770,"content":55771,"nodeType":4569},{},[55772],{"data":55773,"content":55774,"nodeType":860},{},[55775],{"data":55776,"marks":55777,"value":20628,"nodeType":864},{},[],{"data":55779,"content":55780,"nodeType":4581},{},[55781,55791],{"data":55782,"content":55783,"nodeType":4569},{},[55784],{"data":55785,"content":55786,"nodeType":860},{},[55787],{"data":55788,"marks":55789,"value":19856,"nodeType":864},{},[55790],{"type":899},{"data":55792,"content":55793,"nodeType":4569},{},[55794,55804],{"data":55795,"content":55796,"nodeType":860},{},[55797,55801],{"data":55798,"marks":55799,"value":20331,"nodeType":864},{},[55800],{"type":899},{"data":55802,"marks":55803,"value":20981,"nodeType":864},{},[],{"data":55805,"content":55806,"nodeType":860},{},[55807,55811,55814,55818],{"data":55808,"marks":55809,"value":19897,"nodeType":864},{},[55810],{"type":899},{"data":55812,"marks":55813,"value":1171,"nodeType":864},{},[],{"data":55815,"marks":55816,"value":7160,"nodeType":864},{},[55817],{"type":899},{"data":55819,"marks":55820,"value":20999,"nodeType":864},{},[],{"data":55822,"content":55823,"nodeType":4581},{},[55824,55834],{"data":55825,"content":55826,"nodeType":4569},{},[55827],{"data":55828,"content":55829,"nodeType":860},{},[55830],{"data":55831,"marks":55832,"value":19939,"nodeType":864},{},[55833],{"type":899},{"data":55835,"content":55836,"nodeType":4569},{},[55837,55843],{"data":55838,"content":55839,"nodeType":860},{},[55840],{"data":55841,"marks":55842,"value":21022,"nodeType":864},{},[],{"data":55844,"content":55845,"nodeType":860},{},[55846],{"data":55847,"marks":55848,"value":21029,"nodeType":864},{},[],{"data":55850,"content":55851,"nodeType":4581},{},[55852,55862],{"data":55853,"content":55854,"nodeType":4569},{},[55855],{"data":55856,"content":55857,"nodeType":860},{},[55858],{"data":55859,"marks":55860,"value":19991,"nodeType":864},{},[55861],{"type":899},{"data":55863,"content":55864,"nodeType":4569},{},[55865],{"data":55866,"content":55867,"nodeType":860},{},[55868],{"data":55869,"marks":55870,"value":21052,"nodeType":864},{},[],{"data":55872,"content":55873,"nodeType":4581},{},[55874,55884],{"data":55875,"content":55876,"nodeType":4569},{},[55877],{"data":55878,"content":55879,"nodeType":860},{},[55880],{"data":55881,"marks":55882,"value":20214,"nodeType":864},{},[55883],{"type":899},{"data":55885,"content":55886,"nodeType":4569},{},[55887],{"data":55888,"content":55889,"nodeType":860},{},[55890],{"data":55891,"marks":55892,"value":21075,"nodeType":864},{},[],{"data":55894,"content":55897,"nodeType":996},{"target":55895},{"sys":55896},{"id":21080,"type":1001,"linkType":1002},[],{"data":55899,"content":55900,"nodeType":1005},{},[],{"data":55902,"content":55903,"nodeType":1312},{},[55904],{"data":55905,"marks":55906,"value":21092,"nodeType":864},{},[55907],{"type":899},{"data":55909,"content":55910,"nodeType":4845},{},[55911,55933,55955,55977],{"data":55912,"content":55913,"nodeType":4581},{},[55914,55924],{"data":55915,"content":55916,"nodeType":4569},{},[55917],{"data":55918,"content":55919,"nodeType":860},{},[55920],{"data":55921,"marks":55922,"value":19832,"nodeType":864},{},[55923],{"type":899},{"data":55925,"content":55926,"nodeType":4569},{},[55927],{"data":55928,"content":55929,"nodeType":860},{},[55930],{"data":55931,"marks":55932,"value":21118,"nodeType":864},{},[],{"data":55934,"content":55935,"nodeType":4581},{},[55936,55946],{"data":55937,"content":55938,"nodeType":4569},{},[55939],{"data":55940,"content":55941,"nodeType":860},{},[55942],{"data":55943,"marks":55944,"value":19939,"nodeType":864},{},[55945],{"type":899},{"data":55947,"content":55948,"nodeType":4569},{},[55949],{"data":55950,"content":55951,"nodeType":860},{},[55952],{"data":55953,"marks":55954,"value":21141,"nodeType":864},{},[],{"data":55956,"content":55957,"nodeType":4581},{},[55958,55968],{"data":55959,"content":55960,"nodeType":4569},{},[55961],{"data":55962,"content":55963,"nodeType":860},{},[55964],{"data":55965,"marks":55966,"value":19991,"nodeType":864},{},[55967],{"type":899},{"data":55969,"content":55970,"nodeType":4569},{},[55971],{"data":55972,"content":55973,"nodeType":860},{},[55974],{"data":55975,"marks":55976,"value":21164,"nodeType":864},{},[],{"data":55978,"content":55979,"nodeType":4581},{},[55980,55990],{"data":55981,"content":55982,"nodeType":4569},{},[55983],{"data":55984,"content":55985,"nodeType":860},{},[55986],{"data":55987,"marks":55988,"value":20214,"nodeType":864},{},[55989],{"type":899},{"data":55991,"content":55992,"nodeType":4569},{},[55993],{"data":55994,"content":55995,"nodeType":860},{},[55996],{"data":55997,"marks":55998,"value":21187,"nodeType":864},{},[],{"data":56000,"content":56003,"nodeType":996},{"target":56001},{"sys":56002},{"id":21192,"type":1001,"linkType":1002},[],{"data":56005,"content":56006,"nodeType":1005},{},[],{"data":56008,"content":56009,"nodeType":1312},{},[56010],{"data":56011,"marks":56012,"value":21204,"nodeType":864},{},[56013],{"type":899},{"data":56015,"content":56016,"nodeType":4845},{},[56017,56039,56061,56083],{"data":56018,"content":56019,"nodeType":4581},{},[56020,56030],{"data":56021,"content":56022,"nodeType":4569},{},[56023],{"data":56024,"content":56025,"nodeType":860},{},[56026],{"data":56027,"marks":56028,"value":19832,"nodeType":864},{},[56029],{"type":899},{"data":56031,"content":56032,"nodeType":4569},{},[56033],{"data":56034,"content":56035,"nodeType":860},{},[56036],{"data":56037,"marks":56038,"value":20115,"nodeType":864},{},[],{"data":56040,"content":56041,"nodeType":4581},{},[56042,56052],{"data":56043,"content":56044,"nodeType":4569},{},[56045],{"data":56046,"content":56047,"nodeType":860},{},[56048],{"data":56049,"marks":56050,"value":19939,"nodeType":864},{},[56051],{"type":899},{"data":56053,"content":56054,"nodeType":4569},{},[56055],{"data":56056,"content":56057,"nodeType":860},{},[56058],{"data":56059,"marks":56060,"value":21252,"nodeType":864},{},[],{"data":56062,"content":56063,"nodeType":4581},{},[56064,56074],{"data":56065,"content":56066,"nodeType":4569},{},[56067],{"data":56068,"content":56069,"nodeType":860},{},[56070],{"data":56071,"marks":56072,"value":19991,"nodeType":864},{},[56073],{"type":899},{"data":56075,"content":56076,"nodeType":4569},{},[56077],{"data":56078,"content":56079,"nodeType":860},{},[56080],{"data":56081,"marks":56082,"value":21275,"nodeType":864},{},[],{"data":56084,"content":56085,"nodeType":4581},{},[56086,56096],{"data":56087,"content":56088,"nodeType":4569},{},[56089],{"data":56090,"content":56091,"nodeType":860},{},[56092],{"data":56093,"marks":56094,"value":20214,"nodeType":864},{},[56095],{"type":899},{"data":56097,"content":56098,"nodeType":4569},{},[56099],{"data":56100,"content":56101,"nodeType":860},{},[56102],{"data":56103,"marks":56104,"value":21298,"nodeType":864},{},[],{"data":56106,"content":56109,"nodeType":996},{"target":56107},{"sys":56108},{"id":21303,"type":1001,"linkType":1002},[],{"data":56111,"content":56112,"nodeType":1005},{},[],{"data":56114,"content":56115,"nodeType":1312},{},[56116],{"data":56117,"marks":56118,"value":21315,"nodeType":864},{},[56119],{"type":899},{"data":56121,"content":56124,"nodeType":996},{"target":56122},{"sys":56123},{"id":21320,"type":1001,"linkType":1002},[],{"data":56126,"content":56127,"nodeType":4845},{},[56128,56150,56186,56208,56230],{"data":56129,"content":56130,"nodeType":4581},{},[56131,56141],{"data":56132,"content":56133,"nodeType":4569},{},[56134],{"data":56135,"content":56136,"nodeType":860},{},[56137],{"data":56138,"marks":56139,"value":19832,"nodeType":864},{},[56140],{"type":899},{"data":56142,"content":56143,"nodeType":4569},{},[56144],{"data":56145,"content":56146,"nodeType":860},{},[56147],{"data":56148,"marks":56149,"value":21347,"nodeType":864},{},[],{"data":56151,"content":56152,"nodeType":4581},{},[56153,56163],{"data":56154,"content":56155,"nodeType":4569},{},[56156],{"data":56157,"content":56158,"nodeType":860},{},[56159],{"data":56160,"marks":56161,"value":19856,"nodeType":864},{},[56162],{"type":899},{"data":56164,"content":56165,"nodeType":4569},{},[56166,56176],{"data":56167,"content":56168,"nodeType":860},{},[56169,56173],{"data":56170,"marks":56171,"value":20331,"nodeType":864},{},[56172],{"type":899},{"data":56174,"marks":56175,"value":21374,"nodeType":864},{},[],{"data":56177,"content":56178,"nodeType":860},{},[56179,56183],{"data":56180,"marks":56181,"value":19897,"nodeType":864},{},[56182],{"type":899},{"data":56184,"marks":56185,"value":21385,"nodeType":864},{},[],{"data":56187,"content":56188,"nodeType":4581},{},[56189,56199],{"data":56190,"content":56191,"nodeType":4569},{},[56192],{"data":56193,"content":56194,"nodeType":860},{},[56195],{"data":56196,"marks":56197,"value":19939,"nodeType":864},{},[56198],{"type":899},{"data":56200,"content":56201,"nodeType":4569},{},[56202],{"data":56203,"content":56204,"nodeType":860},{},[56205],{"data":56206,"marks":56207,"value":21408,"nodeType":864},{},[],{"data":56209,"content":56210,"nodeType":4581},{},[56211,56221],{"data":56212,"content":56213,"nodeType":4569},{},[56214],{"data":56215,"content":56216,"nodeType":860},{},[56217],{"data":56218,"marks":56219,"value":19991,"nodeType":864},{},[56220],{"type":899},{"data":56222,"content":56223,"nodeType":4569},{},[56224],{"data":56225,"content":56226,"nodeType":860},{},[56227],{"data":56228,"marks":56229,"value":21431,"nodeType":864},{},[],{"data":56231,"content":56232,"nodeType":4581},{},[56233,56243],{"data":56234,"content":56235,"nodeType":4569},{},[56236],{"data":56237,"content":56238,"nodeType":860},{},[56239],{"data":56240,"marks":56241,"value":20214,"nodeType":864},{},[56242],{"type":899},{"data":56244,"content":56245,"nodeType":4569},{},[56246],{"data":56247,"content":56248,"nodeType":860},{},[56249],{"data":56250,"marks":56251,"value":21454,"nodeType":864},{},[],{"data":56253,"content":56256,"nodeType":996},{"target":56254},{"sys":56255},{"id":21459,"type":1001,"linkType":1002},[],{"data":56258,"content":56259,"nodeType":1005},{},[],{"data":56261,"content":56262,"nodeType":1312},{},[56263],{"data":56264,"marks":56265,"value":21471,"nodeType":864},{},[56266],{"type":899},{"data":56268,"content":56269,"nodeType":4845},{},[56270,56292],{"data":56271,"content":56272,"nodeType":4581},{},[56273,56283],{"data":56274,"content":56275,"nodeType":4569},{},[56276],{"data":56277,"content":56278,"nodeType":860},{},[56279],{"data":56280,"marks":56281,"value":19939,"nodeType":864},{},[56282],{"type":899},{"data":56284,"content":56285,"nodeType":4569},{},[56286],{"data":56287,"content":56288,"nodeType":860},{},[56289],{"data":56290,"marks":56291,"value":21497,"nodeType":864},{},[],{"data":56293,"content":56294,"nodeType":4581},{},[56295,56305],{"data":56296,"content":56297,"nodeType":4569},{},[56298],{"data":56299,"content":56300,"nodeType":860},{},[56301],{"data":56302,"marks":56303,"value":19991,"nodeType":864},{},[56304],{"type":899},{"data":56306,"content":56307,"nodeType":4569},{},[56308],{"data":56309,"content":56310,"nodeType":860},{},[56311],{"data":56312,"marks":56313,"value":21520,"nodeType":864},{},[],{"data":56315,"content":56318,"nodeType":996},{"target":56316},{"sys":56317},{"id":21525,"type":1001,"linkType":1002},[],{"data":56320,"content":56321,"nodeType":1005},{},[],{"data":56323,"content":56324,"nodeType":1312},{},[56325],{"data":56326,"marks":56327,"value":21537,"nodeType":864},{},[56328],{"type":899},{"data":56330,"content":56331,"nodeType":4845},{},[56332,56360,56396,56418,56440],{"data":56333,"content":56334,"nodeType":4581},{},[56335,56345],{"data":56336,"content":56337,"nodeType":4569},{},[56338],{"data":56339,"content":56340,"nodeType":860},{},[56341],{"data":56342,"marks":56343,"value":19832,"nodeType":864},{},[56344],{"type":899},{"data":56346,"content":56347,"nodeType":4569},{},[56348,56354],{"data":56349,"content":56350,"nodeType":860},{},[56351],{"data":56352,"marks":56353,"value":21563,"nodeType":864},{},[],{"data":56355,"content":56356,"nodeType":860},{},[56357],{"data":56358,"marks":56359,"value":21570,"nodeType":864},{},[],{"data":56361,"content":56362,"nodeType":4581},{},[56363,56373],{"data":56364,"content":56365,"nodeType":4569},{},[56366],{"data":56367,"content":56368,"nodeType":860},{},[56369],{"data":56370,"marks":56371,"value":19856,"nodeType":864},{},[56372],{"type":899},{"data":56374,"content":56375,"nodeType":4569},{},[56376,56386],{"data":56377,"content":56378,"nodeType":860},{},[56379,56383],{"data":56380,"marks":56381,"value":20331,"nodeType":864},{},[56382],{"type":899},{"data":56384,"marks":56385,"value":21597,"nodeType":864},{},[],{"data":56387,"content":56388,"nodeType":860},{},[56389,56393],{"data":56390,"marks":56391,"value":19897,"nodeType":864},{},[56392],{"type":899},{"data":56394,"marks":56395,"value":20154,"nodeType":864},{},[],{"data":56397,"content":56398,"nodeType":4581},{},[56399,56409],{"data":56400,"content":56401,"nodeType":4569},{},[56402],{"data":56403,"content":56404,"nodeType":860},{},[56405],{"data":56406,"marks":56407,"value":19939,"nodeType":864},{},[56408],{"type":899},{"data":56410,"content":56411,"nodeType":4569},{},[56412],{"data":56413,"content":56414,"nodeType":860},{},[56415],{"data":56416,"marks":56417,"value":21630,"nodeType":864},{},[],{"data":56419,"content":56420,"nodeType":4581},{},[56421,56431],{"data":56422,"content":56423,"nodeType":4569},{},[56424],{"data":56425,"content":56426,"nodeType":860},{},[56427],{"data":56428,"marks":56429,"value":19991,"nodeType":864},{},[56430],{"type":899},{"data":56432,"content":56433,"nodeType":4569},{},[56434],{"data":56435,"content":56436,"nodeType":860},{},[56437],{"data":56438,"marks":56439,"value":21653,"nodeType":864},{},[],{"data":56441,"content":56442,"nodeType":4581},{},[56443,56453],{"data":56444,"content":56445,"nodeType":4569},{},[56446],{"data":56447,"content":56448,"nodeType":860},{},[56449],{"data":56450,"marks":56451,"value":20214,"nodeType":864},{},[56452],{"type":899},{"data":56454,"content":56455,"nodeType":4569},{},[56456],{"data":56457,"content":56458,"nodeType":860},{},[56459],{"data":56460,"marks":56461,"value":21676,"nodeType":864},{},[],{"data":56463,"content":56466,"nodeType":996},{"target":56464},{"sys":56465},{"id":13317,"type":1001,"linkType":1002},[],{"data":56468,"content":56469,"nodeType":1005},{},[],{"data":56471,"content":56472,"nodeType":1312},{},[56473],{"data":56474,"marks":56475,"value":21692,"nodeType":864},{},[56476],{"type":899},{"data":56478,"content":56479,"nodeType":4845},{},[56480,56502,56538,56560,56582],{"data":56481,"content":56482,"nodeType":4581},{},[56483,56493],{"data":56484,"content":56485,"nodeType":4569},{},[56486],{"data":56487,"content":56488,"nodeType":860},{},[56489],{"data":56490,"marks":56491,"value":19832,"nodeType":864},{},[56492],{"type":899},{"data":56494,"content":56495,"nodeType":4569},{},[56496],{"data":56497,"content":56498,"nodeType":860},{},[56499],{"data":56500,"marks":56501,"value":21718,"nodeType":864},{},[],{"data":56503,"content":56504,"nodeType":4581},{},[56505,56515],{"data":56506,"content":56507,"nodeType":4569},{},[56508],{"data":56509,"content":56510,"nodeType":860},{},[56511],{"data":56512,"marks":56513,"value":19856,"nodeType":864},{},[56514],{"type":899},{"data":56516,"content":56517,"nodeType":4569},{},[56518,56528],{"data":56519,"content":56520,"nodeType":860},{},[56521,56525],{"data":56522,"marks":56523,"value":20331,"nodeType":864},{},[56524],{"type":899},{"data":56526,"marks":56527,"value":21745,"nodeType":864},{},[],{"data":56529,"content":56530,"nodeType":860},{},[56531,56535],{"data":56532,"marks":56533,"value":19897,"nodeType":864},{},[56534],{"type":899},{"data":56536,"marks":56537,"value":21756,"nodeType":864},{},[],{"data":56539,"content":56540,"nodeType":4581},{},[56541,56551],{"data":56542,"content":56543,"nodeType":4569},{},[56544],{"data":56545,"content":56546,"nodeType":860},{},[56547],{"data":56548,"marks":56549,"value":19939,"nodeType":864},{},[56550],{"type":899},{"data":56552,"content":56553,"nodeType":4569},{},[56554],{"data":56555,"content":56556,"nodeType":860},{},[56557],{"data":56558,"marks":56559,"value":21630,"nodeType":864},{},[],{"data":56561,"content":56562,"nodeType":4581},{},[56563,56573],{"data":56564,"content":56565,"nodeType":4569},{},[56566],{"data":56567,"content":56568,"nodeType":860},{},[56569],{"data":56570,"marks":56571,"value":19991,"nodeType":864},{},[56572],{"type":899},{"data":56574,"content":56575,"nodeType":4569},{},[56576],{"data":56577,"content":56578,"nodeType":860},{},[56579],{"data":56580,"marks":56581,"value":21801,"nodeType":864},{},[],{"data":56583,"content":56584,"nodeType":4581},{},[56585,56595],{"data":56586,"content":56587,"nodeType":4569},{},[56588],{"data":56589,"content":56590,"nodeType":860},{},[56591],{"data":56592,"marks":56593,"value":20214,"nodeType":864},{},[56594],{"type":899},{"data":56596,"content":56597,"nodeType":4569},{},[56598],{"data":56599,"content":56600,"nodeType":860},{},[56601],{"data":56602,"marks":56603,"value":21824,"nodeType":864},{},[],{"data":56605,"content":56608,"nodeType":996},{"target":56606},{"sys":56607},{"id":21829,"type":1001,"linkType":1002},[],{"data":56610,"content":56611,"nodeType":1005},{},[],{"data":56613,"content":56614,"nodeType":1009},{},[56615],{"data":56616,"marks":56617,"value":21841,"nodeType":864},{},[56618],{"type":899},{"data":56620,"content":56621,"nodeType":860},{},[56622,56625],{"data":56623,"marks":56624,"value":21848,"nodeType":864},{},[],{"data":56626,"marks":56627,"value":21853,"nodeType":864},{},[56628],{"type":899},{"data":56630,"content":56631,"nodeType":860},{},[56632],{"data":56633,"marks":56634,"value":21860,"nodeType":864},{},[],{"data":56636,"content":56639,"nodeType":996},{"target":56637},{"sys":56638},{"id":21865,"type":1001,"linkType":1002},[],{"data":56641,"content":56644,"nodeType":996},{"target":56642},{"sys":56643},{"id":21871,"type":1001,"linkType":1002},[],{"data":56646,"content":56647,"nodeType":860},{},[56648],{"data":56649,"marks":56650,"value":21879,"nodeType":864},{},[],{"data":56652,"content":56653,"nodeType":860},{},[56654,56657,56661,56664],{"data":56655,"marks":56656,"value":21886,"nodeType":864},{},[],{"data":56658,"marks":56659,"value":21891,"nodeType":864},{},[56660],{"type":899},{"data":56662,"marks":56663,"value":21895,"nodeType":864},{},[],{"data":56665,"marks":56666,"value":21900,"nodeType":864},{},[56667],{"type":899},{"data":56669,"content":56670,"nodeType":860},{},[56671,56674,56678],{"data":56672,"marks":56673,"value":21907,"nodeType":864},{},[],{"data":56675,"marks":56676,"value":21912,"nodeType":864},{},[56677],{"type":899},{"data":56679,"marks":56680,"value":21916,"nodeType":864},{},[],{"data":56682,"content":56685,"nodeType":996},{"target":56683},{"sys":56684},{"id":21921,"type":1001,"linkType":1002},[],{"data":56687,"content":56688,"nodeType":1005},{},[],{"data":56690,"content":56691,"nodeType":1009},{},[56692],{"data":56693,"marks":56694,"value":21933,"nodeType":864},{},[56695],{"type":899},{"data":56697,"content":56698,"nodeType":1312},{},[56699],{"data":56700,"marks":56701,"value":21941,"nodeType":864},{},[56702],{"type":899},{"data":56704,"content":56705,"nodeType":860},{},[56706,56709,56713,56716],{"data":56707,"marks":56708,"value":21948,"nodeType":864},{},[],{"data":56710,"marks":56711,"value":21953,"nodeType":864},{},[56712],{"type":899},{"data":56714,"marks":56715,"value":21957,"nodeType":864},{},[],{"data":56717,"marks":56718,"value":21962,"nodeType":864},{},[56719],{"type":899},{"data":56721,"content":56722,"nodeType":860},{},[56723,56727,56730,56734],{"data":56724,"marks":56725,"value":21970,"nodeType":864},{},[56726],{"type":899},{"data":56728,"marks":56729,"value":21974,"nodeType":864},{},[],{"data":56731,"marks":56732,"value":21979,"nodeType":864},{},[56733],{"type":899},{"data":56735,"marks":56736,"value":21983,"nodeType":864},{},[],{"data":56738,"content":56741,"nodeType":996},{"target":56739},{"sys":56740},{"id":20917,"type":1001,"linkType":1002},[],{"data":56743,"content":56744,"nodeType":860},{},[56745],{"data":56746,"marks":56747,"value":21995,"nodeType":864},{},[],{"data":56749,"content":56750,"nodeType":860},{},[56751],{"data":56752,"marks":56753,"value":22002,"nodeType":864},{},[],{"data":56755,"content":56756,"nodeType":1312},{},[56757],{"data":56758,"marks":56759,"value":22010,"nodeType":864},{},[56760],{"type":899},{"data":56762,"content":56763,"nodeType":860},{},[56764],{"data":56765,"marks":56766,"value":22017,"nodeType":864},{},[],{"data":56768,"content":56769,"nodeType":860},{},[56770],{"data":56771,"marks":56772,"value":22024,"nodeType":864},{},[],{"data":56774,"content":56775,"nodeType":860},{},[56776],{"data":56777,"marks":56778,"value":22031,"nodeType":864},{},[],{"data":56780,"content":56781,"nodeType":1312},{},[56782],{"data":56783,"marks":56784,"value":22039,"nodeType":864},{},[56785],{"type":899},{"data":56787,"content":56788,"nodeType":860},{},[56789],{"data":56790,"marks":56791,"value":22046,"nodeType":864},{},[],{"data":56793,"content":56794,"nodeType":941},{},[56795,56808,56821],{"data":56796,"content":56797,"nodeType":945},{},[56798],{"data":56799,"content":56800,"nodeType":860},{},[56801,56805],{"data":56802,"marks":56803,"value":22060,"nodeType":864},{},[56804],{"type":899},{"data":56806,"marks":56807,"value":22064,"nodeType":864},{},[],{"data":56809,"content":56810,"nodeType":945},{},[56811],{"data":56812,"content":56813,"nodeType":860},{},[56814,56818],{"data":56815,"marks":56816,"value":19538,"nodeType":864},{},[56817],{"type":899},{"data":56819,"marks":56820,"value":22078,"nodeType":864},{},[],{"data":56822,"content":56823,"nodeType":945},{},[56824],{"data":56825,"content":56826,"nodeType":860},{},[56827,56830,56834],{"data":56828,"marks":56829,"value":22088,"nodeType":864},{},[],{"data":56831,"marks":56832,"value":22093,"nodeType":864},{},[56833],{"type":899},{"data":56835,"marks":56836,"value":22097,"nodeType":864},{},[],{"data":56838,"content":56841,"nodeType":996},{"target":56839},{"sys":56840},{"id":22102,"type":1001,"linkType":1002},[],{"data":56843,"content":56844,"nodeType":1005},{},[],{"data":56846,"content":56847,"nodeType":1009},{},[56848],{"data":56849,"marks":56850,"value":22114,"nodeType":864},{},[56851],{"type":899},{"data":56853,"content":56854,"nodeType":860},{},[56855],{"data":56856,"marks":56857,"value":22121,"nodeType":864},{},[],{"data":56859,"content":56860,"nodeType":860},{},[56861],{"data":56862,"marks":56863,"value":22128,"nodeType":864},{},[],{"data":56865,"content":56866,"nodeType":860},{},[56867,56870,56877,56880,56884,56887,56891,56894,56898],{"data":56868,"marks":56869,"value":22135,"nodeType":864},{},[],{"data":56871,"content":56872,"nodeType":883},{"uri":22138},[56873],{"data":56874,"marks":56875,"value":22144,"nodeType":864},{},[56876],{"type":1455},{"data":56878,"marks":56879,"value":22148,"nodeType":864},{},[],{"data":56881,"marks":56882,"value":22153,"nodeType":864},{},[56883],{"type":899},{"data":56885,"marks":56886,"value":22157,"nodeType":864},{},[],{"data":56888,"marks":56889,"value":22162,"nodeType":864},{},[56890],{"type":899},{"data":56892,"marks":56893,"value":22166,"nodeType":864},{},[],{"data":56895,"marks":56896,"value":22171,"nodeType":864},{},[56897],{"type":899},{"data":56899,"marks":56900,"value":22175,"nodeType":864},{},[],{"data":56902,"content":56905,"nodeType":996},{"target":56903},{"sys":56904},{"id":22180,"type":1001,"linkType":1002},[],{"data":56907,"content":56908,"nodeType":860},{},[56909],{"data":56910,"marks":56911,"value":22188,"nodeType":864},{},[],{"data":56913,"content":56914,"nodeType":1005},{},[],{"data":56916,"content":56917,"nodeType":1009},{},[56918],{"data":56919,"marks":56920,"value":22199,"nodeType":864},{},[56921],{"type":899},{"data":56923,"content":56924,"nodeType":860},{},[56925],{"data":56926,"marks":56927,"value":22206,"nodeType":864},{},[],{"data":56929,"content":56930,"nodeType":860},{},[56931],{"data":56932,"marks":56933,"value":22213,"nodeType":864},{},[],{"data":56935,"content":56936,"nodeType":860},{},[56937,56940,56947],{"data":56938,"marks":56939,"value":22220,"nodeType":864},{},[],{"data":56941,"content":56942,"nodeType":883},{"uri":22223},[56943],{"data":56944,"marks":56945,"value":22229,"nodeType":864},{},[56946],{"type":1455},{"data":56948,"marks":56949,"value":22233,"nodeType":864},{},[],{"data":56951,"content":56954,"nodeType":996},{"target":56952},{"sys":56953},{"id":22238,"type":1001,"linkType":1002},[],{"data":56956,"content":56957,"nodeType":860},{},[56958],{"data":56959,"marks":56960,"value":22246,"nodeType":864},{},[],{"data":56962,"content":56963,"nodeType":1312},{},[56964],{"data":56965,"marks":56966,"value":3578,"nodeType":864},{},[56967],{"type":899},{"data":56969,"content":56970,"nodeType":860},{},[56971],{"data":56972,"marks":56973,"value":22260,"nodeType":864},{},[],{"data":56975,"content":56976,"nodeType":860},{},[56977,56980,56987,56990,56997,57000,57007],{"data":56978,"marks":56979,"value":16863,"nodeType":864},{},[],{"data":56981,"content":56982,"nodeType":883},{"uri":16866},[56983],{"data":56984,"marks":56985,"value":16871,"nodeType":864},{},[56986],{"type":1455},{"data":56988,"marks":56989,"value":3731,"nodeType":864},{},[],{"data":56991,"content":56992,"nodeType":883},{"uri":16877},[56993],{"data":56994,"marks":56995,"value":16883,"nodeType":864},{},[56996],{"type":1455},{"data":56998,"marks":56999,"value":16887,"nodeType":864},{},[],{"data":57001,"content":57002,"nodeType":883},{"uri":1700},[57003],{"data":57004,"marks":57005,"value":16894,"nodeType":864},{},[57006],{"type":1455},{"data":57008,"marks":57009,"value":2924,"nodeType":864},{},[],{"items":57011},[57012,57014],{"sys":57013,"name":13779},{"id":13778},{"sys":57015,"name":342},{"id":13775},{"items":57017},[57018],{"fullName":22309,"firstName":22310,"jobTitle":22311,"profilePicture":57019},{"url":22313},{"__typename":2059,"sys":57021,"content":57023,"title":57965,"synopsis":57966,"hashTags":59,"publishedDate":57967,"slug":57968,"tagsCollection":57969,"authorsCollection":57975},{"id":57022},"2sFCww9xnI8okIxhtOaiY1",{"json":57024},{"data":57025,"content":57026,"nodeType":856},{},[57027,57034,57041,57048,57051,57059,57066,57073,57079,57086,57092,57111,57118,57130,57133,57141,57148,57164,57171,57183,57189,57192,57200,57208,57214,57223,57243,57252,57259,57268,57287,57296,57303,57312,57343,57352,57359,57368,57386,57392,57401,57408,57417,57458,57461,57469,57478,57498,57507,57514,57523,57556,57562,57571,57578,57584,57587,57594,57603,57610,57669,57675,57678,57685,57694,57701,57707,57710,57718,57725,57732,57800,57807,57870,57877,57880,57888,57895,57902,57908,57911,57918,57925,57932,57939],{"data":57028,"content":57029,"nodeType":860},{},[57030],{"data":57031,"marks":57032,"value":57033,"nodeType":864},{},[],"The biggest cybersecurity story this year (so far) has been the emergence of “Scattered Lapsus$ Hunters” and their record-breaking worldwide hacking spree. ",{"data":57035,"content":57036,"nodeType":860},{},[57037],{"data":57038,"marks":57039,"value":57040,"nodeType":864},{},[],"Scattered Lapsus$ Hunters is part of “The Com”, the name for the broad community of English-speaking cybercriminals with international criminal connections — including with nation-state sponsored groups. They are also known to collaborate with a range of cybercrime “as-a-Service” organizations for phishing, initial access, ransomware, and more. ",{"data":57042,"content":57043,"nodeType":860},{},[57044],{"data":57045,"marks":57046,"value":57047,"nodeType":864},{},[],"It’s difficult to pin down exactly who the individuals are that make up this criminal collective. But what is known is their MO — making money through extortion by means of account takeover, mass data theft, and ransomware deployment. ",{"data":57049,"content":57050,"nodeType":1005},{},[],{"data":57052,"content":57053,"nodeType":1009},{},[57054],{"data":57055,"marks":57056,"value":57058,"nodeType":864},{},[57057],{"type":899},"How did we get here? ",{"data":57060,"content":57061,"nodeType":860},{},[57062],{"data":57063,"marks":57064,"value":57065,"nodeType":864},{},[],"Earlier this year, the threat group known to most analysts as Scattered Spider (also tracked as 0ktapus, Octo Tempest, Scatter Swine, Muddled Libra, and UNC3944) re-emerged after a series of arrests in late 2024. ",{"data":57067,"content":57068,"nodeType":860},{},[57069],{"data":57070,"marks":57071,"value":57072,"nodeType":864},{},[],"This group has been active in peaks and troughs over the years, but are mainly known for high-profile ransomware attacks on Caesars and MGM Resorts in 2024. ",{"data":57074,"content":57078,"nodeType":996},{"target":57075},{"sys":57076},{"id":57077,"type":1001,"linkType":1002},"1Vt269d7n6IGMzOrJs1FDx",[],{"data":57080,"content":57081,"nodeType":860},{},[57082],{"data":57083,"marks":57084,"value":57085,"nodeType":864},{},[],"Scattered Spider hit the headlines again in April 2025 with attacks on UK retailers Marks & Spencer and Co-op, which resulted in significant, prolonged disruption, and a serious downstream impact on the retail supply chain. ",{"data":57087,"content":57091,"nodeType":996},{"target":57088},{"sys":57089},{"id":57090,"type":1001,"linkType":1002},"3kvcGV2zZZUPnM8IK04Y1O",[],{"data":57093,"content":57094,"nodeType":860},{},[57095,57099,57107],{"data":57096,"marks":57097,"value":57098,"nodeType":864},{},[],"It didn’t stop there, though. What followed was a wide-scale campaign targeting Salesforce customers, with the attackers claiming to have stolen ",{"data":57100,"content":57101,"nodeType":883},{"uri":16553},[57102],{"data":57103,"marks":57104,"value":57106,"nodeType":864},{},[57105],{"type":1455},"over 1.5 billion records from 1000+ companies",{"data":57108,"marks":57109,"value":57110,"nodeType":864},{},[]," across multiple verticals, including heavyweights like Google, Cloudflare, Workday, Adidas, FedEx, Disney, LVMH, and many more.",{"data":57112,"content":57113,"nodeType":860},{},[57114],{"data":57115,"marks":57116,"value":57117,"nodeType":864},{},[],"Around this time, the attackers began to refer to themselves as part of a wider collective, assuming the moniker “Scattered Lapsus$ Hunters” (a mash-up of names given by analysts and self-adopted by attackers — Scattered Spider, ShinyHunters, and Lapsus$).",{"data":57119,"content":57120,"nodeType":860},{},[57121,57125],{"data":57122,"marks":57123,"value":57124,"nodeType":864},{},[],"The most significant breach this year to-date impacted Jaguar Land Rover. A ransomware attack resulted in months of disruption that directly impacted the UK’s GDP, with the government underwriting a $1.5B loan to alleviate the supply chain impact. ",{"data":57126,"marks":57127,"value":57129,"nodeType":864},{},[57128],{"type":899},"In fact, this was the most economically consequential cyber attack yet recorded in a G7 economy. ",{"data":57131,"content":57132,"nodeType":1005},{},[],{"data":57134,"content":57135,"nodeType":1009},{},[57136],{"data":57137,"marks":57138,"value":57140,"nodeType":864},{},[57139],{"type":899},"2025 wasn’t a one-off",{"data":57142,"content":57143,"nodeType":860},{},[57144],{"data":57145,"marks":57146,"value":57147,"nodeType":864},{},[],"The developments through 2025 have presented a stronger picture than ever before that cybercriminal operations are heavily interlinked. Groups overlap considerably, and individuals freely move between different cells. ",{"data":57149,"content":57150,"nodeType":860},{},[57151,57155,57160],{"data":57152,"marks":57153,"value":57154,"nodeType":864},{},[],"When we scratch beneath the surface, this is evident in the tactics, techniques and procedures (TTPs) used by these attackers — even stretching as far back as 2021 with the initial rise of Lapsus$. This is not an accident. ",{"data":57156,"marks":57157,"value":57159,"nodeType":864},{},[57158],{"type":899},"The TTPs used show a conscious move by attackers to move away from environments that are well-protected by traditional security tools. ",{"data":57161,"marks":57162,"value":57163,"nodeType":864},{},[],"This means avoiding targeting endpoints with malware, and not relying on software-based exploits. Instead, these attackers look to take over apps and services directly over the internet. ",{"data":57165,"content":57166,"nodeType":860},{},[57167],{"data":57168,"marks":57169,"value":57170,"nodeType":864},{},[],"Most of the time, this is as simple as logging in to a SaaS app, or an enterprise SSO account (e.g. Microsoft, Okta, or Google) and dumping the data. For attackers that want to take it further, they can abuse the sprawl of interconnected apps that make up modern business IT, seeking out specific data or exploitable functionality. Or, they can leverage internet-accessible management portals to chart a path back to your on-premise assets, giving them everything they need to pivot toward more conventional methods such as ransomware deployment. ",{"data":57172,"content":57173,"nodeType":860},{},[57174,57178],{"data":57175,"marks":57176,"value":57177,"nodeType":864},{},[],"When we look at historical breaches, the pattern is clear. ",{"data":57179,"marks":57180,"value":57182,"nodeType":864},{},[57181],{"type":899},"Not one of the attacks attributed to Scattered Lapsus$ Hunters, or its predecessors, started with an endpoint or network attack — they all began with account takeover. ",{"data":57184,"content":57188,"nodeType":996},{"target":57185},{"sys":57186},{"id":57187,"type":1001,"linkType":1002},"6poP5VM2ARrEvwKEG42HgK",[],{"data":57190,"content":57191,"nodeType":1005},{},[],{"data":57193,"content":57194,"nodeType":1009},{},[57195],{"data":57196,"marks":57197,"value":57199,"nodeType":864},{},[57198],{"type":899},"TTP breakdown: Analyzing the top “Scattered Lapsus$ Hunters” breaches since 2021",{"data":57201,"content":57202,"nodeType":1312},{},[57203],{"data":57204,"marks":57205,"value":57207,"nodeType":864},{},[57206],{"type":899},"Phishing and stolen credentials",{"data":57209,"content":57213,"nodeType":996},{"target":57210},{"sys":57211},{"id":57212,"type":1001,"linkType":1002},"4SNOanDIdGZsvRRnMYQVSo",[],{"data":57215,"content":57216,"nodeType":860},{},[57217],{"data":57218,"marks":57219,"value":57222,"nodeType":864},{},[57220,57221],{"type":899},{"type":1455},"EA Games (2021)",{"data":57224,"content":57225,"nodeType":860},{},[57226,57230,57239],{"data":57227,"marks":57228,"value":57229,"nodeType":864},{},[],"Attackers used stolen session cookies to log into EA’s Slack instance, purchased on a criminal forum. Combined with ",{"data":57231,"content":57233,"nodeType":883},{"uri":57232},"https://pushsecurity.com/blog/phishing-slack-persistence/",[57234],{"data":57235,"marks":57236,"value":57238,"nodeType":864},{},[57237],{"type":1455},"social engineering via Slack",{"data":57240,"marks":57241,"value":57242,"nodeType":864},{},[],", this was used to steal 750GB of data, including video game source code. ",{"data":57244,"content":57245,"nodeType":860},{},[57246],{"data":57247,"marks":57248,"value":57251,"nodeType":864},{},[57249,57250],{"type":899},{"type":1455},"Nvidia (2022)",{"data":57253,"content":57254,"nodeType":860},{},[57255],{"data":57256,"marks":57257,"value":57258,"nodeType":864},{},[],"Attackers used stolen credentials to steal 1TB of data from Nvidia’s internal shares, including a significant amount of sensitive information about the designs of Nvidia graphics cards, source code, and the usernames and passwords of more than 71,000 Nvidia employees.",{"data":57260,"content":57261,"nodeType":860},{},[57262],{"data":57263,"marks":57264,"value":57267,"nodeType":864},{},[57265,57266],{"type":899},{"type":1455},"Microsoft (2022)",{"data":57269,"content":57270,"nodeType":860},{},[57271,57275,57283],{"data":57272,"marks":57273,"value":57274,"nodeType":864},{},[],"Attackers used stolen credentials combined with SIM swapping and ",{"data":57276,"content":57278,"nodeType":883},{"uri":57277},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_fatigue/description.md",[57279],{"data":57280,"marks":57281,"value":57282,"nodeType":864},{},[],"MFA fatigue",{"data":57284,"marks":57285,"value":57286,"nodeType":864},{},[]," attacks to steal Azure DevOps source code — leaked a 9GB archive of Microsoft source code – including ~90% of Bing and 45% of Cortana code. ",{"data":57288,"content":57289,"nodeType":860},{},[57290],{"data":57291,"marks":57292,"value":57295,"nodeType":864},{},[57293,57294],{"type":899},{"type":1455},"T-Mobile (2022)",{"data":57297,"content":57298,"nodeType":860},{},[57299],{"data":57300,"marks":57301,"value":57302,"nodeType":864},{},[],"Attackers used stolen credentials to establish initial access, coupled with social engineering T-Mobile staff into approving the attacker’s device for VPN access. This resulted in source code being stolen from over 30,000 repositories. ",{"data":57304,"content":57305,"nodeType":860},{},[57306],{"data":57307,"marks":57308,"value":57311,"nodeType":864},{},[57309,57310],{"type":899},{"type":1455},"Snowflake (165 customers) (2024)",{"data":57313,"content":57314,"nodeType":860},{},[57315,57319,57327,57331,57339],{"data":57316,"marks":57317,"value":57318,"nodeType":864},{},[],"Attackers targeted ",{"data":57320,"content":57321,"nodeType":883},{"uri":3751},[57322],{"data":57323,"marks":57324,"value":57326,"nodeType":864},{},[57325],{"type":1455},"165 Snowflake customers",{"data":57328,"marks":57329,"value":57330,"nodeType":864},{},[]," using stolen credentials from credential breaches dating back as far as 2020. Due to widespread MFA gaps and the presence of ",{"data":57332,"content":57334,"nodeType":883},{"uri":57333},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[57335],{"data":57336,"marks":57337,"value":29819,"nodeType":864},{},[57338],{"type":1455},{"data":57340,"marks":57341,"value":57342,"nodeType":864},{},[],", attackers were able to simply log in to individual customer tenants, dump the data, and use it to extort the companies. In total, 9 public victims were named following the breach, with over 1B breached customer records. ",{"data":57344,"content":57345,"nodeType":860},{},[57346],{"data":57347,"marks":57348,"value":57351,"nodeType":864},{},[57349,57350],{"type":899},{"type":1455},"PowerSchool (2024)",{"data":57353,"content":57354,"nodeType":860},{},[57355],{"data":57356,"marks":57357,"value":57358,"nodeType":864},{},[],"Attackers gained access to a community-focused customer support portal, PowerSource, using compromised credentials and stole data using an \"export data manager\" customer support tool, stealing the data of 62.4 million students and 9.5 million teachers. PowerSchool paid an undisclosed ransom fee, but hackers returned later to extort schools and individuals separately anyway.",{"data":57360,"content":57361,"nodeType":860},{},[57362],{"data":57363,"marks":57364,"value":57367,"nodeType":864},{},[57365,57366],{"type":899},{"type":1455},"Red Hat (2025)",{"data":57369,"content":57370,"nodeType":860},{},[57371,57375,57382],{"data":57372,"marks":57373,"value":57374,"nodeType":864},{},[],"Attackers breached Red Hat’s GitLab instance via a compromised account — the result of ",{"data":57376,"content":57377,"nodeType":883},{"uri":57333},[57378],{"data":57379,"marks":57380,"value":29819,"nodeType":864},{},[57381],{"type":1455},{"data":57383,"marks":57384,"value":57385,"nodeType":864},{},[]," providing a backdoor to access an otherwise secure, SSO-connected account. Stolen data included approximately 800 Customer Engagement Reports (CERs), authentication tokens, full database URIs, and other private information in Red Hat code and CERs, which they claimed to use to gain access to downstream customer infrastructure. ",{"data":57387,"content":57391,"nodeType":996},{"target":57388},{"sys":57389},{"id":57390,"type":1001,"linkType":1002},"G1V7d5Dvevmr9p0YXElPX",[],{"data":57393,"content":57394,"nodeType":860},{},[57395],{"data":57396,"marks":57397,"value":57400,"nodeType":864},{},[57398,57399],{"type":899},{"type":1455},"Discord (2025)",{"data":57402,"content":57403,"nodeType":860},{},[57404],{"data":57405,"marks":57406,"value":57407,"nodeType":864},{},[],"Attackers compromised a Zendesk customer support account, stealing 1.6TB of data. The hackers say this consisted of roughly 8.4 million tickets affecting 5.5 million unique users, and that about 580,000 users contained payment information.",{"data":57409,"content":57410,"nodeType":860},{},[57411],{"data":57412,"marks":57413,"value":57416,"nodeType":864},{},[57414,57415],{"type":899},{"type":1455},"SoundCloud, MatchGroup, Crunchbase, Betterment... (2026)",{"data":57418,"content":57419,"nodeType":860},{},[57420,57424,57432,57435,57443,57447,57454],{"data":57421,"marks":57422,"value":57423,"nodeType":864},{},[],"Scattered Lapsus$ Hunters have already claimed several public victims in 2026, with over 60 million breached records. ",{"data":57425,"content":57427,"nodeType":883},{"uri":57426},"https://www.bleepingcomputer.com/news/security/shinyhunters-claim-to-be-behind-sso-account-data-theft-attacks/",[57428],{"data":57429,"marks":57430,"value":57431,"nodeType":864},{},[],"SoundCloud, Betterment, Crunchbase",{"data":57433,"marks":57434,"value":902,"nodeType":864},{},[],{"data":57436,"content":57438,"nodeType":883},{"uri":57437},"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/",[57439],{"data":57440,"marks":57441,"value":57442,"nodeType":864},{},[],"MatchGroup",{"data":57444,"marks":57445,"value":57446,"nodeType":864},{},[]," have all reported breaches this month, powered by a brand ",{"data":57448,"content":57449,"nodeType":883},{"uri":23901},[57450],{"data":57451,"marks":57452,"value":57453,"nodeType":864},{},[],"new real-time-operated AiTM phishing kit",{"data":57455,"marks":57456,"value":57457,"nodeType":864},{},[]," targeting Okta, Entra, and Google SSO accounts. This is a developing situation, with more victims expected to be announced publicly soon.",{"data":57459,"content":57460,"nodeType":1005},{},[],{"data":57462,"content":57463,"nodeType":1312},{},[57464],{"data":57465,"marks":57466,"value":57468,"nodeType":864},{},[57467],{"type":899},"Vishing and help desk scams",{"data":57470,"content":57471,"nodeType":860},{},[57472],{"data":57473,"marks":57474,"value":57477,"nodeType":864},{},[57475,57476],{"type":899},{"type":1455},"MGM Resorts & Caesars (2023)",{"data":57479,"content":57480,"nodeType":860},{},[57481,57485,57494],{"data":57482,"marks":57483,"value":57484,"nodeType":864},{},[],"MGM Resorts and Caesars were hit with twin breaches in 2023. Attackers socially engineered help desk personnel to take over accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",{"data":57486,"content":57488,"nodeType":883},{"uri":57487},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/inbound_federation/description.md",[57489],{"data":57490,"marks":57491,"value":57493,"nodeType":864},{},[57492],{"type":1455},"inbound federation",{"data":57495,"marks":57496,"value":57497,"nodeType":864},{},[]," — granting comprehensive access that was used to deploy ransomware. ",{"data":57499,"content":57500,"nodeType":860},{},[57501],{"data":57502,"marks":57503,"value":57506,"nodeType":864},{},[57504,57505],{"type":899},{"type":1455},"Transport for London (2024)",{"data":57508,"content":57509,"nodeType":860},{},[57510],{"data":57511,"marks":57512,"value":57513,"nodeType":864},{},[],"Attackers socially engineered the Transport for London help desk to gain privileged access to the IT environment, resulting in prolonged disruption to key online services underpinning London’s public transport network, theft of 5,000 users bank details, and all 30,000 staff members having to reset their online credentials in person.",{"data":57515,"content":57516,"nodeType":860},{},[57517],{"data":57518,"marks":57519,"value":57522,"nodeType":864},{},[57520,57521],{"type":899},{"type":1455},"Marks & Spencer (2025)",{"data":57524,"content":57525,"nodeType":860},{},[57526,57530,57539,57543,57552],{"data":57527,"marks":57528,"value":57529,"nodeType":864},{},[],"Attackers compromised a Microsoft Entra account belonging to a privileged user via a ",{"data":57531,"content":57533,"nodeType":883},{"uri":57532},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams/",[57534],{"data":57535,"marks":57536,"value":57538,"nodeType":864},{},[57537],{"type":1455},"help desk scam",{"data":57540,"marks":57541,"value":57542,"nodeType":864},{},[],", which enabled them to steal sensitive data from cloud environments, as well as pivot to deploy ransomware via the ",{"data":57544,"content":57546,"nodeType":883},{"uri":57545},"https://cloud.google.com/blog/topics/threat-intelligence/vsphere-active-directory-integration-risks",[57547],{"data":57548,"marks":57549,"value":57551,"nodeType":864},{},[57550],{"type":1455},"VMware admin console",{"data":57553,"marks":57554,"value":57555,"nodeType":864},{},[],". This enabled ransomware to be deployed at the hypervisor layer, evading host-based protections like EDR. ",{"data":57557,"content":57561,"nodeType":996},{"target":57558},{"sys":57559},{"id":57560,"type":1001,"linkType":1002},"7hBdHG74NaA3bQfOMpYA9o",[],{"data":57563,"content":57564,"nodeType":860},{},[57565],{"data":57566,"marks":57567,"value":57570,"nodeType":864},{},[57568,57569],{"type":899},{"type":1455},"Jaguar Land Rover (2025)",{"data":57572,"content":57573,"nodeType":860},{},[57574],{"data":57575,"marks":57576,"value":57577,"nodeType":864},{},[],"Attackers compromised highly privileged admin accounts via a help desk scam, which they leveraged to access and deploy ransomware to all aspects of Jaguar’s business, from CAD and engineering software, to payments tracking, to customer car delivery, using similar techniques to the Marks & Spencer breach. ",{"data":57579,"content":57583,"nodeType":996},{"target":57580},{"sys":57581},{"id":57582,"type":1001,"linkType":1002},"6s1X2fo4K9EeVLBmHm4YXb",[],{"data":57585,"content":57586,"nodeType":1005},{},[],{"data":57588,"content":57589,"nodeType":1312},{},[57590],{"data":57591,"marks":57592,"value":694,"nodeType":864},{},[57593],{"type":899},{"data":57595,"content":57596,"nodeType":860},{},[57597],{"data":57598,"marks":57599,"value":57602,"nodeType":864},{},[57600,57601],{"type":899},{"type":1455},"Salesforce & Salesloft (1000+ customers) (2025)",{"data":57604,"content":57605,"nodeType":860},{},[57606],{"data":57607,"marks":57608,"value":57609,"nodeType":864},{},[],"A vast campaign against Salesforce customers resulted in the compromise of 1000+ Salesforce tenants (according to the attacker) with more than 1.5 billion records stolen. This campaign can consisted of three phases:",{"data":57611,"content":57612,"nodeType":941},{},[57613,57628,57643],{"data":57614,"content":57615,"nodeType":945},{},[57616],{"data":57617,"content":57618,"nodeType":860},{},[57619,57624],{"data":57620,"marks":57621,"value":57623,"nodeType":864},{},[57622],{"type":899},"Phase 1:",{"data":57625,"marks":57626,"value":57627,"nodeType":864},{},[]," The attacker conducted a large-scale vishing campaign against Salesforce customers, calling up users and socially engineering them into connecting a malicious version of the “Data Loader” app into their tenant. This was in fact an attacker-controlled app that enabled data to be mass-exfiltrated via API. ",{"data":57629,"content":57630,"nodeType":945},{},[57631],{"data":57632,"content":57633,"nodeType":860},{},[57634,57639],{"data":57635,"marks":57636,"value":57638,"nodeType":864},{},[57637],{"type":899},"Phase 2: ",{"data":57640,"marks":57641,"value":57642,"nodeType":864},{},[],"The attacker conducted a supply-chain compromise against customers of Salesloft. Users of Salesloft’s “Drift” integration were impacted by attackers stealing access tokens from Salesloft’s AWS environment. This integration allowed the attacker to steal data from customers that had deployed Drift to connected environments — namely, Salesforce, and Google Workspace. ",{"data":57644,"content":57645,"nodeType":945},{},[57646],{"data":57647,"content":57648,"nodeType":860},{},[57649,57654,57658,57665],{"data":57650,"marks":57651,"value":57653,"nodeType":864},{},[57652],{"type":899},"Phase 3:",{"data":57655,"marks":57656,"value":57657,"nodeType":864},{},[]," The attacker then conducted a separate supply-chain compromise involving Gainsight (allegedly using OAuth tokens stolen in the Salesloft attack) which enabled them to ",{"data":57659,"content":57660,"nodeType":883},{"uri":16566},[57661],{"data":57662,"marks":57663,"value":57664,"nodeType":864},{},[],"breach a further 285 Salesforce instances",{"data":57666,"marks":57667,"value":57668,"nodeType":864},{},[]," using stolen OAuth tokens from Gainsight's integrations. ",{"data":57670,"content":57674,"nodeType":996},{"target":57671},{"sys":57672},{"id":57673,"type":1001,"linkType":1002},"3TwjpVKQ42SwQRhvGFbZdn",[],{"data":57676,"content":57677,"nodeType":1005},{},[],{"data":57679,"content":57680,"nodeType":1312},{},[57681],{"data":57682,"marks":57683,"value":699,"nodeType":864},{},[57684],{"type":899},{"data":57686,"content":57687,"nodeType":860},{},[57688],{"data":57689,"marks":57690,"value":57693,"nodeType":864},{},[57691,57692],{"type":899},{"type":1455},"CyberHaven (2024)",{"data":57695,"content":57696,"nodeType":860},{},[57697],{"data":57698,"marks":57699,"value":57700,"nodeType":864},{},[],"Hackers phished a CyberHaven extension developer and uploaded a malicious version of the CyberHaven extension to the Chrome Web Store, leading to customer data breaches where installed in user browsers, impacting CyberHaven’s estimated ~400 business customers. This was part of a broader campaign that targeted 35 Chrome extensions, collectively impacting over 2.5 million users.",{"data":57702,"content":57706,"nodeType":996},{"target":57703},{"sys":57704},{"id":57705,"type":1001,"linkType":1002},"4ErDI0xi0Vj2Zrk8Qsb2NB",[],{"data":57708,"content":57709,"nodeType":1005},{},[],{"data":57711,"content":57712,"nodeType":1009},{},[57713],{"data":57714,"marks":57715,"value":57717,"nodeType":864},{},[57716],{"type":899},"The bigger picture",{"data":57719,"content":57720,"nodeType":860},{},[57721],{"data":57722,"marks":57723,"value":57724,"nodeType":864},{},[],"Scattered Lapsus$ Hunters are dominating the headlines right now, but they aren’t the only attackers using these modern techniques and consciously evading established security controls. ",{"data":57726,"content":57727,"nodeType":860},{},[57728],{"data":57729,"marks":57730,"value":57731,"nodeType":864},{},[],"Threat reports agree that attackers are steering away from traditional exploit and malware-driven breaches towards identities:",{"data":57733,"content":57734,"nodeType":941},{},[57735,57757,57779],{"data":57736,"content":57737,"nodeType":945},{},[57738],{"data":57739,"content":57740,"nodeType":860},{},[57741,57745,57753],{"data":57742,"marks":57743,"value":57744,"nodeType":864},{},[],"Identity-based attacks surged 32% in the last year, while 97% of identity attacks are password-based, driven by credential leaks and infostealer malware. (",{"data":57746,"content":57748,"nodeType":883},{"uri":57747},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1",[57749],{"data":57750,"marks":57751,"value":19538,"nodeType":864},{},[57752],{"type":1455},{"data":57754,"marks":57755,"value":57756,"nodeType":864},{},[],")",{"data":57758,"content":57759,"nodeType":945},{},[57760],{"data":57761,"content":57762,"nodeType":860},{},[57763,57767,57776],{"data":57764,"marks":57765,"value":57766,"nodeType":864},{},[],"79% of detections were malware-free in the last year, up from 40% in 2019. (",{"data":57768,"content":57770,"nodeType":883},{"uri":57769},"https://www.crowdstrike.com/en-gb/global-threat-report/",[57771],{"data":57772,"marks":57773,"value":57775,"nodeType":864},{},[57774],{"type":1455},"CrowdStrike",{"data":57777,"marks":57778,"value":57756,"nodeType":864},{},[],{"data":57780,"content":57781,"nodeType":945},{},[57782],{"data":57783,"content":57784,"nodeType":860},{},[57785,57789,57797],{"data":57786,"marks":57787,"value":57788,"nodeType":864},{},[],"Credential abuse and phishing combined accounted for 38% of breaches, making identity the primary breach vector observed. (",{"data":57790,"content":57791,"nodeType":883},{"uri":7170},[57792],{"data":57793,"marks":57794,"value":57796,"nodeType":864},{},[57795],{"type":1455},"Verizon",{"data":57798,"marks":57799,"value":57756,"nodeType":864},{},[],{"data":57801,"content":57802,"nodeType":860},{},[57803],{"data":57804,"marks":57805,"value":57806,"nodeType":864},{},[],"And other public breaches from this year alone demonstrate similar TTPs from outside of the Scattered Lapsus$ Hunters orbit:",{"data":57808,"content":57809,"nodeType":941},{},[57810,57825,57840,57855],{"data":57811,"content":57812,"nodeType":945},{},[57813],{"data":57814,"content":57815,"nodeType":860},{},[57816,57821],{"data":57817,"marks":57818,"value":57820,"nodeType":864},{},[57819],{"type":899},"Nikkei",{"data":57822,"marks":57823,"value":57824,"nodeType":864},{},[],": Japanese publishing giant Nikkei’s Slack messaging platform was compromised using stolen credentials, leaking the names, email addresses, and chat histories for 17,368 individuals registered on Slack.",{"data":57826,"content":57827,"nodeType":945},{},[57828],{"data":57829,"content":57830,"nodeType":860},{},[57831,57836],{"data":57832,"marks":57833,"value":57835,"nodeType":864},{},[57834],{"type":899},"Evertec",{"data":57837,"marks":57838,"value":57839,"nodeType":864},{},[],": Hackers tried to steal $130 million from Evertec’s Brazilian subsidiary Sinqia S.A.after gaining unauthorized access to its environment on the central bank’s real-time payment system (Pix) using stolen credentials.",{"data":57841,"content":57842,"nodeType":945},{},[57843],{"data":57844,"content":57845,"nodeType":860},{},[57846,57851],{"data":57847,"marks":57848,"value":57850,"nodeType":864},{},[57849],{"type":899},"Hy-Vee:",{"data":57852,"marks":57853,"value":57854,"nodeType":864},{},[]," Was hit with a data breach after hackers logged in with stolen credentials, exposing 53GB of sensitive data.",{"data":57856,"content":57857,"nodeType":945},{},[57858],{"data":57859,"content":57860,"nodeType":860},{},[57861,57866],{"data":57862,"marks":57863,"value":57865,"nodeType":864},{},[57864],{"type":899},"Scania: ",{"data":57867,"marks":57868,"value":57869,"nodeType":864},{},[],"Automotive giant Scania confirmed it suffered a cybersecurity incident where threat actors used compromised credentials to breach its Financial Services systems and steal insurance claim documents.",{"data":57871,"content":57872,"nodeType":860},{},[57873],{"data":57874,"marks":57875,"value":57876,"nodeType":864},{},[],"Scattered Lapsus$ Hunters may be grabbing the headlines — but this a huge movement in a vast and flexible community of attackers. And criminals around the world are learning from their success. ",{"data":57878,"content":57879,"nodeType":1005},{},[],{"data":57881,"content":57882,"nodeType":1009},{},[57883],{"data":57884,"marks":57885,"value":57887,"nodeType":864},{},[57886],{"type":899},"Lessons learned",{"data":57889,"content":57890,"nodeType":860},{},[57891],{"data":57892,"marks":57893,"value":57894,"nodeType":864},{},[],"The common thread with all of these attacks is that they are evading established security controls by targeting applications directly, over the internet, via account takeover.",{"data":57896,"content":57897,"nodeType":860},{},[57898],{"data":57899,"marks":57900,"value":57901,"nodeType":864},{},[],"Clearly, the success of these attacks shows the limitations of multiple control layers. Endpoint and network layer controls have no visibility of this attack surface. Identity-focused controls are being undermined by ghost logins and shadow IT. And the limitations of cloud security controls in their ability to encompass all apps, and detect and stop malicious actions in real-time (that often blend in seamlessly with normal user activity). ",{"data":57903,"content":57907,"nodeType":996},{"target":57904},{"sys":57905},{"id":57906,"type":1001,"linkType":1002},"4Dg3fZEGf7ShyQJ8jlNDME",[],{"data":57909,"content":57910,"nodeType":1005},{},[],{"data":57912,"content":57913,"nodeType":1009},{},[57914],{"data":57915,"marks":57916,"value":7533,"nodeType":864},{},[57917],{"type":899},{"data":57919,"content":57920,"nodeType":860},{},[57921],{"data":57922,"marks":57923,"value":57924,"nodeType":864},{},[],"Stopping attacks that are designed to evade established controls is in our DNA — it’s the reason Push was founded. ",{"data":57926,"content":57927,"nodeType":860},{},[57928],{"data":57929,"marks":57930,"value":57931,"nodeType":864},{},[],"The browser is the gateway to to the apps and identities that attackers are now targeting, with many attacks taking place inside the user’s browser — whether that’s entering credentials onto a phishing page, approving a malicious OAuth grant, installing a risky browser extension, or insecurely accessing an app with a weak password and no MFA. ",{"data":57933,"content":57934,"nodeType":860},{},[57935],{"data":57936,"marks":57937,"value":57938,"nodeType":864},{},[],"Push’s browser-based security platform provides comprehensive detection and response capabilities against attacks like AiTM phishing, credential stuffing, malicious browser extensions, malicious OAuth grants, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":57940,"content":57941,"nodeType":860},{},[57942,57945,57952,57955,57962],{"data":57943,"marks":57944,"value":16863,"nodeType":864},{},[],{"data":57946,"content":57947,"nodeType":883},{"uri":16866},[57948],{"data":57949,"marks":57950,"value":16871,"nodeType":864},{},[57951],{"type":1455},{"data":57953,"marks":57954,"value":52968,"nodeType":864},{},[],{"data":57956,"content":57957,"nodeType":883},{"uri":1700},[57958],{"data":57959,"marks":57960,"value":16894,"nodeType":864},{},[57961],{"type":1455},{"data":57963,"marks":57964,"value":2924,"nodeType":864},{},[],"\"Scattered Lapsus$ Hunters\" — how modern attackers exploit the gaps in your security stack ","How Scattered Lapsus$ Hunters breaches demonstrate the evolution of attacker TTPs, shaping the future of cyber attacks.","2025-11-13T00:00:00.000Z","scattered-lapsus-hunters",{"items":57970},[57971,57973],{"sys":57972,"name":13779},{"id":13778},{"sys":57974,"name":342},{"id":13775},{"items":57976},[57977],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":57978},{"url":2740},{"__typename":2059,"sys":57980,"content":57981,"title":53419,"synopsis":53420,"hashTags":59,"publishedDate":53421,"slug":53422,"tagsCollection":59143,"authorsCollection":59149},{"id":52075},{"json":57982},{"data":57983,"content":57984,"nodeType":856},{},[57985,57991,58012,58018,58023,58029,58035,58041,58046,58049,58056,58062,58067,58072,58085,58266,58276,58283,58289,58295,58301,58317,58322,58328,58331,58338,58344,58373,58379,58392,58409,58437,58442,58448,58463,58469,58475,58478,58485,58491,58574,58580,58586,58593,58599,58605,58611,58616,58623,58629,58635,58641,58646,58652,58659,58674,58681,58687,58692,58695,58702,58708,58714,58808,58814,58821,58827,58833,58839,58845,58852,58858,58864,58884,58889,58902,58915,58928,58933,58940,58946,58953,58959,58962,58969,58975,59002,59007,59027,59033,59036,59043,59049,59062,59067,59073,59079,59082,59089,59104,59110],{"data":57986,"content":57987,"nodeType":860},{},[57988],{"data":57989,"marks":57990,"value":52086,"nodeType":864},{},[],{"data":57992,"content":57993,"nodeType":941},{},[57994,58003],{"data":57995,"content":57996,"nodeType":945},{},[57997],{"data":57998,"content":57999,"nodeType":860},{},[58000],{"data":58001,"marks":58002,"value":52099,"nodeType":864},{},[],{"data":58004,"content":58005,"nodeType":945},{},[58006],{"data":58007,"content":58008,"nodeType":860},{},[58009],{"data":58010,"marks":58011,"value":52109,"nodeType":864},{},[],{"data":58013,"content":58014,"nodeType":860},{},[58015],{"data":58016,"marks":58017,"value":52116,"nodeType":864},{},[],{"data":58019,"content":58022,"nodeType":996},{"target":58020},{"sys":58021},{"id":52121,"type":1001,"linkType":1002},[],{"data":58024,"content":58025,"nodeType":860},{},[58026],{"data":58027,"marks":58028,"value":52129,"nodeType":864},{},[],{"data":58030,"content":58031,"nodeType":860},{},[58032],{"data":58033,"marks":58034,"value":52136,"nodeType":864},{},[],{"data":58036,"content":58037,"nodeType":860},{},[58038],{"data":58039,"marks":58040,"value":52143,"nodeType":864},{},[],{"data":58042,"content":58045,"nodeType":996},{"target":58043},{"sys":58044},{"id":52148,"type":1001,"linkType":1002},[],{"data":58047,"content":58048,"nodeType":1005},{},[],{"data":58050,"content":58051,"nodeType":1009},{},[58052],{"data":58053,"marks":58054,"value":52160,"nodeType":864},{},[58055],{"type":899},{"data":58057,"content":58058,"nodeType":860},{},[58059],{"data":58060,"marks":58061,"value":52167,"nodeType":864},{},[],{"data":58063,"content":58066,"nodeType":996},{"target":58064},{"sys":58065},{"id":52172,"type":1001,"linkType":1002},[],{"data":58068,"content":58071,"nodeType":996},{"target":58069},{"sys":58070},{"id":52178,"type":1001,"linkType":1002},[],{"data":58073,"content":58074,"nodeType":860},{},[58075,58078,58082],{"data":58076,"marks":58077,"value":52186,"nodeType":864},{},[],{"data":58079,"marks":58080,"value":52191,"nodeType":864},{},[58081],{"type":2246},{"data":58083,"marks":58084,"value":52195,"nodeType":864},{},[],{"data":58086,"content":58087,"nodeType":4845},{},[58088,58111,58146,58167,58197,58227],{"data":58089,"content":58090,"nodeType":4581},{},[58091,58101],{"data":58092,"content":58093,"nodeType":14464},{},[58094],{"data":58095,"content":58096,"nodeType":860},{},[58097],{"data":58098,"marks":58099,"value":52212,"nodeType":864},{},[58100],{"type":899},{"data":58102,"content":58103,"nodeType":14464},{},[58104],{"data":58105,"content":58106,"nodeType":860},{},[58107],{"data":58108,"marks":58109,"value":52223,"nodeType":864},{},[58110],{"type":899},{"data":58112,"content":58113,"nodeType":4581},{},[58114,58134],{"data":58115,"content":58116,"nodeType":4569},{},[58117],{"data":58118,"content":58119,"nodeType":860},{},[58120,58123,58131],{"data":58121,"marks":58122,"value":52236,"nodeType":864},{},[],{"data":58124,"content":58127,"nodeType":39736},{"target":58125},{"sys":58126},{"id":39958,"type":1001,"linkType":1002},[58128],{"data":58129,"marks":58130,"value":52245,"nodeType":864},{},[],{"data":58132,"marks":58133,"value":52249,"nodeType":864},{},[],{"data":58135,"content":58136,"nodeType":4569},{},[58137],{"data":58138,"content":58139,"nodeType":860},{},[58140,58143],{"data":58141,"marks":58142,"value":52259,"nodeType":864},{},[],{"data":58144,"marks":58145,"value":52263,"nodeType":864},{},[],{"data":58147,"content":58148,"nodeType":4581},{},[58149,58158],{"data":58150,"content":58151,"nodeType":4569},{},[58152],{"data":58153,"content":58154,"nodeType":860},{},[58155],{"data":58156,"marks":58157,"value":52276,"nodeType":864},{},[],{"data":58159,"content":58160,"nodeType":4569},{},[58161],{"data":58162,"content":58163,"nodeType":860},{},[58164],{"data":58165,"marks":58166,"value":52286,"nodeType":864},{},[],{"data":58168,"content":58169,"nodeType":4581},{},[58170,58188],{"data":58171,"content":58172,"nodeType":4569},{},[58173],{"data":58174,"content":58175,"nodeType":860},{},[58176,58179,58185],{"data":58177,"marks":58178,"value":52299,"nodeType":864},{},[],{"data":58180,"content":58181,"nodeType":883},{"uri":52302},[58182],{"data":58183,"marks":58184,"value":52307,"nodeType":864},{},[],{"data":58186,"marks":58187,"value":14316,"nodeType":864},{},[],{"data":58189,"content":58190,"nodeType":4569},{},[58191],{"data":58192,"content":58193,"nodeType":860},{},[58194],{"data":58195,"marks":58196,"value":52320,"nodeType":864},{},[],{"data":58198,"content":58199,"nodeType":4581},{},[58200,58209],{"data":58201,"content":58202,"nodeType":4569},{},[58203],{"data":58204,"content":58205,"nodeType":860},{},[58206],{"data":58207,"marks":58208,"value":52333,"nodeType":864},{},[],{"data":58210,"content":58211,"nodeType":4569},{},[58212],{"data":58213,"content":58214,"nodeType":860},{},[58215,58218,58224],{"data":58216,"marks":58217,"value":52343,"nodeType":864},{},[],{"data":58219,"content":58220,"nodeType":883},{"uri":3259},[58221],{"data":58222,"marks":58223,"value":18962,"nodeType":864},{},[],{"data":58225,"marks":58226,"value":2924,"nodeType":864},{},[],{"data":58228,"content":58229,"nodeType":4581},{},[58230,58239],{"data":58231,"content":58232,"nodeType":4569},{},[58233],{"data":58234,"content":58235,"nodeType":860},{},[58236],{"data":58237,"marks":58238,"value":52365,"nodeType":864},{},[],{"data":58240,"content":58241,"nodeType":4569},{},[58242],{"data":58243,"content":58244,"nodeType":860},{},[58245,58248,58254,58257,58263],{"data":58246,"marks":58247,"value":21,"nodeType":864},{},[],{"data":58249,"content":58250,"nodeType":883},{"uri":52377},[58251],{"data":58252,"marks":58253,"value":315,"nodeType":864},{},[],{"data":58255,"marks":58256,"value":52385,"nodeType":864},{},[],{"data":58258,"content":58259,"nodeType":883},{"uri":11726},[58260],{"data":58261,"marks":58262,"value":11731,"nodeType":864},{},[],{"data":58264,"marks":58265,"value":52395,"nodeType":864},{},[],{"data":58267,"content":58268,"nodeType":860},{},[58269,58272],{"data":58270,"marks":58271,"value":52402,"nodeType":864},{},[],{"data":58273,"marks":58274,"value":52407,"nodeType":864},{},[58275],{"type":899},{"data":58277,"content":58278,"nodeType":1312},{},[58279],{"data":58280,"marks":58281,"value":52415,"nodeType":864},{},[58282],{"type":899},{"data":58284,"content":58285,"nodeType":860},{},[58286],{"data":58287,"marks":58288,"value":52422,"nodeType":864},{},[],{"data":58290,"content":58291,"nodeType":860},{},[58292],{"data":58293,"marks":58294,"value":52429,"nodeType":864},{},[],{"data":58296,"content":58297,"nodeType":860},{},[58298],{"data":58299,"marks":58300,"value":52436,"nodeType":864},{},[],{"data":58302,"content":58303,"nodeType":860},{},[58304,58307,58310,58314],{"data":58305,"marks":58306,"value":52443,"nodeType":864},{},[],{"data":58308,"marks":58309,"value":52447,"nodeType":864},{},[],{"data":58311,"marks":58312,"value":52452,"nodeType":864},{},[58313],{"type":899},{"data":58315,"marks":58316,"value":52456,"nodeType":864},{},[],{"data":58318,"content":58321,"nodeType":996},{"target":58319},{"sys":58320},{"id":52461,"type":1001,"linkType":1002},[],{"data":58323,"content":58324,"nodeType":860},{},[58325],{"data":58326,"marks":58327,"value":52469,"nodeType":864},{},[],{"data":58329,"content":58330,"nodeType":1005},{},[],{"data":58332,"content":58333,"nodeType":1009},{},[58334],{"data":58335,"marks":58336,"value":52480,"nodeType":864},{},[58337],{"type":899},{"data":58339,"content":58340,"nodeType":860},{},[58341],{"data":58342,"marks":58343,"value":52487,"nodeType":864},{},[],{"data":58345,"content":58346,"nodeType":941},{},[58347,58360],{"data":58348,"content":58349,"nodeType":945},{},[58350],{"data":58351,"content":58352,"nodeType":860},{},[58353,58357],{"data":58354,"marks":58355,"value":52501,"nodeType":864},{},[58356],{"type":899},{"data":58358,"marks":58359,"value":52505,"nodeType":864},{},[],{"data":58361,"content":58362,"nodeType":945},{},[58363],{"data":58364,"content":58365,"nodeType":860},{},[58366,58370],{"data":58367,"marks":58368,"value":52516,"nodeType":864},{},[58369],{"type":899},{"data":58371,"marks":58372,"value":52520,"nodeType":864},{},[],{"data":58374,"content":58375,"nodeType":1312},{},[58376],{"data":58377,"marks":58378,"value":52527,"nodeType":864},{},[],{"data":58380,"content":58381,"nodeType":860},{},[58382,58385,58389],{"data":58383,"marks":58384,"value":52534,"nodeType":864},{},[],{"data":58386,"marks":58387,"value":52539,"nodeType":864},{},[58388],{"type":2246},{"data":58390,"marks":58391,"value":52543,"nodeType":864},{},[],{"data":58393,"content":58394,"nodeType":860},{},[58395,58398,58406],{"data":58396,"marks":58397,"value":52550,"nodeType":864},{},[],{"data":58399,"content":58402,"nodeType":39736},{"target":58400},{"sys":58401},{"id":52555,"type":1001,"linkType":1002},[58403],{"data":58404,"marks":58405,"value":52560,"nodeType":864},{},[],{"data":58407,"marks":58408,"value":52564,"nodeType":864},{},[],{"data":58410,"content":58411,"nodeType":860},{},[58412,58415,58423,58426,58434],{"data":58413,"marks":58414,"value":52571,"nodeType":864},{},[],{"data":58416,"content":58419,"nodeType":39736},{"target":58417},{"sys":58418},{"id":52576,"type":1001,"linkType":1002},[58420],{"data":58421,"marks":58422,"value":52581,"nodeType":864},{},[],{"data":58424,"marks":58425,"value":52585,"nodeType":864},{},[],{"data":58427,"content":58430,"nodeType":39736},{"target":58428},{"sys":58429},{"id":52590,"type":1001,"linkType":1002},[58431],{"data":58432,"marks":58433,"value":52595,"nodeType":864},{},[],{"data":58435,"marks":58436,"value":52599,"nodeType":864},{},[],{"data":58438,"content":58441,"nodeType":996},{"target":58439},{"sys":58440},{"id":52604,"type":1001,"linkType":1002},[],{"data":58443,"content":58444,"nodeType":1312},{},[58445],{"data":58446,"marks":58447,"value":52612,"nodeType":864},{},[],{"data":58449,"content":58450,"nodeType":860},{},[58451,58454,58460],{"data":58452,"marks":58453,"value":52619,"nodeType":864},{},[],{"data":58455,"content":58456,"nodeType":883},{"uri":52622},[58457],{"data":58458,"marks":58459,"value":52627,"nodeType":864},{},[],{"data":58461,"marks":58462,"value":52631,"nodeType":864},{},[],{"data":58464,"content":58465,"nodeType":860},{},[58466],{"data":58467,"marks":58468,"value":52638,"nodeType":864},{},[],{"data":58470,"content":58471,"nodeType":860},{},[58472],{"data":58473,"marks":58474,"value":52645,"nodeType":864},{},[],{"data":58476,"content":58477,"nodeType":1005},{},[],{"data":58479,"content":58480,"nodeType":1009},{},[58481],{"data":58482,"marks":58483,"value":52656,"nodeType":864},{},[58484],{"type":899},{"data":58486,"content":58487,"nodeType":860},{},[58488],{"data":58489,"marks":58490,"value":52663,"nodeType":864},{},[],{"data":58492,"content":58493,"nodeType":941},{},[58494,58514,58534,58554],{"data":58495,"content":58496,"nodeType":945},{},[58497],{"data":58498,"content":58499,"nodeType":860},{},[58500,58503,58511],{"data":58501,"marks":58502,"value":21,"nodeType":864},{},[],{"data":58504,"content":58507,"nodeType":39736},{"target":58505},{"sys":58506},{"id":52680,"type":1001,"linkType":1002},[58508],{"data":58509,"marks":58510,"value":52685,"nodeType":864},{},[],{"data":58512,"marks":58513,"value":52689,"nodeType":864},{},[],{"data":58515,"content":58516,"nodeType":945},{},[58517],{"data":58518,"content":58519,"nodeType":860},{},[58520,58523,58531],{"data":58521,"marks":58522,"value":21,"nodeType":864},{},[],{"data":58524,"content":58527,"nodeType":39736},{"target":58525},{"sys":58526},{"id":52703,"type":1001,"linkType":1002},[58528],{"data":58529,"marks":58530,"value":52708,"nodeType":864},{},[],{"data":58532,"marks":58533,"value":52712,"nodeType":864},{},[],{"data":58535,"content":58536,"nodeType":945},{},[58537],{"data":58538,"content":58539,"nodeType":860},{},[58540,58543,58551],{"data":58541,"marks":58542,"value":21,"nodeType":864},{},[],{"data":58544,"content":58547,"nodeType":39736},{"target":58545},{"sys":58546},{"id":52726,"type":1001,"linkType":1002},[58548],{"data":58549,"marks":58550,"value":699,"nodeType":864},{},[],{"data":58552,"marks":58553,"value":21,"nodeType":864},{},[],{"data":58555,"content":58556,"nodeType":945},{},[58557],{"data":58558,"content":58559,"nodeType":860},{},[58560,58563,58571],{"data":58561,"marks":58562,"value":21,"nodeType":864},{},[],{"data":58564,"content":58567,"nodeType":39736},{"target":58565},{"sys":58566},{"id":52747,"type":1001,"linkType":1002},[58568],{"data":58569,"marks":58570,"value":52752,"nodeType":864},{},[],{"data":58572,"marks":58573,"value":52756,"nodeType":864},{},[],{"data":58575,"content":58576,"nodeType":860},{},[58577],{"data":58578,"marks":58579,"value":52763,"nodeType":864},{},[],{"data":58581,"content":58582,"nodeType":860},{},[58583],{"data":58584,"marks":58585,"value":52770,"nodeType":864},{},[],{"data":58587,"content":58588,"nodeType":1312},{},[58589],{"data":58590,"marks":58591,"value":52778,"nodeType":864},{},[58592],{"type":899},{"data":58594,"content":58595,"nodeType":860},{},[58596],{"data":58597,"marks":58598,"value":52785,"nodeType":864},{},[],{"data":58600,"content":58601,"nodeType":860},{},[58602],{"data":58603,"marks":58604,"value":52792,"nodeType":864},{},[],{"data":58606,"content":58607,"nodeType":860},{},[58608],{"data":58609,"marks":58610,"value":52799,"nodeType":864},{},[],{"data":58612,"content":58615,"nodeType":996},{"target":58613},{"sys":58614},{"id":40048,"type":1001,"linkType":1002},[],{"data":58617,"content":58618,"nodeType":1312},{},[58619],{"data":58620,"marks":58621,"value":52812,"nodeType":864},{},[58622],{"type":899},{"data":58624,"content":58625,"nodeType":860},{},[58626],{"data":58627,"marks":58628,"value":52819,"nodeType":864},{},[],{"data":58630,"content":58631,"nodeType":860},{},[58632],{"data":58633,"marks":58634,"value":52826,"nodeType":864},{},[],{"data":58636,"content":58637,"nodeType":860},{},[58638],{"data":58639,"marks":58640,"value":52833,"nodeType":864},{},[],{"data":58642,"content":58645,"nodeType":996},{"target":58643},{"sys":58644},{"id":52838,"type":1001,"linkType":1002},[],{"data":58647,"content":58648,"nodeType":860},{},[58649],{"data":58650,"marks":58651,"value":52846,"nodeType":864},{},[],{"data":58653,"content":58654,"nodeType":1312},{},[58655],{"data":58656,"marks":58657,"value":52854,"nodeType":864},{},[58658],{"type":899},{"data":58660,"content":58661,"nodeType":860},{},[58662,58665,58671],{"data":58663,"marks":58664,"value":52861,"nodeType":864},{},[],{"data":58666,"content":58667,"nodeType":883},{"uri":52864},[58668],{"data":58669,"marks":58670,"value":52869,"nodeType":864},{},[],{"data":58672,"marks":58673,"value":1774,"nodeType":864},{},[],{"data":58675,"content":58676,"nodeType":1312},{},[58677],{"data":58678,"marks":58679,"value":52880,"nodeType":864},{},[58680],{"type":899},{"data":58682,"content":58683,"nodeType":860},{},[58684],{"data":58685,"marks":58686,"value":52887,"nodeType":864},{},[],{"data":58688,"content":58691,"nodeType":996},{"target":58689},{"sys":58690},{"id":52892,"type":1001,"linkType":1002},[],{"data":58693,"content":58694,"nodeType":1005},{},[],{"data":58696,"content":58697,"nodeType":1009},{},[58698],{"data":58699,"marks":58700,"value":52904,"nodeType":864},{},[58701],{"type":899},{"data":58703,"content":58704,"nodeType":860},{},[58705],{"data":58706,"marks":58707,"value":52911,"nodeType":864},{},[],{"data":58709,"content":58710,"nodeType":860},{},[58711],{"data":58712,"marks":58713,"value":52918,"nodeType":864},{},[],{"data":58715,"content":58716,"nodeType":941},{},[58717,58737,58768,58788],{"data":58718,"content":58719,"nodeType":945},{},[58720],{"data":58721,"content":58722,"nodeType":860},{},[58723,58726,58734],{"data":58724,"marks":58725,"value":21,"nodeType":864},{},[],{"data":58727,"content":58730,"nodeType":39736},{"target":58728},{"sys":58729},{"id":52935,"type":1001,"linkType":1002},[58731],{"data":58732,"marks":58733,"value":52940,"nodeType":864},{},[],{"data":58735,"marks":58736,"value":52944,"nodeType":864},{},[],{"data":58738,"content":58739,"nodeType":945},{},[58740],{"data":58741,"content":58742,"nodeType":860},{},[58743,58746,58754,58757,58765],{"data":58744,"marks":58745,"value":52954,"nodeType":864},{},[],{"data":58747,"content":58750,"nodeType":39736},{"target":58748},{"sys":58749},{"id":52959,"type":1001,"linkType":1002},[58751],{"data":58752,"marks":58753,"value":52964,"nodeType":864},{},[],{"data":58755,"marks":58756,"value":52968,"nodeType":864},{},[],{"data":58758,"content":58761,"nodeType":39736},{"target":58759},{"sys":58760},{"id":52973,"type":1001,"linkType":1002},[58762],{"data":58763,"marks":58764,"value":52978,"nodeType":864},{},[],{"data":58766,"marks":58767,"value":52982,"nodeType":864},{},[],{"data":58769,"content":58770,"nodeType":945},{},[58771],{"data":58772,"content":58773,"nodeType":860},{},[58774,58777,58785],{"data":58775,"marks":58776,"value":52992,"nodeType":864},{},[],{"data":58778,"content":58781,"nodeType":39736},{"target":58779},{"sys":58780},{"id":52997,"type":1001,"linkType":1002},[58782],{"data":58783,"marks":58784,"value":53002,"nodeType":864},{},[],{"data":58786,"marks":58787,"value":53006,"nodeType":864},{},[],{"data":58789,"content":58790,"nodeType":945},{},[58791],{"data":58792,"content":58793,"nodeType":860},{},[58794,58797,58805],{"data":58795,"marks":58796,"value":21,"nodeType":864},{},[],{"data":58798,"content":58801,"nodeType":39736},{"target":58799},{"sys":58800},{"id":53020,"type":1001,"linkType":1002},[58802],{"data":58803,"marks":58804,"value":53025,"nodeType":864},{},[],{"data":58806,"marks":58807,"value":53029,"nodeType":864},{},[],{"data":58809,"content":58810,"nodeType":860},{},[58811],{"data":58812,"marks":58813,"value":52770,"nodeType":864},{},[],{"data":58815,"content":58816,"nodeType":1312},{},[58817],{"data":58818,"marks":58819,"value":52778,"nodeType":864},{},[58820],{"type":899},{"data":58822,"content":58823,"nodeType":860},{},[58824],{"data":58825,"marks":58826,"value":53049,"nodeType":864},{},[],{"data":58828,"content":58829,"nodeType":860},{},[58830],{"data":58831,"marks":58832,"value":53056,"nodeType":864},{},[],{"data":58834,"content":58835,"nodeType":860},{},[58836],{"data":58837,"marks":58838,"value":53063,"nodeType":864},{},[],{"data":58840,"content":58841,"nodeType":860},{},[58842],{"data":58843,"marks":58844,"value":53070,"nodeType":864},{},[],{"data":58846,"content":58847,"nodeType":1312},{},[58848],{"data":58849,"marks":58850,"value":53078,"nodeType":864},{},[58851],{"type":899},{"data":58853,"content":58854,"nodeType":860},{},[58855],{"data":58856,"marks":58857,"value":53085,"nodeType":864},{},[],{"data":58859,"content":58860,"nodeType":860},{},[58861],{"data":58862,"marks":58863,"value":53092,"nodeType":864},{},[],{"data":58865,"content":58866,"nodeType":860},{},[58867,58870,58874,58877,58881],{"data":58868,"marks":58869,"value":53099,"nodeType":864},{},[],{"data":58871,"marks":58872,"value":53104,"nodeType":864},{},[58873],{"type":899},{"data":58875,"marks":58876,"value":902,"nodeType":864},{},[],{"data":58878,"marks":58879,"value":53112,"nodeType":864},{},[58880],{"type":899},{"data":58882,"marks":58883,"value":53116,"nodeType":864},{},[],{"data":58885,"content":58888,"nodeType":996},{"target":58886},{"sys":58887},{"id":53121,"type":1001,"linkType":1002},[],{"data":58890,"content":58891,"nodeType":860},{},[58892,58895,58899],{"data":58893,"marks":58894,"value":53129,"nodeType":864},{},[],{"data":58896,"marks":58897,"value":53134,"nodeType":864},{},[58898],{"type":899},{"data":58900,"marks":58901,"value":53138,"nodeType":864},{},[],{"data":58903,"content":58904,"nodeType":860},{},[58905,58908,58912],{"data":58906,"marks":58907,"value":53129,"nodeType":864},{},[],{"data":58909,"marks":58910,"value":53149,"nodeType":864},{},[58911],{"type":899},{"data":58913,"marks":58914,"value":53153,"nodeType":864},{},[],{"data":58916,"content":58917,"nodeType":860},{},[58918,58921,58925],{"data":58919,"marks":58920,"value":53160,"nodeType":864},{},[],{"data":58922,"marks":58923,"value":1366,"nodeType":864},{},[58924],{"type":899},{"data":58926,"marks":58927,"value":53168,"nodeType":864},{},[],{"data":58929,"content":58932,"nodeType":996},{"target":58930},{"sys":58931},{"id":53173,"type":1001,"linkType":1002},[],{"data":58934,"content":58935,"nodeType":1312},{},[58936],{"data":58937,"marks":58938,"value":53182,"nodeType":864},{},[58939],{"type":899},{"data":58941,"content":58942,"nodeType":860},{},[58943],{"data":58944,"marks":58945,"value":53189,"nodeType":864},{},[],{"data":58947,"content":58948,"nodeType":1312},{},[58949],{"data":58950,"marks":58951,"value":53197,"nodeType":864},{},[58952],{"type":899},{"data":58954,"content":58955,"nodeType":860},{},[58956],{"data":58957,"marks":58958,"value":53204,"nodeType":864},{},[],{"data":58960,"content":58961,"nodeType":1005},{},[],{"data":58963,"content":58964,"nodeType":1009},{},[58965],{"data":58966,"marks":58967,"value":53215,"nodeType":864},{},[58968],{"type":899},{"data":58970,"content":58971,"nodeType":860},{},[58972],{"data":58973,"marks":58974,"value":53222,"nodeType":864},{},[],{"data":58976,"content":58977,"nodeType":860},{},[58978,58981,58985,58988,58992,58995,58999],{"data":58979,"marks":58980,"value":53229,"nodeType":864},{},[],{"data":58982,"marks":58983,"value":1334,"nodeType":864},{},[58984],{"type":899},{"data":58986,"marks":58987,"value":53237,"nodeType":864},{},[],{"data":58989,"marks":58990,"value":53112,"nodeType":864},{},[58991],{"type":899},{"data":58993,"marks":58994,"value":53245,"nodeType":864},{},[],{"data":58996,"marks":58997,"value":53250,"nodeType":864},{},[58998],{"type":899},{"data":59000,"marks":59001,"value":53254,"nodeType":864},{},[],{"data":59003,"content":59006,"nodeType":996},{"target":59004},{"sys":59005},{"id":53259,"type":1001,"linkType":1002},[],{"data":59008,"content":59009,"nodeType":860},{},[59010,59013,59017,59020,59024],{"data":59011,"marks":59012,"value":53267,"nodeType":864},{},[],{"data":59014,"marks":59015,"value":1503,"nodeType":864},{},[59016],{"type":899},{"data":59018,"marks":59019,"value":52968,"nodeType":864},{},[],{"data":59021,"marks":59022,"value":1397,"nodeType":864},{},[59023],{"type":899},{"data":59025,"marks":59026,"value":53282,"nodeType":864},{},[],{"data":59028,"content":59029,"nodeType":860},{},[59030],{"data":59031,"marks":59032,"value":53289,"nodeType":864},{},[],{"data":59034,"content":59035,"nodeType":1005},{},[],{"data":59037,"content":59038,"nodeType":1009},{},[59039],{"data":59040,"marks":59041,"value":53300,"nodeType":864},{},[59042],{"type":899},{"data":59044,"content":59045,"nodeType":860},{},[59046],{"data":59047,"marks":59048,"value":53307,"nodeType":864},{},[],{"data":59050,"content":59051,"nodeType":860},{},[59052,59055,59059],{"data":59053,"marks":59054,"value":53314,"nodeType":864},{},[],{"data":59056,"marks":59057,"value":53319,"nodeType":864},{},[59058],{"type":899},{"data":59060,"marks":59061,"value":53323,"nodeType":864},{},[],{"data":59063,"content":59066,"nodeType":996},{"target":59064},{"sys":59065},{"id":53328,"type":1001,"linkType":1002},[],{"data":59068,"content":59069,"nodeType":860},{},[59070],{"data":59071,"marks":59072,"value":53336,"nodeType":864},{},[],{"data":59074,"content":59075,"nodeType":860},{},[59076],{"data":59077,"marks":59078,"value":53343,"nodeType":864},{},[],{"data":59080,"content":59081,"nodeType":1005},{},[],{"data":59083,"content":59084,"nodeType":1009},{},[59085],{"data":59086,"marks":59087,"value":3578,"nodeType":864},{},[59088],{"type":899},{"data":59090,"content":59091,"nodeType":860},{},[59092,59095,59101],{"data":59093,"marks":59094,"value":53360,"nodeType":864},{},[],{"data":59096,"content":59097,"nodeType":883},{"uri":152},[59098],{"data":59099,"marks":59100,"value":53367,"nodeType":864},{},[],{"data":59102,"marks":59103,"value":53371,"nodeType":864},{},[],{"data":59105,"content":59106,"nodeType":860},{},[59107],{"data":59108,"marks":59109,"value":53378,"nodeType":864},{},[],{"data":59111,"content":59112,"nodeType":860},{},[59113,59116,59122,59125,59131,59134,59140],{"data":59114,"marks":59115,"value":53385,"nodeType":864},{},[],{"data":59117,"content":59118,"nodeType":883},{"uri":53388},[59119],{"data":59120,"marks":59121,"value":53393,"nodeType":864},{},[],{"data":59123,"marks":59124,"value":53397,"nodeType":864},{},[],{"data":59126,"content":59127,"nodeType":883},{"uri":53400},[59128],{"data":59129,"marks":59130,"value":53405,"nodeType":864},{},[],{"data":59132,"marks":59133,"value":53409,"nodeType":864},{},[],{"data":59135,"content":59136,"nodeType":883},{"uri":40635},[59137],{"data":59138,"marks":59139,"value":2715,"nodeType":864},{},[],{"data":59141,"marks":59142,"value":2924,"nodeType":864},{},[],{"items":59144},[59145,59147],{"sys":59146,"name":13779},{"id":13778},{"sys":59148,"name":342},{"id":13775},{"items":59150},[59151],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":59152},{"url":853},"blog/unpacking-the-vercel-breach",{"json":59155},{"data":59156,"content":59157,"nodeType":856},{},[59158],{"data":59159,"content":59160,"nodeType":860},{},[59161],{"data":59162,"marks":59163,"value":59164,"nodeType":864},{},[],"In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider. Here’s what you need to know. ",{"id":16149,"publishedAt":59166},"2026-08-12T12:01:06.679Z",{"items":59168},[59169,59171],{"sys":59170,"name":13779},{"id":13778},{"sys":59172,"name":342},{"id":13775},{"items":59174},[59175,59177,59179,59181,59183,59185,59187,59189,59191,59193,59195,59197,59199,59201,59203,59205,59207,59209,59211,59213],{"sys":59176,"name":545,"slug":546,"tier":31},{"id":542},{"sys":59178,"name":235,"slug":236,"tier":31},{"id":232},{"sys":59180,"name":413,"slug":414,"tier":31},{"id":410},{"sys":59182,"name":279,"slug":280,"tier":31},{"id":276},{"sys":59184,"name":297,"slug":298,"tier":31},{"id":294},{"sys":59186,"name":484,"slug":485,"tier":45},{"id":481},{"sys":59188,"name":580,"slug":581,"tier":45},{"id":577},{"sys":59190,"name":633,"slug":634,"tier":45},{"id":630},{"sys":59192,"name":528,"slug":529,"tier":45},{"id":525},{"sys":59194,"name":589,"slug":590,"tier":45},{"id":586},{"sys":59196,"name":422,"slug":423,"tier":45},{"id":419},{"sys":59198,"name":395,"slug":396,"tier":45},{"id":392},{"sys":59200,"name":360,"slug":361,"tier":45},{"id":357},{"sys":59202,"name":288,"slug":289,"tier":45},{"id":285},{"sys":59204,"name":333,"slug":334,"tier":45},{"id":330},{"sys":59206,"name":502,"slug":503,"tier":45},{"id":499},{"sys":59208,"name":457,"slug":458,"tier":45},{"id":454},{"sys":59210,"name":315,"slug":316,"tier":45},{"id":312},{"sys":59212,"name":440,"slug":441,"tier":45},{"id":437},{"sys":59214,"name":404,"slug":405,"tier":45},{"id":401},"7b4KOofBwc7_L33LnSIjbalheJLEQ9Kb7k3oS_lnjZk",{"id":59217,"title":59218,"authorsCollection":59219,"content":59224,"extension":228,"faqItemsCollection":59857,"faqTitle":59,"featured":6,"hashTags":59,"meta":59859,"metaTitle":59860,"ogImage":59,"postType":59861,"publishedDate":59862,"relatedBlogPostsCollection":59863,"slug":62900,"stem":62901,"subtitle":59,"summary":62902,"synopsis":62912,"sys":62913,"tagsCollection":62916,"topicsCollection":62922,"__hash__":62952},"blog/blog/browser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches.json","Browser sync attacks: Where personal account hacks lead to corporate breaches",{"items":59220},[59221],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":59222,"profilePicture":59223},[15231],{"url":2740},{"json":59225,"links":59732},{"data":59226,"content":59227,"nodeType":856},{},[59228,59246,59262,59268,59280,59287,59290,59298,59305,59312,59332,59344,59350,59362,59374,59380,59387,59394,59397,59405,59413,59444,59451,59458,59466,59485,59492,59499,59506,59513,59521,59539,59546,59553,59560,59567,59570,59578,59585,59591,59598,59601,59608,59615,59622,59628,59635,59641,59648,59654,59661,59667,59673,59679,59682,59690,59696],{"data":59229,"content":59230,"nodeType":860},{},[59231,59235,59243],{"data":59232,"marks":59233,"value":59234,"nodeType":864},{},[],"One of the breakaway stories of 2026 has been the rise in attacks powered by ",{"data":59236,"content":59237,"nodeType":883},{"uri":11825},[59238],{"data":59239,"marks":59240,"value":59242,"nodeType":864},{},[59241],{"type":1455},"malicious browser extensions",{"data":59244,"marks":59245,"value":11546,"nodeType":864},{},[],{"data":59247,"content":59248,"nodeType":860},{},[59249,59253,59258],{"data":59250,"marks":59251,"value":59252,"nodeType":864},{},[],"Most browser extension attacks are really targeting the apps your users are accessing ",{"data":59254,"marks":59255,"value":59257,"nodeType":864},{},[59256],{"type":2246},"inside",{"data":59259,"marks":59260,"value":59261,"nodeType":864},{},[]," the browser. They do this by intercepting credentials (passwords, session cookies, and so on) as you browse the internet. ",{"data":59263,"content":59267,"nodeType":996},{"target":59264},{"sys":59265},{"id":59266,"type":1001,"linkType":1002},"1nUMc1L69zkD3MmmdqbYm0",[],{"data":59269,"content":59270,"nodeType":860},{},[59271,59276],{"data":59272,"marks":59273,"value":59275,"nodeType":864},{},[59274],{"type":899},"But there’s an often overlooked vector that leads to the same outcome — synced browser profiles. ",{"data":59277,"marks":59278,"value":59279,"nodeType":864},{},[],"And the most dangerous part of this attack is that it often stems from personal device compromises — naturally, outside the scope of your corporate security software. ",{"data":59281,"content":59282,"nodeType":860},{},[59283],{"data":59284,"marks":59285,"value":59286,"nodeType":864},{},[],"Sign into Chrome or Edge with a Google or Microsoft account, and your passwords, bookmarks, history, and extensions follow you seamlessly across every device. For individual users, it's a quality-of-life improvement. But for organizations, it links corporate accounts to personal ones with far weaker security controls. ",{"data":59288,"content":59289,"nodeType":1005},{},[],{"data":59291,"content":59292,"nodeType":1009},{},[59293],{"data":59294,"marks":59295,"value":59297,"nodeType":864},{},[59296],{"type":899},"How browser sync attacks work",{"data":59299,"content":59300,"nodeType":860},{},[59301],{"data":59302,"marks":59303,"value":59304,"nodeType":864},{},[],"When an employee signs into a personal browser profile on a work device (or saves work credentials on a personal device), the browser's sync mechanism copies those credentials into a cloud account outside the organization's control. That cloud account — typically a personal Google or Microsoft account — becomes the weakest link in the chain.",{"data":59306,"content":59307,"nodeType":860},{},[59308],{"data":59309,"marks":59310,"value":59311,"nodeType":864},{},[],"The typical sequence looks like this:",{"data":59313,"content":59314,"nodeType":860},{},[59315,59320,59324,59328],{"data":59316,"marks":59317,"value":59319,"nodeType":864},{},[59318],{"type":899},"An employee signs into Chrome with their personal Google account on a corporate laptop. ",{"data":59321,"marks":59322,"value":59323,"nodeType":864},{},[],"During the course of their work, the browser prompts them to save passwords — for a VPN, an internal tool, a support system, a cloud platform. They click \"Save.\" The credential is now stored locally in the browser ",{"data":59325,"marks":59326,"value":46919,"nodeType":864},{},[59327],{"type":2246},{"data":59329,"marks":59330,"value":59331,"nodeType":864},{},[]," synced to their personal Google account in the cloud.",{"data":59333,"content":59334,"nodeType":860},{},[59335,59340],{"data":59336,"marks":59337,"value":59339,"nodeType":864},{},[59338],{"type":899},"The personal account is compromised. ",{"data":59341,"marks":59342,"value":59343,"nodeType":864},{},[],"This can happen in a lot of ways, and is made easier by the less secure nature of personal accounts. They are typically accessed from devices with less or no security protection, while MFA and other identity-layer controls are less common. Once the personal device or account is breached, every synced password — including corporate ones — is in the hands of the attacker. ",{"data":59345,"content":59349,"nodeType":996},{"target":59346},{"sys":59347},{"id":59348,"type":1001,"linkType":1002},"2GQ4TVJQWS9VJB5W6fBeLS",[],{"data":59351,"content":59352,"nodeType":860},{},[59353,59358],{"data":59354,"marks":59355,"value":59357,"nodeType":864},{},[59356],{"type":899},"With the harvested corporate credentials, the attacker authenticates to the organization's systems.",{"data":59359,"marks":59360,"value":59361,"nodeType":864},{},[]," If MFA is absent or bypassable (via fatigue attacks, social engineering, or session token reuse), they're in.",{"data":59363,"content":59364,"nodeType":860},{},[59365,59370],{"data":59366,"marks":59367,"value":59369,"nodeType":864},{},[59368],{"type":899},"From here, it's a conventional intrusion — privilege escalation, reconnaissance, and exfiltration. ",{"data":59371,"marks":59372,"value":59373,"nodeType":864},{},[],"But the initial access was entirely outside the defender's visibility. No phishing email hit the corporate mail gateway. No exploit was fired at a corporate asset. The compromise happened in a personal context that security teams had no control over.",{"data":59375,"content":59379,"nodeType":996},{"target":59376},{"sys":59377},{"id":59378,"type":1001,"linkType":1002},"5llxwUFxBOjuXTyr5LXOyy",[],{"data":59381,"content":59382,"nodeType":860},{},[59383],{"data":59384,"marks":59385,"value":59386,"nodeType":864},{},[],"What makes this attack so effective is that it entirely bypasses the corporate security stack. Endpoint detection, email filtering, network monitoring — none of it sees the initial compromise because it happens on a personal device or in a personal cloud account.",{"data":59388,"content":59389,"nodeType":860},{},[59390],{"data":59391,"marks":59392,"value":59393,"nodeType":864},{},[],"The scope isn’t limited to “personal” devices either. BYOD and contractor machines suffer from the same security limitations in that they are a place where personal and corporate use converges, and/or they sit outside of the scope of your security tooling. ",{"data":59395,"content":59396,"nodeType":1005},{},[],{"data":59398,"content":59399,"nodeType":1009},{},[59400],{"data":59401,"marks":59402,"value":59404,"nodeType":864},{},[59403],{"type":899},"Real-world incidents",{"data":59406,"content":59407,"nodeType":1312},{},[59408],{"data":59409,"marks":59410,"value":59412,"nodeType":864},{},[59411],{"type":899},"Cisco (2022)",{"data":59414,"content":59415,"nodeType":860},{},[59416,59419,59428,59432,59440],{"data":59417,"marks":59418,"value":21,"nodeType":864},{},[],{"data":59420,"content":59422,"nodeType":883},{"uri":59421},"https://thehackernews.com/2022/08/cisco-confirms-its-been-hacked-by.html",[59423],{"data":59424,"marks":59425,"value":59427,"nodeType":864},{},[59426],{"type":1455},"Cisco",{"data":59429,"marks":59430,"value":59431,"nodeType":864},{},[]," was breached by an initial access broker with ties to the Yanluowang ransomware group, UNC2447, and the ",{"data":59433,"content":59434,"nodeType":883},{"uri":16015},[59435],{"data":59436,"marks":59437,"value":59439,"nodeType":864},{},[59438],{"type":1455},"Lapsus$",{"data":59441,"marks":59442,"value":59443,"nodeType":864},{},[]," threat actor group. ",{"data":59445,"content":59446,"nodeType":860},{},[59447],{"data":59448,"marks":59449,"value":59450,"nodeType":864},{},[],"A Cisco employee had enabled Chrome's password syncing feature and had stored their Cisco VPN credentials in the browser. Those credentials were synchronized to their personal Google account. The attacker compromised the personal Google account, obtained the VPN credentials, and then used a combination of voice phishing and MFA fatigue — repeatedly sending push notifications until the employee accepted one — to bypass multi-factor authentication and gain VPN access.",{"data":59452,"content":59453,"nodeType":860},{},[59454],{"data":59455,"marks":59456,"value":59457,"nodeType":864},{},[],"Once inside the network, the attacker escalated privileges, moved laterally to Citrix servers and domain controllers, and deployed offensive tooling consistent with pre-ransomware activity. Cisco's security team ultimately detected and removed the attacker before ransomware was deployed, but the adversary made repeated attempts to regain access in the following weeks, including targeting accounts where employees had only made single-character password changes after the company-wide reset.",{"data":59459,"content":59460,"nodeType":1312},{},[59461],{"data":59462,"marks":59463,"value":59465,"nodeType":864},{},[59464],{"type":899},"Okta (2023)",{"data":59467,"content":59468,"nodeType":860},{},[59469,59472,59481],{"data":59470,"marks":59471,"value":2761,"nodeType":864},{},[],{"data":59473,"content":59475,"nodeType":883},{"uri":59474},"https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/",[59476],{"data":59477,"marks":59478,"value":59480,"nodeType":864},{},[59479],{"type":1455},"Okta breach",{"data":59482,"marks":59483,"value":59484,"nodeType":864},{},[]," followed an almost identical pattern to Cisco, but with more severe downstream consequences.",{"data":59486,"content":59487,"nodeType":860},{},[59488],{"data":59489,"marks":59490,"value":59491,"nodeType":864},{},[],"Between September 28 and October 17, 2023, an attacker gained unauthorized access to Okta's customer support case management system. The root cause: an Okta employee had signed into their personal Google profile on Chrome on their Okta-managed laptop. While signed into that personal profile, they accessed a service account for the support system. The service account's username and password were saved by Chrome and synced to the employee's personal Google account.",{"data":59493,"content":59494,"nodeType":860},{},[59495],{"data":59496,"marks":59497,"value":59498,"nodeType":864},{},[],"The attacker — having compromised either the personal Google account or a personal device — obtained these service account credentials and used them to access the support system. The compromised service account had permissions to view and update customer support cases, which contained HAR (HTTP Archive) files uploaded by customers for troubleshooting. Some of these HAR files contained session tokens.",{"data":59500,"content":59501,"nodeType":860},{},[59502],{"data":59503,"marks":59504,"value":59505,"nodeType":864},{},[],"The attacker used the stolen session tokens to hijack the legitimate Okta sessions of five customers, including 1Password, BeyondTrust, and Cloudflare — three security companies that independently detected the suspicious activity and reported it to Okta. In total, files associated with 134 Okta customers were accessed.",{"data":59507,"content":59508,"nodeType":860},{},[59509],{"data":59510,"marks":59511,"value":59512,"nodeType":864},{},[],"What made this breach particularly notable was the detection gap. Okta's security team was unable to identify suspicious file downloads in their logs for 14 days. The attacker navigated directly to the Files tab in the support system rather than opening files through individual support cases, which generated a different log event type that wasn't part of the initial investigation scope. It wasn't until BeyondTrust provided a suspicious IP address on October 13 that Okta was able to correlate the activity.",{"data":59514,"content":59515,"nodeType":1312},{},[59516],{"data":59517,"marks":59518,"value":59520,"nodeType":864},{},[59519],{"type":899},"Snowflake (customers) (2024)",{"data":59522,"content":59523,"nodeType":860},{},[59524,59527,59535],{"data":59525,"marks":59526,"value":2761,"nodeType":864},{},[],{"data":59528,"content":59529,"nodeType":883},{"uri":3751},[59530],{"data":59531,"marks":59532,"value":59534,"nodeType":864},{},[59533],{"type":1455},"Snowflake campaign",{"data":59536,"marks":59537,"value":59538,"nodeType":864},{},[]," represents what happens when the browser-credential-sync problem meets infostealer malware at scale. ",{"data":59540,"content":59541,"nodeType":860},{},[59542],{"data":59543,"marks":59544,"value":59545,"nodeType":864},{},[],"In 2024, a financially motivated threat actor tracked as UNC5537 (associated with the ShinyHunters group) systematically compromised approximately 165 Snowflake customer environments. The attackers didn't exploit any vulnerability in Snowflake itself. They logged in with valid credentials.",{"data":59547,"content":59548,"nodeType":860},{},[59549],{"data":59550,"marks":59551,"value":59552,"nodeType":864},{},[],"Those credentials had been harvested by infostealer malware — including Vidar, RedLine, Lumma, RisePro, Raccoon Stealer, and MetaStealer — from employee and contractor devices over a period stretching back to 2020. Mandiant's investigation found that over 80% of the compromised accounts had prior credential exposure, and critically, the stolen credentials had never been rotated.",{"data":59554,"content":59555,"nodeType":860},{},[59556],{"data":59557,"marks":59558,"value":59559,"nodeType":864},{},[],"The personal/corporate boundary failure was central to the campaign. Mandiant specifically noted that in several cases, the initial infostealer infections occurred on contractor systems that were also used for personal activities, including gaming and downloads of pirated software. These were personal or unmonitored laptops where corporate credentials had been saved in the browser alongside everything else.",{"data":59561,"content":59562,"nodeType":860},{},[59563],{"data":59564,"marks":59565,"value":59566,"nodeType":864},{},[],"The impacted Snowflake accounts lacked MFA (which Snowflake did not enforce by default at the time), and the attackers used a custom tool to automate SQL-based reconnaissance and data exfiltration across customer instances. The stolen data encompassed hundreds of millions of customer records, and at least one victim paid an undisclosed ransom.",{"data":59568,"content":59569,"nodeType":1005},{},[],{"data":59571,"content":59572,"nodeType":1009},{},[59573],{"data":59574,"marks":59575,"value":59577,"nodeType":864},{},[59576],{"type":899},"What security teams can do about it",{"data":59579,"content":59580,"nodeType":860},{},[59581],{"data":59582,"marks":59583,"value":59584,"nodeType":864},{},[],"Chrome Enterprise and Microsoft Edge for Business both support policies that prevent employees from signing into personal accounts on corporate-managed browsers. This is the most direct control. It doesn't prevent all credential leakage scenarios, but it closes the sync-to-personal-cloud path.",{"data":59586,"content":59590,"nodeType":996},{"target":59587},{"sys":59588},{"id":59589,"type":1001,"linkType":1002},"CmrOdYVVW6wz9kdRqxOmX",[],{"data":59592,"content":59593,"nodeType":860},{},[59594],{"data":59595,"marks":59596,"value":59597,"nodeType":864},{},[],"Every incident described above was enabled or worsened by the absence of MFA on the target system. MFA should be mandatory for all human user accounts, and organizations should audit for \"ghost logins\" — local username/password accounts that persist alongside SSO and bypass its MFA enforcement.",{"data":59599,"content":59600,"nodeType":1005},{},[],{"data":59602,"content":59603,"nodeType":1009},{},[59604],{"data":59605,"marks":59606,"value":7533,"nodeType":864},{},[59607],{"type":899},{"data":59609,"content":59610,"nodeType":860},{},[59611],{"data":59612,"marks":59613,"value":59614,"nodeType":864},{},[],"Push makes browser security easier than ever, particularly when dealing with complex environments running different browsers and operating systems. ",{"data":59616,"content":59617,"nodeType":860},{},[59618],{"data":59619,"marks":59620,"value":59621,"nodeType":864},{},[],"You can use Push to surface which users are logged into their browser using a non-work profile and whether the profile is synced across devices. Push captures this information for every browser that your employees are using, including Chrome, Edge, Firefox, Safari, Brave, Opera, Arc, Island, and Prisma (and we’re always adding support for new ones). ",{"data":59623,"content":59627,"nodeType":996},{"target":59624},{"sys":59625},{"id":59626,"type":1001,"linkType":1002},"67sSoSW136TeBZzYIEXggP",[],{"data":59629,"content":59630,"nodeType":860},{},[59631],{"data":59632,"marks":59633,"value":59634,"nodeType":864},{},[],"Sync attacks can impact both saved credentials and browser extensions. This means that even if your employees aren’t saving credentials to their browser profile, you can still be at risk if they’ve installed any extensions in another browser where they’re signed in. ",{"data":59636,"content":59640,"nodeType":996},{"target":59637},{"sys":59638},{"id":59639,"type":1001,"linkType":1002},"1MzuYaPlUpYfTnBJRqUBtO",[],{"data":59642,"content":59643,"nodeType":860},{},[59644],{"data":59645,"marks":59646,"value":59647,"nodeType":864},{},[],"You can use Push to identify where credentials are being saved — for example, are employees using your company-approved password manager, or copying credentials from unsanctioned apps or locations? This includes where users are manually copying passwords from a password manager app rather than auto-populating (this increases the chance of them entering these passwords into phishing pages).",{"data":59649,"content":59653,"nodeType":996},{"target":59650},{"sys":59651},{"id":59652,"type":1001,"linkType":1002},"7gNX2RXqB2NIf1tNnJBIFD",[],{"data":59655,"content":59656,"nodeType":860},{},[59657],{"data":59658,"marks":59659,"value":59660,"nodeType":864},{},[],"You can also see where those credentials have a vulnerability, such as a weak, breached, or reused password. In this scenario, we’re looking for credentials that have been leaked online, where an employee is signed into their work browser with a personal account, and profile sync is enabled. This could indicate that the user has been the victim of an infostealer compromise or malicious extension on their personal device.",{"data":59662,"content":59666,"nodeType":996},{"target":59663},{"sys":59664},{"id":59665,"type":1001,"linkType":1002},"1CBezYXZtlIVbReROF7QpK",[],{"data":59668,"content":59672,"nodeType":996},{"target":59669},{"sys":59670},{"id":59671,"type":1001,"linkType":1002},"4xs0WNCijnwnIVc0xqpUu9",[],{"data":59674,"content":59678,"nodeType":996},{"target":59675},{"sys":59676},{"id":59677,"type":1001,"linkType":1002},"8gVeg0IBB5EV17iBk6XP8",[],{"data":59680,"content":59681,"nodeType":1005},{},[],{"data":59683,"content":59684,"nodeType":1009},{},[59685],{"data":59686,"marks":59687,"value":59689,"nodeType":864},{},[59688],{"type":899},"Stop browser-based attacks with Push",{"data":59691,"content":59692,"nodeType":860},{},[59693],{"data":59694,"marks":59695,"value":22260,"nodeType":864},{},[],{"data":59697,"content":59698,"nodeType":860},{},[59699,59702,59709,59712,59719,59722,59729],{"data":59700,"marks":59701,"value":16863,"nodeType":864},{},[],{"data":59703,"content":59704,"nodeType":883},{"uri":16866},[59705],{"data":59706,"marks":59707,"value":16871,"nodeType":864},{},[59708],{"type":1455},{"data":59710,"marks":59711,"value":3731,"nodeType":864},{},[],{"data":59713,"content":59714,"nodeType":883},{"uri":16877},[59715],{"data":59716,"marks":59717,"value":16883,"nodeType":864},{},[59718],{"type":1455},{"data":59720,"marks":59721,"value":16887,"nodeType":864},{},[],{"data":59723,"content":59724,"nodeType":883},{"uri":1700},[59725],{"data":59726,"marks":59727,"value":16894,"nodeType":864},{},[59728],{"type":1455},{"data":59730,"marks":59731,"value":2924,"nodeType":864},{},[],{"entries":59733},{"hyperlink":59734,"inline":59735,"block":59736},[],[],[59737,59751,59770,59778,59785,59792,59818,59824,59829,59853],{"sys":59738,"__typename":1740,"content":59739,"name":59750,"title":59},{"id":59266},{"json":59740},{"data":59741,"content":59742,"nodeType":856},{},[59743],{"data":59744,"content":59745,"nodeType":860},{},[59746],{"data":59747,"marks":59748,"value":59749,"nodeType":864},{},[],"This is the same for most browser-based attacks, like phishing (of multiple varieties, with AITM phishing and device code phishing being the most common in 2026), and even hybrid attacks like ClickFix (trick victim into installing an infostealer on their device > steal credentials and cookies > log into apps). ","Browser Sync Blog IB1",{"sys":59752,"__typename":1740,"content":59753,"name":59769,"title":59},{"id":59348},{"json":59754},{"nodeType":856,"data":59755,"content":59756},{},[59757],{"nodeType":860,"data":59758,"content":59759},{},[59760,59764],{"nodeType":864,"value":59761,"marks":59762,"data":59763},"Personal devices are far softer targets than corporate endpoints. They typically have no EDR agent, no centrally managed antivirus, no hardened configuration baselines, and no security operations team watching for alerts. And personal browsing habits are way more likely to lead to infostealer deployment, which are often distributed through malicious advertisements on all manner of platforms — search results, social media ads, gaming forums, and so on. ",[],{},{"nodeType":864,"value":59765,"marks":59766,"data":59768},"Notably, the 2025 Verizon DBIR found that 46% of infostealer-infected systems with compromised corporate credentials were non-managed devices. ",[59767],{"type":899},{},"Browser Sync Blog IB2",{"sys":59771,"__typename":1724,"title":59772,"caption":59773,"layoutMode":59,"file":59774},{"id":59378},"Browser sync attack diagram","How a personal account compromise can lead to a corporate breach.",{"url":59775,"width":59776,"height":59777},"https://images.ctfassets.net/y1cdw1ablpvd/7KIXnq2SeCTN2zA7DoIOj4/f2b7c37c47d28ac110cd2769c35652ae/Browser_sync_attack_diagram.png",3922,1636,{"sys":59779,"__typename":1724,"title":59780,"caption":59781,"layoutMode":59,"file":59782},{"id":59589},"Preventing browser profile syncing in Chrome","Preventing browser profile syncing in Chrome.",{"url":59783,"width":1736,"height":59784},"https://images.ctfassets.net/y1cdw1ablpvd/54OsAScfL5a896m3n0is80/ee84ec32221be0a6342eb6792c8b6dca/image1.png",1054,{"sys":59786,"__typename":1724,"title":59787,"caption":59787,"layoutMode":59,"file":59788},{"id":59626},"Identify profile syncing using Push.",{"url":59789,"width":59790,"height":59791},"https://images.ctfassets.net/y1cdw1ablpvd/7Gmo7lSxoyLpmRyeEbXz4H/10e82ddfcba7a390ee5a25c931f730ff/image3.png",1380,465,{"sys":59793,"__typename":1740,"content":59794,"name":59817,"title":59},{"id":59639},{"json":59795},{"data":59796,"content":59797,"nodeType":856},{},[59798],{"data":59799,"content":59800,"nodeType":860},{},[59801,59805,59813],{"data":59802,"marks":59803,"value":59804,"nodeType":864},{},[],"To learn more about how you can use Push to lock down extension use and block malicious extensions from running across every browser, check out our ",{"data":59806,"content":59807,"nodeType":883},{"uri":11825},[59808],{"data":59809,"marks":59810,"value":59812,"nodeType":864},{},[59811],{"type":1455},"guide",{"data":59814,"marks":59815,"value":59816,"nodeType":864},{},[]," here. ","Browser Sync Blog IB3",{"sys":59819,"__typename":1724,"title":59820,"caption":59821,"layoutMode":59,"file":59822},{"id":59652},"Get detailed visibility of password manager use and password entry behavior.","Get deep visibility of password manager use and password entry behavior.",{"url":59823,"width":45755,"height":45756},"https://images.ctfassets.net/y1cdw1ablpvd/74hJdhrMBMXv0enE2Qs5VD/2cdff9be14f70d2ae2283b88da0f3eeb/Push_Password_Manager.gif",{"sys":59825,"__typename":1724,"title":59826,"caption":59826,"layoutMode":59,"file":59827},{"id":59665},"Identify browser profile syncing and whether the user has active credentials that have been leaked online.",{"url":59828,"width":45755,"height":45756},"https://images.ctfassets.net/y1cdw1ablpvd/3BIn8peNvp8EXo1TWqZqXO/0c3f849f24d60fa546603d12abd4c349/Browser_Profile_Sync.gif",{"sys":59830,"__typename":1740,"content":59831,"name":59852,"title":59},{"id":59671},{"json":59832},{"data":59833,"content":59834,"nodeType":856},{},[59835],{"data":59836,"content":59837,"nodeType":860},{},[59838,59842,59849],{"data":59839,"marks":59840,"value":59841,"nodeType":864},{},[],"As well as identifying password vulnerabilities, you can also use Push to harden accounts by detecting MFA gaps and enforcing MFA (even on apps where this isn’t natively possible). Check out our ",{"data":59843,"content":59844,"nodeType":883},{"uri":24926},[59845],{"data":59846,"marks":59847,"value":59812,"nodeType":864},{},[59848],{"type":1455},{"data":59850,"marks":59851,"value":24191,"nodeType":864},{},[],"Browser Sync Blog IB4",{"sys":59854,"__typename":12999,"title":59855,"arcadeDemoUrl":59856,"playText":13002},{"id":59677},"Find and fix vulnerabilities using Push to harden attack paths.","https://demo.arcade.software/3gsvKeVcdatDBiW7oC9g?embed",{"items":59858},[],{},"Analyzing browser sync attacks and how to stop them","threat-research","2026-04-15T00:00:00.000Z",{"items":59864},[59865,61039,62095],{"__typename":2059,"sys":59866,"content":59867,"title":53419,"synopsis":53420,"hashTags":59,"publishedDate":53421,"slug":53422,"tagsCollection":61029,"authorsCollection":61035},{"id":52075},{"json":59868},{"data":59869,"content":59870,"nodeType":856},{},[59871,59877,59898,59904,59909,59915,59921,59927,59932,59935,59942,59948,59953,59958,59971,60152,60162,60169,60175,60181,60187,60203,60208,60214,60217,60224,60230,60259,60265,60278,60295,60323,60328,60334,60349,60355,60361,60364,60371,60377,60460,60466,60472,60479,60485,60491,60497,60502,60509,60515,60521,60527,60532,60538,60545,60560,60567,60573,60578,60581,60588,60594,60600,60694,60700,60707,60713,60719,60725,60731,60738,60744,60750,60770,60775,60788,60801,60814,60819,60826,60832,60839,60845,60848,60855,60861,60888,60893,60913,60919,60922,60929,60935,60948,60953,60959,60965,60968,60975,60990,60996],{"data":59872,"content":59873,"nodeType":860},{},[59874],{"data":59875,"marks":59876,"value":52086,"nodeType":864},{},[],{"data":59878,"content":59879,"nodeType":941},{},[59880,59889],{"data":59881,"content":59882,"nodeType":945},{},[59883],{"data":59884,"content":59885,"nodeType":860},{},[59886],{"data":59887,"marks":59888,"value":52099,"nodeType":864},{},[],{"data":59890,"content":59891,"nodeType":945},{},[59892],{"data":59893,"content":59894,"nodeType":860},{},[59895],{"data":59896,"marks":59897,"value":52109,"nodeType":864},{},[],{"data":59899,"content":59900,"nodeType":860},{},[59901],{"data":59902,"marks":59903,"value":52116,"nodeType":864},{},[],{"data":59905,"content":59908,"nodeType":996},{"target":59906},{"sys":59907},{"id":52121,"type":1001,"linkType":1002},[],{"data":59910,"content":59911,"nodeType":860},{},[59912],{"data":59913,"marks":59914,"value":52129,"nodeType":864},{},[],{"data":59916,"content":59917,"nodeType":860},{},[59918],{"data":59919,"marks":59920,"value":52136,"nodeType":864},{},[],{"data":59922,"content":59923,"nodeType":860},{},[59924],{"data":59925,"marks":59926,"value":52143,"nodeType":864},{},[],{"data":59928,"content":59931,"nodeType":996},{"target":59929},{"sys":59930},{"id":52148,"type":1001,"linkType":1002},[],{"data":59933,"content":59934,"nodeType":1005},{},[],{"data":59936,"content":59937,"nodeType":1009},{},[59938],{"data":59939,"marks":59940,"value":52160,"nodeType":864},{},[59941],{"type":899},{"data":59943,"content":59944,"nodeType":860},{},[59945],{"data":59946,"marks":59947,"value":52167,"nodeType":864},{},[],{"data":59949,"content":59952,"nodeType":996},{"target":59950},{"sys":59951},{"id":52172,"type":1001,"linkType":1002},[],{"data":59954,"content":59957,"nodeType":996},{"target":59955},{"sys":59956},{"id":52178,"type":1001,"linkType":1002},[],{"data":59959,"content":59960,"nodeType":860},{},[59961,59964,59968],{"data":59962,"marks":59963,"value":52186,"nodeType":864},{},[],{"data":59965,"marks":59966,"value":52191,"nodeType":864},{},[59967],{"type":2246},{"data":59969,"marks":59970,"value":52195,"nodeType":864},{},[],{"data":59972,"content":59973,"nodeType":4845},{},[59974,59997,60032,60053,60083,60113],{"data":59975,"content":59976,"nodeType":4581},{},[59977,59987],{"data":59978,"content":59979,"nodeType":14464},{},[59980],{"data":59981,"content":59982,"nodeType":860},{},[59983],{"data":59984,"marks":59985,"value":52212,"nodeType":864},{},[59986],{"type":899},{"data":59988,"content":59989,"nodeType":14464},{},[59990],{"data":59991,"content":59992,"nodeType":860},{},[59993],{"data":59994,"marks":59995,"value":52223,"nodeType":864},{},[59996],{"type":899},{"data":59998,"content":59999,"nodeType":4581},{},[60000,60020],{"data":60001,"content":60002,"nodeType":4569},{},[60003],{"data":60004,"content":60005,"nodeType":860},{},[60006,60009,60017],{"data":60007,"marks":60008,"value":52236,"nodeType":864},{},[],{"data":60010,"content":60013,"nodeType":39736},{"target":60011},{"sys":60012},{"id":39958,"type":1001,"linkType":1002},[60014],{"data":60015,"marks":60016,"value":52245,"nodeType":864},{},[],{"data":60018,"marks":60019,"value":52249,"nodeType":864},{},[],{"data":60021,"content":60022,"nodeType":4569},{},[60023],{"data":60024,"content":60025,"nodeType":860},{},[60026,60029],{"data":60027,"marks":60028,"value":52259,"nodeType":864},{},[],{"data":60030,"marks":60031,"value":52263,"nodeType":864},{},[],{"data":60033,"content":60034,"nodeType":4581},{},[60035,60044],{"data":60036,"content":60037,"nodeType":4569},{},[60038],{"data":60039,"content":60040,"nodeType":860},{},[60041],{"data":60042,"marks":60043,"value":52276,"nodeType":864},{},[],{"data":60045,"content":60046,"nodeType":4569},{},[60047],{"data":60048,"content":60049,"nodeType":860},{},[60050],{"data":60051,"marks":60052,"value":52286,"nodeType":864},{},[],{"data":60054,"content":60055,"nodeType":4581},{},[60056,60074],{"data":60057,"content":60058,"nodeType":4569},{},[60059],{"data":60060,"content":60061,"nodeType":860},{},[60062,60065,60071],{"data":60063,"marks":60064,"value":52299,"nodeType":864},{},[],{"data":60066,"content":60067,"nodeType":883},{"uri":52302},[60068],{"data":60069,"marks":60070,"value":52307,"nodeType":864},{},[],{"data":60072,"marks":60073,"value":14316,"nodeType":864},{},[],{"data":60075,"content":60076,"nodeType":4569},{},[60077],{"data":60078,"content":60079,"nodeType":860},{},[60080],{"data":60081,"marks":60082,"value":52320,"nodeType":864},{},[],{"data":60084,"content":60085,"nodeType":4581},{},[60086,60095],{"data":60087,"content":60088,"nodeType":4569},{},[60089],{"data":60090,"content":60091,"nodeType":860},{},[60092],{"data":60093,"marks":60094,"value":52333,"nodeType":864},{},[],{"data":60096,"content":60097,"nodeType":4569},{},[60098],{"data":60099,"content":60100,"nodeType":860},{},[60101,60104,60110],{"data":60102,"marks":60103,"value":52343,"nodeType":864},{},[],{"data":60105,"content":60106,"nodeType":883},{"uri":3259},[60107],{"data":60108,"marks":60109,"value":18962,"nodeType":864},{},[],{"data":60111,"marks":60112,"value":2924,"nodeType":864},{},[],{"data":60114,"content":60115,"nodeType":4581},{},[60116,60125],{"data":60117,"content":60118,"nodeType":4569},{},[60119],{"data":60120,"content":60121,"nodeType":860},{},[60122],{"data":60123,"marks":60124,"value":52365,"nodeType":864},{},[],{"data":60126,"content":60127,"nodeType":4569},{},[60128],{"data":60129,"content":60130,"nodeType":860},{},[60131,60134,60140,60143,60149],{"data":60132,"marks":60133,"value":21,"nodeType":864},{},[],{"data":60135,"content":60136,"nodeType":883},{"uri":52377},[60137],{"data":60138,"marks":60139,"value":315,"nodeType":864},{},[],{"data":60141,"marks":60142,"value":52385,"nodeType":864},{},[],{"data":60144,"content":60145,"nodeType":883},{"uri":11726},[60146],{"data":60147,"marks":60148,"value":11731,"nodeType":864},{},[],{"data":60150,"marks":60151,"value":52395,"nodeType":864},{},[],{"data":60153,"content":60154,"nodeType":860},{},[60155,60158],{"data":60156,"marks":60157,"value":52402,"nodeType":864},{},[],{"data":60159,"marks":60160,"value":52407,"nodeType":864},{},[60161],{"type":899},{"data":60163,"content":60164,"nodeType":1312},{},[60165],{"data":60166,"marks":60167,"value":52415,"nodeType":864},{},[60168],{"type":899},{"data":60170,"content":60171,"nodeType":860},{},[60172],{"data":60173,"marks":60174,"value":52422,"nodeType":864},{},[],{"data":60176,"content":60177,"nodeType":860},{},[60178],{"data":60179,"marks":60180,"value":52429,"nodeType":864},{},[],{"data":60182,"content":60183,"nodeType":860},{},[60184],{"data":60185,"marks":60186,"value":52436,"nodeType":864},{},[],{"data":60188,"content":60189,"nodeType":860},{},[60190,60193,60196,60200],{"data":60191,"marks":60192,"value":52443,"nodeType":864},{},[],{"data":60194,"marks":60195,"value":52447,"nodeType":864},{},[],{"data":60197,"marks":60198,"value":52452,"nodeType":864},{},[60199],{"type":899},{"data":60201,"marks":60202,"value":52456,"nodeType":864},{},[],{"data":60204,"content":60207,"nodeType":996},{"target":60205},{"sys":60206},{"id":52461,"type":1001,"linkType":1002},[],{"data":60209,"content":60210,"nodeType":860},{},[60211],{"data":60212,"marks":60213,"value":52469,"nodeType":864},{},[],{"data":60215,"content":60216,"nodeType":1005},{},[],{"data":60218,"content":60219,"nodeType":1009},{},[60220],{"data":60221,"marks":60222,"value":52480,"nodeType":864},{},[60223],{"type":899},{"data":60225,"content":60226,"nodeType":860},{},[60227],{"data":60228,"marks":60229,"value":52487,"nodeType":864},{},[],{"data":60231,"content":60232,"nodeType":941},{},[60233,60246],{"data":60234,"content":60235,"nodeType":945},{},[60236],{"data":60237,"content":60238,"nodeType":860},{},[60239,60243],{"data":60240,"marks":60241,"value":52501,"nodeType":864},{},[60242],{"type":899},{"data":60244,"marks":60245,"value":52505,"nodeType":864},{},[],{"data":60247,"content":60248,"nodeType":945},{},[60249],{"data":60250,"content":60251,"nodeType":860},{},[60252,60256],{"data":60253,"marks":60254,"value":52516,"nodeType":864},{},[60255],{"type":899},{"data":60257,"marks":60258,"value":52520,"nodeType":864},{},[],{"data":60260,"content":60261,"nodeType":1312},{},[60262],{"data":60263,"marks":60264,"value":52527,"nodeType":864},{},[],{"data":60266,"content":60267,"nodeType":860},{},[60268,60271,60275],{"data":60269,"marks":60270,"value":52534,"nodeType":864},{},[],{"data":60272,"marks":60273,"value":52539,"nodeType":864},{},[60274],{"type":2246},{"data":60276,"marks":60277,"value":52543,"nodeType":864},{},[],{"data":60279,"content":60280,"nodeType":860},{},[60281,60284,60292],{"data":60282,"marks":60283,"value":52550,"nodeType":864},{},[],{"data":60285,"content":60288,"nodeType":39736},{"target":60286},{"sys":60287},{"id":52555,"type":1001,"linkType":1002},[60289],{"data":60290,"marks":60291,"value":52560,"nodeType":864},{},[],{"data":60293,"marks":60294,"value":52564,"nodeType":864},{},[],{"data":60296,"content":60297,"nodeType":860},{},[60298,60301,60309,60312,60320],{"data":60299,"marks":60300,"value":52571,"nodeType":864},{},[],{"data":60302,"content":60305,"nodeType":39736},{"target":60303},{"sys":60304},{"id":52576,"type":1001,"linkType":1002},[60306],{"data":60307,"marks":60308,"value":52581,"nodeType":864},{},[],{"data":60310,"marks":60311,"value":52585,"nodeType":864},{},[],{"data":60313,"content":60316,"nodeType":39736},{"target":60314},{"sys":60315},{"id":52590,"type":1001,"linkType":1002},[60317],{"data":60318,"marks":60319,"value":52595,"nodeType":864},{},[],{"data":60321,"marks":60322,"value":52599,"nodeType":864},{},[],{"data":60324,"content":60327,"nodeType":996},{"target":60325},{"sys":60326},{"id":52604,"type":1001,"linkType":1002},[],{"data":60329,"content":60330,"nodeType":1312},{},[60331],{"data":60332,"marks":60333,"value":52612,"nodeType":864},{},[],{"data":60335,"content":60336,"nodeType":860},{},[60337,60340,60346],{"data":60338,"marks":60339,"value":52619,"nodeType":864},{},[],{"data":60341,"content":60342,"nodeType":883},{"uri":52622},[60343],{"data":60344,"marks":60345,"value":52627,"nodeType":864},{},[],{"data":60347,"marks":60348,"value":52631,"nodeType":864},{},[],{"data":60350,"content":60351,"nodeType":860},{},[60352],{"data":60353,"marks":60354,"value":52638,"nodeType":864},{},[],{"data":60356,"content":60357,"nodeType":860},{},[60358],{"data":60359,"marks":60360,"value":52645,"nodeType":864},{},[],{"data":60362,"content":60363,"nodeType":1005},{},[],{"data":60365,"content":60366,"nodeType":1009},{},[60367],{"data":60368,"marks":60369,"value":52656,"nodeType":864},{},[60370],{"type":899},{"data":60372,"content":60373,"nodeType":860},{},[60374],{"data":60375,"marks":60376,"value":52663,"nodeType":864},{},[],{"data":60378,"content":60379,"nodeType":941},{},[60380,60400,60420,60440],{"data":60381,"content":60382,"nodeType":945},{},[60383],{"data":60384,"content":60385,"nodeType":860},{},[60386,60389,60397],{"data":60387,"marks":60388,"value":21,"nodeType":864},{},[],{"data":60390,"content":60393,"nodeType":39736},{"target":60391},{"sys":60392},{"id":52680,"type":1001,"linkType":1002},[60394],{"data":60395,"marks":60396,"value":52685,"nodeType":864},{},[],{"data":60398,"marks":60399,"value":52689,"nodeType":864},{},[],{"data":60401,"content":60402,"nodeType":945},{},[60403],{"data":60404,"content":60405,"nodeType":860},{},[60406,60409,60417],{"data":60407,"marks":60408,"value":21,"nodeType":864},{},[],{"data":60410,"content":60413,"nodeType":39736},{"target":60411},{"sys":60412},{"id":52703,"type":1001,"linkType":1002},[60414],{"data":60415,"marks":60416,"value":52708,"nodeType":864},{},[],{"data":60418,"marks":60419,"value":52712,"nodeType":864},{},[],{"data":60421,"content":60422,"nodeType":945},{},[60423],{"data":60424,"content":60425,"nodeType":860},{},[60426,60429,60437],{"data":60427,"marks":60428,"value":21,"nodeType":864},{},[],{"data":60430,"content":60433,"nodeType":39736},{"target":60431},{"sys":60432},{"id":52726,"type":1001,"linkType":1002},[60434],{"data":60435,"marks":60436,"value":699,"nodeType":864},{},[],{"data":60438,"marks":60439,"value":21,"nodeType":864},{},[],{"data":60441,"content":60442,"nodeType":945},{},[60443],{"data":60444,"content":60445,"nodeType":860},{},[60446,60449,60457],{"data":60447,"marks":60448,"value":21,"nodeType":864},{},[],{"data":60450,"content":60453,"nodeType":39736},{"target":60451},{"sys":60452},{"id":52747,"type":1001,"linkType":1002},[60454],{"data":60455,"marks":60456,"value":52752,"nodeType":864},{},[],{"data":60458,"marks":60459,"value":52756,"nodeType":864},{},[],{"data":60461,"content":60462,"nodeType":860},{},[60463],{"data":60464,"marks":60465,"value":52763,"nodeType":864},{},[],{"data":60467,"content":60468,"nodeType":860},{},[60469],{"data":60470,"marks":60471,"value":52770,"nodeType":864},{},[],{"data":60473,"content":60474,"nodeType":1312},{},[60475],{"data":60476,"marks":60477,"value":52778,"nodeType":864},{},[60478],{"type":899},{"data":60480,"content":60481,"nodeType":860},{},[60482],{"data":60483,"marks":60484,"value":52785,"nodeType":864},{},[],{"data":60486,"content":60487,"nodeType":860},{},[60488],{"data":60489,"marks":60490,"value":52792,"nodeType":864},{},[],{"data":60492,"content":60493,"nodeType":860},{},[60494],{"data":60495,"marks":60496,"value":52799,"nodeType":864},{},[],{"data":60498,"content":60501,"nodeType":996},{"target":60499},{"sys":60500},{"id":40048,"type":1001,"linkType":1002},[],{"data":60503,"content":60504,"nodeType":1312},{},[60505],{"data":60506,"marks":60507,"value":52812,"nodeType":864},{},[60508],{"type":899},{"data":60510,"content":60511,"nodeType":860},{},[60512],{"data":60513,"marks":60514,"value":52819,"nodeType":864},{},[],{"data":60516,"content":60517,"nodeType":860},{},[60518],{"data":60519,"marks":60520,"value":52826,"nodeType":864},{},[],{"data":60522,"content":60523,"nodeType":860},{},[60524],{"data":60525,"marks":60526,"value":52833,"nodeType":864},{},[],{"data":60528,"content":60531,"nodeType":996},{"target":60529},{"sys":60530},{"id":52838,"type":1001,"linkType":1002},[],{"data":60533,"content":60534,"nodeType":860},{},[60535],{"data":60536,"marks":60537,"value":52846,"nodeType":864},{},[],{"data":60539,"content":60540,"nodeType":1312},{},[60541],{"data":60542,"marks":60543,"value":52854,"nodeType":864},{},[60544],{"type":899},{"data":60546,"content":60547,"nodeType":860},{},[60548,60551,60557],{"data":60549,"marks":60550,"value":52861,"nodeType":864},{},[],{"data":60552,"content":60553,"nodeType":883},{"uri":52864},[60554],{"data":60555,"marks":60556,"value":52869,"nodeType":864},{},[],{"data":60558,"marks":60559,"value":1774,"nodeType":864},{},[],{"data":60561,"content":60562,"nodeType":1312},{},[60563],{"data":60564,"marks":60565,"value":52880,"nodeType":864},{},[60566],{"type":899},{"data":60568,"content":60569,"nodeType":860},{},[60570],{"data":60571,"marks":60572,"value":52887,"nodeType":864},{},[],{"data":60574,"content":60577,"nodeType":996},{"target":60575},{"sys":60576},{"id":52892,"type":1001,"linkType":1002},[],{"data":60579,"content":60580,"nodeType":1005},{},[],{"data":60582,"content":60583,"nodeType":1009},{},[60584],{"data":60585,"marks":60586,"value":52904,"nodeType":864},{},[60587],{"type":899},{"data":60589,"content":60590,"nodeType":860},{},[60591],{"data":60592,"marks":60593,"value":52911,"nodeType":864},{},[],{"data":60595,"content":60596,"nodeType":860},{},[60597],{"data":60598,"marks":60599,"value":52918,"nodeType":864},{},[],{"data":60601,"content":60602,"nodeType":941},{},[60603,60623,60654,60674],{"data":60604,"content":60605,"nodeType":945},{},[60606],{"data":60607,"content":60608,"nodeType":860},{},[60609,60612,60620],{"data":60610,"marks":60611,"value":21,"nodeType":864},{},[],{"data":60613,"content":60616,"nodeType":39736},{"target":60614},{"sys":60615},{"id":52935,"type":1001,"linkType":1002},[60617],{"data":60618,"marks":60619,"value":52940,"nodeType":864},{},[],{"data":60621,"marks":60622,"value":52944,"nodeType":864},{},[],{"data":60624,"content":60625,"nodeType":945},{},[60626],{"data":60627,"content":60628,"nodeType":860},{},[60629,60632,60640,60643,60651],{"data":60630,"marks":60631,"value":52954,"nodeType":864},{},[],{"data":60633,"content":60636,"nodeType":39736},{"target":60634},{"sys":60635},{"id":52959,"type":1001,"linkType":1002},[60637],{"data":60638,"marks":60639,"value":52964,"nodeType":864},{},[],{"data":60641,"marks":60642,"value":52968,"nodeType":864},{},[],{"data":60644,"content":60647,"nodeType":39736},{"target":60645},{"sys":60646},{"id":52973,"type":1001,"linkType":1002},[60648],{"data":60649,"marks":60650,"value":52978,"nodeType":864},{},[],{"data":60652,"marks":60653,"value":52982,"nodeType":864},{},[],{"data":60655,"content":60656,"nodeType":945},{},[60657],{"data":60658,"content":60659,"nodeType":860},{},[60660,60663,60671],{"data":60661,"marks":60662,"value":52992,"nodeType":864},{},[],{"data":60664,"content":60667,"nodeType":39736},{"target":60665},{"sys":60666},{"id":52997,"type":1001,"linkType":1002},[60668],{"data":60669,"marks":60670,"value":53002,"nodeType":864},{},[],{"data":60672,"marks":60673,"value":53006,"nodeType":864},{},[],{"data":60675,"content":60676,"nodeType":945},{},[60677],{"data":60678,"content":60679,"nodeType":860},{},[60680,60683,60691],{"data":60681,"marks":60682,"value":21,"nodeType":864},{},[],{"data":60684,"content":60687,"nodeType":39736},{"target":60685},{"sys":60686},{"id":53020,"type":1001,"linkType":1002},[60688],{"data":60689,"marks":60690,"value":53025,"nodeType":864},{},[],{"data":60692,"marks":60693,"value":53029,"nodeType":864},{},[],{"data":60695,"content":60696,"nodeType":860},{},[60697],{"data":60698,"marks":60699,"value":52770,"nodeType":864},{},[],{"data":60701,"content":60702,"nodeType":1312},{},[60703],{"data":60704,"marks":60705,"value":52778,"nodeType":864},{},[60706],{"type":899},{"data":60708,"content":60709,"nodeType":860},{},[60710],{"data":60711,"marks":60712,"value":53049,"nodeType":864},{},[],{"data":60714,"content":60715,"nodeType":860},{},[60716],{"data":60717,"marks":60718,"value":53056,"nodeType":864},{},[],{"data":60720,"content":60721,"nodeType":860},{},[60722],{"data":60723,"marks":60724,"value":53063,"nodeType":864},{},[],{"data":60726,"content":60727,"nodeType":860},{},[60728],{"data":60729,"marks":60730,"value":53070,"nodeType":864},{},[],{"data":60732,"content":60733,"nodeType":1312},{},[60734],{"data":60735,"marks":60736,"value":53078,"nodeType":864},{},[60737],{"type":899},{"data":60739,"content":60740,"nodeType":860},{},[60741],{"data":60742,"marks":60743,"value":53085,"nodeType":864},{},[],{"data":60745,"content":60746,"nodeType":860},{},[60747],{"data":60748,"marks":60749,"value":53092,"nodeType":864},{},[],{"data":60751,"content":60752,"nodeType":860},{},[60753,60756,60760,60763,60767],{"data":60754,"marks":60755,"value":53099,"nodeType":864},{},[],{"data":60757,"marks":60758,"value":53104,"nodeType":864},{},[60759],{"type":899},{"data":60761,"marks":60762,"value":902,"nodeType":864},{},[],{"data":60764,"marks":60765,"value":53112,"nodeType":864},{},[60766],{"type":899},{"data":60768,"marks":60769,"value":53116,"nodeType":864},{},[],{"data":60771,"content":60774,"nodeType":996},{"target":60772},{"sys":60773},{"id":53121,"type":1001,"linkType":1002},[],{"data":60776,"content":60777,"nodeType":860},{},[60778,60781,60785],{"data":60779,"marks":60780,"value":53129,"nodeType":864},{},[],{"data":60782,"marks":60783,"value":53134,"nodeType":864},{},[60784],{"type":899},{"data":60786,"marks":60787,"value":53138,"nodeType":864},{},[],{"data":60789,"content":60790,"nodeType":860},{},[60791,60794,60798],{"data":60792,"marks":60793,"value":53129,"nodeType":864},{},[],{"data":60795,"marks":60796,"value":53149,"nodeType":864},{},[60797],{"type":899},{"data":60799,"marks":60800,"value":53153,"nodeType":864},{},[],{"data":60802,"content":60803,"nodeType":860},{},[60804,60807,60811],{"data":60805,"marks":60806,"value":53160,"nodeType":864},{},[],{"data":60808,"marks":60809,"value":1366,"nodeType":864},{},[60810],{"type":899},{"data":60812,"marks":60813,"value":53168,"nodeType":864},{},[],{"data":60815,"content":60818,"nodeType":996},{"target":60816},{"sys":60817},{"id":53173,"type":1001,"linkType":1002},[],{"data":60820,"content":60821,"nodeType":1312},{},[60822],{"data":60823,"marks":60824,"value":53182,"nodeType":864},{},[60825],{"type":899},{"data":60827,"content":60828,"nodeType":860},{},[60829],{"data":60830,"marks":60831,"value":53189,"nodeType":864},{},[],{"data":60833,"content":60834,"nodeType":1312},{},[60835],{"data":60836,"marks":60837,"value":53197,"nodeType":864},{},[60838],{"type":899},{"data":60840,"content":60841,"nodeType":860},{},[60842],{"data":60843,"marks":60844,"value":53204,"nodeType":864},{},[],{"data":60846,"content":60847,"nodeType":1005},{},[],{"data":60849,"content":60850,"nodeType":1009},{},[60851],{"data":60852,"marks":60853,"value":53215,"nodeType":864},{},[60854],{"type":899},{"data":60856,"content":60857,"nodeType":860},{},[60858],{"data":60859,"marks":60860,"value":53222,"nodeType":864},{},[],{"data":60862,"content":60863,"nodeType":860},{},[60864,60867,60871,60874,60878,60881,60885],{"data":60865,"marks":60866,"value":53229,"nodeType":864},{},[],{"data":60868,"marks":60869,"value":1334,"nodeType":864},{},[60870],{"type":899},{"data":60872,"marks":60873,"value":53237,"nodeType":864},{},[],{"data":60875,"marks":60876,"value":53112,"nodeType":864},{},[60877],{"type":899},{"data":60879,"marks":60880,"value":53245,"nodeType":864},{},[],{"data":60882,"marks":60883,"value":53250,"nodeType":864},{},[60884],{"type":899},{"data":60886,"marks":60887,"value":53254,"nodeType":864},{},[],{"data":60889,"content":60892,"nodeType":996},{"target":60890},{"sys":60891},{"id":53259,"type":1001,"linkType":1002},[],{"data":60894,"content":60895,"nodeType":860},{},[60896,60899,60903,60906,60910],{"data":60897,"marks":60898,"value":53267,"nodeType":864},{},[],{"data":60900,"marks":60901,"value":1503,"nodeType":864},{},[60902],{"type":899},{"data":60904,"marks":60905,"value":52968,"nodeType":864},{},[],{"data":60907,"marks":60908,"value":1397,"nodeType":864},{},[60909],{"type":899},{"data":60911,"marks":60912,"value":53282,"nodeType":864},{},[],{"data":60914,"content":60915,"nodeType":860},{},[60916],{"data":60917,"marks":60918,"value":53289,"nodeType":864},{},[],{"data":60920,"content":60921,"nodeType":1005},{},[],{"data":60923,"content":60924,"nodeType":1009},{},[60925],{"data":60926,"marks":60927,"value":53300,"nodeType":864},{},[60928],{"type":899},{"data":60930,"content":60931,"nodeType":860},{},[60932],{"data":60933,"marks":60934,"value":53307,"nodeType":864},{},[],{"data":60936,"content":60937,"nodeType":860},{},[60938,60941,60945],{"data":60939,"marks":60940,"value":53314,"nodeType":864},{},[],{"data":60942,"marks":60943,"value":53319,"nodeType":864},{},[60944],{"type":899},{"data":60946,"marks":60947,"value":53323,"nodeType":864},{},[],{"data":60949,"content":60952,"nodeType":996},{"target":60950},{"sys":60951},{"id":53328,"type":1001,"linkType":1002},[],{"data":60954,"content":60955,"nodeType":860},{},[60956],{"data":60957,"marks":60958,"value":53336,"nodeType":864},{},[],{"data":60960,"content":60961,"nodeType":860},{},[60962],{"data":60963,"marks":60964,"value":53343,"nodeType":864},{},[],{"data":60966,"content":60967,"nodeType":1005},{},[],{"data":60969,"content":60970,"nodeType":1009},{},[60971],{"data":60972,"marks":60973,"value":3578,"nodeType":864},{},[60974],{"type":899},{"data":60976,"content":60977,"nodeType":860},{},[60978,60981,60987],{"data":60979,"marks":60980,"value":53360,"nodeType":864},{},[],{"data":60982,"content":60983,"nodeType":883},{"uri":152},[60984],{"data":60985,"marks":60986,"value":53367,"nodeType":864},{},[],{"data":60988,"marks":60989,"value":53371,"nodeType":864},{},[],{"data":60991,"content":60992,"nodeType":860},{},[60993],{"data":60994,"marks":60995,"value":53378,"nodeType":864},{},[],{"data":60997,"content":60998,"nodeType":860},{},[60999,61002,61008,61011,61017,61020,61026],{"data":61000,"marks":61001,"value":53385,"nodeType":864},{},[],{"data":61003,"content":61004,"nodeType":883},{"uri":53388},[61005],{"data":61006,"marks":61007,"value":53393,"nodeType":864},{},[],{"data":61009,"marks":61010,"value":53397,"nodeType":864},{},[],{"data":61012,"content":61013,"nodeType":883},{"uri":53400},[61014],{"data":61015,"marks":61016,"value":53405,"nodeType":864},{},[],{"data":61018,"marks":61019,"value":53409,"nodeType":864},{},[],{"data":61021,"content":61022,"nodeType":883},{"uri":40635},[61023],{"data":61024,"marks":61025,"value":2715,"nodeType":864},{},[],{"data":61027,"marks":61028,"value":2924,"nodeType":864},{},[],{"items":61030},[61031,61033],{"sys":61032,"name":13779},{"id":13778},{"sys":61034,"name":342},{"id":13775},{"items":61036},[61037],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":61038},{"url":853},{"__typename":2059,"sys":61040,"content":61042,"title":62081,"synopsis":62082,"hashTags":59,"publishedDate":62083,"slug":62084,"tagsCollection":62085,"authorsCollection":62091},{"id":61041},"4DqTwJKeCSPnJUc6YPFC5A",{"json":61043},{"data":61044,"content":61045,"nodeType":856},{},[61046,61113,61120,61126,61129,61137,61144,61151,61159,61166,61222,61238,61245,61252,61255,61263,61270,61332,61340,61347,61353,61359,61366,61373,61391,61398,61446,61452,61460,61481,61488,61495,61588,61595,61611,61617,61624,61631,61638,61645,61706,61712,61718,61726,61733,61740,61763,61770,61776,61798,61803,61810,61817,61824,61831,61864,61883,61890,61901,61904,61912,61919,61925,61928,61936,61944,61951,61970,61977,61984,61990,61997,62004,62010,62013,62020,62036,62042],{"data":61047,"content":61048,"nodeType":860},{},[61049,61053,61062,61065,61074,61077,61086,61090,61098,61101,61109],{"data":61050,"marks":61051,"value":61052,"nodeType":864},{},[],"Attackers are doubling down on malicious browser extensions as their method of choice. Recent campaigns like ",{"data":61054,"content":61056,"nodeType":883},{"uri":61055},"https://www.bleepingcomputer.com/news/security/shadypanda-browser-extensions-amass-43m-installs-in-malicious-campaign/",[61057],{"data":61058,"marks":61059,"value":61061,"nodeType":864},{},[61060],{"type":1455},"ShadyPanda",{"data":61063,"marks":61064,"value":3731,"nodeType":864},{},[],{"data":61066,"content":61068,"nodeType":883},{"uri":61067},"https://www.bleepingcomputer.com/news/security/zoom-stealer-browser-extensions-harvest-corporate-meeting-intelligence/",[61069],{"data":61070,"marks":61071,"value":61073,"nodeType":864},{},[61072],{"type":1455},"ZoomStealer",{"data":61075,"marks":61076,"value":3731,"nodeType":864},{},[],{"data":61078,"content":61080,"nodeType":883},{"uri":61079},"https://www.bleepingcomputer.com/news/security/malicious-ghostposter-browser-extensions-found-with-840-000-installs/",[61081],{"data":61082,"marks":61083,"value":61085,"nodeType":864},{},[61084],{"type":1455},"GhostPoster",{"data":61087,"marks":61088,"value":61089,"nodeType":864},{},[],", and the breaches impacting vendors like ",{"data":61091,"content":61093,"nodeType":883},{"uri":61092},"https://www.bleepingcomputer.com/news/security/cybersecurity-firms-chrome-extension-hijacked-to-steal-users-data/",[61094],{"data":61095,"marks":61096,"value":3948,"nodeType":864},{},[61097],{"type":1455},{"data":61099,"marks":61100,"value":902,"nodeType":864},{},[],{"data":61102,"content":61104,"nodeType":883},{"uri":61103},"https://www.bleepingcomputer.com/news/security/trust-wallet-confirms-extension-hack-led-to-7-million-crypto-theft/",[61105],{"data":61106,"marks":61107,"value":3970,"nodeType":864},{},[61108],{"type":1455},{"data":61110,"marks":61111,"value":61112,"nodeType":864},{},[],", all highlight the threat posed by malicious extensions. ",{"data":61114,"content":61115,"nodeType":860},{},[61116],{"data":61117,"marks":61118,"value":61119,"nodeType":864},{},[],"Most malicious extensions didn’t start that way. Attackers often begin with a legitimate extension — either by creating something that is initially benign, purchasing an extension that already exists and has a large number of installs, or by phishing an extension developer’s account to publish a malicious version. Then, they bide their time, waiting for the right moment to flip the switch and deploy a malicious update, compromising every browser that they’re deployed to. ",{"data":61121,"content":61125,"nodeType":996},{"target":61122},{"sys":61123},{"id":61124,"type":1001,"linkType":1002},"7eTmqh5jqYA3l1Xk4GikVO",[],{"data":61127,"content":61128,"nodeType":1005},{},[],{"data":61130,"content":61131,"nodeType":1009},{},[61132],{"data":61133,"marks":61134,"value":61136,"nodeType":864},{},[61135],{"type":899},"Why tackling malicious extensions is a hard problem for security teams",{"data":61138,"content":61139,"nodeType":860},{},[61140],{"data":61141,"marks":61142,"value":61143,"nodeType":864},{},[],"The Chrome extension store alone has in excess of 100k extensions with a wide range of use cases. Pretty much every major app today has an extension counterpart, and there are countless smaller extensions — from AI overlays, to screen recording, spell checking, and color matching. AI-assisted development has further increased the rate at which new extensions are created and added to the marketplace (for both legit developers and malicious ones). ",{"data":61145,"content":61146,"nodeType":860},{},[61147],{"data":61148,"marks":61149,"value":61150,"nodeType":864},{},[],"For organizations just beginning to think about extension management, this isn’t an easy problem to get a handle on. If you’ve allowed your employees to freely install extensions without restriction, then there could be hundreds, if not thousands, of different extensions in use across your business. ",{"data":61152,"content":61153,"nodeType":1312},{},[61154],{"data":61155,"marks":61156,"value":61158,"nodeType":864},{},[61157],{"type":899},"Malicious extensions are good at hiding bad code",{"data":61160,"content":61161,"nodeType":860},{},[61162],{"data":61163,"marks":61164,"value":61165,"nodeType":864},{},[],"Right now, extension stores are fighting a losing battle against attackers. ",{"data":61167,"content":61168,"nodeType":941},{},[61169,61192,61202,61212],{"data":61170,"content":61171,"nodeType":945},{},[61172],{"data":61173,"content":61174,"nodeType":860},{},[61175,61179,61188],{"data":61176,"marks":61177,"value":61178,"nodeType":864},{},[],"Malicious extensions are being regularly uploaded, bypassing code analysis checks, and even achieving ",{"data":61180,"content":61182,"nodeType":883},{"uri":61181},"https://thehackernews.com/2026/02/malicious-chrome-extensions-caught.html",[61183],{"data":61184,"marks":61185,"value":61187,"nodeType":864},{},[61186],{"type":1455},"“Featured” or “Verified” status",{"data":61189,"marks":61190,"value":61191,"nodeType":864},{},[]," in the app stores. This is because attackers are using dynamically compiled, stealthily smuggled code that can’t be reliably spotted through static code checks or sandbox analysis. ",{"data":61193,"content":61194,"nodeType":945},{},[61195],{"data":61196,"content":61197,"nodeType":860},{},[61198],{"data":61199,"marks":61200,"value":61201,"nodeType":864},{},[],"Bad isn't detected until an extension is observed doing malicious things in the wild. Most of the time, this is because there’s been a breach. ",{"data":61203,"content":61204,"nodeType":945},{},[61205],{"data":61206,"content":61207,"nodeType":860},{},[61208],{"data":61209,"marks":61210,"value":61211,"nodeType":864},{},[],"When an extension is reported as bad, it enters a lengthy review process. Unless there’s pressure to act quickly (e.g. there’s a large amount of reporting), it won’t get prioritized. ",{"data":61213,"content":61214,"nodeType":945},{},[61215],{"data":61216,"content":61217,"nodeType":860},{},[61218],{"data":61219,"marks":61220,"value":61221,"nodeType":864},{},[],"Just because an extension is removed from the store doesn’t mean that it’s automatically removed from browsers where it is installed. ",{"data":61223,"content":61224,"nodeType":860},{},[61225,61230,61233],{"data":61226,"marks":61227,"value":61229,"nodeType":864},{},[61228],{"type":899},"The bottom line:",{"data":61231,"marks":61232,"value":1171,"nodeType":864},{},[],{"data":61234,"marks":61235,"value":61237,"nodeType":864},{},[61236],{"type":899},"The security teams at Google and Microsoft analyse and manually approve every single extension upload and code change that enters their store, and even they aren’t detecting bad before malware executes in the victim’s browser. ",{"data":61239,"content":61240,"nodeType":860},{},[61241],{"data":61242,"marks":61243,"value":61244,"nodeType":864},{},[],"Today, there’s no single magic bullet tool or control that organizations can use — unless you simply want to disable browser extensions altogether, which might not be the best option for users and their productivity.",{"data":61246,"content":61247,"nodeType":860},{},[61248],{"data":61249,"marks":61250,"value":61251,"nodeType":864},{},[],"Fortunately, Push is in a good position to help, with its ability to inventory all your browser extensions and help you find and block malicious ones.",{"data":61253,"content":61254,"nodeType":1005},{},[],{"data":61256,"content":61257,"nodeType":1009},{},[61258],{"data":61259,"marks":61260,"value":61262,"nodeType":864},{},[61261],{"type":899},"How to securely manage browser extensions (and how Push can help)",{"data":61264,"content":61265,"nodeType":860},{},[61266],{"data":61267,"marks":61268,"value":61269,"nodeType":864},{},[],"Here’s our step-by-step guide to securely using browser extensions in your organization.",{"data":61271,"content":61272,"nodeType":941},{},[61273,61292,61302,61312,61322],{"data":61274,"content":61275,"nodeType":945},{},[61276],{"data":61277,"content":61278,"nodeType":860},{},[61279,61283,61288],{"data":61280,"marks":61281,"value":61282,"nodeType":864},{},[],"Step 0: Enable ",{"data":61284,"marks":61285,"value":61287,"nodeType":864},{},[61286],{"type":899},"malicious browser extension detection",{"data":61289,"marks":61290,"value":61291,"nodeType":864},{},[]," to stop known-bad extensions from running in your environment. ",{"data":61293,"content":61294,"nodeType":945},{},[61295],{"data":61296,"content":61297,"nodeType":860},{},[61298],{"data":61299,"marks":61300,"value":61301,"nodeType":864},{},[],"Step 1: Establish an inventory of extensions currently in use across your users and their browsers. ",{"data":61303,"content":61304,"nodeType":945},{},[61305],{"data":61306,"content":61307,"nodeType":860},{},[61308],{"data":61309,"marks":61310,"value":61311,"nodeType":864},{},[],"Step 2: Risk-assess the extensions running in your environment using Push data.",{"data":61313,"content":61314,"nodeType":945},{},[61315],{"data":61316,"content":61317,"nodeType":860},{},[61318],{"data":61319,"marks":61320,"value":61321,"nodeType":864},{},[],"Step 3: Create an allowlist or blocklist to control the extensions active in your environment.",{"data":61323,"content":61324,"nodeType":945},{},[61325],{"data":61326,"content":61327,"nodeType":860},{},[61328],{"data":61329,"marks":61330,"value":61331,"nodeType":864},{},[],"Step 4: Monitor for risky changes.",{"data":61333,"content":61334,"nodeType":1312},{},[61335],{"data":61336,"marks":61337,"value":61339,"nodeType":864},{},[61338],{"type":899},"Step 0: Enable malicious browser extension detection in the Push platform",{"data":61341,"content":61342,"nodeType":860},{},[61343],{"data":61344,"marks":61345,"value":61346,"nodeType":864},{},[],"First, we recommend you take action to ensure that extensions reported as suspicious or malicious are blocked from running in your environment. ",{"data":61348,"content":61352,"nodeType":996},{"target":61349},{"sys":61350},{"id":61351,"type":1001,"linkType":1002},"yniMglSNypgyxmdGVcFxJ",[],{"data":61354,"content":61358,"nodeType":996},{"target":61355},{"sys":61356},{"id":61357,"type":1001,"linkType":1002},"37bID8AChVgerAnD6q8NPZ",[],{"data":61360,"content":61361,"nodeType":860},{},[61362],{"data":61363,"marks":61364,"value":61365,"nodeType":864},{},[],"If you’re a Push customer, you can ensure that any extension that is reported as malicious is automatically blocked in your environment. This means that the extension gets disabled and cannot run in any browser with the Push extension installed. ",{"data":61367,"content":61368,"nodeType":860},{},[61369],{"data":61370,"marks":61371,"value":61372,"nodeType":864},{},[],"The Push Security research team maintains a global list of known-bad extensions based on threat intelligence reporting. This list is continuously updated and ensures that as soon as an extension is reported as malicious, it is blocked. ",{"data":61374,"content":61375,"nodeType":860},{},[61376,61380,61388],{"data":61377,"marks":61378,"value":61379,"nodeType":864},{},[],"You can enable the control via the Controls page in the Push admin console. Admins can configure rules in Off, Monitor, or Block mode. Block mode is recommended, meaning that extensions are disabled and web store access is blocked. You can read more about this in our ",{"data":61381,"content":61383,"nodeType":883},{"uri":61382},"https://pushsecurity.com/help/how-does-push-detect-malicious-browser-extensions",[61384],{"data":61385,"marks":61386,"value":61387,"nodeType":864},{},[],"Help Center",{"data":61389,"marks":61390,"value":1774,"nodeType":864},{},[],{"data":61392,"content":61393,"nodeType":860},{},[61394],{"data":61395,"marks":61396,"value":61397,"nodeType":864},{},[],"When an extension is flagged as malicious, a detection event will be generated and appear on the Detections page in the Push admin console. The severity of these detections is classified as follows:",{"data":61399,"content":61400,"nodeType":941},{},[61401,61416,61431],{"data":61402,"content":61403,"nodeType":945},{},[61404],{"data":61405,"content":61406,"nodeType":860},{},[61407,61412],{"data":61408,"marks":61409,"value":61411,"nodeType":864},{},[61410],{"type":899},"Low",{"data":61413,"marks":61414,"value":61415,"nodeType":864},{},[]," for an extension that has never been enabled. The control prevented either the installation or the extension from being enabled.",{"data":61417,"content":61418,"nodeType":945},{},[61419],{"data":61420,"content":61421,"nodeType":860},{},[61422,61427],{"data":61423,"marks":61424,"value":61426,"nodeType":864},{},[61425],{"type":899},"Medium",{"data":61428,"marks":61429,"value":61430,"nodeType":864},{},[]," for an extension that was installed and enabled, but has been disabled by the control. ",{"data":61432,"content":61433,"nodeType":945},{},[61434],{"data":61435,"content":61436,"nodeType":860},{},[61437,61442],{"data":61438,"marks":61439,"value":61441,"nodeType":864},{},[61440],{"type":899},"High",{"data":61443,"marks":61444,"value":61445,"nodeType":864},{},[]," if the extension was enabled and is still active (i.e. the control was in monitor mode).",{"data":61447,"content":61451,"nodeType":996},{"target":61448},{"sys":61449},{"id":61450,"type":1001,"linkType":1002},"1yOPlBKtLGYyN80OCJ9qMn",[],{"data":61453,"content":61454,"nodeType":1312},{},[61455],{"data":61456,"marks":61457,"value":61459,"nodeType":864},{},[61458],{"type":899},"Step 1: Establish an inventory of existing extensions.",{"data":61461,"content":61462,"nodeType":860},{},[61463,61467,61472,61476],{"data":61464,"marks":61465,"value":61466,"nodeType":864},{},[],"Next, we recommend you take stock of what’s already running in your environment so you can begin to make risk-based decisions about what you allow, and what you don’t. This means building an inventory of ",{"data":61468,"marks":61469,"value":61471,"nodeType":864},{},[61470],{"type":899},"every extension ",{"data":61473,"marks":61474,"value":61475,"nodeType":864},{},[],"running in ",{"data":61477,"marks":61478,"value":61480,"nodeType":864},{},[61479],{"type":899},"every browser. ",{"data":61482,"content":61483,"nodeType":860},{},[61484],{"data":61485,"marks":61486,"value":61487,"nodeType":864},{},[],"Push provides real-time visibility of extensions installed in every browser across your workforce. ",{"data":61489,"content":61490,"nodeType":860},{},[61491],{"data":61492,"marks":61493,"value":61494,"nodeType":864},{},[],"Push tracks several key data points, including: ",{"data":61496,"content":61497,"nodeType":941},{},[61498,61508,61518,61528,61538,61548,61558,61568,61578],{"data":61499,"content":61500,"nodeType":945},{},[61501],{"data":61502,"content":61503,"nodeType":860},{},[61504],{"data":61505,"marks":61506,"value":61507,"nodeType":864},{},[],"Extension name, ID, and version number",{"data":61509,"content":61510,"nodeType":945},{},[61511],{"data":61512,"content":61513,"nodeType":860},{},[61514],{"data":61515,"marks":61516,"value":61517,"nodeType":864},{},[],"Update & homepage URL",{"data":61519,"content":61520,"nodeType":945},{},[61521],{"data":61522,"content":61523,"nodeType":860},{},[61524],{"data":61525,"marks":61526,"value":61527,"nodeType":864},{},[],"Extension permissions",{"data":61529,"content":61530,"nodeType":945},{},[61531],{"data":61532,"content":61533,"nodeType":860},{},[61534],{"data":61535,"marks":61536,"value":61537,"nodeType":864},{},[],"Host permissions (where applicable)",{"data":61539,"content":61540,"nodeType":945},{},[61541],{"data":61542,"content":61543,"nodeType":860},{},[61544],{"data":61545,"marks":61546,"value":61547,"nodeType":864},{},[],"Deployment method (e.g. managed, manual, sideloaded or development)",{"data":61549,"content":61550,"nodeType":945},{},[61551],{"data":61552,"content":61553,"nodeType":860},{},[61554],{"data":61555,"marks":61556,"value":61557,"nodeType":864},{},[],"Which employees use the extension",{"data":61559,"content":61560,"nodeType":945},{},[61561],{"data":61562,"content":61563,"nodeType":860},{},[61564],{"data":61565,"marks":61566,"value":61567,"nodeType":864},{},[],"Which browsers have the extension installed",{"data":61569,"content":61570,"nodeType":945},{},[61571],{"data":61572,"content":61573,"nodeType":860},{},[61574],{"data":61575,"marks":61576,"value":61577,"nodeType":864},{},[],"Whether the extension is enabled or disabled",{"data":61579,"content":61580,"nodeType":945},{},[61581],{"data":61582,"content":61583,"nodeType":860},{},[61584],{"data":61585,"marks":61586,"value":61587,"nodeType":864},{},[],"Useful metadata like install count, ownership history, update history, and whether the extension has been unlisted from the web store.",{"data":61589,"content":61590,"nodeType":860},{},[61591],{"data":61592,"marks":61593,"value":61594,"nodeType":864},{},[],"This information is critical for assessing risk, as well as providing an early warning of future malicious intent. ",{"data":61596,"content":61597,"nodeType":860},{},[61598,61602,61607],{"data":61599,"marks":61600,"value":61601,"nodeType":864},{},[],"You can enable browser extension visibility in the Push platform by going to ",{"data":61603,"marks":61604,"value":61606,"nodeType":864},{},[61605],{"type":899},"Settings > Organization > Browser extension visibility",{"data":61608,"marks":61609,"value":61610,"nodeType":864},{},[]," and toggling on the feature.",{"data":61612,"content":61616,"nodeType":996},{"target":61613},{"sys":61614},{"id":61615,"type":1001,"linkType":1002},"2LCwZNbSazYGIEfWHZKJRU",[],{"data":61618,"content":61619,"nodeType":1312},{},[61620],{"data":61621,"marks":61622,"value":61311,"nodeType":864},{},[61623],{"type":899},{"data":61625,"content":61626,"nodeType":860},{},[61627],{"data":61628,"marks":61629,"value":61630,"nodeType":864},{},[],"Now that you’ve built a real-time inventory, you can start to analyse the data to find risky extensions. ",{"data":61632,"content":61633,"nodeType":860},{},[61634],{"data":61635,"marks":61636,"value":61637,"nodeType":864},{},[],"Every extension that is running in your environment expands your potential attack surface, representing another node that can be compromised by an attacker. So it makes sense to only allow those that are absolutely necessary in order to sensibly control the risk. ",{"data":61639,"content":61640,"nodeType":860},{},[61641],{"data":61642,"marks":61643,"value":61644,"nodeType":864},{},[],"You can start to investigate and prune extensions based on the properties tracked in the Push platform. For example:",{"data":61646,"content":61647,"nodeType":941},{},[61648,61658,61686,61696],{"data":61649,"content":61650,"nodeType":945},{},[61651],{"data":61652,"content":61653,"nodeType":860},{},[61654],{"data":61655,"marks":61656,"value":61657,"nodeType":864},{},[],"Extensions with a low install count from an unverified publisher. ",{"data":61659,"content":61660,"nodeType":945},{},[61661],{"data":61662,"content":61663,"nodeType":860},{},[61664,61668,61673,61677,61682],{"data":61665,"marks":61666,"value":61667,"nodeType":864},{},[],"Extensions that have been ",{"data":61669,"marks":61670,"value":61672,"nodeType":864},{},[61671],{"type":899},"sideloaded",{"data":61674,"marks":61675,"value":61676,"nodeType":864},{},[]," (installed by software on the machine) or are ",{"data":61678,"marks":61679,"value":61681,"nodeType":864},{},[61680],{"type":899},"development",{"data":61683,"marks":61684,"value":61685,"nodeType":864},{},[]," (installed from a folder off-disk when Developer mode is turned on)",{"data":61687,"content":61688,"nodeType":945},{},[61689],{"data":61690,"content":61691,"nodeType":860},{},[61692],{"data":61693,"marks":61694,"value":61695,"nodeType":864},{},[],"Extensions that are used by a small number of employees for niche / non-critical functions. ",{"data":61697,"content":61698,"nodeType":945},{},[61699],{"data":61700,"content":61701,"nodeType":860},{},[61702],{"data":61703,"marks":61704,"value":61705,"nodeType":864},{},[],"Extensions with risky permissions.",{"data":61707,"content":61711,"nodeType":996},{"target":61708},{"sys":61709},{"id":61710,"type":1001,"linkType":1002},"FpGNvFgEGj6eAGihoWEUi",[],{"data":61713,"content":61717,"nodeType":996},{"target":61714},{"sys":61715},{"id":61716,"type":1001,"linkType":1002},"5JccSPh103QIQJxIh9pk4x",[],{"data":61719,"content":61720,"nodeType":1312},{},[61721],{"data":61722,"marks":61723,"value":61725,"nodeType":864},{},[61724],{"type":899},"Step 3: Create an allowlist to control the extensions active in your environment.",{"data":61727,"content":61728,"nodeType":860},{},[61729],{"data":61730,"marks":61731,"value":61732,"nodeType":864},{},[],"Using the output of your risk assessment and the data provided by the Push platform, you can control the extensions that you allow your employees to use.",{"data":61734,"content":61735,"nodeType":860},{},[61736],{"data":61737,"marks":61738,"value":61739,"nodeType":864},{},[],"To do this, you need to allowlist the extensions you’re happy for employees to use (and block everything else). That way, you remove the ability for employees to add new extensions unless approved by an admin. This means you either:",{"data":61741,"content":61742,"nodeType":941},{},[61743,61753],{"data":61744,"content":61745,"nodeType":945},{},[61746],{"data":61747,"content":61748,"nodeType":860},{},[61749],{"data":61750,"marks":61751,"value":61752,"nodeType":864},{},[],"Add every extension you currently have running in your environment to an allowlist, block everything else, and then start to prune extensions from that list. ",{"data":61754,"content":61755,"nodeType":945},{},[61756],{"data":61757,"content":61758,"nodeType":860},{},[61759],{"data":61760,"marks":61761,"value":61762,"nodeType":864},{},[],"Create a shortened allowlist from the outset. ",{"data":61764,"content":61765,"nodeType":860},{},[61766],{"data":61767,"marks":61768,"value":61769,"nodeType":864},{},[],"Both are valid ways of solving the problem, with the first option being the least potentially disruptive (i.e. you’re not switching off a load of extensions in one go). That said, this might not be a viable solution depending on your company size. ",{"data":61771,"content":61775,"nodeType":996},{"target":61772},{"sys":61773},{"id":61774,"type":1001,"linkType":1002},"6wQW4VqLeLXMXdPPWLhQAF",[],{"data":61777,"content":61778,"nodeType":860},{},[61779,61784,61794],{"data":61780,"marks":61781,"value":61783,"nodeType":864},{},[61782],{"type":899},"You can do this in lots of different ways depending on the OS and browsers used across your workforce. This can get messy depending on the complexity of your environment. But you can do it in a streamlined, browser-agnostic way ",{"data":61785,"content":61787,"nodeType":883},{"uri":61786},"https://pushsecurity.com/help/10138/#start",[61788],{"data":61789,"marks":61790,"value":61793,"nodeType":864},{},[61791,61792],{"type":1455},{"type":899},"using Push",{"data":61795,"marks":61796,"value":11546,"nodeType":864},{},[61797],{"type":899},{"data":61799,"content":61802,"nodeType":996},{"target":61800},{"sys":61801},{"id":49781,"type":1001,"linkType":1002},[],{"data":61804,"content":61805,"nodeType":860},{},[61806],{"data":61807,"marks":61808,"value":61809,"nodeType":864},{},[],"Managing which extensions you’ve opted to allow is a continuous process that will change as user behavior changes and new extensions are added. It’s important that you regularly review whether your current allowlist is fit for purpose. ",{"data":61811,"content":61812,"nodeType":1312},{},[61813],{"data":61814,"marks":61815,"value":61331,"nodeType":864},{},[61816],{"type":899},{"data":61818,"content":61819,"nodeType":860},{},[61820],{"data":61821,"marks":61822,"value":61823,"nodeType":864},{},[],"Finally, once you’ve begun the process of pruning the extensions in your environment and you’ve reached a baseline you’re happy with, it’s now about reviewing and approving any new extension requests, and monitoring for risky changes. ",{"data":61825,"content":61826,"nodeType":860},{},[61827],{"data":61828,"marks":61829,"value":61830,"nodeType":864},{},[],"We recommend monitoring for things like:",{"data":61832,"content":61833,"nodeType":941},{},[61834,61844,61854],{"data":61835,"content":61836,"nodeType":945},{},[61837],{"data":61838,"content":61839,"nodeType":860},{},[61840],{"data":61841,"marks":61842,"value":61843,"nodeType":864},{},[],"Regularly reviewing changes in extension ownership + recent updates",{"data":61845,"content":61846,"nodeType":945},{},[61847],{"data":61848,"content":61849,"nodeType":860},{},[61850],{"data":61851,"marks":61852,"value":61853,"nodeType":864},{},[],"Monitoring for updates to extensions to track risky permissions being added ",{"data":61855,"content":61856,"nodeType":945},{},[61857],{"data":61858,"content":61859,"nodeType":860},{},[61860],{"data":61861,"marks":61862,"value":61863,"nodeType":864},{},[],"Monitoring for new malicious browser extension detections",{"data":61865,"content":61866,"nodeType":860},{},[61867,61871,61880],{"data":61868,"marks":61869,"value":61870,"nodeType":864},{},[],"It’s super simple to use Push data to create alerts and feed your detection and response workflows. ",{"data":61872,"content":61874,"nodeType":883},{"uri":61873},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/#start",[61875],{"data":61876,"marks":61877,"value":61879,"nodeType":864},{},[61878],{"type":1455},"See how to connect Push to your SIEM/SOAR and learn more about the Push REST API and webhooks. ",{"data":61881,"marks":61882,"value":21,"nodeType":864},{},[],{"data":61884,"content":61885,"nodeType":860},{},[61886],{"data":61887,"marks":61888,"value":61889,"nodeType":864},{},[],"At this point, you can then triage and investigate further to see whether additional action is required. ",{"data":61891,"content":61892,"nodeType":1116},{},[61893],{"data":61894,"content":61895,"nodeType":860},{},[61896],{"data":61897,"marks":61898,"value":61900,"nodeType":864},{},[61899],{"type":899},"And there you have it! You’ve secured browser extension use across your organization using Push. ",{"data":61902,"content":61903,"nodeType":1005},{},[],{"data":61905,"content":61906,"nodeType":1312},{},[61907],{"data":61908,"marks":61909,"value":61911,"nodeType":864},{},[61910],{"type":899},"Don’t take our word for it …",{"data":61913,"content":61914,"nodeType":860},{},[61915],{"data":61916,"marks":61917,"value":61918,"nodeType":864},{},[],"Our friends at GitLab echo our thoughts on browser extensions and the value of tools like Push that help them to solve this problem.",{"data":61920,"content":61924,"nodeType":996},{"target":61921},{"sys":61922},{"id":61923,"type":1001,"linkType":1002},"1m0x2Q6MmOn7ANqCtpYptu",[],{"data":61926,"content":61927,"nodeType":1005},{},[],{"data":61929,"content":61930,"nodeType":1009},{},[61931],{"data":61932,"marks":61933,"value":61935,"nodeType":864},{},[61934],{"type":899},"Additional tips",{"data":61937,"content":61938,"nodeType":1312},{},[61939],{"data":61940,"marks":61941,"value":61943,"nodeType":864},{},[61942],{"type":899},"Disable browser syncing",{"data":61945,"content":61946,"nodeType":860},{},[61947],{"data":61948,"marks":61949,"value":61950,"nodeType":864},{},[],"If you’re in the early stages of your extension management process, an extra step you might want to consider is disabling browser syncing for extensions. ",{"data":61952,"content":61953,"nodeType":860},{},[61954,61958,61967],{"data":61955,"marks":61956,"value":61957,"nodeType":864},{},[],"When we deploy Push, we find it’s not unusual for people to sign into their work browser with a personal email profile. There’s a significant risk here — if you end up saving and syncing credentials across devices, a compromise on a (usually less secure) personal device can lead to business accounts being compromised. Notably, this was exploited in a ",{"data":61959,"content":61961,"nodeType":883},{"uri":61960},"https://sec.okta.com/articles/harfiles/",[61962],{"data":61963,"marks":61964,"value":61966,"nodeType":864},{},[61965],{"type":1455},"2023 Okta security breach",{"data":61968,"marks":61969,"value":2924,"nodeType":864},{},[],{"data":61971,"content":61972,"nodeType":860},{},[61973],{"data":61974,"marks":61975,"value":61976,"nodeType":864},{},[],"The same model applies to browser extensions. By default, any extension installed from the web store is synced across devices where a profile is logged in and syncing is enabled. ",{"data":61978,"content":61979,"nodeType":860},{},[61980],{"data":61981,"marks":61982,"value":61983,"nodeType":864},{},[],"As an example, you can see how to disable browser extension syncing if you manage Chrome in Google Workspace.",{"data":61985,"content":61989,"nodeType":996},{"target":61986},{"sys":61987},{"id":61988,"type":1001,"linkType":1002},"23gbN24WiOzszvwP9zy2MM",[],{"data":61991,"content":61992,"nodeType":860},{},[61993],{"data":61994,"marks":61995,"value":61996,"nodeType":864},{},[],"This only applies if you haven’t yet created an allowlist for extensions in your environment, in which case any extensions not on the list will be blocked. ",{"data":61998,"content":61999,"nodeType":860},{},[62000],{"data":62001,"marks":62002,"value":62003,"nodeType":864},{},[],"You can also use Push to surface which users are logged into their browser using a non-work profile and whether the profile is synced across devices. ",{"data":62005,"content":62009,"nodeType":996},{"target":62006},{"sys":62007},{"id":62008,"type":1001,"linkType":1002},"421C3CL6Sfa8gmn56X7lRI",[],{"data":62011,"content":62012,"nodeType":1005},{},[],{"data":62014,"content":62015,"nodeType":1009},{},[62016],{"data":62017,"marks":62018,"value":3578,"nodeType":864},{},[62019],{"type":899},{"data":62021,"content":62022,"nodeType":860},{},[62023,62026,62033],{"data":62024,"marks":62025,"value":53360,"nodeType":864},{},[],{"data":62027,"content":62028,"nodeType":883},{"uri":27},[62029],{"data":62030,"marks":62031,"value":62032,"nodeType":864},{},[],"modern attack techniques that are the leading cause of breaches today",{"data":62034,"marks":62035,"value":2924,"nodeType":864},{},[],{"data":62037,"content":62038,"nodeType":860},{},[62039],{"data":62040,"marks":62041,"value":53378,"nodeType":864},{},[],{"data":62043,"content":62044,"nodeType":860},{},[62045,62049,62057,62060,62068,62071,62078],{"data":62046,"marks":62047,"value":62048,"nodeType":864},{},[],"Want to learn more about Push? ",{"data":62050,"content":62051,"nodeType":883},{"uri":16866},[62052],{"data":62053,"marks":62054,"value":62056,"nodeType":864},{},[62055],{"type":1455},"Check out our latest product overview",{"data":62058,"marks":62059,"value":3731,"nodeType":864},{},[],{"data":62061,"content":62062,"nodeType":883},{"uri":16877},[62063],{"data":62064,"marks":62065,"value":62067,"nodeType":864},{},[62066],{"type":1455},"visit our demo library",{"data":62069,"marks":62070,"value":16887,"nodeType":864},{},[],{"data":62072,"content":62073,"nodeType":883},{"uri":1700},[62074],{"data":62075,"marks":62076,"value":16894,"nodeType":864},{},[62077],{"type":1455},{"data":62079,"marks":62080,"value":2924,"nodeType":864},{},[],"Guide: How to manage and block browser extensions using Push","How to detect risky and malicious extensions and block them from running in employee browsers. ","2026-03-04T00:00:00.000Z","browser-extension-management-guide",{"items":62086},[62087,62089],{"sys":62088,"name":13779},{"id":13778},{"sys":62090,"name":342},{"id":13775},{"items":62092},[62093],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":62094},{"url":2740},{"__typename":2059,"sys":62096,"content":62098,"title":62888,"synopsis":62889,"hashTags":59,"publishedDate":62890,"slug":62891,"tagsCollection":62892,"authorsCollection":62896},{"id":62097},"PAPJPr3CIB6J20udYyy1r",{"json":62099},{"data":62100,"content":62101,"nodeType":856},{},[62102,62108,62128,62135,62142,62148,62151,62159,62166,62184,62195,62202,62209,62216,62309,62312,62320,62403,62409,62412,62420,62428,62435,62442,62450,62467,62474,62482,62489,62496,62504,62511,62518,62538,62544,62547,62555,62563,62570,62674,62681,62689,62696,62703,62709,62717,62724,62731,62738,62746,62753,62760,62767,62774,62780,62783,62791,62798,62831,62838,62856,62876,62882],{"data":62103,"content":62107,"nodeType":996},{"target":62104},{"sys":62105},{"id":62106,"type":1001,"linkType":1002},"1eBClNW4NOR66F0tl9h6lD",[],{"data":62109,"content":62110,"nodeType":860},{},[62111,62115,62124],{"data":62112,"marks":62113,"value":62114,"nodeType":864},{},[],"The attacks on Snowflake customers in 2024 collectively constituted the biggest cyber security event of the year in terms of the number of organizations and individuals affected (at least, if you exclude CrowdStrike causing a worldwide outage in July) — certainly, it was the largest perpetrated by a criminal group against commercial enterprises. It has been touted by some news outlets as ‘",{"data":62116,"content":62118,"nodeType":883},{"uri":62117},"https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/",[62119],{"data":62120,"marks":62121,"value":62123,"nodeType":864},{},[62122],{"type":1455},"one of the biggest breaches ever",{"data":62125,"marks":62126,"value":62127,"nodeType":864},{},[],"’.  ",{"data":62129,"content":62130,"nodeType":860},{},[62131],{"data":62132,"marks":62133,"value":62134,"nodeType":864},{},[],"Snowflake was a watershed moment that signalled the significant opportunity presented by identity attacks on cloud services. It demonstrated how comparatively unsophisticated methods (logging in to user accounts with stolen credentials and dumping the data) can have the same or greater impact as a traditional network or endpoint based cyber attack involving vulnerability exploitation, malware deployment, ransomware, etc. ",{"data":62136,"content":62137,"nodeType":860},{},[62138],{"data":62139,"marks":62140,"value":62141,"nodeType":864},{},[],"Here’s everything you need to know about the Snowflake attacks — and what you can do to protect yourself against the next Snowflake in the future.",{"data":62143,"content":62147,"nodeType":996},{"target":62144},{"sys":62145},{"id":62146,"type":1001,"linkType":1002},"4QoPUiP5q6Mwj1eWUZT15Q",[],{"data":62149,"content":62150,"nodeType":1005},{},[],{"data":62152,"content":62153,"nodeType":1009},{},[62154],{"data":62155,"marks":62156,"value":62158,"nodeType":864},{},[62157],{"type":899},"Snowflake: The facts",{"data":62160,"content":62161,"nodeType":860},{},[62162],{"data":62163,"marks":62164,"value":62165,"nodeType":864},{},[],"Cyber criminals associated with the threat group known as ShinyHunters claimed responsibility for breaching multiple organizations using Snowflake, a cloud-based data warehousing and analytics platform. ",{"data":62167,"content":62168,"nodeType":860},{},[62169,62173,62181],{"data":62170,"marks":62171,"value":62172,"nodeType":864},{},[],"ShinyHunters associates targeted ~165 organizations that were subjected to account takeover attacks using stolen credentials harvested from historical infostealer infections dating back as far as 2020, ",{"data":62174,"content":62175,"nodeType":883},{"uri":29070},[62176],{"data":62177,"marks":62178,"value":62180,"nodeType":864},{},[62179],{"type":1455},"according to Mandiant’s investigation",{"data":62182,"marks":62183,"value":11546,"nodeType":864},{},[],{"data":62185,"content":62186,"nodeType":1116},{},[62187],{"data":62188,"content":62189,"nodeType":860},{},[62190],{"data":62191,"marks":62192,"value":62194,"nodeType":864},{},[62193],{"type":899},">80% of the compromised accounts belonging to Snowflake customers had prior credential exposure. ",{"data":62196,"content":62197,"nodeType":860},{},[62198],{"data":62199,"marks":62200,"value":62201,"nodeType":864},{},[],"The impacted accounts lacked MFA, meaning successful authentication only required a valid username and password. As the Snowflake credentials found in infostealer malware credential dumps had not been rotated or updated, they remained valid and could be used to authenticate to user accounts on Snowflake tenants belonging to various customers.",{"data":62203,"content":62204,"nodeType":860},{},[62205],{"data":62206,"marks":62207,"value":62208,"nodeType":864},{},[],"As a data warehousing platform integrated with a range of connected cloud services, access to a customer’s Snowflake tenant provided attackers with large quantities of sensitive commercial and personal data that could be stolen and monetized by attackers in a variety of ways — such as by ransoming the victim organization, extorting individual end-customers, and selling the data on to other criminal organizations. ",{"data":62210,"content":62211,"nodeType":860},{},[62212],{"data":62213,"marks":62214,"value":62215,"nodeType":864},{},[],"In total, 9 public victims were named following the breach, collectively impacting hundreds of millions of people. ",{"data":62217,"content":62218,"nodeType":941},{},[62219,62229,62239,62249,62259,62269,62279,62289,62299],{"data":62220,"content":62221,"nodeType":945},{},[62222],{"data":62223,"content":62224,"nodeType":860},{},[62225],{"data":62226,"marks":62227,"value":62228,"nodeType":864},{},[],"Lending Tree: Sensitive data for over 190 million people available online including customer details, partial credit card numbers, insurance quotes and other information, being sold for $2m.",{"data":62230,"content":62231,"nodeType":945},{},[62232],{"data":62233,"content":62234,"nodeType":860},{},[62235],{"data":62236,"marks":62237,"value":62238,"nodeType":864},{},[],"Truist Bank: Information belonging to 65,000 employees being sold online for $1m",{"data":62240,"content":62241,"nodeType":945},{},[62242],{"data":62243,"content":62244,"nodeType":860},{},[62245],{"data":62246,"marks":62247,"value":62248,"nodeType":864},{},[],"Advance Auto Parts: 3TB of data for sale for $1.5 million. Affected 2.3 million people, as well as current and former employees and job applicants.",{"data":62250,"content":62251,"nodeType":945},{},[62252],{"data":62253,"content":62254,"nodeType":860},{},[62255],{"data":62256,"marks":62257,"value":62258,"nodeType":864},{},[],"Pure Storage: Workspace with 11k customer records including company, email, LDAP username and software version numbers.",{"data":62260,"content":62261,"nodeType":945},{},[62262],{"data":62263,"content":62264,"nodeType":860},{},[62265],{"data":62266,"marks":62267,"value":62268,"nodeType":864},{},[],"Los Angeles Unified: Student data, disability information, discipline details, and parent information, being sold online for $150k.",{"data":62270,"content":62271,"nodeType":945},{},[62272],{"data":62273,"content":62274,"nodeType":860},{},[62275],{"data":62276,"marks":62277,"value":62278,"nodeType":864},{},[],"Neiman Marcus: 31m email addresses exposed alongside various personal information.",{"data":62280,"content":62281,"nodeType":945},{},[62282],{"data":62283,"content":62284,"nodeType":860},{},[62285],{"data":62286,"marks":62287,"value":62288,"nodeType":864},{},[],"Santander: 30 million customer details for sale relating to customers of Santander Chile, Spain, and Uruguay.",{"data":62290,"content":62291,"nodeType":945},{},[62292],{"data":62293,"content":62294,"nodeType":860},{},[62295],{"data":62296,"marks":62297,"value":62298,"nodeType":864},{},[],"Ticketmaster: 560 million customer details for sale, disruption to events and ticketing worldwide, increasing in scam ticket production.",{"data":62300,"content":62301,"nodeType":945},{},[62302],{"data":62303,"content":62304,"nodeType":860},{},[62305],{"data":62306,"marks":62307,"value":62308,"nodeType":864},{},[],"AT&T: Call logs stolen for approximately 109 million customers (nearly all of its mobile customers). AT&T paid an undisclosed ransom fee. ",{"data":62310,"content":62311,"nodeType":1005},{},[],{"data":62313,"content":62314,"nodeType":1009},{},[62315],{"data":62316,"marks":62317,"value":62319,"nodeType":864},{},[62318],{"type":899},"The Snowflake attacks step-by-step",{"data":62321,"content":62322,"nodeType":941},{},[62323,62333,62343,62353,62363,62373,62383,62393],{"data":62324,"content":62325,"nodeType":945},{},[62326],{"data":62327,"content":62328,"nodeType":860},{},[62329],{"data":62330,"marks":62331,"value":62332,"nodeType":864},{},[],"Snowflake users were infected with infostealer malware that harvested credentials from user devices over an extended period via several infostealer malware variants, including; VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER.",{"data":62334,"content":62335,"nodeType":945},{},[62336],{"data":62337,"content":62338,"nodeType":860},{},[62339],{"data":62340,"marks":62341,"value":62342,"nodeType":864},{},[],"Credentials appeared on criminal marketplaces e.g. dark web forums and Telegram channels.",{"data":62344,"content":62345,"nodeType":945},{},[62346],{"data":62347,"content":62348,"nodeType":860},{},[62349],{"data":62350,"marks":62351,"value":62352,"nodeType":864},{},[],"ShinyHunters saw the potential in targeting Snowflake users, based on the availability of credentials, number of customer organizations, and the value of the data that can be accessed in Snowflake. ",{"data":62354,"content":62355,"nodeType":945},{},[62356],{"data":62357,"content":62358,"nodeType":860},{},[62359],{"data":62360,"marks":62361,"value":62362,"nodeType":864},{},[],"ShinyHunters embarked on a large-scale campaign targeting Snowflake customer accounts using previously breached credentials. ",{"data":62364,"content":62365,"nodeType":945},{},[62366],{"data":62367,"content":62368,"nodeType":860},{},[62369],{"data":62370,"marks":62371,"value":62372,"nodeType":864},{},[],"ShinyHunters accessed user accounts that lacked MFA, belonging to approximately 165 Snowflake customers. ",{"data":62374,"content":62375,"nodeType":945},{},[62376],{"data":62377,"content":62378,"nodeType":860},{},[62379],{"data":62380,"marks":62381,"value":62382,"nodeType":864},{},[],"ShinyHunters used SQL-based reconnaissance, staging, and data exfiltration techniques, expedited by custom hacker tooling developed specifically for Snowflake, to conduct attacks at scale.",{"data":62384,"content":62385,"nodeType":945},{},[62386],{"data":62387,"content":62388,"nodeType":860},{},[62389],{"data":62390,"marks":62391,"value":62392,"nodeType":864},{},[],"ShinyHunters acquired massive quantities of Snowflake data based on the information that each customer stored in Snowflake or connected apps. ",{"data":62394,"content":62395,"nodeType":945},{},[62396],{"data":62397,"content":62398,"nodeType":860},{},[62399],{"data":62400,"marks":62401,"value":62402,"nodeType":864},{},[],"ShinyHunters began attempts to extort Snowflake and end-customers using the data acquired.",{"data":62404,"content":62408,"nodeType":996},{"target":62405},{"sys":62406},{"id":62407,"type":1001,"linkType":1002},"2J92gFLs1wAAGC4nQTaiWu",[],{"data":62410,"content":62411,"nodeType":1005},{},[],{"data":62413,"content":62414,"nodeType":1009},{},[62415],{"data":62416,"marks":62417,"value":62419,"nodeType":864},{},[62418],{"type":899},"Why did the Snowflake breaches happen?",{"data":62421,"content":62422,"nodeType":1312},{},[62423],{"data":62424,"marks":62425,"value":62427,"nodeType":864},{},[62426],{"type":899},"Stolen credentials remained valid for years",{"data":62429,"content":62430,"nodeType":860},{},[62431],{"data":62432,"marks":62433,"value":62434,"nodeType":864},{},[],"The credentials used to access Snowflake accounts from historical infostealer infections had not been changed or rotated despite dating back as far as 2020, and remained valid. ",{"data":62436,"content":62437,"nodeType":860},{},[62438],{"data":62439,"marks":62440,"value":62441,"nodeType":864},{},[],"This highlights the potential risk of breached credentials already in the public domain, particularly in the case of cloud services like Snowflake that may not be subject to the same levels of credential hygiene as other traditional enterprise domain accounts. ",{"data":62443,"content":62444,"nodeType":1312},{},[62445],{"data":62446,"marks":62447,"value":62449,"nodeType":864},{},[62448],{"type":899},"Local logins lacked MFA ",{"data":62451,"content":62452,"nodeType":860},{},[62453,62457,62464],{"data":62454,"marks":62455,"value":62456,"nodeType":864},{},[],"Even where organizations were primarily encouraging employees to use SSO to access their Snowflake tenant, previously created local logins with a username and password continue to exist even after introducing SSO-based logins. Further, MFA was not globally enforceable at the application level, meaning that MFA was only set when logging into an IdP account for SSO, but not for local logins. We call this problem ",{"data":62458,"content":62459,"nodeType":883},{"uri":11813},[62460],{"data":62461,"marks":62462,"value":29819,"nodeType":864},{},[62463],{"type":1455},{"data":62465,"marks":62466,"value":11546,"nodeType":864},{},[],{"data":62468,"content":62469,"nodeType":860},{},[62470],{"data":62471,"marks":62472,"value":62473,"nodeType":864},{},[],"This meant that attackers were able to take over Snowflake accounts with only a single authentication factor (username & password). ",{"data":62475,"content":62476,"nodeType":1312},{},[62477],{"data":62478,"marks":62479,"value":62481,"nodeType":864},{},[62480],{"type":899},"Snowflake was a high-value target used by many organizations",{"data":62483,"content":62484,"nodeType":860},{},[62485],{"data":62486,"marks":62487,"value":62488,"nodeType":864},{},[],"As a data warehousing platform used by a vast number of organizations, Snowflake represented a high-value target based on the data typically stored within it, and the repeatable way in which Snowflake users could be targeted. ",{"data":62490,"content":62491,"nodeType":860},{},[62492],{"data":62493,"marks":62494,"value":62495,"nodeType":864},{},[],"The attacker followed a near identical process when targeting Snowflake victims, meaning it could be scripted and executed at scale, with attacks taking a matter of minutes. ",{"data":62497,"content":62498,"nodeType":1312},{},[62499],{"data":62500,"marks":62501,"value":62503,"nodeType":864},{},[62502],{"type":899},"Infostealer infections are driving credential availability",{"data":62505,"content":62506,"nodeType":860},{},[62507],{"data":62508,"marks":62509,"value":62510,"nodeType":864},{},[],"Infostealers are often seen as a low-priority issue, but are the primary source of stolen credentials used in campaigns like this one. ",{"data":62512,"content":62513,"nodeType":860},{},[62514],{"data":62515,"marks":62516,"value":62517,"nodeType":864},{},[],"EDR is a strong protection but is often bypassed by infostealers as attackers continually modify them to bypass security controls. Further, unmanaged devices such as those used by third-party contractors or BYOD employees often lack the robust controls applied to company-managed devices and are naturally more susceptible to infostealer attacks. And since browser profiles can be synced across devices, even personal device compromises can result in the capture of corporate credentials.  ",{"data":62519,"content":62520,"nodeType":860},{},[62521,62525,62534],{"data":62522,"marks":62523,"value":62524,"nodeType":864},{},[],"There is some suggestion that targeting key third-party suppliers – ",{"data":62526,"content":62528,"nodeType":883},{"uri":62527},"https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/",[62529],{"data":62530,"marks":62531,"value":62533,"nodeType":864},{},[62532],{"type":1455},"such as EPAM Systems, a software engineering firm and Snowflake ‘Elite Tier Partner’",{"data":62535,"marks":62536,"value":62537,"nodeType":864},{},[]," – provided some of the access to Snowflake customers needed. It’s unclear what came first, but it’s possible (likely, even) that EPAM was identified as a target specifically because of its lucrative customer base and Snowflake credentials — adding another indicator that Snowflake was potentially a premeditated attack inspired by the availability of Snowflake credentials online.",{"data":62539,"content":62543,"nodeType":996},{"target":62540},{"sys":62541},{"id":62542,"type":1001,"linkType":1002},"4D0gjt5oJLNKJH8GzjP8Je",[],{"data":62545,"content":62546,"nodeType":1005},{},[],{"data":62548,"content":62549,"nodeType":1009},{},[62550],{"data":62551,"marks":62552,"value":62554,"nodeType":864},{},[62553],{"type":899},"Key takeaways from the Snowflake attacks",{"data":62556,"content":62557,"nodeType":1312},{},[62558],{"data":62559,"marks":62560,"value":62562,"nodeType":864},{},[62561],{"type":899},"Securing your IdP accounts is not enough",{"data":62564,"content":62565,"nodeType":860},{},[62566],{"data":62567,"marks":62568,"value":62569,"nodeType":864},{},[],"SSO can help reduce your identity attack surface, but it's not feasible to get every workforce identity behind it.",{"data":62571,"content":62572,"nodeType":941},{},[62573,62596,62617,62652],{"data":62574,"content":62575,"nodeType":945},{},[62576],{"data":62577,"content":62578,"nodeType":860},{},[62579,62583,62592],{"data":62580,"marks":62581,"value":62582,"nodeType":864},{},[],"Only 1 in 3 apps support SAML SSO, and those that offer it often charge more for it; the “",{"data":62584,"content":62586,"nodeType":883},{"uri":62585},"https://ssotax.org/",[62587],{"data":62588,"marks":62589,"value":62591,"nodeType":864},{},[62590],{"type":1455},"SSO tax",{"data":62593,"marks":62594,"value":62595,"nodeType":864},{},[],"”.",{"data":62597,"content":62598,"nodeType":945},{},[62599],{"data":62600,"content":62601,"nodeType":860},{},[62602,62606,62614],{"data":62603,"marks":62604,"value":62605,"nodeType":864},{},[],"Many apps are self-adopted by employees, leaving security teams unaware and unable to enforce SSO.  The typical organization has ",{"data":62607,"content":62608,"nodeType":883},{"uri":25338},[62609],{"data":62610,"marks":62611,"value":62613,"nodeType":864},{},[62612],{"type":1455},"hundreds of apps and thousands of unmanaged identities outside of SSO",{"data":62615,"marks":62616,"value":2924,"nodeType":864},{},[],{"data":62618,"content":62619,"nodeType":945},{},[62620],{"data":62621,"content":62622,"nodeType":860},{},[62623,62627,62635,62639,62648],{"data":62624,"marks":62625,"value":62626,"nodeType":864},{},[],"Most apps do not prevent users from creating additional \"",{"data":62628,"content":62629,"nodeType":883},{"uri":11813},[62630],{"data":62631,"marks":62632,"value":62634,"nodeType":864},{},[62633],{"type":1455},"ghost login",{"data":62636,"marks":62637,"value":62638,"nodeType":864},{},[],"\" methods outside of SSO (especially by default), accounting for around ",{"data":62640,"content":62642,"nodeType":883},{"uri":62641},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/#id-identity-configurations-and-how-they-can-be-exploited_id-many-accounts-lack-the-most-basic-protections",[62643],{"data":62644,"marks":62645,"value":62647,"nodeType":864},{},[62646],{"type":1455},"10% of all identities",{"data":62649,"marks":62650,"value":62651,"nodeType":864},{},[]," observed by Push. ",{"data":62653,"content":62654,"nodeType":945},{},[62655],{"data":62656,"content":62657,"nodeType":860},{},[62658,62662,62670],{"data":62659,"marks":62660,"value":62661,"nodeType":864},{},[],"In total, we identified that ",{"data":62663,"content":62664,"nodeType":883},{"uri":25338},[62665],{"data":62666,"marks":62667,"value":62669,"nodeType":864},{},[62668],{"type":1455},"37% (2 in 5) accounts have a password login set with no MFA",{"data":62671,"marks":62672,"value":62673,"nodeType":864},{},[],", while 9% have no MFA AND a weak, breached, or reused password.",{"data":62675,"content":62676,"nodeType":860},{},[62677],{"data":62678,"marks":62679,"value":62680,"nodeType":864},{},[],"So, relying on locked-down IdP accounts and maximising the use of SSO is an important pillar of an effective identity security strategy, but there will always be gaps. Unless you recognize this, you may be blindsided by attackers finding them before you do. ",{"data":62682,"content":62683,"nodeType":1312},{},[62684],{"data":62685,"marks":62686,"value":62688,"nodeType":864},{},[62687],{"type":899},"The threat of infostealers and stolen credentials needs to be taken seriously",{"data":62690,"content":62691,"nodeType":860},{},[62692],{"data":62693,"marks":62694,"value":62695,"nodeType":864},{},[],"Breached credentials appearing online is not always seen as a top priority for security teams, particularly when there’s so much noise from all of the outdated or simply erroneous findings (anyone that’s ever subscribed to a credential TI feed knows the pain of this). ",{"data":62697,"content":62698,"nodeType":860},{},[62699],{"data":62700,"marks":62701,"value":62702,"nodeType":864},{},[],"But Snowflake serves as a stark reminder that despite all the false positives, stolen credentials are sometimes valid — and when weaponized at-scale they can be a powerful tool for attackers. ",{"data":62704,"content":62708,"nodeType":996},{"target":62705},{"sys":62706},{"id":62707,"type":1001,"linkType":1002},"4EODpwKsqNivpvP2yMtZCd",[],{"data":62710,"content":62711,"nodeType":1312},{},[62712],{"data":62713,"marks":62714,"value":62716,"nodeType":864},{},[62715],{"type":899},"Don’t rely on third-parties to protect your identities for you",{"data":62718,"content":62719,"nodeType":860},{},[62720],{"data":62721,"marks":62722,"value":62723,"nodeType":864},{},[],"Snowflake came under fire following the attacks for not enabling MFA by default, or giving security teams sufficient tools to deal with the incident. ",{"data":62725,"content":62726,"nodeType":860},{},[62727],{"data":62728,"marks":62729,"value":62730,"nodeType":864},{},[],"This is perhaps justifiable, but is hardly the exception. Very few apps enforce MFA by default or provide a global MFA enforcement mechanism. Most don’t even provide audit logs (and when they do, the scope of logging is pretty limited). And we regularly encounter apps that don’t give you any information about account configuration as an admin — like which accounts have MFA, or the login methods that they’re using (e.g. SSO via SAML, SSO via OIDC, password, which IdPs are being used…) which is essential information to be able to secure your identity attack surface. ",{"data":62732,"content":62733,"nodeType":860},{},[62734],{"data":62735,"marks":62736,"value":62737,"nodeType":864},{},[],"Yes, it would be great if app vendors put security first and made controls available by default, for all customers (not just the premium ones). But in the absence of an industrywide shift toward security-first product development, it’s important that organizations don’t just point the finger at service providers — and take matters into their own hands when it comes to securing their user identities. ",{"data":62739,"content":62740,"nodeType":1312},{},[62741],{"data":62742,"marks":62743,"value":62745,"nodeType":864},{},[62744],{"type":899},"This isn’t a specific Snowflake problem — it could have been any application",{"data":62747,"content":62748,"nodeType":860},{},[62749],{"data":62750,"marks":62751,"value":62752,"nodeType":864},{},[],"While Snowflake was admittedly a high-value target because of the data it collected, apps with sensitive data (or with integrations connecting them to data collected in adjacent apps) are not in short supply. ",{"data":62754,"content":62755,"nodeType":860},{},[62756],{"data":62757,"marks":62758,"value":62759,"nodeType":864},{},[],"If we accept that many other apps are similarly desirable targets, then we should also consider that it’s unlikely that Snowflake is the only app that has valid credentials sitting around on the internet, waiting to be weaponized by criminals. Equally, it’s not the only app that doesn’t require mandatory MFA for user accounts, as we discussed above. The next Snowflake is likely to lurk in the same breached datasets, possibly even using the same credentials.",{"data":62761,"content":62762,"nodeType":860},{},[62763],{"data":62764,"marks":62765,"value":62766,"nodeType":864},{},[],"There’s been a clear increase in the number of infostealer and stolen credential related breaches and news stories since Snowflake as attackers wise up to the potential opportunity and start seeing the dollar signs. It would be naive to think that this was a one off event — the next Snowflake is probably not too far away. ",{"data":62768,"content":62769,"nodeType":860},{},[62770],{"data":62771,"marks":62772,"value":62773,"nodeType":864},{},[],"For a deep-dive analysis of the impact of Snowflake, check out our on-demand webinar from earlier this year.",{"data":62775,"content":62779,"nodeType":996},{"target":62776},{"sys":62777},{"id":62778,"type":1001,"linkType":1002},"7LkU5DqE9HJ1PQu9BTg6Mw",[],{"data":62781,"content":62782,"nodeType":1005},{},[],{"data":62784,"content":62785,"nodeType":1009},{},[62786],{"data":62787,"marks":62788,"value":62790,"nodeType":864},{},[62789],{"type":899},"How to protect yourself from the next Snowflake using Push",{"data":62792,"content":62793,"nodeType":860},{},[62794],{"data":62795,"marks":62796,"value":62797,"nodeType":864},{},[],"Organizations looking to reduce their exposure to account takeover using stolen credentials should look to:",{"data":62799,"content":62800,"nodeType":941},{},[62801,62811,62821],{"data":62802,"content":62803,"nodeType":945},{},[62804],{"data":62805,"content":62806,"nodeType":860},{},[62807],{"data":62808,"marks":62809,"value":62810,"nodeType":864},{},[],"Identify the apps being used across the business and locate vulnerable workforce identities using weak, breached, or reused credentials, and missing MFA. Where SSO is the preferred login method, local username & password logins should ideally be removed. ",{"data":62812,"content":62813,"nodeType":945},{},[62814],{"data":62815,"content":62816,"nodeType":860},{},[62817],{"data":62818,"marks":62819,"value":62820,"nodeType":864},{},[],"Where credentials appear in third-party data breaches, verify where they are still valid and ensure that the credentials are changed. ",{"data":62822,"content":62823,"nodeType":945},{},[62824],{"data":62825,"content":62826,"nodeType":860},{},[62827],{"data":62828,"marks":62829,"value":62830,"nodeType":864},{},[],"Detect unauthorized access to workforce identities where sessions are initiated or resumed from unusual or unexpected locations. It should be noted that while this is a fairly common feature for larger enterprise cloud platforms with configurable access control policies, this is not typically possible for most SaaS applications.  ",{"data":62832,"content":62833,"nodeType":860},{},[62834],{"data":62835,"marks":62836,"value":62837,"nodeType":864},{},[],"All of these use cases can be achieved using Push. The Push browser extension detects all logins performed in employee browsers, capturing granular information about the login method and MFA types used, and enriching this data by integrating with your preferred IdP.",{"data":62839,"content":62840,"nodeType":860},{},[62841,62844,62852],{"data":62842,"marks":62843,"value":1238,"nodeType":864},{},[],{"data":62845,"content":62847,"nodeType":883},{"uri":62846},"https://pushsecurity.com/blog/verified-stolen-credential-detection",[62848],{"data":62849,"marks":62850,"value":62851,"nodeType":864},{},[],"verified stolen credential detection feature",{"data":62853,"marks":62854,"value":62855,"nodeType":864},{},[]," compares a k-anonymized hash of user passwords observed with stolen credential TI feeds to cut through the noise and identify where stolen credentials appearing online represent a genuine vulnerability.   ",{"data":62857,"content":62858,"nodeType":860},{},[62859,62863,62872],{"data":62860,"marks":62861,"value":62862,"nodeType":864},{},[],"On top of this, all logins made in browsers protected by the Push extension, across every app, are verified by ",{"data":62864,"content":62866,"nodeType":883},{"uri":62865},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[62867],{"data":62868,"marks":62869,"value":62871,"nodeType":864},{},[62870],{"type":1455},"adding a unique marker to the user agent string of the session",{"data":62873,"marks":62874,"value":62875,"nodeType":864},{},[],", which will then appear in your IdP logs. This means that any session occurring outside of the Push-protected estate can be flagged to your security team via SIEM alert — including where an attacker uses stolen credentials to log into an app from a browser without the Push extension running. ",{"data":62877,"content":62881,"nodeType":996},{"target":62878},{"sys":62879},{"id":62880,"type":1001,"linkType":1002},"3tqVk7Vr7pYLOEVukIJM2g",[],{"data":62883,"content":62884,"nodeType":860},{},[62885],{"data":62886,"marks":62887,"value":21,"nodeType":864},{},[],"Snowflake: Looking back on 2024’s landmark security event","165 Snowflake customers were targeted by criminals using stolen credentials from infostealer infections, impacting hundreds of millions of people. ","2024-11-29T00:00:00.000Z","snowflake-retro",{"items":62893},[62894],{"sys":62895,"name":13779},{"id":13778},{"items":62897},[62898],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":62899},{"url":2740},"browser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches","blog/browser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches",{"json":62903},{"data":62904,"content":62905,"nodeType":856},{},[62906],{"data":62907,"content":62908,"nodeType":860},{},[62909],{"data":62910,"marks":62911,"value":62912,"nodeType":864},{},[],"Browser sync attacks result in business credentials being compromised via personal account and device breaches. Here's what you need to know. ",{"id":62914,"publishedAt":62915},"4Mq5IZ2E0h9HRT3YkkHaLU","2026-08-12T11:52:59.142Z",{"items":62917},[62918,62920],{"sys":62919,"name":342},{"id":13775},{"sys":62921,"name":13779},{"id":13778},{"items":62923},[62924,62926,62928,62930,62932,62934,62936,62938,62940,62942,62944,62946,62948,62950],{"sys":62925,"name":279,"slug":280,"tier":31},{"id":276},{"sys":62927,"name":297,"slug":298,"tier":31},{"id":294},{"sys":62929,"name":413,"slug":414,"tier":31},{"id":410},{"sys":62931,"name":342,"slug":343,"tier":31},{"id":339},{"sys":62933,"name":642,"slug":643,"tier":31},{"id":639},{"sys":62935,"name":422,"slug":423,"tier":45},{"id":419},{"sys":62937,"name":333,"slug":334,"tier":45},{"id":330},{"sys":62939,"name":466,"slug":467,"tier":45},{"id":463},{"sys":62941,"name":457,"slug":458,"tier":45},{"id":454},{"sys":62943,"name":502,"slug":503,"tier":45},{"id":499},{"sys":62945,"name":288,"slug":289,"tier":45},{"id":285},{"sys":62947,"name":528,"slug":529,"tier":45},{"id":525},{"sys":62949,"name":395,"slug":396,"tier":45},{"id":392},{"sys":62951,"name":571,"slug":572,"tier":45},{"id":568},"ZsXQRkqi5W2ZtXmydvB1CbxG4M10tCO76RfYE_qu3J0",{"id":62954,"title":53419,"authorsCollection":62955,"content":62959,"extension":228,"faqItemsCollection":64369,"faqTitle":59,"featured":6,"hashTags":59,"meta":64371,"metaTitle":64372,"ogImage":59,"postType":59812,"publishedDate":53421,"relatedBlogPostsCollection":64373,"slug":53422,"stem":64375,"subtitle":59,"summary":64376,"synopsis":53420,"sys":64387,"tagsCollection":64389,"topicsCollection":64395,"__hash__":64433},"blog/blog/guide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks.json",{"items":62956},[62957],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":59,"profilePicture":62958},{"url":853},{"json":62960,"links":64121},{"data":62961,"content":62962,"nodeType":856},{},[62963,62969,62990,62996,63001,63007,63013,63019,63024,63027,63034,63040,63045,63050,63063,63244,63254,63261,63267,63273,63279,63295,63300,63306,63309,63316,63322,63351,63357,63370,63387,63415,63420,63426,63441,63447,63453,63456,63463,63469,63552,63558,63564,63571,63577,63583,63589,63594,63601,63607,63613,63619,63624,63630,63637,63652,63659,63665,63670,63673,63680,63686,63692,63786,63792,63799,63805,63811,63817,63823,63830,63836,63842,63862,63867,63880,63893,63906,63911,63918,63924,63931,63937,63940,63947,63953,63980,63985,64005,64011,64014,64021,64027,64040,64045,64051,64057,64060,64067,64082,64088],{"data":62964,"content":62965,"nodeType":860},{},[62966],{"data":62967,"marks":62968,"value":52086,"nodeType":864},{},[],{"data":62970,"content":62971,"nodeType":941},{},[62972,62981],{"data":62973,"content":62974,"nodeType":945},{},[62975],{"data":62976,"content":62977,"nodeType":860},{},[62978],{"data":62979,"marks":62980,"value":52099,"nodeType":864},{},[],{"data":62982,"content":62983,"nodeType":945},{},[62984],{"data":62985,"content":62986,"nodeType":860},{},[62987],{"data":62988,"marks":62989,"value":52109,"nodeType":864},{},[],{"data":62991,"content":62992,"nodeType":860},{},[62993],{"data":62994,"marks":62995,"value":52116,"nodeType":864},{},[],{"data":62997,"content":63000,"nodeType":996},{"target":62998},{"sys":62999},{"id":52121,"type":1001,"linkType":1002},[],{"data":63002,"content":63003,"nodeType":860},{},[63004],{"data":63005,"marks":63006,"value":52129,"nodeType":864},{},[],{"data":63008,"content":63009,"nodeType":860},{},[63010],{"data":63011,"marks":63012,"value":52136,"nodeType":864},{},[],{"data":63014,"content":63015,"nodeType":860},{},[63016],{"data":63017,"marks":63018,"value":52143,"nodeType":864},{},[],{"data":63020,"content":63023,"nodeType":996},{"target":63021},{"sys":63022},{"id":52148,"type":1001,"linkType":1002},[],{"data":63025,"content":63026,"nodeType":1005},{},[],{"data":63028,"content":63029,"nodeType":1009},{},[63030],{"data":63031,"marks":63032,"value":52160,"nodeType":864},{},[63033],{"type":899},{"data":63035,"content":63036,"nodeType":860},{},[63037],{"data":63038,"marks":63039,"value":52167,"nodeType":864},{},[],{"data":63041,"content":63044,"nodeType":996},{"target":63042},{"sys":63043},{"id":52172,"type":1001,"linkType":1002},[],{"data":63046,"content":63049,"nodeType":996},{"target":63047},{"sys":63048},{"id":52178,"type":1001,"linkType":1002},[],{"data":63051,"content":63052,"nodeType":860},{},[63053,63056,63060],{"data":63054,"marks":63055,"value":52186,"nodeType":864},{},[],{"data":63057,"marks":63058,"value":52191,"nodeType":864},{},[63059],{"type":2246},{"data":63061,"marks":63062,"value":52195,"nodeType":864},{},[],{"data":63064,"content":63065,"nodeType":4845},{},[63066,63089,63124,63145,63175,63205],{"data":63067,"content":63068,"nodeType":4581},{},[63069,63079],{"data":63070,"content":63071,"nodeType":14464},{},[63072],{"data":63073,"content":63074,"nodeType":860},{},[63075],{"data":63076,"marks":63077,"value":52212,"nodeType":864},{},[63078],{"type":899},{"data":63080,"content":63081,"nodeType":14464},{},[63082],{"data":63083,"content":63084,"nodeType":860},{},[63085],{"data":63086,"marks":63087,"value":52223,"nodeType":864},{},[63088],{"type":899},{"data":63090,"content":63091,"nodeType":4581},{},[63092,63112],{"data":63093,"content":63094,"nodeType":4569},{},[63095],{"data":63096,"content":63097,"nodeType":860},{},[63098,63101,63109],{"data":63099,"marks":63100,"value":52236,"nodeType":864},{},[],{"data":63102,"content":63105,"nodeType":39736},{"target":63103},{"sys":63104},{"id":39958,"type":1001,"linkType":1002},[63106],{"data":63107,"marks":63108,"value":52245,"nodeType":864},{},[],{"data":63110,"marks":63111,"value":52249,"nodeType":864},{},[],{"data":63113,"content":63114,"nodeType":4569},{},[63115],{"data":63116,"content":63117,"nodeType":860},{},[63118,63121],{"data":63119,"marks":63120,"value":52259,"nodeType":864},{},[],{"data":63122,"marks":63123,"value":52263,"nodeType":864},{},[],{"data":63125,"content":63126,"nodeType":4581},{},[63127,63136],{"data":63128,"content":63129,"nodeType":4569},{},[63130],{"data":63131,"content":63132,"nodeType":860},{},[63133],{"data":63134,"marks":63135,"value":52276,"nodeType":864},{},[],{"data":63137,"content":63138,"nodeType":4569},{},[63139],{"data":63140,"content":63141,"nodeType":860},{},[63142],{"data":63143,"marks":63144,"value":52286,"nodeType":864},{},[],{"data":63146,"content":63147,"nodeType":4581},{},[63148,63166],{"data":63149,"content":63150,"nodeType":4569},{},[63151],{"data":63152,"content":63153,"nodeType":860},{},[63154,63157,63163],{"data":63155,"marks":63156,"value":52299,"nodeType":864},{},[],{"data":63158,"content":63159,"nodeType":883},{"uri":52302},[63160],{"data":63161,"marks":63162,"value":52307,"nodeType":864},{},[],{"data":63164,"marks":63165,"value":14316,"nodeType":864},{},[],{"data":63167,"content":63168,"nodeType":4569},{},[63169],{"data":63170,"content":63171,"nodeType":860},{},[63172],{"data":63173,"marks":63174,"value":52320,"nodeType":864},{},[],{"data":63176,"content":63177,"nodeType":4581},{},[63178,63187],{"data":63179,"content":63180,"nodeType":4569},{},[63181],{"data":63182,"content":63183,"nodeType":860},{},[63184],{"data":63185,"marks":63186,"value":52333,"nodeType":864},{},[],{"data":63188,"content":63189,"nodeType":4569},{},[63190],{"data":63191,"content":63192,"nodeType":860},{},[63193,63196,63202],{"data":63194,"marks":63195,"value":52343,"nodeType":864},{},[],{"data":63197,"content":63198,"nodeType":883},{"uri":3259},[63199],{"data":63200,"marks":63201,"value":18962,"nodeType":864},{},[],{"data":63203,"marks":63204,"value":2924,"nodeType":864},{},[],{"data":63206,"content":63207,"nodeType":4581},{},[63208,63217],{"data":63209,"content":63210,"nodeType":4569},{},[63211],{"data":63212,"content":63213,"nodeType":860},{},[63214],{"data":63215,"marks":63216,"value":52365,"nodeType":864},{},[],{"data":63218,"content":63219,"nodeType":4569},{},[63220],{"data":63221,"content":63222,"nodeType":860},{},[63223,63226,63232,63235,63241],{"data":63224,"marks":63225,"value":21,"nodeType":864},{},[],{"data":63227,"content":63228,"nodeType":883},{"uri":52377},[63229],{"data":63230,"marks":63231,"value":315,"nodeType":864},{},[],{"data":63233,"marks":63234,"value":52385,"nodeType":864},{},[],{"data":63236,"content":63237,"nodeType":883},{"uri":11726},[63238],{"data":63239,"marks":63240,"value":11731,"nodeType":864},{},[],{"data":63242,"marks":63243,"value":52395,"nodeType":864},{},[],{"data":63245,"content":63246,"nodeType":860},{},[63247,63250],{"data":63248,"marks":63249,"value":52402,"nodeType":864},{},[],{"data":63251,"marks":63252,"value":52407,"nodeType":864},{},[63253],{"type":899},{"data":63255,"content":63256,"nodeType":1312},{},[63257],{"data":63258,"marks":63259,"value":52415,"nodeType":864},{},[63260],{"type":899},{"data":63262,"content":63263,"nodeType":860},{},[63264],{"data":63265,"marks":63266,"value":52422,"nodeType":864},{},[],{"data":63268,"content":63269,"nodeType":860},{},[63270],{"data":63271,"marks":63272,"value":52429,"nodeType":864},{},[],{"data":63274,"content":63275,"nodeType":860},{},[63276],{"data":63277,"marks":63278,"value":52436,"nodeType":864},{},[],{"data":63280,"content":63281,"nodeType":860},{},[63282,63285,63288,63292],{"data":63283,"marks":63284,"value":52443,"nodeType":864},{},[],{"data":63286,"marks":63287,"value":52447,"nodeType":864},{},[],{"data":63289,"marks":63290,"value":52452,"nodeType":864},{},[63291],{"type":899},{"data":63293,"marks":63294,"value":52456,"nodeType":864},{},[],{"data":63296,"content":63299,"nodeType":996},{"target":63297},{"sys":63298},{"id":52461,"type":1001,"linkType":1002},[],{"data":63301,"content":63302,"nodeType":860},{},[63303],{"data":63304,"marks":63305,"value":52469,"nodeType":864},{},[],{"data":63307,"content":63308,"nodeType":1005},{},[],{"data":63310,"content":63311,"nodeType":1009},{},[63312],{"data":63313,"marks":63314,"value":52480,"nodeType":864},{},[63315],{"type":899},{"data":63317,"content":63318,"nodeType":860},{},[63319],{"data":63320,"marks":63321,"value":52487,"nodeType":864},{},[],{"data":63323,"content":63324,"nodeType":941},{},[63325,63338],{"data":63326,"content":63327,"nodeType":945},{},[63328],{"data":63329,"content":63330,"nodeType":860},{},[63331,63335],{"data":63332,"marks":63333,"value":52501,"nodeType":864},{},[63334],{"type":899},{"data":63336,"marks":63337,"value":52505,"nodeType":864},{},[],{"data":63339,"content":63340,"nodeType":945},{},[63341],{"data":63342,"content":63343,"nodeType":860},{},[63344,63348],{"data":63345,"marks":63346,"value":52516,"nodeType":864},{},[63347],{"type":899},{"data":63349,"marks":63350,"value":52520,"nodeType":864},{},[],{"data":63352,"content":63353,"nodeType":1312},{},[63354],{"data":63355,"marks":63356,"value":52527,"nodeType":864},{},[],{"data":63358,"content":63359,"nodeType":860},{},[63360,63363,63367],{"data":63361,"marks":63362,"value":52534,"nodeType":864},{},[],{"data":63364,"marks":63365,"value":52539,"nodeType":864},{},[63366],{"type":2246},{"data":63368,"marks":63369,"value":52543,"nodeType":864},{},[],{"data":63371,"content":63372,"nodeType":860},{},[63373,63376,63384],{"data":63374,"marks":63375,"value":52550,"nodeType":864},{},[],{"data":63377,"content":63380,"nodeType":39736},{"target":63378},{"sys":63379},{"id":52555,"type":1001,"linkType":1002},[63381],{"data":63382,"marks":63383,"value":52560,"nodeType":864},{},[],{"data":63385,"marks":63386,"value":52564,"nodeType":864},{},[],{"data":63388,"content":63389,"nodeType":860},{},[63390,63393,63401,63404,63412],{"data":63391,"marks":63392,"value":52571,"nodeType":864},{},[],{"data":63394,"content":63397,"nodeType":39736},{"target":63395},{"sys":63396},{"id":52576,"type":1001,"linkType":1002},[63398],{"data":63399,"marks":63400,"value":52581,"nodeType":864},{},[],{"data":63402,"marks":63403,"value":52585,"nodeType":864},{},[],{"data":63405,"content":63408,"nodeType":39736},{"target":63406},{"sys":63407},{"id":52590,"type":1001,"linkType":1002},[63409],{"data":63410,"marks":63411,"value":52595,"nodeType":864},{},[],{"data":63413,"marks":63414,"value":52599,"nodeType":864},{},[],{"data":63416,"content":63419,"nodeType":996},{"target":63417},{"sys":63418},{"id":52604,"type":1001,"linkType":1002},[],{"data":63421,"content":63422,"nodeType":1312},{},[63423],{"data":63424,"marks":63425,"value":52612,"nodeType":864},{},[],{"data":63427,"content":63428,"nodeType":860},{},[63429,63432,63438],{"data":63430,"marks":63431,"value":52619,"nodeType":864},{},[],{"data":63433,"content":63434,"nodeType":883},{"uri":52622},[63435],{"data":63436,"marks":63437,"value":52627,"nodeType":864},{},[],{"data":63439,"marks":63440,"value":52631,"nodeType":864},{},[],{"data":63442,"content":63443,"nodeType":860},{},[63444],{"data":63445,"marks":63446,"value":52638,"nodeType":864},{},[],{"data":63448,"content":63449,"nodeType":860},{},[63450],{"data":63451,"marks":63452,"value":52645,"nodeType":864},{},[],{"data":63454,"content":63455,"nodeType":1005},{},[],{"data":63457,"content":63458,"nodeType":1009},{},[63459],{"data":63460,"marks":63461,"value":52656,"nodeType":864},{},[63462],{"type":899},{"data":63464,"content":63465,"nodeType":860},{},[63466],{"data":63467,"marks":63468,"value":52663,"nodeType":864},{},[],{"data":63470,"content":63471,"nodeType":941},{},[63472,63492,63512,63532],{"data":63473,"content":63474,"nodeType":945},{},[63475],{"data":63476,"content":63477,"nodeType":860},{},[63478,63481,63489],{"data":63479,"marks":63480,"value":21,"nodeType":864},{},[],{"data":63482,"content":63485,"nodeType":39736},{"target":63483},{"sys":63484},{"id":52680,"type":1001,"linkType":1002},[63486],{"data":63487,"marks":63488,"value":52685,"nodeType":864},{},[],{"data":63490,"marks":63491,"value":52689,"nodeType":864},{},[],{"data":63493,"content":63494,"nodeType":945},{},[63495],{"data":63496,"content":63497,"nodeType":860},{},[63498,63501,63509],{"data":63499,"marks":63500,"value":21,"nodeType":864},{},[],{"data":63502,"content":63505,"nodeType":39736},{"target":63503},{"sys":63504},{"id":52703,"type":1001,"linkType":1002},[63506],{"data":63507,"marks":63508,"value":52708,"nodeType":864},{},[],{"data":63510,"marks":63511,"value":52712,"nodeType":864},{},[],{"data":63513,"content":63514,"nodeType":945},{},[63515],{"data":63516,"content":63517,"nodeType":860},{},[63518,63521,63529],{"data":63519,"marks":63520,"value":21,"nodeType":864},{},[],{"data":63522,"content":63525,"nodeType":39736},{"target":63523},{"sys":63524},{"id":52726,"type":1001,"linkType":1002},[63526],{"data":63527,"marks":63528,"value":699,"nodeType":864},{},[],{"data":63530,"marks":63531,"value":21,"nodeType":864},{},[],{"data":63533,"content":63534,"nodeType":945},{},[63535],{"data":63536,"content":63537,"nodeType":860},{},[63538,63541,63549],{"data":63539,"marks":63540,"value":21,"nodeType":864},{},[],{"data":63542,"content":63545,"nodeType":39736},{"target":63543},{"sys":63544},{"id":52747,"type":1001,"linkType":1002},[63546],{"data":63547,"marks":63548,"value":52752,"nodeType":864},{},[],{"data":63550,"marks":63551,"value":52756,"nodeType":864},{},[],{"data":63553,"content":63554,"nodeType":860},{},[63555],{"data":63556,"marks":63557,"value":52763,"nodeType":864},{},[],{"data":63559,"content":63560,"nodeType":860},{},[63561],{"data":63562,"marks":63563,"value":52770,"nodeType":864},{},[],{"data":63565,"content":63566,"nodeType":1312},{},[63567],{"data":63568,"marks":63569,"value":52778,"nodeType":864},{},[63570],{"type":899},{"data":63572,"content":63573,"nodeType":860},{},[63574],{"data":63575,"marks":63576,"value":52785,"nodeType":864},{},[],{"data":63578,"content":63579,"nodeType":860},{},[63580],{"data":63581,"marks":63582,"value":52792,"nodeType":864},{},[],{"data":63584,"content":63585,"nodeType":860},{},[63586],{"data":63587,"marks":63588,"value":52799,"nodeType":864},{},[],{"data":63590,"content":63593,"nodeType":996},{"target":63591},{"sys":63592},{"id":40048,"type":1001,"linkType":1002},[],{"data":63595,"content":63596,"nodeType":1312},{},[63597],{"data":63598,"marks":63599,"value":52812,"nodeType":864},{},[63600],{"type":899},{"data":63602,"content":63603,"nodeType":860},{},[63604],{"data":63605,"marks":63606,"value":52819,"nodeType":864},{},[],{"data":63608,"content":63609,"nodeType":860},{},[63610],{"data":63611,"marks":63612,"value":52826,"nodeType":864},{},[],{"data":63614,"content":63615,"nodeType":860},{},[63616],{"data":63617,"marks":63618,"value":52833,"nodeType":864},{},[],{"data":63620,"content":63623,"nodeType":996},{"target":63621},{"sys":63622},{"id":52838,"type":1001,"linkType":1002},[],{"data":63625,"content":63626,"nodeType":860},{},[63627],{"data":63628,"marks":63629,"value":52846,"nodeType":864},{},[],{"data":63631,"content":63632,"nodeType":1312},{},[63633],{"data":63634,"marks":63635,"value":52854,"nodeType":864},{},[63636],{"type":899},{"data":63638,"content":63639,"nodeType":860},{},[63640,63643,63649],{"data":63641,"marks":63642,"value":52861,"nodeType":864},{},[],{"data":63644,"content":63645,"nodeType":883},{"uri":52864},[63646],{"data":63647,"marks":63648,"value":52869,"nodeType":864},{},[],{"data":63650,"marks":63651,"value":1774,"nodeType":864},{},[],{"data":63653,"content":63654,"nodeType":1312},{},[63655],{"data":63656,"marks":63657,"value":52880,"nodeType":864},{},[63658],{"type":899},{"data":63660,"content":63661,"nodeType":860},{},[63662],{"data":63663,"marks":63664,"value":52887,"nodeType":864},{},[],{"data":63666,"content":63669,"nodeType":996},{"target":63667},{"sys":63668},{"id":52892,"type":1001,"linkType":1002},[],{"data":63671,"content":63672,"nodeType":1005},{},[],{"data":63674,"content":63675,"nodeType":1009},{},[63676],{"data":63677,"marks":63678,"value":52904,"nodeType":864},{},[63679],{"type":899},{"data":63681,"content":63682,"nodeType":860},{},[63683],{"data":63684,"marks":63685,"value":52911,"nodeType":864},{},[],{"data":63687,"content":63688,"nodeType":860},{},[63689],{"data":63690,"marks":63691,"value":52918,"nodeType":864},{},[],{"data":63693,"content":63694,"nodeType":941},{},[63695,63715,63746,63766],{"data":63696,"content":63697,"nodeType":945},{},[63698],{"data":63699,"content":63700,"nodeType":860},{},[63701,63704,63712],{"data":63702,"marks":63703,"value":21,"nodeType":864},{},[],{"data":63705,"content":63708,"nodeType":39736},{"target":63706},{"sys":63707},{"id":52935,"type":1001,"linkType":1002},[63709],{"data":63710,"marks":63711,"value":52940,"nodeType":864},{},[],{"data":63713,"marks":63714,"value":52944,"nodeType":864},{},[],{"data":63716,"content":63717,"nodeType":945},{},[63718],{"data":63719,"content":63720,"nodeType":860},{},[63721,63724,63732,63735,63743],{"data":63722,"marks":63723,"value":52954,"nodeType":864},{},[],{"data":63725,"content":63728,"nodeType":39736},{"target":63726},{"sys":63727},{"id":52959,"type":1001,"linkType":1002},[63729],{"data":63730,"marks":63731,"value":52964,"nodeType":864},{},[],{"data":63733,"marks":63734,"value":52968,"nodeType":864},{},[],{"data":63736,"content":63739,"nodeType":39736},{"target":63737},{"sys":63738},{"id":52973,"type":1001,"linkType":1002},[63740],{"data":63741,"marks":63742,"value":52978,"nodeType":864},{},[],{"data":63744,"marks":63745,"value":52982,"nodeType":864},{},[],{"data":63747,"content":63748,"nodeType":945},{},[63749],{"data":63750,"content":63751,"nodeType":860},{},[63752,63755,63763],{"data":63753,"marks":63754,"value":52992,"nodeType":864},{},[],{"data":63756,"content":63759,"nodeType":39736},{"target":63757},{"sys":63758},{"id":52997,"type":1001,"linkType":1002},[63760],{"data":63761,"marks":63762,"value":53002,"nodeType":864},{},[],{"data":63764,"marks":63765,"value":53006,"nodeType":864},{},[],{"data":63767,"content":63768,"nodeType":945},{},[63769],{"data":63770,"content":63771,"nodeType":860},{},[63772,63775,63783],{"data":63773,"marks":63774,"value":21,"nodeType":864},{},[],{"data":63776,"content":63779,"nodeType":39736},{"target":63777},{"sys":63778},{"id":53020,"type":1001,"linkType":1002},[63780],{"data":63781,"marks":63782,"value":53025,"nodeType":864},{},[],{"data":63784,"marks":63785,"value":53029,"nodeType":864},{},[],{"data":63787,"content":63788,"nodeType":860},{},[63789],{"data":63790,"marks":63791,"value":52770,"nodeType":864},{},[],{"data":63793,"content":63794,"nodeType":1312},{},[63795],{"data":63796,"marks":63797,"value":52778,"nodeType":864},{},[63798],{"type":899},{"data":63800,"content":63801,"nodeType":860},{},[63802],{"data":63803,"marks":63804,"value":53049,"nodeType":864},{},[],{"data":63806,"content":63807,"nodeType":860},{},[63808],{"data":63809,"marks":63810,"value":53056,"nodeType":864},{},[],{"data":63812,"content":63813,"nodeType":860},{},[63814],{"data":63815,"marks":63816,"value":53063,"nodeType":864},{},[],{"data":63818,"content":63819,"nodeType":860},{},[63820],{"data":63821,"marks":63822,"value":53070,"nodeType":864},{},[],{"data":63824,"content":63825,"nodeType":1312},{},[63826],{"data":63827,"marks":63828,"value":53078,"nodeType":864},{},[63829],{"type":899},{"data":63831,"content":63832,"nodeType":860},{},[63833],{"data":63834,"marks":63835,"value":53085,"nodeType":864},{},[],{"data":63837,"content":63838,"nodeType":860},{},[63839],{"data":63840,"marks":63841,"value":53092,"nodeType":864},{},[],{"data":63843,"content":63844,"nodeType":860},{},[63845,63848,63852,63855,63859],{"data":63846,"marks":63847,"value":53099,"nodeType":864},{},[],{"data":63849,"marks":63850,"value":53104,"nodeType":864},{},[63851],{"type":899},{"data":63853,"marks":63854,"value":902,"nodeType":864},{},[],{"data":63856,"marks":63857,"value":53112,"nodeType":864},{},[63858],{"type":899},{"data":63860,"marks":63861,"value":53116,"nodeType":864},{},[],{"data":63863,"content":63866,"nodeType":996},{"target":63864},{"sys":63865},{"id":53121,"type":1001,"linkType":1002},[],{"data":63868,"content":63869,"nodeType":860},{},[63870,63873,63877],{"data":63871,"marks":63872,"value":53129,"nodeType":864},{},[],{"data":63874,"marks":63875,"value":53134,"nodeType":864},{},[63876],{"type":899},{"data":63878,"marks":63879,"value":53138,"nodeType":864},{},[],{"data":63881,"content":63882,"nodeType":860},{},[63883,63886,63890],{"data":63884,"marks":63885,"value":53129,"nodeType":864},{},[],{"data":63887,"marks":63888,"value":53149,"nodeType":864},{},[63889],{"type":899},{"data":63891,"marks":63892,"value":53153,"nodeType":864},{},[],{"data":63894,"content":63895,"nodeType":860},{},[63896,63899,63903],{"data":63897,"marks":63898,"value":53160,"nodeType":864},{},[],{"data":63900,"marks":63901,"value":1366,"nodeType":864},{},[63902],{"type":899},{"data":63904,"marks":63905,"value":53168,"nodeType":864},{},[],{"data":63907,"content":63910,"nodeType":996},{"target":63908},{"sys":63909},{"id":53173,"type":1001,"linkType":1002},[],{"data":63912,"content":63913,"nodeType":1312},{},[63914],{"data":63915,"marks":63916,"value":53182,"nodeType":864},{},[63917],{"type":899},{"data":63919,"content":63920,"nodeType":860},{},[63921],{"data":63922,"marks":63923,"value":53189,"nodeType":864},{},[],{"data":63925,"content":63926,"nodeType":1312},{},[63927],{"data":63928,"marks":63929,"value":53197,"nodeType":864},{},[63930],{"type":899},{"data":63932,"content":63933,"nodeType":860},{},[63934],{"data":63935,"marks":63936,"value":53204,"nodeType":864},{},[],{"data":63938,"content":63939,"nodeType":1005},{},[],{"data":63941,"content":63942,"nodeType":1009},{},[63943],{"data":63944,"marks":63945,"value":53215,"nodeType":864},{},[63946],{"type":899},{"data":63948,"content":63949,"nodeType":860},{},[63950],{"data":63951,"marks":63952,"value":53222,"nodeType":864},{},[],{"data":63954,"content":63955,"nodeType":860},{},[63956,63959,63963,63966,63970,63973,63977],{"data":63957,"marks":63958,"value":53229,"nodeType":864},{},[],{"data":63960,"marks":63961,"value":1334,"nodeType":864},{},[63962],{"type":899},{"data":63964,"marks":63965,"value":53237,"nodeType":864},{},[],{"data":63967,"marks":63968,"value":53112,"nodeType":864},{},[63969],{"type":899},{"data":63971,"marks":63972,"value":53245,"nodeType":864},{},[],{"data":63974,"marks":63975,"value":53250,"nodeType":864},{},[63976],{"type":899},{"data":63978,"marks":63979,"value":53254,"nodeType":864},{},[],{"data":63981,"content":63984,"nodeType":996},{"target":63982},{"sys":63983},{"id":53259,"type":1001,"linkType":1002},[],{"data":63986,"content":63987,"nodeType":860},{},[63988,63991,63995,63998,64002],{"data":63989,"marks":63990,"value":53267,"nodeType":864},{},[],{"data":63992,"marks":63993,"value":1503,"nodeType":864},{},[63994],{"type":899},{"data":63996,"marks":63997,"value":52968,"nodeType":864},{},[],{"data":63999,"marks":64000,"value":1397,"nodeType":864},{},[64001],{"type":899},{"data":64003,"marks":64004,"value":53282,"nodeType":864},{},[],{"data":64006,"content":64007,"nodeType":860},{},[64008],{"data":64009,"marks":64010,"value":53289,"nodeType":864},{},[],{"data":64012,"content":64013,"nodeType":1005},{},[],{"data":64015,"content":64016,"nodeType":1009},{},[64017],{"data":64018,"marks":64019,"value":53300,"nodeType":864},{},[64020],{"type":899},{"data":64022,"content":64023,"nodeType":860},{},[64024],{"data":64025,"marks":64026,"value":53307,"nodeType":864},{},[],{"data":64028,"content":64029,"nodeType":860},{},[64030,64033,64037],{"data":64031,"marks":64032,"value":53314,"nodeType":864},{},[],{"data":64034,"marks":64035,"value":53319,"nodeType":864},{},[64036],{"type":899},{"data":64038,"marks":64039,"value":53323,"nodeType":864},{},[],{"data":64041,"content":64044,"nodeType":996},{"target":64042},{"sys":64043},{"id":53328,"type":1001,"linkType":1002},[],{"data":64046,"content":64047,"nodeType":860},{},[64048],{"data":64049,"marks":64050,"value":53336,"nodeType":864},{},[],{"data":64052,"content":64053,"nodeType":860},{},[64054],{"data":64055,"marks":64056,"value":53343,"nodeType":864},{},[],{"data":64058,"content":64059,"nodeType":1005},{},[],{"data":64061,"content":64062,"nodeType":1009},{},[64063],{"data":64064,"marks":64065,"value":3578,"nodeType":864},{},[64066],{"type":899},{"data":64068,"content":64069,"nodeType":860},{},[64070,64073,64079],{"data":64071,"marks":64072,"value":53360,"nodeType":864},{},[],{"data":64074,"content":64075,"nodeType":883},{"uri":152},[64076],{"data":64077,"marks":64078,"value":53367,"nodeType":864},{},[],{"data":64080,"marks":64081,"value":53371,"nodeType":864},{},[],{"data":64083,"content":64084,"nodeType":860},{},[64085],{"data":64086,"marks":64087,"value":53378,"nodeType":864},{},[],{"data":64089,"content":64090,"nodeType":860},{},[64091,64094,64100,64103,64109,64112,64118],{"data":64092,"marks":64093,"value":53385,"nodeType":864},{},[],{"data":64095,"content":64096,"nodeType":883},{"uri":53388},[64097],{"data":64098,"marks":64099,"value":53393,"nodeType":864},{},[],{"data":64101,"marks":64102,"value":53397,"nodeType":864},{},[],{"data":64104,"content":64105,"nodeType":883},{"uri":53400},[64106],{"data":64107,"marks":64108,"value":53405,"nodeType":864},{},[],{"data":64110,"marks":64111,"value":53409,"nodeType":864},{},[],{"data":64113,"content":64114,"nodeType":883},{"uri":40635},[64115],{"data":64116,"marks":64117,"value":2715,"nodeType":864},{},[],{"data":64119,"marks":64120,"value":2924,"nodeType":864},{},[],{"entries":64122},{"inline":64123,"hyperlink":64124,"block":64187},[],[64125,64129,64133,64137,64141,64147,64152,64157,64162,64167,64172,64177,64182],{"sys":64126,"__typename":2059,"title":64127,"slug":64128},{"id":39958},"Google Search malvertising campaign continues, now impersonating Ahrefs","google-search-malvertising-campaign-continues-now-impersonating-ahrefs",{"sys":64130,"__typename":2059,"title":64131,"slug":64132},{"id":52555},"Push + Network Security: The gap between seeing the packet and securing the session","push-plus-network-security",{"sys":64134,"__typename":2059,"title":64135,"slug":64136},{"id":52576},"Push + Endpoint Security: Extending detection and response to the browser","push-plus-endpoint-security",{"sys":64138,"__typename":2059,"title":64139,"slug":64140},{"id":52590},"Push + Cloud Security: What do you do when bad looks normal?","push-plus-cloud-security",{"sys":64142,"__typename":64143,"title":64144,"slug":64145,"articleId":64146},{"id":52680},"HelpArticle","Can I use Push to detect phishing tools like Evilginx, Modlishka, NakedPages, or Muraena?","can-i-use-push-to-detect-phishing-tools-like-evilnovnc-and-evilginx",10113,{"sys":64148,"__typename":64143,"title":64149,"slug":64150,"articleId":64151},{"id":52703},"How does Push detect cloned login pages?","how-does-push-detect-cloned-login-pages",10117,{"sys":64153,"__typename":64143,"title":64154,"slug":64155,"articleId":64156},{"id":52726},"How does Push detect malicious browser extensions?","how-does-push-detect-malicious-browser-extensions",10148,{"sys":64158,"__typename":64143,"title":64159,"slug":64160,"articleId":64161},{"id":52747},"How does Push detect attacks like ClickFix and FileFix?","how-does-push-detect-attacks-like-clickfix-and-filefix",10141,{"sys":64163,"__typename":64143,"title":64164,"slug":64165,"articleId":64166},{"id":52935},"How does Push protect passwords from being reused or phished?","how-does-push-detect-and-prevent-phishing-attacks",10109,{"sys":64168,"__typename":64143,"title":64169,"slug":64170,"articleId":64171},{"id":52959},"How does MFA enforcement work?","how-does-mfa-enforcement-work",10121,{"sys":64173,"__typename":64143,"title":64174,"slug":64175,"articleId":64176},{"id":52973},"How does strong password enforcement work?","how-does-strong-password-enforcement-work",10129,{"sys":64178,"__typename":64143,"title":64179,"slug":64180,"articleId":64181},{"id":52997},"What can I use the app banner for? Templates and examples","what-can-i-use-the-app-banner-for-templates-and-examples",10106,{"sys":64183,"__typename":64143,"title":64184,"slug":64185,"articleId":64186},{"id":53020},"Can Push detect and disable other installed browser extensions?","can-push-detect-other-installed-browser-extensions",10138,[64188,64224,64228,64247,64254,64279,64316,64321,64329,64337,64345,64353,64361],{"sys":64189,"__typename":1740,"content":64190,"name":64223,"title":59},{"id":52121},{"json":64191},{"nodeType":856,"data":64192,"content":64193},{},[64194],{"nodeType":860,"data":64195,"content":64196},{},[64197,64200,64208,64212,64219],{"nodeType":864,"value":21,"marks":64198,"data":64199},[],{},{"nodeType":883,"data":64201,"content":64203},{"uri":64202},"https://www.crowdstrike.com/explore/2026-global-threat-report?utm_medium=dir",[64204],{"nodeType":864,"value":64205,"marks":64206,"data":64207},"Crowdstrike reports",[],{},{"nodeType":864,"value":64209,"marks":64210,"data":64211}," that valid account abuse accounted for 35% of incidents in 2025, while ",[],{},{"nodeType":883,"data":64213,"content":64214},{"uri":7170},[64215],{"nodeType":864,"value":64216,"marks":64217,"data":64218},"Verizon reports",[],{},{"nodeType":864,"value":64220,"marks":64221,"data":64222}," that identity is now the primary breach vector observed across all methods.",[],{},"Guide: Protecting Users IB 1",{"sys":64225,"__typename":12999,"title":64226,"arcadeDemoUrl":64227,"playText":13002},{"id":52148},"Custom branding for Push controls","https://demo.arcade.software/kBqjoJqArDTsUtB6HHwR?embed",{"sys":64229,"__typename":1740,"content":64230,"name":64246,"title":59},{"id":52172},{"json":64231},{"nodeType":856,"data":64232,"content":64233},{},[64234],{"nodeType":860,"data":64235,"content":64236},{},[64237,64241],{"nodeType":864,"value":64238,"marks":64239,"data":64240},"It's harder than ever to identify malicious scenarios when browsing the web as part of your routine, daily activities — and the list of attacks to be aware of is growing every day. ",[],{},{"nodeType":864,"value":64242,"marks":64243,"data":64245},"It was hard enough to train users not to click links in emails when that was pretty much the only thing they had to watch out for.  ",[64244],{"type":899},{},"Guide: Protecting Users IB 3",{"sys":64248,"__typename":1724,"title":64249,"caption":64250,"layoutMode":59,"file":64251},{"id":52178},"Don't make employees the weak link image - blog - custom branding","It's harder than ever for users to identify malicious content on the web, with attackers abusing an ever-increasing list of actions that feel pretty normal to users, with a wide range of malicious payloads.",{"url":64252,"width":64253,"height":42494},"https://images.ctfassets.net/y1cdw1ablpvd/2aSm6QBWDOU6JBtOLfyp6R/d63cacab198ef9b325cbcfdbe0373b5a/Browser_Attacks_Targeting_Users__1_.png",4046,{"sys":64255,"__typename":1740,"content":64256,"name":64278,"title":59},{"id":52461},{"json":64257},{"nodeType":856,"data":64258,"content":64259},{},[64260],{"nodeType":860,"data":64261,"content":64262},{},[64263,64267,64274],{"nodeType":864,"value":64264,"marks":64265,"data":64266},"Learn more about the browser-based attack techniques driving the biggest breaches of the last year in our ",[],{},{"nodeType":883,"data":64268,"content":64269},{"uri":152},[64270],{"nodeType":864,"value":64271,"marks":64272,"data":64273},"2026 Browser Attack Techniques",[],{},{"nodeType":864,"value":64275,"marks":64276,"data":64277}," ebook.",[],{},"Browser attack techniques ebook callout",{"sys":64280,"__typename":1740,"content":64281,"name":64315,"title":59},{"id":52604},{"json":64282},{"nodeType":856,"data":64283,"content":64284},{},[64285],{"nodeType":860,"data":64286,"content":64287},{},[64288,64292,64300,64304,64311],{"nodeType":864,"value":64289,"marks":64290,"data":64291},"The Push research team has written extensively about how cloud-first operators like ",[],{},{"nodeType":39736,"data":64293,"content":64296},{"target":64294},{"sys":64295},{"id":57022,"type":1001,"linkType":1002},[64297],{"nodeType":864,"value":16018,"marks":64298,"data":64299},[],{},{"nodeType":864,"value":64301,"marks":64302,"data":64303}," use a variety of methods to ",[],{},{"nodeType":883,"data":64305,"content":64306},{"uri":14307},[64307],{"nodeType":864,"value":64308,"marks":64309,"data":64310},"evade existing security controls",[],{},{"nodeType":864,"value":64312,"marks":64313,"data":64314},", if you’d like to dig into the details.",[],{},"Guide: Protecting Users IB 2",{"sys":64317,"__typename":1724,"title":64318,"caption":5718,"layoutMode":59,"file":64319},{"id":40048},"Sample detection - blog article - custom branding",{"url":64320,"width":1736,"height":5721},"https://images.ctfassets.net/y1cdw1ablpvd/6k8qVn1iYXbBl6lcHvphIa/dd802537d883cf6ddafdd78034c3412a/sample_detection.png",{"sys":64322,"__typename":1724,"title":64323,"caption":64324,"layoutMode":59,"file":64325},{"id":52838},"Sample ClickFix detection - blog article - custom branding","Sample screenshot captured from a malicious copy-paste attack",{"url":64326,"width":64327,"height":64328},"https://images.ctfassets.net/y1cdw1ablpvd/3xaJZGyhSbqqLZ7iyiqb40/427c9eeb7312dc1d85d57b10b2ffec11/clickfix_screenshot_example.png",947,244,{"sys":64330,"__typename":1724,"title":64331,"caption":64332,"layoutMode":59,"file":64333},{"id":52892},"Sample phishing block page - blog article - custom branding","Sample phishing block page with custom branding",{"url":64334,"width":64335,"height":64336},"https://images.ctfassets.net/y1cdw1ablpvd/2eQNuARuzPujGm1tfYxFhf/1ebce9e33cf89368d1e9ce9104382641/phishing_block_page_branded.png",1274,719,{"sys":64338,"__typename":1724,"title":64339,"caption":64340,"layoutMode":59,"file":64341},{"id":53121},"MFA enforcement banner example - blog article - custom branding","MFA enforcement banner with custom branding and dark theme option",{"url":64342,"width":64343,"height":64344},"https://images.ctfassets.net/y1cdw1ablpvd/8srMEvq3vFJQiEyIaESDw/fdff9a4f3bd0eadb5f58ff9fac4ada74/MFA_enforcement_banner_branded_sample.png",1472,756,{"sys":64346,"__typename":1724,"title":64347,"caption":64348,"layoutMode":59,"file":64349},{"id":53173},"Sample blocking banner - blog article - custom branding","Sample blocking banner",{"url":64350,"width":64351,"height":64352},"https://images.ctfassets.net/y1cdw1ablpvd/2b3bGaN3vQBXn5SL8BlbzZ/fbe21cc6e6387856e2d3a56ffb6a1e82/banner_example_branded_block.png",1304,812,{"sys":64354,"__typename":1724,"title":64355,"caption":64356,"layoutMode":59,"file":64357},{"id":53259},"Rule configuration example - blog article - custom branding","Rule configuration slideout for Phishing tool detection",{"url":64358,"width":64359,"height":64360},"https://images.ctfassets.net/y1cdw1ablpvd/2O0ptkRr7E0QPlfABl3zq9/1e2204b441b50129f543177a99c46fa6/config_rule_scope_mode_example.png",739,820,{"sys":64362,"__typename":1724,"title":64363,"caption":64364,"layoutMode":59,"file":64365},{"id":53328},"Branding settings - blog article - custom branding","Branding configuration options for banners and block pages",{"url":64366,"width":64367,"height":64368},"https://images.ctfassets.net/y1cdw1ablpvd/4EX3DqVhvOMCyNFYSBJ1rF/caabcddde02e65e363f2354aa7ab2be0/branding_settings.png",995,817,{"items":64370},[],{},"Guide: How to use Push to protect users from browser threats",{"items":64374},[],"blog/guide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks",{"json":64377},{"data":64378,"content":64379,"nodeType":856},{},[64380],{"data":64381,"content":64382,"nodeType":860},{},[64383],{"data":64384,"marks":64385,"value":64386,"nodeType":864},{},[],"If you want to protect employees working in the browser, you need to get as close to the user as possible. In this Push product guide, we’ll cover how to use in-browser controls to stop attacks before compromise can occur, and to guide users to remediate vulnerabilities — all using your custom branding to increase trust.",{"id":52075,"publishedAt":64388},"2026-08-12T11:53:00.921Z",{"items":64390},[64391,64393],{"sys":64392,"name":13779},{"id":13778},{"sys":64394,"name":342},{"id":13775},{"items":64396},[64397,64399,64401,64403,64405,64407,64409,64411,64413,64415,64417,64419,64421,64423,64425,64427,64429,64431],{"sys":64398,"name":279,"slug":280,"tier":31},{"id":276},{"sys":64400,"name":297,"slug":298,"tier":31},{"id":294},{"sys":64402,"name":519,"slug":520,"tier":31},{"id":516},{"sys":64404,"name":342,"slug":343,"tier":31},{"id":339},{"sys":64406,"name":413,"slug":414,"tier":31},{"id":410},{"sys":64408,"name":261,"slug":262,"tier":45},{"id":258},{"sys":64410,"name":315,"slug":316,"tier":45},{"id":312},{"sys":64412,"name":324,"slug":325,"tier":45},{"id":321},{"sys":64414,"name":457,"slug":458,"tier":45},{"id":454},{"sys":64416,"name":466,"slug":467,"tier":45},{"id":463},{"sys":64418,"name":502,"slug":503,"tier":45},{"id":499},{"sys":64420,"name":288,"slug":289,"tier":45},{"id":285},{"sys":64422,"name":607,"slug":608,"tier":45},{"id":604},{"sys":64424,"name":448,"slug":449,"tier":45},{"id":445},{"sys":64426,"name":589,"slug":590,"tier":45},{"id":586},{"sys":64428,"name":580,"slug":581,"tier":45},{"id":577},{"sys":64430,"name":351,"slug":352,"tier":45},{"id":348},{"sys":64432,"name":598,"slug":599,"tier":45},{"id":595},"r6A4hwgdXf1AftoB3nqlkUp1HAEfQHUQeYO8ACKCPuA",{"id":64435,"title":64436,"authorsCollection":64437,"content":64445,"extension":228,"faqItemsCollection":64987,"faqTitle":59,"featured":6,"hashTags":59,"meta":64989,"metaTitle":64990,"ogImage":59,"postType":64991,"publishedDate":64992,"relatedBlogPostsCollection":64993,"slug":65713,"stem":65714,"subtitle":59,"summary":65715,"synopsis":65726,"sys":65727,"tagsCollection":65730,"topicsCollection":65734,"__hash__":65744},"blog/blog/product-release-march-2026.json","Product release: March 2026",{"items":64438},[64439],{"fullName":64440,"firstName":64441,"jobTitle":64442,"socialLinks":59,"profilePicture":64443},"Andy Waugh","Andy","VP Product",{"url":64444},"https://images.ctfassets.net/y1cdw1ablpvd/3Rf76rJn6S9inMb4dUnAIJ/0a787f8141d05b95300e2fe77c4493fa/DSC_6868.jpg",{"json":64446,"links":64940},{"data":64447,"content":64448,"nodeType":856},{},[64449,64456,64519,64526,64533,64549,64565,64571,64588,64594,64609,64616,64622,64639,64645,64666,64699,64716,64722,64729,64744,64750,64768,64774,64781,64804,64829,64847,64854,64861,64934],{"data":64450,"content":64451,"nodeType":1009},{},[64452],{"data":64453,"marks":64454,"value":64455,"nodeType":864},{},[],"What's new this month:",{"data":64457,"content":64458,"nodeType":941},{},[64459,64469,64479,64489,64499,64509],{"data":64460,"content":64461,"nodeType":945},{},[64462],{"data":64463,"content":64464,"nodeType":860},{},[64465],{"data":64466,"marks":64467,"value":64468,"nodeType":864},{},[],"Detect malicious browser extensions",{"data":64470,"content":64471,"nodeType":945},{},[64472],{"data":64473,"content":64474,"nodeType":860},{},[64475],{"data":64476,"marks":64477,"value":64478,"nodeType":864},{},[],"Create a blocklist or allowlist for browser extensions",{"data":64480,"content":64481,"nodeType":945},{},[64482],{"data":64483,"content":64484,"nodeType":860},{},[64485],{"data":64486,"marks":64487,"value":64488,"nodeType":864},{},[],"Block ClickFix-style attacks and collect payloads for investigation",{"data":64490,"content":64491,"nodeType":945},{},[64492],{"data":64493,"content":64494,"nodeType":860},{},[64495],{"data":64496,"marks":64497,"value":64498,"nodeType":864},{},[],"Custom branding for employee-facing banners and block pages",{"data":64500,"content":64501,"nodeType":945},{},[64502],{"data":64503,"content":64504,"nodeType":860},{},[64505],{"data":64506,"marks":64507,"value":64508,"nodeType":864},{},[],"Collect additional metadata to support threat detection",{"data":64510,"content":64511,"nodeType":945},{},[64512],{"data":64513,"content":64514,"nodeType":860},{},[64515],{"data":64516,"marks":64517,"value":64518,"nodeType":864},{},[],"And a few other things … ",{"data":64520,"content":64521,"nodeType":1009},{},[64522],{"data":64523,"marks":64524,"value":64525,"nodeType":864},{},[],"Detect malicious extensions",{"data":64527,"content":64528,"nodeType":860},{},[64529],{"data":64530,"marks":64531,"value":64532,"nodeType":864},{},[],"Push can now detect and block malicious browser extensions found in your environment. ",{"data":64534,"content":64535,"nodeType":860},{},[64536,64540,64545],{"data":64537,"marks":64538,"value":64539,"nodeType":864},{},[],"Push maintains a global list of malicious extensions based on our own threat research and publicly available threat intelligence. When an extension in your environment matches a malicious extension ID, Push will raise a detection on the ",{"data":64541,"marks":64542,"value":64544,"nodeType":864},{},[64543],{"type":899},"Detections",{"data":64546,"marks":64547,"value":64548,"nodeType":864},{},[]," page of the Push admin console. You can also configure the control to warn or block users automatically.",{"data":64550,"content":64551,"nodeType":860},{},[64552,64556,64561],{"data":64553,"marks":64554,"value":64555,"nodeType":864},{},[],"To enable malicious extension detection, go to the ",{"data":64557,"marks":64558,"value":64560,"nodeType":864},{},[64559],{"type":899},"Controls",{"data":64562,"marks":64563,"value":64564,"nodeType":864},{},[]," page in the Push admin console. ",{"data":64566,"content":64570,"nodeType":996},{"target":64567},{"sys":64568},{"id":64569,"type":1001,"linkType":1002},"1QV5UQ04MYLpWY7jTocvO4",[],{"data":64572,"content":64573,"nodeType":860},{},[64574,64577,64585],{"data":64575,"marks":64576,"value":21,"nodeType":864},{},[],{"data":64578,"content":64581,"nodeType":39736},{"target":64579},{"sys":64580},{"id":52726,"type":1001,"linkType":1002},[64582],{"data":64583,"marks":64584,"value":40614,"nodeType":864},{},[],{"data":64586,"marks":64587,"value":21,"nodeType":864},{},[],{"data":64589,"content":64590,"nodeType":1009},{},[64591],{"data":64592,"marks":64593,"value":64478,"nodeType":864},{},[],{"data":64595,"content":64596,"nodeType":860},{},[64597,64601,64605],{"data":64598,"marks":64599,"value":64600,"nodeType":864},{},[],"You can also block unwanted extensions or allowlist only the extensions you want in your environment, using Push’s ",{"data":64602,"marks":64603,"value":53149,"nodeType":864},{},[64604],{"type":899},{"data":64606,"marks":64607,"value":64608,"nodeType":864},{},[]," control.",{"data":64610,"content":64611,"nodeType":860},{},[64612],{"data":64613,"marks":64614,"value":64615,"nodeType":864},{},[],"End-users will see a block page if they attempt to enable a blocked extension or install one via the Chrome or Microsoft extension stores.",{"data":64617,"content":64621,"nodeType":996},{"target":64618},{"sys":64619},{"id":64620,"type":1001,"linkType":1002},"3OCdGfsyNTLXQx77dwzY9L",[],{"data":64623,"content":64624,"nodeType":860},{},[64625,64628,64636],{"data":64626,"marks":64627,"value":21,"nodeType":864},{},[],{"data":64629,"content":64632,"nodeType":39736},{"target":64630},{"sys":64631},{"id":53020,"type":1001,"linkType":1002},[64633],{"data":64634,"marks":64635,"value":40614,"nodeType":864},{},[],{"data":64637,"marks":64638,"value":21,"nodeType":864},{},[],{"data":64640,"content":64641,"nodeType":1009},{},[64642],{"data":64643,"marks":64644,"value":64488,"nodeType":864},{},[],{"data":64646,"content":64647,"nodeType":860},{},[64648,64652,64662],{"data":64649,"marks":64650,"value":64651,"nodeType":864},{},[],"You can now block ClickFix-style malicious copy and paste attacks using Push. These are one of the ",{"data":64653,"content":64657,"nodeType":39736},{"target":64654},{"sys":64655},{"id":64656,"type":1001,"linkType":1002},"1u8RJxC00HbBhCBVxcDnkK",[64658],{"data":64659,"marks":64660,"value":64661,"nodeType":864},{},[],"fastest-growing",{"data":64663,"marks":64664,"value":64665,"nodeType":864},{},[]," browser-based attacks. You can also choose to collect the payload for your security team to investigate.",{"data":64667,"content":64668,"nodeType":860},{},[64669,64673,64678,64682,64687,64690,64695],{"data":64670,"marks":64671,"value":64672,"nodeType":864},{},[],"From the Push admin console, go to ",{"data":64674,"marks":64675,"value":64677,"nodeType":864},{},[64676],{"type":899},"Controls > Malicious copy and paste detection",{"data":64679,"marks":64680,"value":64681,"nodeType":864},{},[],". Then create a configuration rule to select the ",{"data":64683,"marks":64684,"value":64686,"nodeType":864},{},[64685],{"type":899},"Mode",{"data":64688,"marks":64689,"value":902,"nodeType":864},{},[],{"data":64691,"marks":64692,"value":64694,"nodeType":864},{},[64693],{"type":899},"Scope",{"data":64696,"marks":64697,"value":64698,"nodeType":864},{},[],". If you’ve enabled payload collection, Push will collect the malicious payload and include it in the detection event.",{"data":64700,"content":64701,"nodeType":860},{},[64702,64705,64713],{"data":64703,"marks":64704,"value":21,"nodeType":864},{},[],{"data":64706,"content":64709,"nodeType":39736},{"target":64707},{"sys":64708},{"id":52747,"type":1001,"linkType":1002},[64710],{"data":64711,"marks":64712,"value":40614,"nodeType":864},{},[],{"data":64714,"marks":64715,"value":21,"nodeType":864},{},[],{"data":64717,"content":64718,"nodeType":1009},{},[64719],{"data":64720,"marks":64721,"value":64498,"nodeType":864},{},[],{"data":64723,"content":64724,"nodeType":860},{},[64725],{"data":64726,"marks":64727,"value":64728,"nodeType":864},{},[],"Customize the look and feel of employee-facing banners and warn or block pages by adding your company logo, accent color, and choice of light or dark mode themes. ",{"data":64730,"content":64731,"nodeType":860},{},[64732,64736,64741],{"data":64733,"marks":64734,"value":64735,"nodeType":864},{},[],"To add your brand elements, go to ",{"data":64737,"marks":64738,"value":64740,"nodeType":864},{},[64739],{"type":899},"Settings > Branding",{"data":64742,"marks":64743,"value":2924,"nodeType":864},{},[],{"data":64745,"content":64749,"nodeType":996},{"target":64746},{"sys":64747},{"id":64748,"type":1001,"linkType":1002},"3Jawd7IBSA3GF2XBHARsn",[],{"data":64751,"content":64752,"nodeType":860},{},[64753,64756,64765],{"data":64754,"marks":64755,"value":21,"nodeType":864},{},[],{"data":64757,"content":64761,"nodeType":39736},{"target":64758},{"sys":64759},{"id":64760,"type":1001,"linkType":1002},"4i1KWgBfYqtFYlUFRYiGdW",[64762],{"data":64763,"marks":64764,"value":40614,"nodeType":864},{},[],{"data":64766,"marks":64767,"value":21,"nodeType":864},{},[],{"data":64769,"content":64770,"nodeType":1009},{},[64771],{"data":64772,"marks":64773,"value":64508,"nodeType":864},{},[],{"data":64775,"content":64776,"nodeType":860},{},[64777],{"data":64778,"marks":64779,"value":64780,"nodeType":864},{},[],"The Push browser extension can now collect additional metadata and store it locally for up to 30 days, powering more diverse and precise detections, including for emerging threats. ",{"data":64782,"content":64783,"nodeType":860},{},[64784,64788,64792,64796,64800],{"data":64785,"marks":64786,"value":64787,"nodeType":864},{},[],"Detections informed by this metadata will be raised on the ",{"data":64789,"marks":64790,"value":64544,"nodeType":864},{},[64791],{"type":899},{"data":64793,"marks":64794,"value":64795,"nodeType":864},{},[]," page. Note that these detections do not block end-user activity and are ",{"data":64797,"marks":64798,"value":1334,"nodeType":864},{},[64799],{"type":899},{"data":64801,"marks":64802,"value":64803,"nodeType":864},{},[]," mode only.",{"data":64805,"content":64806,"nodeType":860},{},[64807,64811,64816,64820,64825],{"data":64808,"marks":64809,"value":64810,"nodeType":864},{},[],"We recommend you enable ",{"data":64812,"marks":64813,"value":64815,"nodeType":864},{},[64814],{"type":899},"Browser event storage",{"data":64817,"marks":64818,"value":64819,"nodeType":864},{},[]," to take advantage of this capability. Go to ",{"data":64821,"marks":64822,"value":64824,"nodeType":864},{},[64823],{"type":899},"Settings > Telemetry > Browser event storage",{"data":64826,"marks":64827,"value":64828,"nodeType":864},{},[]," in the admin console.",{"data":64830,"content":64831,"nodeType":860},{},[64832,64835,64844],{"data":64833,"marks":64834,"value":21,"nodeType":864},{},[],{"data":64836,"content":64840,"nodeType":39736},{"target":64837},{"sys":64838},{"id":64839,"type":1001,"linkType":1002},"1x69JxXcDWEDIzYXUM8nGb",[64841],{"data":64842,"marks":64843,"value":40614,"nodeType":864},{},[],{"data":64845,"marks":64846,"value":21,"nodeType":864},{},[],{"data":64848,"content":64849,"nodeType":1009},{},[64850],{"data":64851,"marks":64852,"value":64853,"nodeType":864},{},[],"And a few other things ...",{"data":64855,"content":64856,"nodeType":860},{},[64857],{"data":64858,"marks":64859,"value":64860,"nodeType":864},{},[],"Other new features or improvements to the platform include:",{"data":64862,"content":64863,"nodeType":941},{},[64864,64884,64894,64914],{"data":64865,"content":64866,"nodeType":945},{},[64867],{"data":64868,"content":64869,"nodeType":860},{},[64870,64874,64881],{"data":64871,"marks":64872,"value":64873,"nodeType":864},{},[],"You can now configure the frequency with which app banners will be displayed: either per-tab or per-browser. ",{"data":64875,"content":64877,"nodeType":883},{"uri":64876},"/help/10125#frequency",[64878],{"data":64879,"marks":64880,"value":40614,"nodeType":864},{},[],{"data":64882,"marks":64883,"value":21,"nodeType":864},{},[],{"data":64885,"content":64886,"nodeType":945},{},[64887],{"data":64888,"content":64889,"nodeType":860},{},[64890],{"data":64891,"marks":64892,"value":64893,"nodeType":864},{},[],"You can now define an Owner role as part of Push’s RBAC options. Only Owners can edit roles, delete your team (e.g. tenant), change default SAML roles, or update your team name.",{"data":64895,"content":64896,"nodeType":945},{},[64897],{"data":64898,"content":64899,"nodeType":860},{},[64900,64904,64911],{"data":64901,"marks":64902,"value":64903,"nodeType":864},{},[],"Webhook events now include detection details, for greater context. ",{"data":64905,"content":64907,"nodeType":883},{"uri":64906},"https://pushsecurity.com/help/audience/engineering/webhooks-v1/detections",[64908],{"data":64909,"marks":64910,"value":40614,"nodeType":864},{},[],{"data":64912,"marks":64913,"value":21,"nodeType":864},{},[],{"data":64915,"content":64916,"nodeType":945},{},[64917],{"data":64918,"content":64919,"nodeType":860},{},[64920,64924,64931],{"data":64921,"marks":64922,"value":64923,"nodeType":864},{},[],"Push now uses static IP addresses to emit webhook events. These IP addresses are in the same range we previously used, but if you wish to update your network filtering to these new, narrower IP addresses, you can. ",{"data":64925,"content":64927,"nodeType":883},{"uri":64926},"https://pushsecurity.com/help/audience/engineering/webhooks-v1/section/ip-addresses",[64928],{"data":64929,"marks":64930,"value":40614,"nodeType":864},{},[],{"data":64932,"marks":64933,"value":21,"nodeType":864},{},[],{"data":64935,"content":64936,"nodeType":860},{},[64937],{"data":64938,"marks":64939,"value":21,"nodeType":864},{},[],{"entries":64941},{"inline":64942,"hyperlink":64943,"block":64964},[],[64944,64946,64948,64952,64954,64959],{"sys":64945,"__typename":64143,"title":64154,"slug":64155,"articleId":64156},{"id":52726},{"sys":64947,"__typename":64143,"title":64184,"slug":64185,"articleId":64186},{"id":53020},{"sys":64949,"__typename":2059,"title":64950,"slug":64951},{"id":64656},"Introducing malicious copy and paste detection","introducing-malicious-copy-paste-detection",{"sys":64953,"__typename":64143,"title":64159,"slug":64160,"articleId":64161},{"id":52747},{"sys":64955,"__typename":64143,"title":64956,"slug":64957,"articleId":64958},{"id":64760},"How do I add custom branding to Push banners and block pages?","how-do-i-add-custom-branding-to-push-banners-and-block-pages",10147,{"sys":64960,"__typename":64143,"title":64961,"slug":64962,"articleId":64963},{"id":64839},"How do I configure browser event storage?","how-do-i-configure-browser-event-storage",10146,[64965,64972,64979],{"sys":64966,"__typename":1724,"title":64967,"caption":59,"layoutMode":59,"file":64968},{"id":64569},"Malicious extension detection - Controls page - for release notes",{"url":64969,"width":64970,"height":64971},"https://images.ctfassets.net/y1cdw1ablpvd/2OhoXumfBK0saT2oLeCPrI/95950149e4c7f11c53948ba0cf0b09b5/malicious_ext_det_controls_pg.png",1337,767,{"sys":64973,"__typename":1724,"title":64974,"caption":59,"layoutMode":59,"file":64975},{"id":64620},"Browser extension block screen - KB 10138",{"url":64976,"width":64977,"height":64978},"https://images.ctfassets.net/y1cdw1ablpvd/3i6Sj2jgOimCqGtpKy1B7p/3cc3e6b1e9f0b7c61565f3b3f7974844/extension_block_branded_20260420.png",2670,1626,{"sys":64980,"__typename":1724,"title":64981,"caption":64982,"layoutMode":59,"file":64983},{"id":64748},"Branded banner example - dark style - KB 10147","Example of a dark style mid-screen banner",{"url":64984,"width":64985,"height":64986},"https://images.ctfassets.net/y1cdw1ablpvd/F8v8jKH2SXlMeHbG83Nvh/2b7c51c8bbb2ad74947f4a2bcee3048b/midscreen_dark_banner.png",2944,562,{"items":64988},[],{},"Push Security new product features for March 2026","release-notes","2026-03-10T00:00:00.000Z",{"items":64994},[64995],{"__typename":2059,"sys":64996,"content":64998,"title":65699,"synopsis":65700,"hashTags":59,"publishedDate":65701,"slug":65702,"tagsCollection":65703,"authorsCollection":65709},{"id":64997},"3ygDMHnTN58Lyb3W3k969w",{"json":64999},{"data":65000,"content":65001,"nodeType":856},{},[65002,65008,65080,65086,65093,65118,65142,65175,65181,65198,65204,65211,65218,65250,65256,65273,65279,65295,65302,65325,65332,65339,65362,65378,65384,65390,65397,65413,65420,65473,65480,65486,65504,65510,65525,65532,65555,65577,65583,65589,65693],{"data":65003,"content":65004,"nodeType":1009},{},[65005],{"data":65006,"marks":65007,"value":64455,"nodeType":864},{},[],{"data":65009,"content":65010,"nodeType":941},{},[65011,65021,65031,65041,65051,65061,65071],{"data":65012,"content":65013,"nodeType":945},{},[65014],{"data":65015,"content":65016,"nodeType":860},{},[65017],{"data":65018,"marks":65019,"value":65020,"nodeType":864},{},[],"Get visibility for all installed browser extensions in your environment",{"data":65022,"content":65023,"nodeType":945},{},[65024],{"data":65025,"content":65026,"nodeType":860},{},[65027],{"data":65028,"marks":65029,"value":65030,"nodeType":864},{},[],"New detection for ClickFix-style malicious copy-paste attacks",{"data":65032,"content":65033,"nodeType":945},{},[65034],{"data":65035,"content":65036,"nodeType":860},{},[65037],{"data":65038,"marks":65039,"value":65040,"nodeType":864},{},[],"New Labs feature: Experimental detections",{"data":65042,"content":65043,"nodeType":945},{},[65044],{"data":65045,"content":65046,"nodeType":860},{},[65047],{"data":65048,"marks":65049,"value":65050,"nodeType":864},{},[],"RBAC for the Push admin console",{"data":65052,"content":65053,"nodeType":945},{},[65054],{"data":65055,"content":65056,"nodeType":860},{},[65057],{"data":65058,"marks":65059,"value":65060,"nodeType":864},{},[],"URLscan.io and domain registration enrichment for detections",{"data":65062,"content":65063,"nodeType":945},{},[65064],{"data":65065,"content":65066,"nodeType":860},{},[65067],{"data":65068,"marks":65069,"value":65070,"nodeType":864},{},[],"Filter events by entities",{"data":65072,"content":65073,"nodeType":945},{},[65074],{"data":65075,"content":65076,"nodeType":860},{},[65077],{"data":65078,"marks":65079,"value":64518,"nodeType":864},{},[],{"data":65081,"content":65082,"nodeType":1009},{},[65083],{"data":65084,"marks":65085,"value":65020,"nodeType":864},{},[],{"data":65087,"content":65088,"nodeType":860},{},[65089],{"data":65090,"marks":65091,"value":65092,"nodeType":864},{},[],"You can now use Push to see other browser extensions installed on your employees’ browsers.",{"data":65094,"content":65095,"nodeType":860},{},[65096,65100,65105,65109,65114],{"data":65097,"marks":65098,"value":65099,"nodeType":864},{},[],"You can enable this feature by going to ",{"data":65101,"marks":65102,"value":65104,"nodeType":864},{},[65103],{"type":899},"Settings > Organization",{"data":65106,"marks":65107,"value":65108,"nodeType":864},{},[]," in the Push admin console and toggling on ",{"data":65110,"marks":65111,"value":65113,"nodeType":864},{},[65112],{"type":899},"Browser extension visibility",{"data":65115,"marks":65116,"value":65117,"nodeType":864},{},[],". There is no end-user impact when you enable this feature.",{"data":65119,"content":65120,"nodeType":860},{},[65121,65125,65129,65133,65138],{"data":65122,"marks":65123,"value":65124,"nodeType":864},{},[],"You’ll see browser extension data populate a new ",{"data":65126,"marks":65127,"value":288,"nodeType":864},{},[65128],{"type":899},{"data":65130,"marks":65131,"value":65132,"nodeType":864},{},[]," page in the admin console under ",{"data":65134,"marks":65135,"value":65137,"nodeType":864},{},[65136],{"type":899},"Investigate",{"data":65139,"marks":65140,"value":65141,"nodeType":864},{},[],". With this information, you can see:",{"data":65143,"content":65144,"nodeType":941},{},[65145,65155,65165],{"data":65146,"content":65147,"nodeType":945},{},[65148],{"data":65149,"content":65150,"nodeType":860},{},[65151],{"data":65152,"marks":65153,"value":65154,"nodeType":864},{},[],"Which extensions have been installed for each employee and browser.",{"data":65156,"content":65157,"nodeType":945},{},[65158],{"data":65159,"content":65160,"nodeType":860},{},[65161],{"data":65162,"marks":65163,"value":65164,"nodeType":864},{},[],"How they were installed (e.g. by policy, manually, or sideloaded).",{"data":65166,"content":65167,"nodeType":945},{},[65168],{"data":65169,"content":65170,"nodeType":860},{},[65171],{"data":65172,"marks":65173,"value":65174,"nodeType":864},{},[],"Which permissions they have.",{"data":65176,"content":65180,"nodeType":996},{"target":65177},{"sys":65178},{"id":65179,"type":1001,"linkType":1002},"5J5jdmwugy7yU8GGwxe7iH",[],{"data":65182,"content":65183,"nodeType":860},{},[65184,65187,65195],{"data":65185,"marks":65186,"value":21,"nodeType":864},{},[],{"data":65188,"content":65191,"nodeType":39736},{"target":65189},{"sys":65190},{"id":53020,"type":1001,"linkType":1002},[65192],{"data":65193,"marks":65194,"value":40614,"nodeType":864},{},[],{"data":65196,"marks":65197,"value":21,"nodeType":864},{},[],{"data":65199,"content":65200,"nodeType":1009},{},[65201],{"data":65202,"marks":65203,"value":65030,"nodeType":864},{},[],{"data":65205,"content":65206,"nodeType":860},{},[65207],{"data":65208,"marks":65209,"value":65210,"nodeType":864},{},[],"Push can now detect malicious copy and paste attacks like ClickFix, FileFix, and other fake CAPTCHA-style techniques.",{"data":65212,"content":65213,"nodeType":860},{},[65214],{"data":65215,"marks":65216,"value":65217,"nodeType":864},{},[],"These techniques have become one of the most prevalent attack types this year, and rely on deceiving users into manually or automatically copying malicious code and running it locally.",{"data":65219,"content":65220,"nodeType":860},{},[65221,65225,65230,65234,65238,65242,65246],{"data":65222,"marks":65223,"value":65224,"nodeType":864},{},[],"You can enable ",{"data":65226,"marks":65227,"value":65229,"nodeType":864},{},[65228],{"type":899},"Malicious copy and paste detection",{"data":65231,"marks":65232,"value":65233,"nodeType":864},{},[]," from the ",{"data":65235,"marks":65236,"value":64560,"nodeType":864},{},[65237],{"type":899},{"data":65239,"marks":65240,"value":65241,"nodeType":864},{},[]," page of the Push admin console. Add a configuration rule to set the detection to ",{"data":65243,"marks":65244,"value":1334,"nodeType":864},{},[65245],{"type":899},{"data":65247,"marks":65248,"value":65249,"nodeType":864},{},[],". You can also add an exception for any staff who routinely handle malicious scripts, such as security team members, or add domains to the ignore list as needed.",{"data":65251,"content":65255,"nodeType":996},{"target":65252},{"sys":65253},{"id":65254,"type":1001,"linkType":1002},"2fPaiwRCAUd8lMvsVO03HZ",[],{"data":65257,"content":65258,"nodeType":860},{},[65259,65262,65270],{"data":65260,"marks":65261,"value":21,"nodeType":864},{},[],{"data":65263,"content":65266,"nodeType":39736},{"target":65264},{"sys":65265},{"id":64656,"type":1001,"linkType":1002},[65267],{"data":65268,"marks":65269,"value":40614,"nodeType":864},{},[],{"data":65271,"marks":65272,"value":21,"nodeType":864},{},[],{"data":65274,"content":65275,"nodeType":1009},{},[65276],{"data":65277,"marks":65278,"value":65040,"nodeType":864},{},[],{"data":65280,"content":65281,"nodeType":860},{},[65282,65286,65291],{"data":65283,"marks":65284,"value":65285,"nodeType":864},{},[],"Get early access to new detections from the Push research team by enabling ",{"data":65287,"marks":65288,"value":65290,"nodeType":864},{},[65289],{"type":899},"Experimental detections",{"data":65292,"marks":65293,"value":65294,"nodeType":864},{},[],", a Labs feature.",{"data":65296,"content":65297,"nodeType":860},{},[65298],{"data":65299,"marks":65300,"value":65301,"nodeType":864},{},[],"Labs features are new features Push is testing before releasing them. Early access detections are designed to catch emerging attacker techniques, but may also produce more false positives while we finetune them. These early access detections do not block any user actions.",{"data":65303,"content":65304,"nodeType":860},{},[65305,65309,65313,65317,65322],{"data":65306,"marks":65307,"value":65308,"nodeType":864},{},[],"Enable ",{"data":65310,"marks":65311,"value":65290,"nodeType":864},{},[65312],{"type":899},{"data":65314,"marks":65315,"value":65316,"nodeType":864},{},[]," by going to ",{"data":65318,"marks":65319,"value":65321,"nodeType":864},{},[65320],{"type":899},"Settings > Labs",{"data":65323,"marks":65324,"value":64828,"nodeType":864},{},[],{"data":65326,"content":65327,"nodeType":1009},{},[65328],{"data":65329,"marks":65330,"value":65331,"nodeType":864},{},[],"RBAC for the Push platform",{"data":65333,"content":65334,"nodeType":860},{},[65335],{"data":65336,"marks":65337,"value":65338,"nodeType":864},{},[],"You can now provide read-only access to the Push admin console to facilitate investigations, review detections, check app usage by department, help with employee offboarding — or anything else you need.",{"data":65340,"content":65341,"nodeType":860},{},[65342,65346,65350,65354,65359],{"data":65343,"marks":65344,"value":65345,"nodeType":864},{},[],"To add a read-only admin, go to ",{"data":65347,"marks":65348,"value":65104,"nodeType":864},{},[65349],{"type":899},{"data":65351,"marks":65352,"value":65353,"nodeType":864},{},[]," in the admin console. Enter the email address of the admin you want to invite and set the role to ",{"data":65355,"marks":65356,"value":65358,"nodeType":864},{},[65357],{"type":899},"Read only",{"data":65360,"marks":65361,"value":2924,"nodeType":864},{},[],{"data":65363,"content":65364,"nodeType":860},{},[65365,65369,65374],{"data":65366,"marks":65367,"value":65368,"nodeType":864},{},[],"Note that existing Push admins now have the role of ",{"data":65370,"marks":65371,"value":65373,"nodeType":864},{},[65372],{"type":899},"Full access",{"data":65375,"marks":65376,"value":65377,"nodeType":864},{},[],". You can adjust that role as needed from the Organization page, too.",{"data":65379,"content":65383,"nodeType":996},{"target":65380},{"sys":65381},{"id":65382,"type":1001,"linkType":1002},"7kraCfSP2YwdEEwZ8FxM1t",[],{"data":65385,"content":65386,"nodeType":1009},{},[65387],{"data":65388,"marks":65389,"value":65060,"nodeType":864},{},[],{"data":65391,"content":65392,"nodeType":860},{},[65393],{"data":65394,"marks":65395,"value":65396,"nodeType":864},{},[],"You can now enrich detections in Push with information from urlscan.io, and see when the domain was first registered. This information gives you domain-relevant context to support investigations.",{"data":65398,"content":65399,"nodeType":860},{},[65400,65404,65409],{"data":65401,"marks":65402,"value":65403,"nodeType":864},{},[],"To enable this feature, go to ",{"data":65405,"marks":65406,"value":65408,"nodeType":864},{},[65407],{"type":899},"Settings > Advanced > Domain enrichment",{"data":65410,"marks":65411,"value":65412,"nodeType":864},{},[]," in the Push admin console or enable it from any existing detection event.",{"data":65414,"content":65415,"nodeType":860},{},[65416],{"data":65417,"marks":65418,"value":65419,"nodeType":864},{},[],"With this enrichment, you can quickly see:",{"data":65421,"content":65422,"nodeType":941},{},[65423,65433,65443,65453,65463],{"data":65424,"content":65425,"nodeType":945},{},[65426],{"data":65427,"content":65428,"nodeType":860},{},[65429],{"data":65430,"marks":65431,"value":65432,"nodeType":864},{},[],"The timestamp for when a domain was first registered",{"data":65434,"content":65435,"nodeType":945},{},[65436],{"data":65437,"content":65438,"nodeType":860},{},[65439],{"data":65440,"marks":65441,"value":65442,"nodeType":864},{},[],"The number of times a domain was scanned on urlscan",{"data":65444,"content":65445,"nodeType":945},{},[65446],{"data":65447,"content":65448,"nodeType":860},{},[65449],{"data":65450,"marks":65451,"value":65452,"nodeType":864},{},[],"The first time a domain was scanned",{"data":65454,"content":65455,"nodeType":945},{},[65456],{"data":65457,"content":65458,"nodeType":860},{},[65459],{"data":65460,"marks":65461,"value":65462,"nodeType":864},{},[],"The last time a domain or IP was scanned",{"data":65464,"content":65465,"nodeType":945},{},[65466],{"data":65467,"content":65468,"nodeType":860},{},[65469],{"data":65470,"marks":65471,"value":65472,"nodeType":864},{},[],"A urlscan verdict (e.g. “potentially malicious”)",{"data":65474,"content":65475,"nodeType":860},{},[65476],{"data":65477,"marks":65478,"value":65479,"nodeType":864},{},[],"You’ll see the enrichment data on the details slideout for an individual detection.",{"data":65481,"content":65485,"nodeType":996},{"target":65482},{"sys":65483},{"id":65484,"type":1001,"linkType":1002},"563fJFSgoLDOwSXSQ9Y0MM",[],{"data":65487,"content":65488,"nodeType":860},{},[65489,65492,65501],{"data":65490,"marks":65491,"value":21,"nodeType":864},{},[],{"data":65493,"content":65497,"nodeType":39736},{"target":65494},{"sys":65495},{"id":65496,"type":1001,"linkType":1002},"19qsIXEG6EN9EK0VRH3pw9",[65498],{"data":65499,"marks":65500,"value":40614,"nodeType":864},{},[],{"data":65502,"marks":65503,"value":21,"nodeType":864},{},[],{"data":65505,"content":65506,"nodeType":1009},{},[65507],{"data":65508,"marks":65509,"value":65070,"nodeType":864},{},[],{"data":65511,"content":65512,"nodeType":860},{},[65513,65517,65521],{"data":65514,"marks":65515,"value":65516,"nodeType":864},{},[],"You can now filter the ",{"data":65518,"marks":65519,"value":53250,"nodeType":864},{},[65520],{"type":899},{"data":65522,"marks":65523,"value":65524,"nodeType":864},{},[]," page in the Push admin console by entities such as employees and apps to make triage more efficient.",{"data":65526,"content":65527,"nodeType":860},{},[65528],{"data":65529,"marks":65530,"value":65531,"nodeType":864},{},[],"With this option, you can do quick searches such as:",{"data":65533,"content":65534,"nodeType":941},{},[65535,65545],{"data":65536,"content":65537,"nodeType":945},{},[65538],{"data":65539,"content":65540,"nodeType":860},{},[65541],{"data":65542,"marks":65543,"value":65544,"nodeType":864},{},[],"See all recent events associated with an employee",{"data":65546,"content":65547,"nodeType":945},{},[65548],{"data":65549,"content":65550,"nodeType":860},{},[65551],{"data":65552,"marks":65553,"value":65554,"nodeType":864},{},[],"See all recent logins for a given app",{"data":65556,"content":65557,"nodeType":860},{},[65558,65561,65565,65569,65574],{"data":65559,"marks":65560,"value":53314,"nodeType":864},{},[],{"data":65562,"marks":65563,"value":53250,"nodeType":864},{},[65564],{"type":899},{"data":65566,"marks":65567,"value":65568,"nodeType":864},{},[]," page, go to ",{"data":65570,"marks":65571,"value":65573,"nodeType":864},{},[65572],{"type":899},"Filters > Entity type",{"data":65575,"marks":65576,"value":2924,"nodeType":864},{},[],{"data":65578,"content":65579,"nodeType":1009},{},[65580],{"data":65581,"marks":65582,"value":64518,"nodeType":864},{},[],{"data":65584,"content":65585,"nodeType":860},{},[65586],{"data":65587,"marks":65588,"value":64860,"nodeType":864},{},[],{"data":65590,"content":65591,"nodeType":941},{},[65592,65629,65651,65661,65683],{"data":65593,"content":65594,"nodeType":945},{},[65595],{"data":65596,"content":65597,"nodeType":860},{},[65598,65602,65612,65615,65625],{"data":65599,"marks":65600,"value":65601,"nodeType":864},{},[],"You can now configure exceptions for ",{"data":65603,"content":65607,"nodeType":39736},{"target":65604},{"sys":65605},{"id":65606,"type":1001,"linkType":1002},"4oOTN6FXPpZg9MLgQUujys",[65608],{"data":65609,"marks":65610,"value":65611,"nodeType":864},{},[],"MFA findings",{"data":65613,"marks":65614,"value":902,"nodeType":864},{},[],{"data":65616,"content":65620,"nodeType":39736},{"target":65617},{"sys":65618},{"id":65619,"type":1001,"linkType":1002},"2eOzRGosD2Ghaipao7NY8W",[65621],{"data":65622,"marks":65623,"value":65624,"nodeType":864},{},[],"reused password",{"data":65626,"marks":65627,"value":65628,"nodeType":864},{},[]," findings. This is useful if you purposefully reuse passwords between systems or enforce MFA through a third-party provider.",{"data":65630,"content":65631,"nodeType":945},{},[65632],{"data":65633,"content":65634,"nodeType":860},{},[65635,65639,65648],{"data":65636,"marks":65637,"value":65638,"nodeType":864},{},[],"We’ve added several first-class SIEM integrations. ",{"data":65640,"content":65644,"nodeType":39736},{"target":65641},{"sys":65642},{"id":65643,"type":1001,"linkType":1002},"2M73i6A90S9MY6Pe8uVjVv",[65645],{"data":65646,"marks":65647,"value":40614,"nodeType":864},{},[],{"data":65649,"marks":65650,"value":2924,"nodeType":864},{},[],{"data":65652,"content":65653,"nodeType":945},{},[65654],{"data":65655,"content":65656,"nodeType":860},{},[65657],{"data":65658,"marks":65659,"value":65660,"nodeType":864},{},[],"We’ve expanded the limit for URLs you can block using the URL blocking control to 2,000.",{"data":65662,"content":65663,"nodeType":945},{},[65664],{"data":65665,"content":65666,"nodeType":860},{},[65667,65671,65680],{"data":65668,"marks":65669,"value":65670,"nodeType":864},{},[],"You can now set a time period after which to automatically un-license inactive employees, to make license management easier. ",{"data":65672,"content":65676,"nodeType":39736},{"target":65673},{"sys":65674},{"id":65675,"type":1001,"linkType":1002},"6Ad43w7Cjz2L5fZN2klIOn",[65677],{"data":65678,"marks":65679,"value":40614,"nodeType":864},{},[],{"data":65681,"marks":65682,"value":2924,"nodeType":864},{},[],{"data":65684,"content":65685,"nodeType":945},{},[65686],{"data":65687,"content":65688,"nodeType":860},{},[65689],{"data":65690,"marks":65691,"value":65692,"nodeType":864},{},[],"Push now supports Prisma Access browser.\n",{"data":65694,"content":65695,"nodeType":860},{},[65696],{"data":65697,"marks":65698,"value":21,"nodeType":864},{},[],"Product release: November 2025","Here’s what’s new on the Push platform for November 2025.","2025-11-04T00:00:00.000Z","product-release-november-2025",{"items":65704},[65705],{"sys":65706,"name":65708},{"id":65707},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"items":65710},[65711],{"fullName":64440,"firstName":64441,"jobTitle":64442,"profilePicture":65712},{"url":64444},"product-release-march-2026","blog/product-release-march-2026",{"json":65716},{"data":65717,"content":65718,"nodeType":856},{},[65719],{"data":65720,"content":65721,"nodeType":860},{},[65722],{"data":65723,"marks":65724,"value":65725,"nodeType":864},{},[],"Malicious extension detection, block ClickFix-style attacks, custom branding and more","Here’s what’s new on the Push platform for March 2026.",{"id":65728,"publishedAt":65729},"3Yw48rVLntipUijLR0CYf2","2026-08-13T09:35:00.930Z",{"items":65731},[65732],{"sys":65733,"name":65708},{"id":65707},{"items":65735},[65736,65738,65740,65742],{"sys":65737,"name":297,"slug":298,"tier":31},{"id":294},{"sys":65739,"name":288,"slug":289,"tier":45},{"id":285},{"sys":65741,"name":315,"slug":316,"tier":45},{"id":312},{"sys":65743,"name":448,"slug":449,"tier":45},{"id":445},"eIqymJShskbNuC00g5SpN2S_4nuP1K1uJN6I7pLSXb4",{"id":65746,"title":62081,"authorsCollection":65747,"content":65752,"extension":228,"faqItemsCollection":66786,"faqTitle":59,"featured":6,"hashTags":59,"meta":66788,"metaTitle":66789,"ogImage":59,"postType":59812,"publishedDate":62083,"relatedBlogPostsCollection":66790,"slug":62084,"stem":68992,"subtitle":59,"summary":68993,"synopsis":62082,"sys":69004,"tagsCollection":69006,"topicsCollection":69012,"__hash__":69026},"blog/blog/browser-extension-management-guide.json",{"items":65748},[65749],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":65750,"profilePicture":65751},[15231],{"url":2740},{"json":65753,"links":66662},{"data":65754,"content":65755,"nodeType":856},{},[65756,65812,65818,65823,65826,65833,65839,65845,65852,65858,65907,65921,65927,65933,65936,65943,65949,66004,66011,66017,66022,66027,66033,66039,66054,66060,66102,66107,66114,66131,66137,66143,66227,66233,66246,66251,66258,66264,66270,66276,66329,66334,66339,66346,66352,66358,66379,66385,66390,66409,66414,66420,66427,66433,66439,66469,66485,66491,66501,66504,66511,66517,66522,66525,66532,66539,66545,66561,66567,66573,66578,66584,66590,66595,66598,66605,66620,66626],{"data":65757,"content":65758,"nodeType":860},{},[65759,65762,65769,65772,65779,65782,65789,65792,65799,65802,65809],{"data":65760,"marks":65761,"value":61052,"nodeType":864},{},[],{"data":65763,"content":65764,"nodeType":883},{"uri":61055},[65765],{"data":65766,"marks":65767,"value":61061,"nodeType":864},{},[65768],{"type":1455},{"data":65770,"marks":65771,"value":3731,"nodeType":864},{},[],{"data":65773,"content":65774,"nodeType":883},{"uri":61067},[65775],{"data":65776,"marks":65777,"value":61073,"nodeType":864},{},[65778],{"type":1455},{"data":65780,"marks":65781,"value":3731,"nodeType":864},{},[],{"data":65783,"content":65784,"nodeType":883},{"uri":61079},[65785],{"data":65786,"marks":65787,"value":61085,"nodeType":864},{},[65788],{"type":1455},{"data":65790,"marks":65791,"value":61089,"nodeType":864},{},[],{"data":65793,"content":65794,"nodeType":883},{"uri":61092},[65795],{"data":65796,"marks":65797,"value":3948,"nodeType":864},{},[65798],{"type":1455},{"data":65800,"marks":65801,"value":902,"nodeType":864},{},[],{"data":65803,"content":65804,"nodeType":883},{"uri":61103},[65805],{"data":65806,"marks":65807,"value":3970,"nodeType":864},{},[65808],{"type":1455},{"data":65810,"marks":65811,"value":61112,"nodeType":864},{},[],{"data":65813,"content":65814,"nodeType":860},{},[65815],{"data":65816,"marks":65817,"value":61119,"nodeType":864},{},[],{"data":65819,"content":65822,"nodeType":996},{"target":65820},{"sys":65821},{"id":61124,"type":1001,"linkType":1002},[],{"data":65824,"content":65825,"nodeType":1005},{},[],{"data":65827,"content":65828,"nodeType":1009},{},[65829],{"data":65830,"marks":65831,"value":61136,"nodeType":864},{},[65832],{"type":899},{"data":65834,"content":65835,"nodeType":860},{},[65836],{"data":65837,"marks":65838,"value":61143,"nodeType":864},{},[],{"data":65840,"content":65841,"nodeType":860},{},[65842],{"data":65843,"marks":65844,"value":61150,"nodeType":864},{},[],{"data":65846,"content":65847,"nodeType":1312},{},[65848],{"data":65849,"marks":65850,"value":61158,"nodeType":864},{},[65851],{"type":899},{"data":65853,"content":65854,"nodeType":860},{},[65855],{"data":65856,"marks":65857,"value":61165,"nodeType":864},{},[],{"data":65859,"content":65860,"nodeType":941},{},[65861,65880,65889,65898],{"data":65862,"content":65863,"nodeType":945},{},[65864],{"data":65865,"content":65866,"nodeType":860},{},[65867,65870,65877],{"data":65868,"marks":65869,"value":61178,"nodeType":864},{},[],{"data":65871,"content":65872,"nodeType":883},{"uri":61181},[65873],{"data":65874,"marks":65875,"value":61187,"nodeType":864},{},[65876],{"type":1455},{"data":65878,"marks":65879,"value":61191,"nodeType":864},{},[],{"data":65881,"content":65882,"nodeType":945},{},[65883],{"data":65884,"content":65885,"nodeType":860},{},[65886],{"data":65887,"marks":65888,"value":61201,"nodeType":864},{},[],{"data":65890,"content":65891,"nodeType":945},{},[65892],{"data":65893,"content":65894,"nodeType":860},{},[65895],{"data":65896,"marks":65897,"value":61211,"nodeType":864},{},[],{"data":65899,"content":65900,"nodeType":945},{},[65901],{"data":65902,"content":65903,"nodeType":860},{},[65904],{"data":65905,"marks":65906,"value":61221,"nodeType":864},{},[],{"data":65908,"content":65909,"nodeType":860},{},[65910,65914,65917],{"data":65911,"marks":65912,"value":61229,"nodeType":864},{},[65913],{"type":899},{"data":65915,"marks":65916,"value":1171,"nodeType":864},{},[],{"data":65918,"marks":65919,"value":61237,"nodeType":864},{},[65920],{"type":899},{"data":65922,"content":65923,"nodeType":860},{},[65924],{"data":65925,"marks":65926,"value":61244,"nodeType":864},{},[],{"data":65928,"content":65929,"nodeType":860},{},[65930],{"data":65931,"marks":65932,"value":61251,"nodeType":864},{},[],{"data":65934,"content":65935,"nodeType":1005},{},[],{"data":65937,"content":65938,"nodeType":1009},{},[65939],{"data":65940,"marks":65941,"value":61262,"nodeType":864},{},[65942],{"type":899},{"data":65944,"content":65945,"nodeType":860},{},[65946],{"data":65947,"marks":65948,"value":61269,"nodeType":864},{},[],{"data":65950,"content":65951,"nodeType":941},{},[65952,65968,65977,65986,65995],{"data":65953,"content":65954,"nodeType":945},{},[65955],{"data":65956,"content":65957,"nodeType":860},{},[65958,65961,65965],{"data":65959,"marks":65960,"value":61282,"nodeType":864},{},[],{"data":65962,"marks":65963,"value":61287,"nodeType":864},{},[65964],{"type":899},{"data":65966,"marks":65967,"value":61291,"nodeType":864},{},[],{"data":65969,"content":65970,"nodeType":945},{},[65971],{"data":65972,"content":65973,"nodeType":860},{},[65974],{"data":65975,"marks":65976,"value":61301,"nodeType":864},{},[],{"data":65978,"content":65979,"nodeType":945},{},[65980],{"data":65981,"content":65982,"nodeType":860},{},[65983],{"data":65984,"marks":65985,"value":61311,"nodeType":864},{},[],{"data":65987,"content":65988,"nodeType":945},{},[65989],{"data":65990,"content":65991,"nodeType":860},{},[65992],{"data":65993,"marks":65994,"value":61321,"nodeType":864},{},[],{"data":65996,"content":65997,"nodeType":945},{},[65998],{"data":65999,"content":66000,"nodeType":860},{},[66001],{"data":66002,"marks":66003,"value":61331,"nodeType":864},{},[],{"data":66005,"content":66006,"nodeType":1312},{},[66007],{"data":66008,"marks":66009,"value":61339,"nodeType":864},{},[66010],{"type":899},{"data":66012,"content":66013,"nodeType":860},{},[66014],{"data":66015,"marks":66016,"value":61346,"nodeType":864},{},[],{"data":66018,"content":66021,"nodeType":996},{"target":66019},{"sys":66020},{"id":61351,"type":1001,"linkType":1002},[],{"data":66023,"content":66026,"nodeType":996},{"target":66024},{"sys":66025},{"id":61357,"type":1001,"linkType":1002},[],{"data":66028,"content":66029,"nodeType":860},{},[66030],{"data":66031,"marks":66032,"value":61365,"nodeType":864},{},[],{"data":66034,"content":66035,"nodeType":860},{},[66036],{"data":66037,"marks":66038,"value":61372,"nodeType":864},{},[],{"data":66040,"content":66041,"nodeType":860},{},[66042,66045,66051],{"data":66043,"marks":66044,"value":61379,"nodeType":864},{},[],{"data":66046,"content":66047,"nodeType":883},{"uri":61382},[66048],{"data":66049,"marks":66050,"value":61387,"nodeType":864},{},[],{"data":66052,"marks":66053,"value":1774,"nodeType":864},{},[],{"data":66055,"content":66056,"nodeType":860},{},[66057],{"data":66058,"marks":66059,"value":61397,"nodeType":864},{},[],{"data":66061,"content":66062,"nodeType":941},{},[66063,66076,66089],{"data":66064,"content":66065,"nodeType":945},{},[66066],{"data":66067,"content":66068,"nodeType":860},{},[66069,66073],{"data":66070,"marks":66071,"value":61411,"nodeType":864},{},[66072],{"type":899},{"data":66074,"marks":66075,"value":61415,"nodeType":864},{},[],{"data":66077,"content":66078,"nodeType":945},{},[66079],{"data":66080,"content":66081,"nodeType":860},{},[66082,66086],{"data":66083,"marks":66084,"value":61426,"nodeType":864},{},[66085],{"type":899},{"data":66087,"marks":66088,"value":61430,"nodeType":864},{},[],{"data":66090,"content":66091,"nodeType":945},{},[66092],{"data":66093,"content":66094,"nodeType":860},{},[66095,66099],{"data":66096,"marks":66097,"value":61441,"nodeType":864},{},[66098],{"type":899},{"data":66100,"marks":66101,"value":61445,"nodeType":864},{},[],{"data":66103,"content":66106,"nodeType":996},{"target":66104},{"sys":66105},{"id":61450,"type":1001,"linkType":1002},[],{"data":66108,"content":66109,"nodeType":1312},{},[66110],{"data":66111,"marks":66112,"value":61459,"nodeType":864},{},[66113],{"type":899},{"data":66115,"content":66116,"nodeType":860},{},[66117,66120,66124,66127],{"data":66118,"marks":66119,"value":61466,"nodeType":864},{},[],{"data":66121,"marks":66122,"value":61471,"nodeType":864},{},[66123],{"type":899},{"data":66125,"marks":66126,"value":61475,"nodeType":864},{},[],{"data":66128,"marks":66129,"value":61480,"nodeType":864},{},[66130],{"type":899},{"data":66132,"content":66133,"nodeType":860},{},[66134],{"data":66135,"marks":66136,"value":61487,"nodeType":864},{},[],{"data":66138,"content":66139,"nodeType":860},{},[66140],{"data":66141,"marks":66142,"value":61494,"nodeType":864},{},[],{"data":66144,"content":66145,"nodeType":941},{},[66146,66155,66164,66173,66182,66191,66200,66209,66218],{"data":66147,"content":66148,"nodeType":945},{},[66149],{"data":66150,"content":66151,"nodeType":860},{},[66152],{"data":66153,"marks":66154,"value":61507,"nodeType":864},{},[],{"data":66156,"content":66157,"nodeType":945},{},[66158],{"data":66159,"content":66160,"nodeType":860},{},[66161],{"data":66162,"marks":66163,"value":61517,"nodeType":864},{},[],{"data":66165,"content":66166,"nodeType":945},{},[66167],{"data":66168,"content":66169,"nodeType":860},{},[66170],{"data":66171,"marks":66172,"value":61527,"nodeType":864},{},[],{"data":66174,"content":66175,"nodeType":945},{},[66176],{"data":66177,"content":66178,"nodeType":860},{},[66179],{"data":66180,"marks":66181,"value":61537,"nodeType":864},{},[],{"data":66183,"content":66184,"nodeType":945},{},[66185],{"data":66186,"content":66187,"nodeType":860},{},[66188],{"data":66189,"marks":66190,"value":61547,"nodeType":864},{},[],{"data":66192,"content":66193,"nodeType":945},{},[66194],{"data":66195,"content":66196,"nodeType":860},{},[66197],{"data":66198,"marks":66199,"value":61557,"nodeType":864},{},[],{"data":66201,"content":66202,"nodeType":945},{},[66203],{"data":66204,"content":66205,"nodeType":860},{},[66206],{"data":66207,"marks":66208,"value":61567,"nodeType":864},{},[],{"data":66210,"content":66211,"nodeType":945},{},[66212],{"data":66213,"content":66214,"nodeType":860},{},[66215],{"data":66216,"marks":66217,"value":61577,"nodeType":864},{},[],{"data":66219,"content":66220,"nodeType":945},{},[66221],{"data":66222,"content":66223,"nodeType":860},{},[66224],{"data":66225,"marks":66226,"value":61587,"nodeType":864},{},[],{"data":66228,"content":66229,"nodeType":860},{},[66230],{"data":66231,"marks":66232,"value":61594,"nodeType":864},{},[],{"data":66234,"content":66235,"nodeType":860},{},[66236,66239,66243],{"data":66237,"marks":66238,"value":61601,"nodeType":864},{},[],{"data":66240,"marks":66241,"value":61606,"nodeType":864},{},[66242],{"type":899},{"data":66244,"marks":66245,"value":61610,"nodeType":864},{},[],{"data":66247,"content":66250,"nodeType":996},{"target":66248},{"sys":66249},{"id":61615,"type":1001,"linkType":1002},[],{"data":66252,"content":66253,"nodeType":1312},{},[66254],{"data":66255,"marks":66256,"value":61311,"nodeType":864},{},[66257],{"type":899},{"data":66259,"content":66260,"nodeType":860},{},[66261],{"data":66262,"marks":66263,"value":61630,"nodeType":864},{},[],{"data":66265,"content":66266,"nodeType":860},{},[66267],{"data":66268,"marks":66269,"value":61637,"nodeType":864},{},[],{"data":66271,"content":66272,"nodeType":860},{},[66273],{"data":66274,"marks":66275,"value":61644,"nodeType":864},{},[],{"data":66277,"content":66278,"nodeType":941},{},[66279,66288,66311,66320],{"data":66280,"content":66281,"nodeType":945},{},[66282],{"data":66283,"content":66284,"nodeType":860},{},[66285],{"data":66286,"marks":66287,"value":61657,"nodeType":864},{},[],{"data":66289,"content":66290,"nodeType":945},{},[66291],{"data":66292,"content":66293,"nodeType":860},{},[66294,66297,66301,66304,66308],{"data":66295,"marks":66296,"value":61667,"nodeType":864},{},[],{"data":66298,"marks":66299,"value":61672,"nodeType":864},{},[66300],{"type":899},{"data":66302,"marks":66303,"value":61676,"nodeType":864},{},[],{"data":66305,"marks":66306,"value":61681,"nodeType":864},{},[66307],{"type":899},{"data":66309,"marks":66310,"value":61685,"nodeType":864},{},[],{"data":66312,"content":66313,"nodeType":945},{},[66314],{"data":66315,"content":66316,"nodeType":860},{},[66317],{"data":66318,"marks":66319,"value":61695,"nodeType":864},{},[],{"data":66321,"content":66322,"nodeType":945},{},[66323],{"data":66324,"content":66325,"nodeType":860},{},[66326],{"data":66327,"marks":66328,"value":61705,"nodeType":864},{},[],{"data":66330,"content":66333,"nodeType":996},{"target":66331},{"sys":66332},{"id":61710,"type":1001,"linkType":1002},[],{"data":66335,"content":66338,"nodeType":996},{"target":66336},{"sys":66337},{"id":61716,"type":1001,"linkType":1002},[],{"data":66340,"content":66341,"nodeType":1312},{},[66342],{"data":66343,"marks":66344,"value":61725,"nodeType":864},{},[66345],{"type":899},{"data":66347,"content":66348,"nodeType":860},{},[66349],{"data":66350,"marks":66351,"value":61732,"nodeType":864},{},[],{"data":66353,"content":66354,"nodeType":860},{},[66355],{"data":66356,"marks":66357,"value":61739,"nodeType":864},{},[],{"data":66359,"content":66360,"nodeType":941},{},[66361,66370],{"data":66362,"content":66363,"nodeType":945},{},[66364],{"data":66365,"content":66366,"nodeType":860},{},[66367],{"data":66368,"marks":66369,"value":61752,"nodeType":864},{},[],{"data":66371,"content":66372,"nodeType":945},{},[66373],{"data":66374,"content":66375,"nodeType":860},{},[66376],{"data":66377,"marks":66378,"value":61762,"nodeType":864},{},[],{"data":66380,"content":66381,"nodeType":860},{},[66382],{"data":66383,"marks":66384,"value":61769,"nodeType":864},{},[],{"data":66386,"content":66389,"nodeType":996},{"target":66387},{"sys":66388},{"id":61774,"type":1001,"linkType":1002},[],{"data":66391,"content":66392,"nodeType":860},{},[66393,66397,66405],{"data":66394,"marks":66395,"value":61783,"nodeType":864},{},[66396],{"type":899},{"data":66398,"content":66399,"nodeType":883},{"uri":61786},[66400],{"data":66401,"marks":66402,"value":61793,"nodeType":864},{},[66403,66404],{"type":1455},{"type":899},{"data":66406,"marks":66407,"value":11546,"nodeType":864},{},[66408],{"type":899},{"data":66410,"content":66413,"nodeType":996},{"target":66411},{"sys":66412},{"id":49781,"type":1001,"linkType":1002},[],{"data":66415,"content":66416,"nodeType":860},{},[66417],{"data":66418,"marks":66419,"value":61809,"nodeType":864},{},[],{"data":66421,"content":66422,"nodeType":1312},{},[66423],{"data":66424,"marks":66425,"value":61331,"nodeType":864},{},[66426],{"type":899},{"data":66428,"content":66429,"nodeType":860},{},[66430],{"data":66431,"marks":66432,"value":61823,"nodeType":864},{},[],{"data":66434,"content":66435,"nodeType":860},{},[66436],{"data":66437,"marks":66438,"value":61830,"nodeType":864},{},[],{"data":66440,"content":66441,"nodeType":941},{},[66442,66451,66460],{"data":66443,"content":66444,"nodeType":945},{},[66445],{"data":66446,"content":66447,"nodeType":860},{},[66448],{"data":66449,"marks":66450,"value":61843,"nodeType":864},{},[],{"data":66452,"content":66453,"nodeType":945},{},[66454],{"data":66455,"content":66456,"nodeType":860},{},[66457],{"data":66458,"marks":66459,"value":61853,"nodeType":864},{},[],{"data":66461,"content":66462,"nodeType":945},{},[66463],{"data":66464,"content":66465,"nodeType":860},{},[66466],{"data":66467,"marks":66468,"value":61863,"nodeType":864},{},[],{"data":66470,"content":66471,"nodeType":860},{},[66472,66475,66482],{"data":66473,"marks":66474,"value":61870,"nodeType":864},{},[],{"data":66476,"content":66477,"nodeType":883},{"uri":61873},[66478],{"data":66479,"marks":66480,"value":61879,"nodeType":864},{},[66481],{"type":1455},{"data":66483,"marks":66484,"value":21,"nodeType":864},{},[],{"data":66486,"content":66487,"nodeType":860},{},[66488],{"data":66489,"marks":66490,"value":61889,"nodeType":864},{},[],{"data":66492,"content":66493,"nodeType":1116},{},[66494],{"data":66495,"content":66496,"nodeType":860},{},[66497],{"data":66498,"marks":66499,"value":61900,"nodeType":864},{},[66500],{"type":899},{"data":66502,"content":66503,"nodeType":1005},{},[],{"data":66505,"content":66506,"nodeType":1312},{},[66507],{"data":66508,"marks":66509,"value":61911,"nodeType":864},{},[66510],{"type":899},{"data":66512,"content":66513,"nodeType":860},{},[66514],{"data":66515,"marks":66516,"value":61918,"nodeType":864},{},[],{"data":66518,"content":66521,"nodeType":996},{"target":66519},{"sys":66520},{"id":61923,"type":1001,"linkType":1002},[],{"data":66523,"content":66524,"nodeType":1005},{},[],{"data":66526,"content":66527,"nodeType":1009},{},[66528],{"data":66529,"marks":66530,"value":61935,"nodeType":864},{},[66531],{"type":899},{"data":66533,"content":66534,"nodeType":1312},{},[66535],{"data":66536,"marks":66537,"value":61943,"nodeType":864},{},[66538],{"type":899},{"data":66540,"content":66541,"nodeType":860},{},[66542],{"data":66543,"marks":66544,"value":61950,"nodeType":864},{},[],{"data":66546,"content":66547,"nodeType":860},{},[66548,66551,66558],{"data":66549,"marks":66550,"value":61957,"nodeType":864},{},[],{"data":66552,"content":66553,"nodeType":883},{"uri":61960},[66554],{"data":66555,"marks":66556,"value":61966,"nodeType":864},{},[66557],{"type":1455},{"data":66559,"marks":66560,"value":2924,"nodeType":864},{},[],{"data":66562,"content":66563,"nodeType":860},{},[66564],{"data":66565,"marks":66566,"value":61976,"nodeType":864},{},[],{"data":66568,"content":66569,"nodeType":860},{},[66570],{"data":66571,"marks":66572,"value":61983,"nodeType":864},{},[],{"data":66574,"content":66577,"nodeType":996},{"target":66575},{"sys":66576},{"id":61988,"type":1001,"linkType":1002},[],{"data":66579,"content":66580,"nodeType":860},{},[66581],{"data":66582,"marks":66583,"value":61996,"nodeType":864},{},[],{"data":66585,"content":66586,"nodeType":860},{},[66587],{"data":66588,"marks":66589,"value":62003,"nodeType":864},{},[],{"data":66591,"content":66594,"nodeType":996},{"target":66592},{"sys":66593},{"id":62008,"type":1001,"linkType":1002},[],{"data":66596,"content":66597,"nodeType":1005},{},[],{"data":66599,"content":66600,"nodeType":1009},{},[66601],{"data":66602,"marks":66603,"value":3578,"nodeType":864},{},[66604],{"type":899},{"data":66606,"content":66607,"nodeType":860},{},[66608,66611,66617],{"data":66609,"marks":66610,"value":53360,"nodeType":864},{},[],{"data":66612,"content":66613,"nodeType":883},{"uri":27},[66614],{"data":66615,"marks":66616,"value":62032,"nodeType":864},{},[],{"data":66618,"marks":66619,"value":2924,"nodeType":864},{},[],{"data":66621,"content":66622,"nodeType":860},{},[66623],{"data":66624,"marks":66625,"value":53378,"nodeType":864},{},[],{"data":66627,"content":66628,"nodeType":860},{},[66629,66632,66639,66642,66649,66652,66659],{"data":66630,"marks":66631,"value":62048,"nodeType":864},{},[],{"data":66633,"content":66634,"nodeType":883},{"uri":16866},[66635],{"data":66636,"marks":66637,"value":62056,"nodeType":864},{},[66638],{"type":1455},{"data":66640,"marks":66641,"value":3731,"nodeType":864},{},[],{"data":66643,"content":66644,"nodeType":883},{"uri":16877},[66645],{"data":66646,"marks":66647,"value":62067,"nodeType":864},{},[66648],{"type":1455},{"data":66650,"marks":66651,"value":16887,"nodeType":864},{},[],{"data":66653,"content":66654,"nodeType":883},{"uri":1700},[66655],{"data":66656,"marks":66657,"value":16894,"nodeType":864},{},[66658],{"type":1455},{"data":66660,"marks":66661,"value":2924,"nodeType":864},{},[],{"entries":66663},{"hyperlink":66664,"inline":66665,"block":66666},[],[],[66667,66703,66708,66722,66728,66733,66738,66752,66766,66769,66774,66781],{"sys":66668,"__typename":1740,"content":66669,"name":66702,"title":59},{"id":61124},{"json":66670},{"data":66671,"content":66672,"nodeType":856},{},[66673,66680],{"data":66674,"content":66675,"nodeType":860},{},[66676],{"data":66677,"marks":66678,"value":66679,"nodeType":864},{},[],"Imagine the scenario. There’s a small dev team responsible for a basic but widely used extension (let’s say a color picker tool) with millions of users. An attacker just needs to phish a dev (that might not even be working from a device with proper security software or controls), grab the extension code that is publicly available from the store, insert obfuscated malicious code, and upload the new version to the store. As soon as the extension updates, millions of browsers are compromised. ",{"data":66681,"content":66682,"nodeType":860},{},[66683,66688,66698],{"data":66684,"marks":66685,"value":66687,"nodeType":864},{},[66686],{"type":899},"This is why we take our own security processes around extension management so seriously. ",{"data":66689,"content":66691,"nodeType":883},{"uri":66690},"https://pushsecurity.com/blog/guide-to-secure-browser-extension-deployment/",[66692],{"data":66693,"marks":66694,"value":66697,"nodeType":864},{},[66695,66696],{"type":1455},{"type":899},"You can find out more about our process here",{"data":66699,"marks":66700,"value":1774,"nodeType":864},{},[66701],{"type":899},"Managing Extensions Guide: IB1",{"sys":66704,"__typename":1724,"title":66705,"caption":66705,"layoutMode":59,"file":66706},{"id":61351},"Enabling the malicious extension detection feature in the Push platform",{"url":66707,"width":64970,"height":64971},"https://images.ctfassets.net/y1cdw1ablpvd/5DUcgBc8Fcx825yar7LX67/f18970551bfb9d59f206add2af106b89/image6.png",{"sys":66709,"__typename":1740,"content":66710,"name":66721,"title":59},{"id":61357},{"json":66711},{"nodeType":856,"data":66712,"content":66713},{},[66714],{"nodeType":860,"data":66715,"content":66716},{},[66717],{"nodeType":864,"value":66718,"marks":66719,"data":66720},"Even if you’re blocking employees from installing extensions without admin approval, an extension that was safe and approved yesterday can be malicious today. This is why it’s vital that organizations proactively block known-bad extensions — particularly when extension stores cannot be relied upon to disable extensions already installed in your employee browsers. Early intervention can mean the difference between a malicious update being deployed and browser secrets being stolen, and disabling the extension before any harm is done. ",[],{},"Managing Extensions Guide: IB2",{"sys":66723,"__typename":1724,"title":66724,"caption":66725,"layoutMode":59,"file":66726},{"id":61450},"Malicious browser extension detection event including install path","Malicious browser extension detection event",{"url":66727,"width":50166,"height":50167},"https://images.ctfassets.net/y1cdw1ablpvd/2p1cdetW36dOixy4kRIhn0/2298cef9060ae451780d359896588a39/malicious_extension_detection_slideout.png",{"sys":66729,"__typename":1717,"type":1718,"ctaText":66730,"buttonLabel":66731,"buttonColour":1721,"buttonUrl":66732},{"id":61615},"Join Push Security Field CTO Mark Orlando for a teardown of malicious browser extension functionality, and what security teams can do about this growing threat.","Now On-Demand","https://pushsecurity.com/webinar/browser-extension-attacks",{"sys":66734,"__typename":1724,"title":66735,"caption":66735,"layoutMode":59,"file":66736},{"id":61710},"Browser extension permission filtering",{"url":66737,"width":45755,"height":45756},"https://images.ctfassets.net/y1cdw1ablpvd/297Zj9KN9kGGkSXVK6zWiG/2b4d559fe5fec1e067e602edae889be0/Browser_extension_permission_filtering__2_.gif",{"sys":66739,"__typename":1740,"content":66740,"name":66751,"title":59},{"id":61716},{"json":66741},{"data":66742,"content":66743,"nodeType":856},{},[66744],{"data":66745,"content":66746,"nodeType":860},{},[66747],{"data":66748,"marks":66749,"value":66750,"nodeType":864},{},[],"Pretty much every extension has permissions that could be considered risky and exploited by an attacker, so permissions alone are not a great benchmark for whether it should be allowed or not. But extensive permissions plus an unverified publisher or a recent change in ownership might be enough to prioritize an extension for removal.","Managing Extensions Guide: IB4",{"sys":66753,"__typename":1740,"content":66754,"name":66765,"title":59},{"id":61774},{"json":66755},{"nodeType":856,"data":66756,"content":66757},{},[66758],{"nodeType":860,"data":66759,"content":66760},{},[66761],{"nodeType":864,"value":66762,"marks":66763,"data":66764},"If you plan to restrict the extensions that your employees can install and run, you’ll need to create a workflow where employees can request new extensions and the number of extensions that would need to be reviewed. This is something that you should be able to create using your ITSM tooling in the same way that any other software is requested. ",[],{},"Managing Extensions Guide: IB5",{"sys":66767,"__typename":1724,"title":50155,"caption":50156,"layoutMode":59,"file":66768},{"id":49781},{"url":50158,"width":50159,"height":50160},{"sys":66770,"__typename":1724,"title":66771,"caption":59,"layoutMode":59,"file":66772},{"id":61923},"GitLab malicious extensions quote",{"url":66773,"width":1736,"height":1737},"https://images.ctfassets.net/y1cdw1ablpvd/xod7FhG6yTK1iTePEKahw/7f30d66068fd2e36648ed9bab35920c4/image7.png",{"sys":66775,"__typename":1724,"title":66776,"caption":59,"layoutMode":59,"file":66777},{"id":61988},"Disable browser extension syncing in Google Workspace",{"url":66778,"width":66779,"height":66780},"https://images.ctfassets.net/y1cdw1ablpvd/5YSw6EyTZgcx36eXwwdrBQ/8b4ea60632667f07bb6d11841aa8a86c/image4.png",1256,662,{"sys":66782,"__typename":1724,"title":66783,"caption":66783,"layoutMode":59,"file":66784},{"id":62008},"See browser profile across all browsers using Push",{"url":66785,"width":59790,"height":59791},"https://images.ctfassets.net/y1cdw1ablpvd/3eWEtmkukL5JzeArcty88m/22aec4f6ce2ef0d309eab015e1efe493/image1.png",{"items":66787},[],{},"How to manage and block browser extensions using Push",{"items":66791},[66792,68090,68489],{"__typename":2059,"sys":66793,"content":66795,"title":68076,"synopsis":68077,"hashTags":59,"publishedDate":68078,"slug":68079,"tagsCollection":68080,"authorsCollection":68086},{"id":66794},"37KWV8V5L3aNZBSx6JMd0Z",{"json":66796},{"data":66797,"content":66798,"nodeType":856},{},[66799,66806,66813,66874,66881,66950,66956,66963,66970,66973,66980,66987,66994,67096,67115,67122,67164,67171,67178,67185,67218,67224,67255,67260,67267,67274,67307,67327,67330,67337,67343,67374,67381,67388,67395,67401,67408,67414,67429,67472,67478,67497,67500,67507,67513,67533,67540,67569,67588,67594,67615,67622,67629,67689,67696,67702,67716,67730,67750,67756,67777,67784,67787,67794,67800,67807,67814,67834,67840,67860,67865,67872,67905,67923,67926,67933,67939,67946,67967,67973,67988,67994,68001,68008,68027,68030,68036,68043,68050],{"data":66800,"content":66801,"nodeType":860},{},[66802],{"data":66803,"marks":66804,"value":66805,"nodeType":864},{},[],"Looking back over the year’s headlines and trending TTPs, it’s clear that 2025 was the year that browser-based account takeover techniques made the leap into the mainstream.",{"data":66807,"content":66808,"nodeType":860},{},[66809],{"data":66810,"marks":66811,"value":66812,"nodeType":864},{},[],"A few stats tell the story …",{"data":66814,"content":66815,"nodeType":941},{},[66816,66835,66854],{"data":66817,"content":66818,"nodeType":945},{},[66819],{"data":66820,"content":66821,"nodeType":860},{},[66822,66826,66832],{"data":66823,"marks":66824,"value":66825,"nodeType":864},{},[],"Identity-based attacks surged by 32% over the last year, and 97% of identity attacks were password-based, driven by a combination of credential leaks and infostealer malware. (",{"data":66827,"content":66828,"nodeType":883},{"uri":57747},[66829],{"data":66830,"marks":66831,"value":19538,"nodeType":864},{},[],{"data":66833,"marks":66834,"value":57756,"nodeType":864},{},[],{"data":66836,"content":66837,"nodeType":945},{},[66838],{"data":66839,"content":66840,"nodeType":860},{},[66841,66845,66851],{"data":66842,"marks":66843,"value":66844,"nodeType":864},{},[],"ClickFix was the most common initial point of access for adversaries in the past year, accounting for a whopping 47% of observed attacks. (",{"data":66846,"content":66847,"nodeType":883},{"uri":57747},[66848],{"data":66849,"marks":66850,"value":19538,"nodeType":864},{},[],{"data":66852,"marks":66853,"value":57756,"nodeType":864},{},[],{"data":66855,"content":66856,"nodeType":945},{},[66857],{"data":66858,"content":66859,"nodeType":860},{},[66860,66864,66871],{"data":66861,"marks":66862,"value":66863,"nodeType":864},{},[],"Pure malware-based attacks declined, as adversaries continued to shift from targeting endpoints to corporate identities. In the last year-plus, 79% of detections were malware-free, up from 40% in 2019. And abuse of valid accounts was responsible for more than one-third of all cloud-related incidents. (",{"data":66865,"content":66866,"nodeType":883},{"uri":57769},[66867],{"data":66868,"marks":66869,"value":66870,"nodeType":864},{},[],"Crowdstrike",{"data":66872,"marks":66873,"value":57756,"nodeType":864},{},[],{"data":66875,"content":66876,"nodeType":860},{},[66877],{"data":66878,"marks":66879,"value":66880,"nodeType":864},{},[],"… and so do the headlines from 2025:",{"data":66882,"content":66883,"nodeType":941},{},[66884,66903,66931],{"data":66885,"content":66886,"nodeType":945},{},[66887],{"data":66888,"content":66889,"nodeType":860},{},[66890,66894,66899],{"data":66891,"marks":66892,"value":66893,"nodeType":864},{},[],"Attackers stole over ",{"data":66895,"marks":66896,"value":66898,"nodeType":864},{},[66897],{"type":899},"1.5 billion records",{"data":66900,"marks":66901,"value":66902,"nodeType":864},{},[]," from an estimated 1,000+ Salesforce tenants by exploiting integrations (Salesloft, Gainsight), phishing credentials, and by tricking users into installing a malicious OAuth app.",{"data":66904,"content":66905,"nodeType":945},{},[66906],{"data":66907,"content":66908,"nodeType":860},{},[66909,66913,66918,66922,66927],{"data":66910,"marks":66911,"value":66912,"nodeType":864},{},[],"Marks & Spencer was hit with a help desk scam that led to a compromised Microsoft Entra account, followed by a ransomware deployment resulting in months of disruption, ",{"data":66914,"marks":66915,"value":66917,"nodeType":864},{},[66916],{"type":899},"$400M",{"data":66919,"marks":66920,"value":66921,"nodeType":864},{},[]," in lost profits, and around ",{"data":66923,"marks":66924,"value":66926,"nodeType":864},{},[66925],{"type":899},"$1.3B",{"data":66928,"marks":66929,"value":66930,"nodeType":864},{},[]," wiped off their stock market valuation at one stage.",{"data":66932,"content":66933,"nodeType":945},{},[66934],{"data":66935,"content":66936,"nodeType":860},{},[66937,66941,66946],{"data":66938,"marks":66939,"value":66940,"nodeType":864},{},[],"Jaguar Land Rover was compromised via highly privileged admin accounts — another help desk scam targeting workforce credentials for initial access — resulting in months of disruption that led the UK government to underwrite a ",{"data":66942,"marks":66943,"value":66945,"nodeType":864},{},[66944],{"type":899},"$1.5B",{"data":66947,"marks":66948,"value":66949,"nodeType":864},{},[]," loan to alleviate the supply chain impact. This was the most economically consequential cyber attack yet recorded in a G7 economy.",{"data":66951,"content":66955,"nodeType":996},{"target":66952},{"sys":66953},{"id":66954,"type":1001,"linkType":1002},"v5YYnjP2NViOh6Ucxp2Fe",[],{"data":66957,"content":66958,"nodeType":860},{},[66959],{"data":66960,"marks":66961,"value":66962,"nodeType":864},{},[],"At Push, we’ve been closely tracking the evolution of browser-based attacks. Looking back at 2025, we’ve seen a notable increase in the sophistication and frequency of modern attack techniques methods like ClickFix, commodified phish kits that bypass MFA, malicious browser extensions, and many more. (Writing phish kit teardowns for the Push blog is practically a full-time job now.)",{"data":66964,"content":66965,"nodeType":860},{},[66966],{"data":66967,"marks":66968,"value":66969,"nodeType":864},{},[],"In this article, we’ll take a look at how real-world attacks and our own research drove the features we delivered for Push customers this year to take the fight to adversaries.",{"data":66971,"content":66972,"nodeType":1005},{},[],{"data":66974,"content":66975,"nodeType":1009},{},[66976],{"data":66977,"marks":66978,"value":66979,"nodeType":864},{},[],"Detecting and blocking increasingly sophisticated phishing-as-a-service tools",{"data":66981,"content":66982,"nodeType":1312},{},[66983],{"data":66984,"marks":66985,"value":66986,"nodeType":864},{},[],"What happened",{"data":66988,"content":66989,"nodeType":860},{},[66990],{"data":66991,"marks":66992,"value":66993,"nodeType":864},{},[],"The current state of the art for phishing centers on three core developments:",{"data":66995,"content":66996,"nodeType":941},{},[66997,67026,67067],{"data":66998,"content":66999,"nodeType":945},{},[67000],{"data":67001,"content":67002,"nodeType":860},{},[67003,67008,67012,67022],{"data":67004,"marks":67005,"value":67007,"nodeType":864},{},[67006],{"type":899},"Detection evasion: ",{"data":67009,"marks":67010,"value":67011,"nodeType":864},{},[],"Adversaries demonstrated a ",{"data":67013,"content":67017,"nodeType":39736},{"target":67014},{"sys":67015},{"id":67016,"type":1001,"linkType":1002},"4XZ6qCr8pjJvcD7hi09x2Y",[67018],{"data":67019,"marks":67020,"value":67021,"nodeType":864},{},[],"creative array of approaches",{"data":67023,"marks":67024,"value":67025,"nodeType":864},{},[]," this year to hide their intentions from end-users and defenders, using methods such as sending phishing emails from legitimate services; serving phishing pages via malvertising and SEO poisoning; and obfuscating URLs. More sophisticated techniques used page-level obfuscation, cross-domain iframes, single-use links, and legitimate OIDC logins to evade detection and analysis from traditional tools.",{"data":67027,"content":67028,"nodeType":945},{},[67029],{"data":67030,"content":67031,"nodeType":860},{},[67032,67037,67041,67050,67054,67064],{"data":67033,"marks":67034,"value":67036,"nodeType":864},{},[67035],{"type":899},"Multi-channel delivery of lures:",{"data":67038,"marks":67039,"value":67040,"nodeType":864},{},[]," Adversaries proved the truism of “phishing doesn’t just happen in the mailbox” this year by increasing their observed use of ",{"data":67042,"content":67046,"nodeType":39736},{"target":67043},{"sys":67044},{"id":67045,"type":1001,"linkType":1002},"72lLmy0CXnOp3LWOdcUguX",[67047],{"data":67048,"marks":67049,"value":441,"nodeType":864},{},[],{"data":67051,"marks":67052,"value":67053,"nodeType":864},{},[]," and SEO poisoning — techniques that place malicious pages within trusted contexts like the Google search engine results page — as well as the use of social media services like LinkedIn to ",{"data":67055,"content":67059,"nodeType":39736},{"target":67056},{"sys":67057},{"id":67058,"type":1001,"linkType":1002},"2yEhB2gFC2TJDLquVP3cg2",[67060],{"data":67061,"marks":67062,"value":67063,"nodeType":864},{},[],"deliver phishing lures",{"data":67065,"marks":67066,"value":1774,"nodeType":864},{},[],{"data":67068,"content":67069,"nodeType":945},{},[67070],{"data":67071,"content":67072,"nodeType":860},{},[67073,67078,67082,67092],{"data":67074,"marks":67075,"value":67077,"nodeType":864},{},[67076],{"type":899},"Commodification of phishing toolkits:",{"data":67079,"marks":67080,"value":67081,"nodeType":864},{},[]," Phishing-as-a-service (PhaaS) kits have become another SaaS with their own supply chain, including developers of malicious tooling, operators who run the campaigns, and brokers who sell stolen credentials and tokens. The incentives for attackers are clear: quick ROI from targeting workforce identities, and out-of-the-box tools that make it easier to efficiently spin up new campaigns or try new techniques. As with any SaaS offering, the customer (attackers, in this case) benefits from rapid innovations they didn’t have to build. We saw this recently with the ",{"data":67083,"content":67087,"nodeType":39736},{"target":67084},{"sys":67085},{"id":67086,"type":1001,"linkType":1002},"6QLonRmBzbj9h88Y7jD0LU",[67088],{"data":67089,"marks":67090,"value":67091,"nodeType":864},{},[],"addition of a browser-in-the-browser (BitB) technique",{"data":67093,"marks":67094,"value":67095,"nodeType":864},{},[]," to the phish kit Sneaky2FA — a change that makes it even more effective.",{"data":67097,"content":67098,"nodeType":860},{},[67099,67103,67111],{"data":67100,"marks":67101,"value":67102,"nodeType":864},{},[],"In 2025, Push researchers tracked how each of these developments expanded in scope and sophistication. Check out our ",{"data":67104,"content":67106,"nodeType":883},{"uri":67105},"https://pushsecurity.github.io/phishing-techniques/",[67107],{"data":67108,"marks":67109,"value":67110,"nodeType":864},{},[],"phishing detection evasion techniques matrix",{"data":67112,"marks":67113,"value":67114,"nodeType":864},{},[]," on Github for more detail. ",{"data":67116,"content":67117,"nodeType":860},{},[67118],{"data":67119,"marks":67120,"value":67121,"nodeType":864},{},[],"The takeaways for security teams?",{"data":67123,"content":67124,"nodeType":941},{},[67125,67135,67154],{"data":67126,"content":67127,"nodeType":945},{},[67128],{"data":67129,"content":67130,"nodeType":860},{},[67131],{"data":67132,"marks":67133,"value":67134,"nodeType":864},{},[],"You can’t block your way to safety when adversaries are using the same legitimate apps that your employees use.",{"data":67136,"content":67137,"nodeType":945},{},[67138],{"data":67139,"content":67140,"nodeType":860},{},[67141,67145,67150],{"data":67142,"marks":67143,"value":67144,"nodeType":864},{},[],"Similarly, while end-user training is important, it’s not reasonable to expect employees to know when a SharePoint document link is malicious when it looks identical to the ones they trust every day — because adversaries ",{"data":67146,"marks":67147,"value":67149,"nodeType":864},{},[67148],{"type":2246},"are using the legitimate service",{"data":67151,"marks":67152,"value":67153,"nodeType":864},{},[],". Push researchers have observed the abuse of hundreds of legitimate services in phishing attacks this year.",{"data":67155,"content":67156,"nodeType":945},{},[67157],{"data":67158,"content":67159,"nodeType":860},{},[67160],{"data":67161,"marks":67162,"value":67163,"nodeType":864},{},[],"Security solutions need to be able to analyze real-time context and behavior, not rely solely on inferences from secondary characteristics like domain reputation.",{"data":67165,"content":67166,"nodeType":860},{},[67167],{"data":67168,"marks":67169,"value":67170,"nodeType":864},{},[],"Here's what we built to help defend organizations.",{"data":67172,"content":67173,"nodeType":1312},{},[67174],{"data":67175,"marks":67176,"value":67177,"nodeType":864},{},[],"What we built",{"data":67179,"content":67180,"nodeType":860},{},[67181],{"data":67182,"marks":67183,"value":67184,"nodeType":864},{},[],"The feature we built in 2025 that gave us unique insight into these TTPs is Push’s Detections capability. With Detections, you can:",{"data":67186,"content":67187,"nodeType":941},{},[67188,67198,67208],{"data":67189,"content":67190,"nodeType":945},{},[67191],{"data":67192,"content":67193,"nodeType":860},{},[67194],{"data":67195,"marks":67196,"value":67197,"nodeType":864},{},[],"Get alerted when Push detects a browser-based attack, and see how the Push agent responded to block the attack. The platform provides a front-end view for quick triage, and you can also pipe the detection events to your SIEM or other platform of choice.",{"data":67199,"content":67200,"nodeType":945},{},[67201],{"data":67202,"content":67203,"nodeType":860},{},[67204],{"data":67205,"marks":67206,"value":67207,"nodeType":864},{},[],"Review a timeline of the incident: Where a phishing link originated; whether a user entered their credentials; what kind of phishkit was detected; and how Push responded (configurable based on your environment).",{"data":67209,"content":67210,"nodeType":945},{},[67211],{"data":67212,"content":67213,"nodeType":860},{},[67214],{"data":67215,"marks":67216,"value":67217,"nodeType":864},{},[],"Get actionable telemetry and metadata about an incident, including a screenshot of the malicious page to see exactly what the user saw; intel about the involved domains, including when they were registered and if they’ve been scanned by urlscan before; and the blast radius of an attack, including other apps that shared a password with the potentially compromised account",{"data":67219,"content":67223,"nodeType":996},{"target":67220},{"sys":67221},{"id":67222,"type":1001,"linkType":1002},"5dygPaG3Gfw4Yeicffv6tV",[],{"data":67225,"content":67226,"nodeType":860},{},[67227,67231,67236,67239,67244,67247,67251],{"data":67228,"marks":67229,"value":67230,"nodeType":864},{},[],"This telemetry — combined with Push’s out-of-the-box controls like ",{"data":67232,"marks":67233,"value":67235,"nodeType":864},{},[67234],{"type":899},"Phishing tool detection",{"data":67237,"marks":67238,"value":3731,"nodeType":864},{},[],{"data":67240,"marks":67241,"value":67243,"nodeType":864},{},[67242],{"type":899},"Cloned login page detection",{"data":67245,"marks":67246,"value":2232,"nodeType":864},{},[],{"data":67248,"marks":67249,"value":65229,"nodeType":864},{},[67250],{"type":899},{"data":67252,"marks":67253,"value":67254,"nodeType":864},{},[]," (aka ClickFix detection) — give you a seat on the user’s side of the equation, capturing real-time information about what users did and the TTPs of an attack so you can investigate and respond efficiently and confidently.",{"data":67256,"content":67259,"nodeType":996},{"target":67257},{"sys":67258},{"id":65484,"type":1001,"linkType":1002},[],{"data":67261,"content":67262,"nodeType":860},{},[67263],{"data":67264,"marks":67265,"value":67266,"nodeType":864},{},[],"With the visibility provided by this telemetry across Push’s install base, our R&D and Product teams have rapidly iterated all year on our detections to increase coverage and respond quickly to newly identified attack types.",{"data":67268,"content":67269,"nodeType":860},{},[67270],{"data":67271,"marks":67272,"value":67273,"nodeType":864},{},[],"This year, we also released:",{"data":67275,"content":67276,"nodeType":941},{},[67277,67287,67297],{"data":67278,"content":67279,"nodeType":945},{},[67280],{"data":67281,"content":67282,"nodeType":860},{},[67283],{"data":67284,"marks":67285,"value":67286,"nodeType":864},{},[],"Detections for new variants of cloned login pages and AiTM phish kits.",{"data":67288,"content":67289,"nodeType":945},{},[67290],{"data":67291,"content":67292,"nodeType":860},{},[67293],{"data":67294,"marks":67295,"value":67296,"nodeType":864},{},[],"12+ pre-release detections focused on flagging emerging attacker techniques.",{"data":67298,"content":67299,"nodeType":945},{},[67300],{"data":67301,"content":67302,"nodeType":860},{},[67303],{"data":67304,"marks":67305,"value":67306,"nodeType":864},{},[],"7+ first-class SIEM and SOAR integrations, to make it simpler to ingest Push telemetry and operationalize it.",{"data":67308,"content":67309,"nodeType":860},{},[67310,67314,67324],{"data":67311,"marks":67312,"value":67313,"nodeType":864},{},[],"Learn more about Push’s detections features in our ",{"data":67315,"content":67319,"nodeType":39736},{"target":67316},{"sys":67317},{"id":67318,"type":1001,"linkType":1002},"6OFdfAsoPUECeRAetWvedp",[67320],{"data":67321,"marks":67322,"value":67323,"nodeType":864},{},[],"blog article",{"data":67325,"marks":67326,"value":2924,"nodeType":864},{},[],{"data":67328,"content":67329,"nodeType":1005},{},[],{"data":67331,"content":67332,"nodeType":1009},{},[67333],{"data":67334,"marks":67335,"value":67336,"nodeType":864},{},[],"Detecting and blocking ClickFix-style malicious copy and paste attacks",{"data":67338,"content":67339,"nodeType":1312},{},[67340],{"data":67341,"marks":67342,"value":66986,"nodeType":864},{},[],{"data":67344,"content":67345,"nodeType":860},{},[67346,67350,67358,67362,67370],{"data":67347,"marks":67348,"value":67349,"nodeType":864},{},[],"ClickFix-style attacks left their mark in 2025, quickly becoming one of the most prevalent attack techniques — with ",{"data":67351,"content":67353,"nodeType":883},{"uri":67352},"https://www.scworld.com/news/clickfix-phishing-links-increased-nearly-400-in-12-months-report-says",[67354],{"data":67355,"marks":67356,"value":67357,"nodeType":864},{},[],"estimates",{"data":67359,"marks":67360,"value":67361,"nodeType":864},{},[]," of a 400 percent year-over-year increase, and another ",{"data":67363,"content":67365,"nodeType":883},{"uri":67364},"https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12025.pdf",[67366],{"data":67367,"marks":67368,"value":67369,"nodeType":864},{},[],"report",{"data":67371,"marks":67372,"value":67373,"nodeType":864},{},[]," documenting a 517 percent growth in just the last 6 months of the year.",{"data":67375,"content":67376,"nodeType":860},{},[67377],{"data":67378,"marks":67379,"value":67380,"nodeType":864},{},[],"What is ClickFix? This attack technique prompts the user to solve some kind of problem or troubleshooting step in the browser — often presented as a CAPTCHA challenge. The key aspect of the attack is that it tricks users into running malicious commands on their device by copying malicious code from the page clipboard and running it locally. (The copy typically occurs  automatically via the page itself, but can also be performed manually by the user.)",{"data":67382,"content":67383,"nodeType":860},{},[67384],{"data":67385,"marks":67386,"value":67387,"nodeType":864},{},[],"These malicious copy and paste attacks are often used to deliver infostealer malware or remote access software, with the attacker’s end goal being stealing session cookies and credentials to facilitate attacks on business apps.",{"data":67389,"content":67390,"nodeType":860},{},[67391],{"data":67392,"marks":67393,"value":67394,"nodeType":864},{},[],"What’s especially challenging about this attack type is that it usually can only be detected after the fact — when a machine is already compromised, or malicious code attempts to execute (if EDR catches it). Even if it is detected, security teams are left flying blind when they try to determine the initial vector for the attack, and which other users might have been targeted.",{"data":67396,"content":67397,"nodeType":1312},{},[67398],{"data":67399,"marks":67400,"value":67177,"nodeType":864},{},[],{"data":67402,"content":67403,"nodeType":860},{},[67404],{"data":67405,"marks":67406,"value":67407,"nodeType":864},{},[],"Because of our position in the browser, Push is uniquely positioned to detect and block browser-native attacks like ClickFix and other forms of malicious copy and paste techniques. So that’s what we built.",{"data":67409,"content":67413,"nodeType":996},{"target":67410},{"sys":67411},{"id":67412,"type":1001,"linkType":1002},"56jVT7dbNqUGiSRTfTCQw2",[],{"data":67415,"content":67416,"nodeType":860},{},[67417,67421,67425],{"data":67418,"marks":67419,"value":67420,"nodeType":864},{},[],"With our ",{"data":67422,"marks":67423,"value":65229,"nodeType":864},{},[67424],{"type":899},{"data":67426,"marks":67427,"value":67428,"nodeType":864},{},[],", you can:",{"data":67430,"content":67431,"nodeType":941},{},[67432,67442,67452,67462],{"data":67433,"content":67434,"nodeType":945},{},[67435],{"data":67436,"content":67437,"nodeType":860},{},[67438],{"data":67439,"marks":67440,"value":67441,"nodeType":864},{},[],"Detect ClickFix-style attacks as soon as they target end-users, regardless of the delivery channel for the lure, or the specifics of the malware type and execution.",{"data":67443,"content":67444,"nodeType":945},{},[67445],{"data":67446,"content":67447,"nodeType":860},{},[67448],{"data":67449,"marks":67450,"value":67451,"nodeType":864},{},[],"Block these attacks before the malicious code is copied to the clipboard.",{"data":67453,"content":67454,"nodeType":945},{},[67455],{"data":67456,"content":67457,"nodeType":860},{},[67458],{"data":67459,"marks":67460,"value":67461,"nodeType":864},{},[],"Safely collect the payload for further investigation by your security team, and replace the clipboard contents with safe text as part of the blocking action.",{"data":67463,"content":67464,"nodeType":945},{},[67465],{"data":67466,"content":67467,"nodeType":860},{},[67468],{"data":67469,"marks":67470,"value":67471,"nodeType":864},{},[],"Capture a detailed timeline of events to see how users were targeted and how the attack unfolded.",{"data":67473,"content":67477,"nodeType":996},{"target":67474},{"sys":67475},{"id":67476,"type":1001,"linkType":1002},"sALkMt8UbTZ2f34hKvGLj",[],{"data":67479,"content":67480,"nodeType":860},{},[67481,67485,67494],{"data":67482,"marks":67483,"value":67484,"nodeType":864},{},[],"Learn more about ClickFix detection in our ",{"data":67486,"content":67489,"nodeType":39736},{"target":67487},{"sys":67488},{"id":52747,"type":1001,"linkType":1002},[67490],{"data":67491,"marks":67492,"value":67493,"nodeType":864},{},[],"documentation",{"data":67495,"marks":67496,"value":2924,"nodeType":864},{},[],{"data":67498,"content":67499,"nodeType":1005},{},[],{"data":67501,"content":67502,"nodeType":1009},{},[67503],{"data":67504,"marks":67505,"value":67506,"nodeType":864},{},[],"Getting ahead of breaches tied to stolen credentials and ghost logins",{"data":67508,"content":67509,"nodeType":1312},{},[67510],{"data":67511,"marks":67512,"value":66986,"nodeType":864},{},[],{"data":67514,"content":67515,"nodeType":860},{},[67516,67520,67530],{"data":67517,"marks":67518,"value":67519,"nodeType":864},{},[],"Starting in November 2024 and continuing through July 2025, adversaries linked to the HELLCAT threat group compromised Jira tenants belonging to 10 organizations using ",{"data":67521,"content":67525,"nodeType":39736},{"target":67522},{"sys":67523},{"id":67524,"type":1001,"linkType":1002},"gANCbeL9AnxmbGAE5HhyG",[67526],{"data":67527,"marks":67528,"value":67529,"nodeType":864},{},[],"stolen credentials",{"data":67531,"marks":67532,"value":1774,"nodeType":864},{},[],{"data":67534,"content":67535,"nodeType":860},{},[67536],{"data":67537,"marks":67538,"value":67539,"nodeType":864},{},[],"Business-critical applications like Jira are prime targets for attackers, who in this case dumped valuable data and then held it for ransom (or sold it on criminal marketplaces). Of course, this isn’t just a problem for Jira — data from Push’s initial deployment into customer environments shows that lots of critical apps lack basic controls like strong passwords and MFA.",{"data":67541,"content":67542,"nodeType":860},{},[67543,67547,67555,67559,67565],{"data":67544,"marks":67545,"value":67546,"nodeType":864},{},[],"The evolving threat group known as ",{"data":67548,"content":67551,"nodeType":39736},{"target":67549},{"sys":67550},{"id":57022,"type":1001,"linkType":1002},[67552],{"data":67553,"marks":67554,"value":16018,"nodeType":864},{},[],{"data":67556,"marks":67557,"value":67558,"nodeType":864},{},[]," has also embraced the use of stolen creds, session cookies, and unprotected local account logins — aka ",{"data":67560,"content":67561,"nodeType":883},{"uri":57333},[67562],{"data":67563,"marks":67564,"value":29819,"nodeType":864},{},[],{"data":67566,"marks":67567,"value":67568,"nodeType":864},{},[]," — to compromise large organizations.",{"data":67570,"content":67571,"nodeType":860},{},[67572,67576,67584],{"data":67573,"marks":67574,"value":67575,"nodeType":864},{},[],"In 2025, Red Hat’s GitLab instance was compromised due to a local account that essentially provided a backdoor to an otherwise secure and SSO-connected account — an attack reminiscent of the ",{"data":67577,"content":67580,"nodeType":39736},{"target":67578},{"sys":67579},{"id":62097,"type":1001,"linkType":1002},[67581],{"data":67582,"marks":67583,"value":28735,"nodeType":864},{},[],{"data":67585,"marks":67586,"value":67587,"nodeType":864},{},[],", which targeted local logins that lacked MFA.",{"data":67589,"content":67590,"nodeType":1312},{},[67591],{"data":67592,"marks":67593,"value":67177,"nodeType":864},{},[],{"data":67595,"content":67596,"nodeType":860},{},[67597,67601,67611],{"data":67598,"marks":67599,"value":67600,"nodeType":864},{},[],"Push already provided the ability to detect stolen credentials being actively used by employees in your organization with our ",{"data":67602,"content":67606,"nodeType":39736},{"target":67603},{"sys":67604},{"id":67605,"type":1001,"linkType":1002},"6vCr4d3R1XA1E8dU883l7N",[67607],{"data":67608,"marks":67609,"value":67610,"nodeType":864},{},[],"Stolen credential detection control",{"data":67612,"marks":67613,"value":67614,"nodeType":864},{},[],". This provides an early-warning signal when Push finds a match between credentials for sale on criminal forums with those still being used by your employees, reducing some 99.5% of false positives we usually see with TI feed data.",{"data":67616,"content":67617,"nodeType":860},{},[67618],{"data":67619,"marks":67620,"value":67621,"nodeType":864},{},[],"With Push, you can also identify where employees are logging in with passwords on apps that otherwise should be using SAML, OIDC, or some other federated mechanism — aka the ghost login vulnerability.",{"data":67623,"content":67624,"nodeType":860},{},[67625],{"data":67626,"marks":67627,"value":67628,"nodeType":864},{},[],"This year, we made it easier for security teams to enforce two security fundamentals that help harden accounts and reduce the risk of ATO, even on unmanaged apps:",{"data":67630,"content":67631,"nodeType":941},{},[67632,67661],{"data":67633,"content":67634,"nodeType":945},{},[67635],{"data":67636,"content":67637,"nodeType":860},{},[67638,67643,67647,67657],{"data":67639,"marks":67640,"value":67642,"nodeType":864},{},[67641],{"type":899},"Strong password enforcement:",{"data":67644,"marks":67645,"value":67646,"nodeType":864},{},[]," With this control, you can prompt end-users to ",{"data":67648,"content":67652,"nodeType":39736},{"target":67649},{"sys":67650},{"id":67651,"type":1001,"linkType":1002},"5aB5x5VXrMv7PDmH0iiK0c",[67653],{"data":67654,"marks":67655,"value":67656,"nodeType":864},{},[],"fix an insecure password",{"data":67658,"marks":67659,"value":67660,"nodeType":864},{},[]," on all your workforce apps, even the ones you don’t centrally manage. ",{"data":67662,"content":67663,"nodeType":945},{},[67664],{"data":67665,"content":67666,"nodeType":860},{},[67667,67672,67675,67685],{"data":67668,"marks":67669,"value":67671,"nodeType":864},{},[67670],{"type":899},"MFA enforcement:",{"data":67673,"marks":67674,"value":67646,"nodeType":864},{},[],{"data":67676,"content":67680,"nodeType":39736},{"target":67677},{"sys":67678},{"id":67679,"type":1001,"linkType":1002},"wikyVxlHwKUOKM9xo19eP",[67681],{"data":67682,"marks":67683,"value":67684,"nodeType":864},{},[],"register for MFA",{"data":67686,"marks":67687,"value":67688,"nodeType":864},{},[]," where Push detects it’s missing — again, even on unmanaged apps.",{"data":67690,"content":67691,"nodeType":860},{},[67692],{"data":67693,"marks":67694,"value":67695,"nodeType":864},{},[],"Both of these controls use in-browser banners to provide point-in-time guidance to users when they’re most likely to see it and act on it.",{"data":67697,"content":67701,"nodeType":996},{"target":67698},{"sys":67699},{"id":67700,"type":1001,"linkType":1002},"3XH0hnnhcZNI47PhdiD4q0",[],{"data":67703,"content":67704,"nodeType":860},{},[67705,67709,67713],{"data":67706,"marks":67707,"value":67708,"nodeType":864},{},[],"To address the pattern of adversaries moving from targeting hardened core apps such as identity providers to the likes of GitLab, Postman, Jira, and others containing valuable corporate data, we also expanded one of the Push platform’s core security controls called ",{"data":67710,"marks":67711,"value":53134,"nodeType":864},{},[67712],{"type":899},{"data":67714,"marks":67715,"value":2924,"nodeType":864},{},[],{"data":67717,"content":67718,"nodeType":860},{},[67719,67722,67726],{"data":67720,"marks":67721,"value":2761,"nodeType":864},{},[],{"data":67723,"marks":67724,"value":53134,"nodeType":864},{},[67725],{"type":899},{"data":67727,"marks":67728,"value":67729,"nodeType":864},{},[]," control previously could be applied only to IdP passwords, allowing you to essentially “pin” the credential for those systems so that it could never be entered on a phishing page or reused on any other app. ",{"data":67731,"content":67732,"nodeType":860},{},[67733,67737,67746],{"data":67734,"marks":67735,"value":67736,"nodeType":864},{},[],"We expanded that control to allow you to ",{"data":67738,"content":67741,"nodeType":39736},{"target":67739},{"sys":67740},{"id":52935,"type":1001,"linkType":1002},[67742],{"data":67743,"marks":67744,"value":67745,"nodeType":864},{},[],"protect passwords on any valuable app",{"data":67747,"marks":67748,"value":67749,"nodeType":864},{},[],", preventing account takeover through phished creds and reducing the blast radius of attacks when a compromised account has been reusing passwords on multiple applications.",{"data":67751,"content":67755,"nodeType":996},{"target":67752},{"sys":67753},{"id":67754,"type":1001,"linkType":1002},"74l82HIeaumFX4u9AMjj79",[],{"data":67757,"content":67758,"nodeType":860},{},[67759,67763,67773],{"data":67760,"marks":67761,"value":67762,"nodeType":864},{},[],"Push also now gives you visibility into where employees are ",{"data":67764,"content":67768,"nodeType":39736},{"target":67765},{"sys":67766},{"id":67767,"type":1001,"linkType":1002},"7uLeQ9twNl5RyNaWkkJNjd",[67769],{"data":67770,"marks":67771,"value":67772,"nodeType":864},{},[],"syncing their corporate browser profile",{"data":67774,"marks":67775,"value":67776,"nodeType":864},{},[]," to a personal profile, raising the risk of syncing corporate passwords to unmanaged devices — another vector for credential harvesting if those endpoints become compromised.",{"data":67778,"content":67779,"nodeType":860},{},[67780],{"data":67781,"marks":67782,"value":67783,"nodeType":864},{},[],"And of course, underlying all these features is the foundational visibility of all your apps, accounts, account vulnerabilities, and login methods that Push provides.",{"data":67785,"content":67786,"nodeType":1005},{},[],{"data":67788,"content":67789,"nodeType":1009},{},[67790],{"data":67791,"marks":67792,"value":67793,"nodeType":864},{},[],"Blocking malicious browser extensions",{"data":67795,"content":67796,"nodeType":1312},{},[67797],{"data":67798,"marks":67799,"value":66986,"nodeType":864},{},[],{"data":67801,"content":67802,"nodeType":860},{},[67803],{"data":67804,"marks":67805,"value":67806,"nodeType":864},{},[],"Getting visibility and control over all the browser extensions used across your workforce has long been a thorny problem for security teams. ",{"data":67808,"content":67809,"nodeType":860},{},[67810],{"data":67811,"marks":67812,"value":67813,"nodeType":864},{},[],"The possible solutions haven’t been great, either. Teams could either apply a blunt-force block for most or all extensions, or spend painstaking time trying to understand what was installed, why, and by whom, across all the browsers in the environment.",{"data":67815,"content":67816,"nodeType":860},{},[67817,67821,67830],{"data":67818,"marks":67819,"value":67820,"nodeType":864},{},[],"The urgency of solving this problem increased for many organizations this year after the December 2024 compromise of at least 35 Google Chrome extensions in a ",{"data":67822,"content":67825,"nodeType":39736},{"target":67823},{"sys":67824},{"id":50825,"type":1001,"linkType":1002},[67826],{"data":67827,"marks":67828,"value":67829,"nodeType":864},{},[],"campaign targeting browser extension developers",{"data":67831,"marks":67832,"value":67833,"nodeType":864},{},[],". Cyberhaven’s extension was one of these, and the campaign inherited their name.",{"data":67835,"content":67836,"nodeType":1312},{},[67837],{"data":67838,"marks":67839,"value":67177,"nodeType":864},{},[],{"data":67841,"content":67842,"nodeType":860},{},[67843,67847,67856],{"data":67844,"marks":67845,"value":67846,"nodeType":864},{},[],"With Push, you can now get visibility across ",{"data":67848,"content":67851,"nodeType":39736},{"target":67849},{"sys":67850},{"id":53020,"type":1001,"linkType":1002},[67852],{"data":67853,"marks":67854,"value":67855,"nodeType":864},{},[],"all the browser extensions",{"data":67857,"marks":67858,"value":67859,"nodeType":864},{},[]," installed on employee browsers in your environment, and block the ones you don’t want.",{"data":67861,"content":67864,"nodeType":996},{"target":67862},{"sys":67863},{"id":65179,"type":1001,"linkType":1002},[],{"data":67866,"content":67867,"nodeType":860},{},[67868],{"data":67869,"marks":67870,"value":67871,"nodeType":864},{},[],"You can also:",{"data":67873,"content":67874,"nodeType":941},{},[67875,67885,67895],{"data":67876,"content":67877,"nodeType":945},{},[67878],{"data":67879,"content":67880,"nodeType":860},{},[67881],{"data":67882,"marks":67883,"value":67884,"nodeType":864},{},[],"Review extensions with risky permissions.",{"data":67886,"content":67887,"nodeType":945},{},[67888],{"data":67889,"content":67890,"nodeType":860},{},[67891],{"data":67892,"marks":67893,"value":67894,"nodeType":864},{},[],"Identify extensions with potentially suspicious installation methods, such as sideloaded or manually installed.",{"data":67896,"content":67897,"nodeType":945},{},[67898],{"data":67899,"content":67900,"nodeType":860},{},[67901],{"data":67902,"marks":67903,"value":67904,"nodeType":864},{},[],"Block extensions based on user groups and browser profiles (e.g. profiles logged in with a company domain).",{"data":67906,"content":67907,"nodeType":860},{},[67908,67912,67920],{"data":67909,"marks":67910,"value":67911,"nodeType":864},{},[],"Learn more about extension visibility and management in our ",{"data":67913,"content":67916,"nodeType":39736},{"target":67914},{"sys":67915},{"id":53020,"type":1001,"linkType":1002},[67917],{"data":67918,"marks":67919,"value":67493,"nodeType":864},{},[],{"data":67921,"marks":67922,"value":2924,"nodeType":864},{},[],{"data":67924,"content":67925,"nodeType":1005},{},[],{"data":67927,"content":67928,"nodeType":1009},{},[67929],{"data":67930,"marks":67931,"value":67932,"nodeType":864},{},[],"Adding a layer of protection against help desk scams",{"data":67934,"content":67935,"nodeType":1312},{},[67936],{"data":67937,"marks":67938,"value":66986,"nodeType":864},{},[],{"data":67940,"content":67941,"nodeType":860},{},[67942],{"data":67943,"marks":67944,"value":67945,"nodeType":864},{},[],"Finally, another big theme in this year’s TTPs was the use of help desk social engineering to compromise organizations. ",{"data":67947,"content":67948,"nodeType":860},{},[67949,67953,67963],{"data":67950,"marks":67951,"value":67952,"nodeType":864},{},[],"Attackers like ",{"data":67954,"content":67958,"nodeType":39736},{"target":67955},{"sys":67956},{"id":67957,"type":1001,"linkType":1002},"wgpdyHDn9NcpIJNr7jnFp",[67959],{"data":67960,"marks":67961,"value":67962,"nodeType":864},{},[],"Scattered Spider",{"data":67964,"marks":67965,"value":67966,"nodeType":864},{},[]," — now known as part of the evolving cybercriminal group Scattered Lapsus$ Hunters — have targeted organizations including MGM Resorts and Marks & Spencer by convincing help desk staff to help them bypass MFA or reset credentials for accounts they then use to access corporate systems. ",{"data":67968,"content":67969,"nodeType":1312},{},[67970],{"data":67971,"marks":67972,"value":67177,"nodeType":864},{},[],{"data":67974,"content":67975,"nodeType":860},{},[67976,67980,67985],{"data":67977,"marks":67978,"value":67979,"nodeType":864},{},[],"To provide an additional layer of security when verifying employee identities during help desk interactions, Push introduced ",{"data":67981,"marks":67982,"value":67984,"nodeType":864},{},[67983],{"type":899},"Employee verification codes",{"data":67986,"marks":67987,"value":2924,"nodeType":864},{},[],{"data":67989,"content":67993,"nodeType":996},{"target":67990},{"sys":67991},{"id":67992,"type":1001,"linkType":1002},"19Baqh5QwbonzsR0EcaDS8",[],{"data":67995,"content":67996,"nodeType":860},{},[67997],{"data":67998,"marks":67999,"value":68000,"nodeType":864},{},[],"These are a rotating 6-digit verification code accessible via the Push Security extension dropdown. When an employee contacts your help desk, staff can use this code to help verify their identity before performing any sensitive account changes.",{"data":68002,"content":68003,"nodeType":860},{},[68004],{"data":68005,"marks":68006,"value":68007,"nodeType":864},{},[],"Employee verification codes are lightweight, rotate every 24 hours, and don’t require any additional apps or devices.",{"data":68009,"content":68010,"nodeType":860},{},[68011,68015,68024],{"data":68012,"marks":68013,"value":68014,"nodeType":864},{},[],"Learn more about verification codes in our ",{"data":68016,"content":68020,"nodeType":39736},{"target":68017},{"sys":68018},{"id":68019,"type":1001,"linkType":1002},"4rLP8wr6HnvBG2OzqYYKpF",[68021],{"data":68022,"marks":68023,"value":67323,"nodeType":864},{},[],{"data":68025,"marks":68026,"value":2924,"nodeType":864},{},[],{"data":68028,"content":68029,"nodeType":1005},{},[],{"data":68031,"content":68032,"nodeType":1009},{},[68033],{"data":68034,"marks":68035,"value":3578,"nodeType":864},{},[],{"data":68037,"content":68038,"nodeType":860},{},[68039],{"data":68040,"marks":68041,"value":68042,"nodeType":864},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. ",{"data":68044,"content":68045,"nodeType":860},{},[68046],{"data":68047,"marks":68048,"value":68049,"nodeType":864},{},[],"You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":68051,"content":68052,"nodeType":860},{},[68053,68057,68063,68067,68073],{"data":68054,"marks":68055,"value":68056,"nodeType":864},{},[],"To learn more about Push, check out our latest ",{"data":68058,"content":68059,"nodeType":883},{"uri":53388},[68060],{"data":68061,"marks":68062,"value":53393,"nodeType":864},{},[],{"data":68064,"marks":68065,"value":68066,"nodeType":864},{},[]," or book some time with one of our team for a ",{"data":68068,"content":68069,"nodeType":883},{"uri":40635},[68070],{"data":68071,"marks":68072,"value":2715,"nodeType":864},{},[],{"data":68074,"marks":68075,"value":2924,"nodeType":864},{},[],"Taking the fight to attackers: Push’s top features of 2025","Here’s how real-world attacks and our own R&D informed what we built for Push customers over the last year.","2025-12-17T00:00:00.000Z","taking-the-fight-to-attackers-top-features-of-2025",{"items":68081},[68082,68084],{"sys":68083,"name":342},{"id":13775},{"sys":68085,"name":13779},{"id":13778},{"items":68087},[68088],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":68089},{"url":853},{"__typename":2059,"sys":68091,"content":68092,"title":64135,"synopsis":68474,"hashTags":59,"publishedDate":68475,"slug":64136,"tagsCollection":68476,"authorsCollection":68482},{"id":52576},{"json":68093},{"data":68094,"content":68095,"nodeType":856},{},[68096,68104,68111,68118,68130,68142,68150,68157,68164,68171,68177,68180,68188,68195,68202,68214,68221,68228,68236,68243,68291,68307,68314,68322,68329,68356,68363,68371,68419,68426,68462,68468],{"data":68097,"content":68098,"nodeType":1009},{},[68099],{"data":68100,"marks":68101,"value":68103,"nodeType":864},{},[68102],{"type":899},"EDR is still the best tool for attacks that touch the endpoint",{"data":68105,"content":68106,"nodeType":860},{},[68107],{"data":68108,"marks":68109,"value":68110,"nodeType":864},{},[],"Endpoint Detection and Response (EDR) tooling is fundamental to modern security. It earned its place as a foundational control by moving defense away from static, known-bad indicators and toward deep, real-time detection, investigation, and response based on behavior observed in a live environment. ",{"data":68112,"content":68113,"nodeType":860},{},[68114],{"data":68115,"marks":68116,"value":68117,"nodeType":864},{},[],"By running an agent inside the operating system, EDR gave defenders something they never had before: visibility into what was actually happening on the host as it happened, and the ability to act on it.",{"data":68119,"content":68120,"nodeType":860},{},[68121,68125],{"data":68122,"marks":68123,"value":68124,"nodeType":864},{},[],"That agent-level visibility is still incredibly powerful. File system changes, process execution, memory behavior, or registry modifications is the kind of telemetry that enables threat hunting, exposes fileless attacks, and allows teams to contain incidents by isolating a device or killing a malicious process. ",{"data":68126,"marks":68127,"value":68129,"nodeType":864},{},[68128],{"type":899},"For anything that touches the endpoint, EDR remains the right tool.",{"data":68131,"content":68132,"nodeType":860},{},[68133,68137],{"data":68134,"marks":68135,"value":68136,"nodeType":864},{},[],"But that’s the key constraint: ",{"data":68138,"marks":68139,"value":68141,"nodeType":864},{},[68140],{"type":2246},"for anything that touches the endpoint.",{"data":68143,"content":68144,"nodeType":1312},{},[68145],{"data":68146,"marks":68147,"value":68149,"nodeType":864},{},[68148],{"type":899},"But modern attacks have moved beyond the endpoint",{"data":68151,"content":68152,"nodeType":860},{},[68153],{"data":68154,"marks":68155,"value":68156,"nodeType":864},{},[],"The reality of how work gets done has shifted. Most applications are now SaaS-based and accessed entirely through a browser. Employees authenticate, move data, administer systems, and interact with customers inside a browser window. And attackers have followed them there.",{"data":68158,"content":68159,"nodeType":860},{},[68160],{"data":68161,"marks":68162,"value":68163,"nodeType":864},{},[],"When attacks play out in the browser, endpoint-level signals often never appear. From the operating system’s perspective, there’s just a browser process behaving normally. The EDR agent is doing exactly what it was designed to do, but the activity that matters is happening within the browser itself.",{"data":68165,"content":68166,"nodeType":860},{},[68167],{"data":68168,"marks":68169,"value":68170,"nodeType":864},{},[],"That’s the gap teams are running into. EDR protects the integrity of the host, but it has no visibility into the live application session inside the browser. And as attackers consciously avoid the endpoint entirely, that blind spot is becoming harder to ignore.",{"data":68172,"content":68176,"nodeType":996},{"target":68173},{"sys":68174},{"id":68175,"type":1001,"linkType":1002},"7aVTgi4Btxl6PpzQl8kipW",[],{"data":68178,"content":68179,"nodeType":1005},{},[],{"data":68181,"content":68182,"nodeType":1009},{},[68183],{"data":68184,"marks":68185,"value":68187,"nodeType":864},{},[68186],{"type":899},"Attackers are consciously evading EDR",{"data":68189,"content":68190,"nodeType":860},{},[68191],{"data":68192,"marks":68193,"value":68194,"nodeType":864},{},[],"The gap endpoint teams are running into isn’t accidental. It’s the result of attackers adapting to where defenders are strongest (and weakest).",{"data":68196,"content":68197,"nodeType":860},{},[68198],{"data":68199,"marks":68200,"value":68201,"nodeType":864},{},[],"Modern EDR has made compromising the host operating system expensive and noisy. Deep telemetry and constant monitoring mean that even when an attacker manages to execute code on a device, that action is quickly under scrutiny. From there, progress is slow. After all, lateral movement and persistence take time, and all of it carries risk and generates signals defenders are good at catching.",{"data":68203,"content":68204,"nodeType":860},{},[68205,68210],{"data":68206,"marks":68207,"value":68209,"nodeType":864},{},[68208],{"type":899},"So attackers take a different route. ",{"data":68211,"marks":68212,"value":68213,"nodeType":864},{},[],"Instead of targeting the OS, they operate inside the browser session, abusing legitimate access paths to cloud applications directly over the internet. The endpoint just sees a browser session, not the malicious activity that's happening inside it. ",{"data":68215,"content":68216,"nodeType":860},{},[68217],{"data":68218,"marks":68219,"value":68220,"nodeType":864},{},[],"EDR agents are extremely good at protecting the operating system, but their visibility largely stops at the browser boundary. They can see that a browser process is running. They can’t see what a user is actually interacting with inside a specific tab, or what code is executing within the browser.",{"data":68222,"content":68223,"nodeType":860},{},[68224],{"data":68225,"marks":68226,"value":68227,"nodeType":864},{},[],"This is the shift security teams are feeling. Attacks don’t trigger endpoint alerts because they aren’t endpoint attacks. They unfold inside the browser, over standard web sessions, using legitimate accounts. To EDR, the host is unaffected. To the business, the damage is already underway.",{"data":68229,"content":68230,"nodeType":1312},{},[68231],{"data":68232,"marks":68233,"value":68235,"nodeType":864},{},[68234],{"type":899},"How modern attacks circumvent EDR",{"data":68237,"content":68238,"nodeType":860},{},[68239],{"data":68240,"marks":68241,"value":68242,"nodeType":864},{},[],"Examples of modern attacks that are consciously evading EDR by staying off the endpoint include:",{"data":68244,"content":68245,"nodeType":941},{},[68246,68261,68276],{"data":68247,"content":68248,"nodeType":945},{},[68249],{"data":68250,"content":68251,"nodeType":860},{},[68252,68257],{"data":68253,"marks":68254,"value":68256,"nodeType":864},{},[68255],{"type":899},"AiTM phishing: ",{"data":68258,"marks":68259,"value":68260,"nodeType":864},{},[],"Sophisticated attacker-in-the-middle phishing kits render convincing login pages directly in the browser and proxy authentication in real time, stealing credentials or MFA tokens as the user enters them. From the OS perspective, nothing appears unusual; EDR can’t see the page structure or scripts running inside the tab.",{"data":68262,"content":68263,"nodeType":945},{},[68264],{"data":68265,"content":68266,"nodeType":860},{},[68267,68272],{"data":68268,"marks":68269,"value":68271,"nodeType":864},{},[68270],{"type":899},"Session hijacking:",{"data":68273,"marks":68274,"value":68275,"nodeType":864},{},[]," When attackers obtain a valid session token, they gain persistent access to an account without needing a password at all. Once in use, the session typically blends into normal browser activity, generating no endpoint data. ",{"data":68277,"content":68278,"nodeType":945},{},[68279],{"data":68280,"content":68281,"nodeType":860},{},[68282,68287],{"data":68283,"marks":68284,"value":68286,"nodeType":864},{},[68285],{"type":899},"Malicious browser extensions:",{"data":68288,"marks":68289,"value":68290,"nodeType":864},{},[]," Malicious extensions (either made by attackers or hijacked by them) can read page content, intercept credentials, or siphon session tokens. Because extensions operate inside the browser’s execution model, their behavior is largely invisible to endpoint tooling focused on OS-level activity.",{"data":68292,"content":68293,"nodeType":860},{},[68294,68298,68303],{"data":68295,"marks":68296,"value":68297,"nodeType":864},{},[],"Even attacks that nominally involve the endpoint often stay outside EDR’s strongest visibility. ",{"data":68299,"marks":68300,"value":68302,"nodeType":864},{},[68301],{"type":899},"ClickFix-style social engineering",{"data":68304,"marks":68305,"value":68306,"nodeType":864},{},[]," is a good example. Attackers manipulate users into taking risky actions that look legitimate, the most prominent example being executing malicious commands on the host that are deliberately obfuscated or broken into benign-looking steps. While EDR may catch the code execution (and any malware the execution attempts to install), these techniques are designed to stay ambiguous enough to avoid reliable detection.",{"data":68308,"content":68309,"nodeType":860},{},[68310],{"data":68311,"marks":68312,"value":68313,"nodeType":864},{},[],"All of these attacks succeed for the same reason: the activity unfolds inside the browser. And because EDR was never designed to observe or control what happens inside a live browser session, attackers can operate there with far less resistance.",{"data":68315,"content":68316,"nodeType":1312},{},[68317],{"data":68318,"marks":68319,"value":68321,"nodeType":864},{},[68320],{"type":899},"Extending detection and response to the browser",{"data":68323,"content":68324,"nodeType":860},{},[68325],{"data":68326,"marks":68327,"value":68328,"nodeType":864},{},[],"Defenders need to meet attackers where they actually operate. That means establishing real detection and response capabilities inside the browser itself.",{"data":68330,"content":68331,"nodeType":860},{},[68332,68336,68341,68345,68353],{"data":68333,"marks":68334,"value":68335,"nodeType":864},{},[],"When endpoint security evolved, it did so by putting an agent on the host to observe behavior, collect telemetry, and act at the source — ",{"data":68337,"marks":68338,"value":68340,"nodeType":864},{},[68339],{"type":899},"getting inside the data stream",{"data":68342,"marks":68343,"value":68344,"nodeType":864},{},[],". The same logic applies here. If the browser is where credentials are entered, sessions are established, and attacks unfold, then it needs to be treated as a security surface in its own right. ",{"data":68346,"content":68348,"nodeType":883},{"uri":68347},"https://pushsecurity.com/blog/push-plus-network-security",[68349],{"data":68350,"marks":68351,"value":68352,"nodeType":864},{},[],"That doesn't mean just looking at web traffic, but examining client-side browser processes and activity that are the best, earliest indicators of bad activity. ",{"data":68354,"marks":68355,"value":21,"nodeType":864},{},[],{"data":68357,"content":68358,"nodeType":860},{},[68359],{"data":68360,"marks":68361,"value":68362,"nodeType":864},{},[],"This doesn’t replace EDR. EDR secures the host. Identity tools govern authentication. But the browser, the layer that connects users to everything else, is a blind spot. Extending detection and response into that layer fills the gap while complementing the controls that already work.",{"data":68364,"content":68365,"nodeType":1312},{},[68366],{"data":68367,"marks":68368,"value":68370,"nodeType":864},{},[68369],{"type":899},"Your browser detection and response checklist",{"data":68372,"content":68373,"nodeType":941},{},[68374,68389,68404],{"data":68375,"content":68376,"nodeType":945},{},[68377],{"data":68378,"content":68379,"nodeType":860},{},[68380,68385],{"data":68381,"marks":68382,"value":68384,"nodeType":864},{},[68383],{"type":899},"Browser-native protection: ",{"data":68386,"marks":68387,"value":68388,"nodeType":864},{},[],"Running inside the browser is the only way you can see what page a user is interacting with, what scripts are running, and how the session is behaving in real time. It’s also the only place you can reliably distinguish between normal user activity and attacker-driven manipulation.",{"data":68390,"content":68391,"nodeType":945},{},[68392],{"data":68393,"content":68394,"nodeType":860},{},[68395,68400],{"data":68396,"marks":68397,"value":68399,"nodeType":864},{},[68398],{"type":899},"Behavioral detection:",{"data":68401,"marks":68402,"value":68403,"nodeType":864},{},[]," Detection can’t rely on static indicators. It has to be based on behaviors — like how pages render, how credentials are submitted, and how sessions are established and abused. ",{"data":68405,"content":68406,"nodeType":945},{},[68407],{"data":68408,"content":68409,"nodeType":860},{},[68410,68415],{"data":68411,"marks":68412,"value":68414,"nodeType":864},{},[68413],{"type":899},"Real-time interception:",{"data":68416,"marks":68417,"value":68418,"nodeType":864},{},[]," Response has to be immediate. Blocking credential submission, interrupting a malicious action, capturing high-fidelity context, all of that needs to happen at the point of interaction — before an account is compromised.",{"data":68420,"content":68421,"nodeType":860},{},[68422],{"data":68423,"marks":68424,"value":68425,"nodeType":864},{},[],"This is what it means to extend detection and response to the browser: not another tool bolted onto the stack, but a necessary evolution in how modern attacks are actually stopped.",{"data":68427,"content":68428,"nodeType":1116},{},[68429],{"data":68430,"content":68431,"nodeType":860},{},[68432,68435,68441,68444,68450,68453,68459],{"data":68433,"marks":68434,"value":62048,"nodeType":864},{},[],{"data":68436,"content":68437,"nodeType":883},{"uri":16866},[68438],{"data":68439,"marks":68440,"value":62056,"nodeType":864},{},[],{"data":68442,"marks":68443,"value":3731,"nodeType":864},{},[],{"data":68445,"content":68446,"nodeType":883},{"uri":16877},[68447],{"data":68448,"marks":68449,"value":62067,"nodeType":864},{},[],{"data":68451,"marks":68452,"value":16887,"nodeType":864},{},[],{"data":68454,"content":68455,"nodeType":883},{"uri":1700},[68456],{"data":68457,"marks":68458,"value":16894,"nodeType":864},{},[],{"data":68460,"marks":68461,"value":2924,"nodeType":864},{},[],{"data":68463,"content":68467,"nodeType":996},{"target":68464},{"sys":68465},{"id":68466,"type":1001,"linkType":1002},"1doMkOu2ZuGqMp2VJgV5pb",[],{"data":68469,"content":68470,"nodeType":860},{},[68471],{"data":68472,"marks":68473,"value":21,"nodeType":864},{},[],"Why extending detection and response into the browser is crucial in the face of modern attacks that consciously evade the network and endpoint. ","2026-01-30T00:00:00.000Z",{"items":68477},[68478,68480],{"sys":68479,"name":13779},{"id":13778},{"sys":68481,"name":342},{"id":13775},{"items":68483},[68484],{"fullName":68485,"firstName":68486,"jobTitle":851,"profilePicture":68487},"Peyton Padfield","Peyton",{"url":68488},"https://images.ctfassets.net/y1cdw1ablpvd/1GU01HXElmc07nwi89qP3b/3188050420106c62e9df2ed4e4893b7f/1677005177901__1_.jpeg",{"__typename":2059,"sys":68490,"content":68491,"title":64131,"synopsis":68981,"hashTags":59,"publishedDate":68475,"slug":64132,"tagsCollection":68982,"authorsCollection":68988},{"id":52555},{"json":68492},{"data":68493,"content":68494,"nodeType":856},{},[68495,68503,68510,68517,68529,68537,68544,68551,68558,68566,68569,68577,68584,68591,68598,68616,68622,68629,68647,68655,68773,68776,68784,68791,68803,68810,68816,68823,68830,68838,68845,68853,68860,68867,68874,68922,68934,68970,68975],{"data":68496,"content":68497,"nodeType":1009},{},[68498],{"data":68499,"marks":68500,"value":68502,"nodeType":864},{},[68501],{"type":899},"Defense used to start at the network perimeter",{"data":68504,"content":68505,"nodeType":860},{},[68506],{"data":68507,"marks":68508,"value":68509,"nodeType":864},{},[],"If you've been working in security for any length of time, you know where defense starts: the network. Long before cloud-first or SaaS-first became default, the perimeter was where defenders had leverage: visibility, enforcement, and control over traffic moving in and out of the organization.",{"data":68511,"content":68512,"nodeType":860},{},[68513],{"data":68514,"marks":68515,"value":68516,"nodeType":864},{},[],"That mental model hasn’t disappeared. Secure Web Gateways, Cloud Access Security Brokers, and the converged Security Service Edge architecture exist because the problem they solve is still real. Organizations generate an enormous volume of web traffic, and someone has to monitor it, filter it, and enforce policy at scale. These tools sit inline, log metadata, apply categorization, and block what’s already known to be dangerous. Without them, the environment quickly becomes unmanageable and extremely difficult to secure.",{"data":68518,"content":68519,"nodeType":860},{},[68520,68524],{"data":68521,"marks":68522,"value":68523,"nodeType":864},{},[],"They are very good at what they were designed to do: securing the wire. ",{"data":68525,"marks":68526,"value":68528,"nodeType":864},{},[68527],{"type":899},"But what happens over the wire is not the full picture. ",{"data":68530,"content":68531,"nodeType":1312},{},[68532],{"data":68533,"marks":68534,"value":68536,"nodeType":864},{},[68535],{"type":899},"Traffic isn't the whole picture anymore",{"data":68538,"content":68539,"nodeType":860},{},[68540],{"data":68541,"marks":68542,"value":68543,"nodeType":864},{},[],"A significant amount of activity happens locally, inside the browser, beyond the visibility of network controls. Modern webpages are effectively complicated web apps that are rendered client-side via JavaScript — and not everything that happens on the page is traffic-generating. ",{"data":68545,"content":68546,"nodeType":860},{},[68547],{"data":68548,"marks":68549,"value":68550,"nodeType":864},{},[],"That distinction matters more than it used to. Authentication, data access, administrative actions, almost all of it now happens inside a browser tab. As a result, the browser has become a central point of both productivity and risk.",{"data":68552,"content":68553,"nodeType":860},{},[68554],{"data":68555,"marks":68556,"value":68557,"nodeType":864},{},[],"Network tools still see the pipeline of traffic moving back and forth. But attackers have adapted to operate within that pipeline rather than around it. They don’t need to break the connection or trigger obvious anomalies. They target the content rendered inside the browser and the user interacting with it.",{"data":68559,"content":68560,"nodeType":860},{},[68561],{"data":68562,"marks":68563,"value":68565,"nodeType":864},{},[68564],{"type":899},"That leaves security teams with noisy traffic visibility and very little insight into the actual attack unfolding inside the browser session.",{"data":68567,"content":68568,"nodeType":1005},{},[],{"data":68570,"content":68571,"nodeType":1009},{},[68572],{"data":68573,"marks":68574,"value":68576,"nodeType":864},{},[68575],{"type":899},"Traffic visibility vs. in-browser context",{"data":68578,"content":68579,"nodeType":860},{},[68580],{"data":68581,"marks":68582,"value":68583,"nodeType":864},{},[],"The modern attacker's playbook is built on a simple idea: stay inside the network’s line of sight without triggering detections or enforcement. Containing operations to the browser layer provides attackers with an easy bypass of many traditional network controls without ever needing to break or evade them outright.",{"data":68585,"content":68586,"nodeType":860},{},[68587],{"data":68588,"marks":68589,"value":68590,"nodeType":864},{},[],"They do this by staying ahead of known-bad detection models, constantly rotating domains and URLs, using anti-analysis techniques, and delivering phishing lures through channels that bypass traditional network ingress points like the email gateway (like social media or SMS). In many cases, the link is never evaluated by perimeter controls at all.",{"data":68592,"content":68593,"nodeType":860},{},[68594],{"data":68595,"marks":68596,"value":68597,"nodeType":864},{},[],"This creates a fundamental visibility gap. Network security tools can see a request going to a legitimate-looking destination, but they can’t observe what happens once the page executes client-side in the browser. Malicious scripts and phishing elements often don’t appear until after the page loads and a user interacts with it, leaving nothing obviously known-bad for network controls to detect.",{"data":68599,"content":68600,"nodeType":860},{},[68601,68605,68612],{"data":68602,"marks":68603,"value":68604,"nodeType":864},{},[],"Blocklists don’t help much here either. Domains rotate constantly, and the window between a phishing site going live and being categorized as malicious is more than enough time for an attacker to succeed. Until that happens, the traffic appears benign and the user is free to interact with the page. And to make matters worse, attackers are leveraging ",{"data":68606,"content":68608,"nodeType":883},{"uri":68607},"https://pushsecurity.com/blog/phishing-detection-evasion-launch/",[68609],{"data":68610,"marks":68611,"value":19763,"nodeType":864},{},[],{"data":68613,"marks":68614,"value":68615,"nodeType":864},{},[]," designed to frustrate these detections — meaning most bad pages aren't spotted until it's way too late. ",{"data":68617,"content":68621,"nodeType":996},{"target":68618},{"sys":68619},{"id":68620,"type":1001,"linkType":1002},"38X1De97xJ8B6GNXTHW6Y5",[],{"data":68623,"content":68624,"nodeType":860},{},[68625],{"data":68626,"marks":68627,"value":68628,"nodeType":864},{},[],"Consider attacker-in-the-middle phishing. From the proxy’s perspective, everything looks clean: user → reputable domain → “standard” web traffic. The phishing infrastructure is often hidden behind redirects or conditional logic designed to screen out proxies and scanners. Inside the browser session, however, credentials are intercepted, session tokens are harvested, and MFA is bypassed in real time.",{"data":68630,"content":68631,"nodeType":860},{},[68632,68636,68643],{"data":68633,"marks":68634,"value":68635,"nodeType":864},{},[],"For ",{"data":68637,"content":68638,"nodeType":883},{"uri":16015},[68639],{"data":68640,"marks":68641,"value":68642,"nodeType":864},{},[],"modern threat groups",{"data":68644,"marks":68645,"value":68646,"nodeType":864},{},[],", these obscured attack vectors lead directly to initial access and account takeover. The network is no longer the control point where the most consequential attacks can be reliably stopped.",{"data":68648,"content":68649,"nodeType":860},{},[68650],{"data":68651,"marks":68652,"value":68654,"nodeType":864},{},[68653],{"type":2246},"Browser telemetry is key to detecting and blocking malicious content in real-time, rather than relying on blocklists using known-bad indicators like domains and IPs that go out of date as quickly as new entries appear.",{"data":68656,"content":68657,"nodeType":4845},{},[68658,68681,68704,68727,68750],{"data":68659,"content":68660,"nodeType":4581},{},[68661,68671],{"data":68662,"content":68663,"nodeType":14464},{},[68664],{"data":68665,"content":68666,"nodeType":860},{},[68667],{"data":68668,"marks":68669,"value":68670,"nodeType":864},{},[],"What you see with traffic analysis",{"data":68672,"content":68673,"nodeType":14464},{},[68674],{"data":68675,"content":68676,"nodeType":860},{},[68677],{"data":68678,"marks":68679,"value":68680,"nodeType":864},{},[],"What you can see with browser telemetry",{"data":68682,"content":68683,"nodeType":4581},{},[68684,68694],{"data":68685,"content":68686,"nodeType":4569},{},[68687],{"data":68688,"content":68689,"nodeType":860},{},[68690],{"data":68691,"marks":68692,"value":68693,"nodeType":864},{},[],"HTTP request/response bodies ",{"data":68695,"content":68696,"nodeType":4569},{},[68697],{"data":68698,"content":68699,"nodeType":860},{},[68700],{"data":68701,"marks":68702,"value":68703,"nodeType":864},{},[],"DOM structure fingerprints",{"data":68705,"content":68706,"nodeType":4581},{},[68707,68717],{"data":68708,"content":68709,"nodeType":4569},{},[68710],{"data":68711,"content":68712,"nodeType":860},{},[68713],{"data":68714,"marks":68715,"value":68716,"nodeType":864},{},[],"URLs and headers",{"data":68718,"content":68719,"nodeType":4569},{},[68720],{"data":68721,"content":68722,"nodeType":860},{},[68723],{"data":68724,"marks":68725,"value":68726,"nodeType":864},{},[],"User interaction metadata ",{"data":68728,"content":68729,"nodeType":4581},{},[68730,68740],{"data":68731,"content":68732,"nodeType":4569},{},[68733],{"data":68734,"content":68735,"nodeType":860},{},[68736],{"data":68737,"marks":68738,"value":68739,"nodeType":864},{},[],"Cookie values in transit",{"data":68741,"content":68742,"nodeType":4569},{},[68743],{"data":68744,"content":68745,"nodeType":860},{},[68746],{"data":68747,"marks":68748,"value":68749,"nodeType":864},{},[],"Cookie names and attributes",{"data":68751,"content":68752,"nodeType":4581},{},[68753,68763],{"data":68754,"content":68755,"nodeType":4569},{},[68756],{"data":68757,"content":68758,"nodeType":860},{},[68759],{"data":68760,"marks":68761,"value":68762,"nodeType":864},{},[],"Static JS code",{"data":68764,"content":68765,"nodeType":4569},{},[68766],{"data":68767,"content":68768,"nodeType":860},{},[68769],{"data":68770,"marks":68771,"value":68772,"nodeType":864},{},[],"Script execution patterns and dynamic JS analysis",{"data":68774,"content":68775,"nodeType":1005},{},[],{"data":68777,"content":68778,"nodeType":1009},{},[68779],{"data":68780,"marks":68781,"value":68783,"nodeType":864},{},[68782],{"type":899},"Securing the browser session is key to stopping modern threats",{"data":68785,"content":68786,"nodeType":860},{},[68787],{"data":68788,"marks":68789,"value":68790,"nodeType":864},{},[],"If the browser is where users actually work, and where attackers actually operate, then that’s the layer that defenders need to understand and control.",{"data":68792,"content":68793,"nodeType":860},{},[68794,68798],{"data":68795,"marks":68796,"value":68797,"nodeType":864},{},[],"Modern web-based attacks don’t succeed because traffic goes uninspected. They succeed because network inspection can’t follow the interaction far enough. Traffic shows where data went, not what the user actually saw or did, ",{"data":68799,"marks":68800,"value":68802,"nodeType":864},{},[68801],{"type":899},"and in today’s attacks, that distinction matters.",{"data":68804,"content":68805,"nodeType":860},{},[68806],{"data":68807,"marks":68808,"value":68809,"nodeType":864},{},[],"To stop these threats, you have to see what the user is actually interacting with. Things like what scripts are loading, how the DOM is being manipulated, or whether the login form a user is using is legitimate or being proxied. Those are page-level signals, and they only exist inside the browser tab.",{"data":68811,"content":68815,"nodeType":996},{"target":68812},{"sys":68813},{"id":68814,"type":1001,"linkType":1002},"6qMaivxhJ3xT9DkwXGcCSJ",[],{"data":68817,"content":68818,"nodeType":860},{},[68819],{"data":68820,"marks":68821,"value":68822,"nodeType":864},{},[],"That same shift applies to control. Destination-based blocking breaks down when the destination itself appears legitimate. Effective intervention requires decisions based on behavior as it unfolds so teams can stop risky or malicious activity that would compromise an account.",{"data":68824,"content":68825,"nodeType":860},{},[68826],{"data":68827,"marks":68828,"value":68829,"nodeType":864},{},[],"And visibility can’t stop at centrally managed applications. Shadow SaaS breaks any assumption that access patterns are uniform or fully governed by the IdP. Local accounts, duplicate identities, and password-only logins don’t show up clearly in network telemetry, but they materially expand the attack surface. Seeing every login, across every app, directly from the browser is the only way to build an accurate picture of who has access to what.",{"data":68831,"content":68832,"nodeType":1312},{},[68833],{"data":68834,"marks":68835,"value":68837,"nodeType":864},{},[68836],{"type":899},"Push provides the missing context for network security",{"data":68839,"content":68840,"nodeType":860},{},[68841],{"data":68842,"marks":68843,"value":68844,"nodeType":864},{},[],"At this point, the gap should be clear. Network security gives you strong control over traffic, but very little insight into what actually happens once that traffic lands in a user’s browser.",{"data":68846,"content":68847,"nodeType":860},{},[68848],{"data":68849,"marks":68850,"value":68852,"nodeType":864},{},[68851],{"type":899},"This is where Push can help.",{"data":68854,"content":68855,"nodeType":860},{},[68856],{"data":68857,"marks":68858,"value":68859,"nodeType":864},{},[],"The Push browser agent extends monitoring into the browser itself, providing the visibility and control that perimeter-based tools can’t deliver. It doesn’t replace SSE, SWG, or CASB. Those tools remain the right way to manage traffic and enforce policy at the edge. Push complements them by operating in the one place they can’t: inside the live browser session.",{"data":68861,"content":68862,"nodeType":860},{},[68863],{"data":68864,"marks":68865,"value":68866,"nodeType":864},{},[],"Push does this by deploying a browser-native agent, similar in spirit to how EDR works at the host level. That agent gives defenders direct insight into what the network can’t see like the page being rendered, how the user is interacting with it, and the attack techniques that play out entirely within the tab.",{"data":68868,"content":68869,"nodeType":860},{},[68870],{"data":68871,"marks":68872,"value":68873,"nodeType":864},{},[],"With Push deployed, teams gain:",{"data":68875,"content":68876,"nodeType":941},{},[68877,68892,68907],{"data":68878,"content":68879,"nodeType":945},{},[68880],{"data":68881,"content":68882,"nodeType":860},{},[68883,68888],{"data":68884,"marks":68885,"value":68887,"nodeType":864},{},[68886],{"type":899},"Real-time, in-browser threat detection:",{"data":68889,"marks":68890,"value":68891,"nodeType":864},{},[]," Detect and stop attacks like AiTM phishing and session hijacking based on what’s actually happening in the browser. Instead of relying on blocklists or downstream signals, Push identifies attacker behavior as it unfolds and can intervene before credentials or session tokens are stolen.",{"data":68893,"content":68894,"nodeType":945},{},[68895],{"data":68896,"content":68897,"nodeType":860},{},[68898,68903],{"data":68899,"marks":68900,"value":68902,"nodeType":864},{},[68901],{"type":899},"Complete visibility into SaaS access: ",{"data":68904,"marks":68905,"value":68906,"nodeType":864},{},[],"Build a true inventory of user identities and authentication methods across every application in use, including shadow SaaS. Push fills the gaps left by network and IdP logs, giving teams a real picture of where access exists and how it’s being granted.",{"data":68908,"content":68909,"nodeType":945},{},[68910],{"data":68911,"content":68912,"nodeType":860},{},[68913,68918],{"data":68914,"marks":68915,"value":68917,"nodeType":864},{},[68916],{"type":899},"Streamlined hardening at the point of access:",{"data":68919,"marks":68920,"value":68921,"nodeType":864},{},[]," Use the browser as a control point to enforce secure login behavior everywhere it matters. Mandate MFA, steer users toward SSO, and block risky credentials on unmanaged apps, shifting from reactive cleanup to continuous, preventative hardening.",{"data":68923,"content":68924,"nodeType":860},{},[68925,68929],{"data":68926,"marks":68927,"value":68928,"nodeType":864},{},[],"The result is a unified model and real defense in depth. ",{"data":68930,"marks":68931,"value":68933,"nodeType":864},{},[68932],{"type":899},"Network tools secure the pipeline, and Push secures the user moving through it.",{"data":68935,"content":68936,"nodeType":1116},{},[68937],{"data":68938,"content":68939,"nodeType":860},{},[68940,68943,68949,68952,68958,68961,68967],{"data":68941,"marks":68942,"value":62048,"nodeType":864},{},[],{"data":68944,"content":68945,"nodeType":883},{"uri":16866},[68946],{"data":68947,"marks":68948,"value":62056,"nodeType":864},{},[],{"data":68950,"marks":68951,"value":3731,"nodeType":864},{},[],{"data":68953,"content":68954,"nodeType":883},{"uri":16877},[68955],{"data":68956,"marks":68957,"value":62067,"nodeType":864},{},[],{"data":68959,"marks":68960,"value":16887,"nodeType":864},{},[],{"data":68962,"content":68963,"nodeType":883},{"uri":1700},[68964],{"data":68965,"marks":68966,"value":16894,"nodeType":864},{},[],{"data":68968,"marks":68969,"value":2924,"nodeType":864},{},[],{"data":68971,"content":68974,"nodeType":996},{"target":68972},{"sys":68973},{"id":68466,"type":1001,"linkType":1002},[],{"data":68976,"content":68977,"nodeType":860},{},[68978],{"data":68979,"marks":68980,"value":21,"nodeType":864},{},[],"Why network and web traffic only gives you part of the picture when it comes to modern browser-based attacks. ",{"items":68983},[68984,68986],{"sys":68985,"name":13779},{"id":13778},{"sys":68987,"name":342},{"id":13775},{"items":68989},[68990],{"fullName":68485,"firstName":68486,"jobTitle":851,"profilePicture":68991},{"url":68488},"blog/browser-extension-management-guide",{"json":68994},{"data":68995,"content":68996,"nodeType":856},{},[68997],{"data":68998,"content":68999,"nodeType":860},{},[69000],{"data":69001,"marks":69002,"value":69003,"nodeType":864},{},[],"Detect risky and malicious extensions and block them from running in employee browsers using Push.",{"id":61041,"publishedAt":69005},"2026-08-12T11:53:09.239Z",{"items":69007},[69008,69010],{"sys":69009,"name":13779},{"id":13778},{"sys":69011,"name":342},{"id":13775},{"items":69013},[69014,69016,69018,69020,69022,69024],{"sys":69015,"name":279,"slug":280,"tier":31},{"id":276},{"sys":69017,"name":297,"slug":298,"tier":31},{"id":294},{"sys":69019,"name":342,"slug":343,"tier":31},{"id":339},{"sys":69021,"name":288,"slug":289,"tier":45},{"id":285},{"sys":69023,"name":633,"slug":634,"tier":45},{"id":630},{"sys":69025,"name":351,"slug":352,"tier":45},{"id":348},"vl_c7avQPw8tARNE4qwt9A3vPfBbetoBf6URaXxK1_8",{"id":69028,"title":64135,"authorsCollection":69029,"content":69033,"extension":228,"faqItemsCollection":69383,"faqTitle":59,"featured":6,"hashTags":59,"meta":69385,"metaTitle":69386,"ogImage":59,"postType":5726,"publishedDate":68475,"relatedBlogPostsCollection":69387,"slug":64136,"stem":70221,"subtitle":59,"summary":70222,"synopsis":68474,"sys":70233,"tagsCollection":70235,"topicsCollection":70241,"__hash__":70259},"blog/blog/push-plus-endpoint-security.json",{"items":69030},[69031],{"fullName":68485,"firstName":68486,"jobTitle":851,"socialLinks":59,"profilePicture":69032},{"url":68488},{"json":69034,"links":69367},{"data":69035,"content":69036,"nodeType":856},{},[69037,69044,69050,69056,69066,69076,69083,69089,69095,69101,69106,69109,69116,69122,69128,69138,69144,69150,69157,69163,69205,69218,69224,69231,69237,69259,69265,69272,69314,69320,69356,69361],{"data":69038,"content":69039,"nodeType":1009},{},[69040],{"data":69041,"marks":69042,"value":68103,"nodeType":864},{},[69043],{"type":899},{"data":69045,"content":69046,"nodeType":860},{},[69047],{"data":69048,"marks":69049,"value":68110,"nodeType":864},{},[],{"data":69051,"content":69052,"nodeType":860},{},[69053],{"data":69054,"marks":69055,"value":68117,"nodeType":864},{},[],{"data":69057,"content":69058,"nodeType":860},{},[69059,69062],{"data":69060,"marks":69061,"value":68124,"nodeType":864},{},[],{"data":69063,"marks":69064,"value":68129,"nodeType":864},{},[69065],{"type":899},{"data":69067,"content":69068,"nodeType":860},{},[69069,69072],{"data":69070,"marks":69071,"value":68136,"nodeType":864},{},[],{"data":69073,"marks":69074,"value":68141,"nodeType":864},{},[69075],{"type":2246},{"data":69077,"content":69078,"nodeType":1312},{},[69079],{"data":69080,"marks":69081,"value":68149,"nodeType":864},{},[69082],{"type":899},{"data":69084,"content":69085,"nodeType":860},{},[69086],{"data":69087,"marks":69088,"value":68156,"nodeType":864},{},[],{"data":69090,"content":69091,"nodeType":860},{},[69092],{"data":69093,"marks":69094,"value":68163,"nodeType":864},{},[],{"data":69096,"content":69097,"nodeType":860},{},[69098],{"data":69099,"marks":69100,"value":68170,"nodeType":864},{},[],{"data":69102,"content":69105,"nodeType":996},{"target":69103},{"sys":69104},{"id":68175,"type":1001,"linkType":1002},[],{"data":69107,"content":69108,"nodeType":1005},{},[],{"data":69110,"content":69111,"nodeType":1009},{},[69112],{"data":69113,"marks":69114,"value":68187,"nodeType":864},{},[69115],{"type":899},{"data":69117,"content":69118,"nodeType":860},{},[69119],{"data":69120,"marks":69121,"value":68194,"nodeType":864},{},[],{"data":69123,"content":69124,"nodeType":860},{},[69125],{"data":69126,"marks":69127,"value":68201,"nodeType":864},{},[],{"data":69129,"content":69130,"nodeType":860},{},[69131,69135],{"data":69132,"marks":69133,"value":68209,"nodeType":864},{},[69134],{"type":899},{"data":69136,"marks":69137,"value":68213,"nodeType":864},{},[],{"data":69139,"content":69140,"nodeType":860},{},[69141],{"data":69142,"marks":69143,"value":68220,"nodeType":864},{},[],{"data":69145,"content":69146,"nodeType":860},{},[69147],{"data":69148,"marks":69149,"value":68227,"nodeType":864},{},[],{"data":69151,"content":69152,"nodeType":1312},{},[69153],{"data":69154,"marks":69155,"value":68235,"nodeType":864},{},[69156],{"type":899},{"data":69158,"content":69159,"nodeType":860},{},[69160],{"data":69161,"marks":69162,"value":68242,"nodeType":864},{},[],{"data":69164,"content":69165,"nodeType":941},{},[69166,69179,69192],{"data":69167,"content":69168,"nodeType":945},{},[69169],{"data":69170,"content":69171,"nodeType":860},{},[69172,69176],{"data":69173,"marks":69174,"value":68256,"nodeType":864},{},[69175],{"type":899},{"data":69177,"marks":69178,"value":68260,"nodeType":864},{},[],{"data":69180,"content":69181,"nodeType":945},{},[69182],{"data":69183,"content":69184,"nodeType":860},{},[69185,69189],{"data":69186,"marks":69187,"value":68271,"nodeType":864},{},[69188],{"type":899},{"data":69190,"marks":69191,"value":68275,"nodeType":864},{},[],{"data":69193,"content":69194,"nodeType":945},{},[69195],{"data":69196,"content":69197,"nodeType":860},{},[69198,69202],{"data":69199,"marks":69200,"value":68286,"nodeType":864},{},[69201],{"type":899},{"data":69203,"marks":69204,"value":68290,"nodeType":864},{},[],{"data":69206,"content":69207,"nodeType":860},{},[69208,69211,69215],{"data":69209,"marks":69210,"value":68297,"nodeType":864},{},[],{"data":69212,"marks":69213,"value":68302,"nodeType":864},{},[69214],{"type":899},{"data":69216,"marks":69217,"value":68306,"nodeType":864},{},[],{"data":69219,"content":69220,"nodeType":860},{},[69221],{"data":69222,"marks":69223,"value":68313,"nodeType":864},{},[],{"data":69225,"content":69226,"nodeType":1312},{},[69227],{"data":69228,"marks":69229,"value":68321,"nodeType":864},{},[69230],{"type":899},{"data":69232,"content":69233,"nodeType":860},{},[69234],{"data":69235,"marks":69236,"value":68328,"nodeType":864},{},[],{"data":69238,"content":69239,"nodeType":860},{},[69240,69243,69247,69250,69256],{"data":69241,"marks":69242,"value":68335,"nodeType":864},{},[],{"data":69244,"marks":69245,"value":68340,"nodeType":864},{},[69246],{"type":899},{"data":69248,"marks":69249,"value":68344,"nodeType":864},{},[],{"data":69251,"content":69252,"nodeType":883},{"uri":68347},[69253],{"data":69254,"marks":69255,"value":68352,"nodeType":864},{},[],{"data":69257,"marks":69258,"value":21,"nodeType":864},{},[],{"data":69260,"content":69261,"nodeType":860},{},[69262],{"data":69263,"marks":69264,"value":68362,"nodeType":864},{},[],{"data":69266,"content":69267,"nodeType":1312},{},[69268],{"data":69269,"marks":69270,"value":68370,"nodeType":864},{},[69271],{"type":899},{"data":69273,"content":69274,"nodeType":941},{},[69275,69288,69301],{"data":69276,"content":69277,"nodeType":945},{},[69278],{"data":69279,"content":69280,"nodeType":860},{},[69281,69285],{"data":69282,"marks":69283,"value":68384,"nodeType":864},{},[69284],{"type":899},{"data":69286,"marks":69287,"value":68388,"nodeType":864},{},[],{"data":69289,"content":69290,"nodeType":945},{},[69291],{"data":69292,"content":69293,"nodeType":860},{},[69294,69298],{"data":69295,"marks":69296,"value":68399,"nodeType":864},{},[69297],{"type":899},{"data":69299,"marks":69300,"value":68403,"nodeType":864},{},[],{"data":69302,"content":69303,"nodeType":945},{},[69304],{"data":69305,"content":69306,"nodeType":860},{},[69307,69311],{"data":69308,"marks":69309,"value":68414,"nodeType":864},{},[69310],{"type":899},{"data":69312,"marks":69313,"value":68418,"nodeType":864},{},[],{"data":69315,"content":69316,"nodeType":860},{},[69317],{"data":69318,"marks":69319,"value":68425,"nodeType":864},{},[],{"data":69321,"content":69322,"nodeType":1116},{},[69323],{"data":69324,"content":69325,"nodeType":860},{},[69326,69329,69335,69338,69344,69347,69353],{"data":69327,"marks":69328,"value":62048,"nodeType":864},{},[],{"data":69330,"content":69331,"nodeType":883},{"uri":16866},[69332],{"data":69333,"marks":69334,"value":62056,"nodeType":864},{},[],{"data":69336,"marks":69337,"value":3731,"nodeType":864},{},[],{"data":69339,"content":69340,"nodeType":883},{"uri":16877},[69341],{"data":69342,"marks":69343,"value":62067,"nodeType":864},{},[],{"data":69345,"marks":69346,"value":16887,"nodeType":864},{},[],{"data":69348,"content":69349,"nodeType":883},{"uri":1700},[69350],{"data":69351,"marks":69352,"value":16894,"nodeType":864},{},[],{"data":69354,"marks":69355,"value":2924,"nodeType":864},{},[],{"data":69357,"content":69360,"nodeType":996},{"target":69358},{"sys":69359},{"id":68466,"type":1001,"linkType":1002},[],{"data":69362,"content":69363,"nodeType":860},{},[69364],{"data":69365,"marks":69366,"value":21,"nodeType":864},{},[],{"entries":69368},{"hyperlink":69369,"inline":69370,"block":69371},[],[],[69372,69380],{"sys":69373,"__typename":1724,"title":69374,"caption":69375,"layoutMode":59,"file":69376},{"id":68175},"Security Eras","Modern attacks play out in the browser, exploiting a security blindspot",{"url":69377,"width":69378,"height":69379},"https://images.ctfassets.net/y1cdw1ablpvd/4zqrAlec1qJaCnE4OUFT7A/7dcd3f568ec90308ba1025ab5be686bb/Screenshot_2026-01-30_at_12.22.19.png",3418,1788,{"sys":69381,"__typename":1717,"type":1718,"ctaText":69382,"buttonLabel":39699,"buttonColour":1721,"buttonUrl":14401},{"id":68466},"Stop browser-based attacks in real time. Book a demo today. ",{"items":69384},[],{},"Push + Endpoint Security: Extending D&R to the browser",{"items":69388},[69389,69836],{"__typename":2059,"sys":69390,"content":69391,"title":64131,"synopsis":68981,"hashTags":59,"publishedDate":68475,"slug":64132,"tagsCollection":69826,"authorsCollection":69832},{"id":52555},{"json":69392},{"data":69393,"content":69394,"nodeType":856},{},[69395,69402,69408,69414,69424,69431,69437,69443,69449,69456,69459,69466,69472,69478,69484,69499,69504,69510,69525,69532,69640,69643,69650,69656,69666,69672,69677,69683,69689,69696,69702,69709,69715,69721,69727,69769,69779,69815,69820],{"data":69396,"content":69397,"nodeType":1009},{},[69398],{"data":69399,"marks":69400,"value":68502,"nodeType":864},{},[69401],{"type":899},{"data":69403,"content":69404,"nodeType":860},{},[69405],{"data":69406,"marks":69407,"value":68509,"nodeType":864},{},[],{"data":69409,"content":69410,"nodeType":860},{},[69411],{"data":69412,"marks":69413,"value":68516,"nodeType":864},{},[],{"data":69415,"content":69416,"nodeType":860},{},[69417,69420],{"data":69418,"marks":69419,"value":68523,"nodeType":864},{},[],{"data":69421,"marks":69422,"value":68528,"nodeType":864},{},[69423],{"type":899},{"data":69425,"content":69426,"nodeType":1312},{},[69427],{"data":69428,"marks":69429,"value":68536,"nodeType":864},{},[69430],{"type":899},{"data":69432,"content":69433,"nodeType":860},{},[69434],{"data":69435,"marks":69436,"value":68543,"nodeType":864},{},[],{"data":69438,"content":69439,"nodeType":860},{},[69440],{"data":69441,"marks":69442,"value":68550,"nodeType":864},{},[],{"data":69444,"content":69445,"nodeType":860},{},[69446],{"data":69447,"marks":69448,"value":68557,"nodeType":864},{},[],{"data":69450,"content":69451,"nodeType":860},{},[69452],{"data":69453,"marks":69454,"value":68565,"nodeType":864},{},[69455],{"type":899},{"data":69457,"content":69458,"nodeType":1005},{},[],{"data":69460,"content":69461,"nodeType":1009},{},[69462],{"data":69463,"marks":69464,"value":68576,"nodeType":864},{},[69465],{"type":899},{"data":69467,"content":69468,"nodeType":860},{},[69469],{"data":69470,"marks":69471,"value":68583,"nodeType":864},{},[],{"data":69473,"content":69474,"nodeType":860},{},[69475],{"data":69476,"marks":69477,"value":68590,"nodeType":864},{},[],{"data":69479,"content":69480,"nodeType":860},{},[69481],{"data":69482,"marks":69483,"value":68597,"nodeType":864},{},[],{"data":69485,"content":69486,"nodeType":860},{},[69487,69490,69496],{"data":69488,"marks":69489,"value":68604,"nodeType":864},{},[],{"data":69491,"content":69492,"nodeType":883},{"uri":68607},[69493],{"data":69494,"marks":69495,"value":19763,"nodeType":864},{},[],{"data":69497,"marks":69498,"value":68615,"nodeType":864},{},[],{"data":69500,"content":69503,"nodeType":996},{"target":69501},{"sys":69502},{"id":68620,"type":1001,"linkType":1002},[],{"data":69505,"content":69506,"nodeType":860},{},[69507],{"data":69508,"marks":69509,"value":68628,"nodeType":864},{},[],{"data":69511,"content":69512,"nodeType":860},{},[69513,69516,69522],{"data":69514,"marks":69515,"value":68635,"nodeType":864},{},[],{"data":69517,"content":69518,"nodeType":883},{"uri":16015},[69519],{"data":69520,"marks":69521,"value":68642,"nodeType":864},{},[],{"data":69523,"marks":69524,"value":68646,"nodeType":864},{},[],{"data":69526,"content":69527,"nodeType":860},{},[69528],{"data":69529,"marks":69530,"value":68654,"nodeType":864},{},[69531],{"type":2246},{"data":69533,"content":69534,"nodeType":4845},{},[69535,69556,69577,69598,69619],{"data":69536,"content":69537,"nodeType":4581},{},[69538,69547],{"data":69539,"content":69540,"nodeType":14464},{},[69541],{"data":69542,"content":69543,"nodeType":860},{},[69544],{"data":69545,"marks":69546,"value":68670,"nodeType":864},{},[],{"data":69548,"content":69549,"nodeType":14464},{},[69550],{"data":69551,"content":69552,"nodeType":860},{},[69553],{"data":69554,"marks":69555,"value":68680,"nodeType":864},{},[],{"data":69557,"content":69558,"nodeType":4581},{},[69559,69568],{"data":69560,"content":69561,"nodeType":4569},{},[69562],{"data":69563,"content":69564,"nodeType":860},{},[69565],{"data":69566,"marks":69567,"value":68693,"nodeType":864},{},[],{"data":69569,"content":69570,"nodeType":4569},{},[69571],{"data":69572,"content":69573,"nodeType":860},{},[69574],{"data":69575,"marks":69576,"value":68703,"nodeType":864},{},[],{"data":69578,"content":69579,"nodeType":4581},{},[69580,69589],{"data":69581,"content":69582,"nodeType":4569},{},[69583],{"data":69584,"content":69585,"nodeType":860},{},[69586],{"data":69587,"marks":69588,"value":68716,"nodeType":864},{},[],{"data":69590,"content":69591,"nodeType":4569},{},[69592],{"data":69593,"content":69594,"nodeType":860},{},[69595],{"data":69596,"marks":69597,"value":68726,"nodeType":864},{},[],{"data":69599,"content":69600,"nodeType":4581},{},[69601,69610],{"data":69602,"content":69603,"nodeType":4569},{},[69604],{"data":69605,"content":69606,"nodeType":860},{},[69607],{"data":69608,"marks":69609,"value":68739,"nodeType":864},{},[],{"data":69611,"content":69612,"nodeType":4569},{},[69613],{"data":69614,"content":69615,"nodeType":860},{},[69616],{"data":69617,"marks":69618,"value":68749,"nodeType":864},{},[],{"data":69620,"content":69621,"nodeType":4581},{},[69622,69631],{"data":69623,"content":69624,"nodeType":4569},{},[69625],{"data":69626,"content":69627,"nodeType":860},{},[69628],{"data":69629,"marks":69630,"value":68762,"nodeType":864},{},[],{"data":69632,"content":69633,"nodeType":4569},{},[69634],{"data":69635,"content":69636,"nodeType":860},{},[69637],{"data":69638,"marks":69639,"value":68772,"nodeType":864},{},[],{"data":69641,"content":69642,"nodeType":1005},{},[],{"data":69644,"content":69645,"nodeType":1009},{},[69646],{"data":69647,"marks":69648,"value":68783,"nodeType":864},{},[69649],{"type":899},{"data":69651,"content":69652,"nodeType":860},{},[69653],{"data":69654,"marks":69655,"value":68790,"nodeType":864},{},[],{"data":69657,"content":69658,"nodeType":860},{},[69659,69662],{"data":69660,"marks":69661,"value":68797,"nodeType":864},{},[],{"data":69663,"marks":69664,"value":68802,"nodeType":864},{},[69665],{"type":899},{"data":69667,"content":69668,"nodeType":860},{},[69669],{"data":69670,"marks":69671,"value":68809,"nodeType":864},{},[],{"data":69673,"content":69676,"nodeType":996},{"target":69674},{"sys":69675},{"id":68814,"type":1001,"linkType":1002},[],{"data":69678,"content":69679,"nodeType":860},{},[69680],{"data":69681,"marks":69682,"value":68822,"nodeType":864},{},[],{"data":69684,"content":69685,"nodeType":860},{},[69686],{"data":69687,"marks":69688,"value":68829,"nodeType":864},{},[],{"data":69690,"content":69691,"nodeType":1312},{},[69692],{"data":69693,"marks":69694,"value":68837,"nodeType":864},{},[69695],{"type":899},{"data":69697,"content":69698,"nodeType":860},{},[69699],{"data":69700,"marks":69701,"value":68844,"nodeType":864},{},[],{"data":69703,"content":69704,"nodeType":860},{},[69705],{"data":69706,"marks":69707,"value":68852,"nodeType":864},{},[69708],{"type":899},{"data":69710,"content":69711,"nodeType":860},{},[69712],{"data":69713,"marks":69714,"value":68859,"nodeType":864},{},[],{"data":69716,"content":69717,"nodeType":860},{},[69718],{"data":69719,"marks":69720,"value":68866,"nodeType":864},{},[],{"data":69722,"content":69723,"nodeType":860},{},[69724],{"data":69725,"marks":69726,"value":68873,"nodeType":864},{},[],{"data":69728,"content":69729,"nodeType":941},{},[69730,69743,69756],{"data":69731,"content":69732,"nodeType":945},{},[69733],{"data":69734,"content":69735,"nodeType":860},{},[69736,69740],{"data":69737,"marks":69738,"value":68887,"nodeType":864},{},[69739],{"type":899},{"data":69741,"marks":69742,"value":68891,"nodeType":864},{},[],{"data":69744,"content":69745,"nodeType":945},{},[69746],{"data":69747,"content":69748,"nodeType":860},{},[69749,69753],{"data":69750,"marks":69751,"value":68902,"nodeType":864},{},[69752],{"type":899},{"data":69754,"marks":69755,"value":68906,"nodeType":864},{},[],{"data":69757,"content":69758,"nodeType":945},{},[69759],{"data":69760,"content":69761,"nodeType":860},{},[69762,69766],{"data":69763,"marks":69764,"value":68917,"nodeType":864},{},[69765],{"type":899},{"data":69767,"marks":69768,"value":68921,"nodeType":864},{},[],{"data":69770,"content":69771,"nodeType":860},{},[69772,69775],{"data":69773,"marks":69774,"value":68928,"nodeType":864},{},[],{"data":69776,"marks":69777,"value":68933,"nodeType":864},{},[69778],{"type":899},{"data":69780,"content":69781,"nodeType":1116},{},[69782],{"data":69783,"content":69784,"nodeType":860},{},[69785,69788,69794,69797,69803,69806,69812],{"data":69786,"marks":69787,"value":62048,"nodeType":864},{},[],{"data":69789,"content":69790,"nodeType":883},{"uri":16866},[69791],{"data":69792,"marks":69793,"value":62056,"nodeType":864},{},[],{"data":69795,"marks":69796,"value":3731,"nodeType":864},{},[],{"data":69798,"content":69799,"nodeType":883},{"uri":16877},[69800],{"data":69801,"marks":69802,"value":62067,"nodeType":864},{},[],{"data":69804,"marks":69805,"value":16887,"nodeType":864},{},[],{"data":69807,"content":69808,"nodeType":883},{"uri":1700},[69809],{"data":69810,"marks":69811,"value":16894,"nodeType":864},{},[],{"data":69813,"marks":69814,"value":2924,"nodeType":864},{},[],{"data":69816,"content":69819,"nodeType":996},{"target":69817},{"sys":69818},{"id":68466,"type":1001,"linkType":1002},[],{"data":69821,"content":69822,"nodeType":860},{},[69823],{"data":69824,"marks":69825,"value":21,"nodeType":864},{},[],{"items":69827},[69828,69830],{"sys":69829,"name":13779},{"id":13778},{"sys":69831,"name":342},{"id":13775},{"items":69833},[69834],{"fullName":68485,"firstName":68486,"jobTitle":851,"profilePicture":69835},{"url":68488},{"__typename":2059,"sys":69837,"content":69838,"title":64139,"synopsis":70209,"hashTags":59,"publishedDate":70210,"slug":64140,"tagsCollection":70211,"authorsCollection":70217},{"id":52590},{"json":69839},{"data":69840,"content":69841,"nodeType":856},{},[69842,69850,69857,69864,69871,69878,69885,69893,69900,69907,69914,69917,69925,69932,69939,69946,69953,69971,69979,69986,69993,70000,70003,70011,70027,70043,70050,70058,70065,70072,70079,70086,70091,70098,70161,70164,70203],{"data":69843,"content":69844,"nodeType":1009},{},[69845],{"data":69846,"marks":69847,"value":69849,"nodeType":864},{},[69848],{"type":899},"Cloud security tools ensure secure configurations",{"data":69851,"content":69852,"nodeType":860},{},[69853],{"data":69854,"marks":69855,"value":69856,"nodeType":864},{},[],"If you’re a cloud security architect, you probably don’t think in terms of firewalls and perimeters anymore. You think in control planes. Your job isn’t protecting a box or a subnet; it’s governing a sprawling web of IAM roles, service principals, APIs, and permissions that exist mostly as configuration and code. In this world, the boundary isn’t physical or even networked, it’s defined entirely by how your environment is configured.",{"data":69858,"content":69859,"nodeType":860},{},[69860],{"data":69861,"marks":69862,"value":69863,"nodeType":864},{},[],"The way most teams approached that problem was pragmatic. As cloud environments scaled, it became impossible to secure it by inspection or tribal knowledge. Cloud Security Posture Management tools and, later, Cloud Native Application Protection Platforms emerged to solve a very real problem: visibility and control over cloud configuration at scale. They gave teams a way to continuously assess infrastructure, track misconfigurations, and understand risk across accounts, regions, and services without drowning in raw provider logs.",{"data":69865,"content":69866,"nodeType":860},{},[69867],{"data":69868,"marks":69869,"value":69870,"nodeType":864},{},[],"That capability is important. Without it, cloud security simply doesn’t function. ",{"data":69872,"content":69873,"nodeType":860},{},[69874],{"data":69875,"marks":69876,"value":69877,"nodeType":864},{},[],"CSPM and CNAPP answer the question of “is my cloud environment configured securely?”. They tell you whether an IAM role is too permissive, whether a resource is exposed, or whether a policy violates best practice. They tell you when a user or account is trying to do something they shouldn’t. ",{"data":69879,"content":69880,"nodeType":860},{},[69881],{"data":69882,"marks":69883,"value":69884,"nodeType":864},{},[],"What they don’t answer is a different, increasingly important question: “What happens when attacker behavior is indistinguishable from legitimate user behavior?”",{"data":69886,"content":69887,"nodeType":1312},{},[69888],{"data":69889,"marks":69890,"value":69892,"nodeType":864},{},[69891],{"type":899},"But they can’t stop “legitimate” actions",{"data":69894,"content":69895,"nodeType":860},{},[69896],{"data":69897,"marks":69898,"value":69899,"nodeType":864},{},[],"The gap (or lack of) between legitimate user behavior and malicious abuse is becoming more relevant as cloud breaches change shape. ",{"data":69901,"content":69902,"nodeType":860},{},[69903],{"data":69904,"marks":69905,"value":69906,"nodeType":864},{},[],"In many of today’s incidents, attackers aren’t exploiting misconfigurations or abusing the cloud control plane directly. They’re compromising users. Once an authentication has occurred through illegitimate means, whether phishing, session hijacking, or token theft, the attacker operates entirely within an approved session.",{"data":69908,"content":69909,"nodeType":860},{},[69910],{"data":69911,"marks":69912,"value":69913,"nodeType":864},{},[],"From the perspective of cloud security tooling, very little looks wrong. The identity is valid. The access patterns appear expected. The infrastructure remains correctly configured. As long as the attacker operates within the bounds of what looks “normal”, no alarms are triggered. Meanwhile, sensitive actions are carried out through the browser, using the same interfaces and workflows as a real user.",{"data":69915,"content":69916,"nodeType":1005},{},[],{"data":69918,"content":69919,"nodeType":1009},{},[69920],{"data":69921,"marks":69922,"value":69924,"nodeType":864},{},[69923],{"type":899},"The gap between the IdP and the final API call — the “missing middle” in your security stack",{"data":69926,"content":69927,"nodeType":860},{},[69928],{"data":69929,"marks":69930,"value":69931,"nodeType":864},{},[],"The browser session sits outside the telemetry and control model of infrastructure-focused cloud security tools. We call this the \"missing middle.\" It’s the space between the IdP login and the final cloud API call. ",{"data":69933,"content":69934,"nodeType":860},{},[69935],{"data":69936,"marks":69937,"value":69938,"nodeType":864},{},[],"In theory, you could try to close the gap by stitching together logs from every SaaS application in your environment. In practice, anyone who’s attempted this knows how quickly it falls apart. ",{"data":69940,"content":69941,"nodeType":860},{},[69942],{"data":69943,"marks":69944,"value":69945,"nodeType":864},{},[],"Each integration is brittle and expensive to maintain, and many applications don’t expose the level of telemetry you actually need, even if you’re willing to fork out for the top Security++ product tier. When you’re dealing with hundreds of apps per enterprise, each with their own configuration complexity, there’s a good chance that your solution focused on “core” cloud apps doesn’t actually have visibility of the full attack surface.",{"data":69947,"content":69948,"nodeType":860},{},[69949],{"data":69950,"marks":69951,"value":69952,"nodeType":864},{},[],"When logs do exist, they rarely show what you actually need. To a CSPM or CNAPP, it looks like an authorized user doing authorized things. A file was accessed or a setting was changed. What those tools can’t see is that the browser session itself was being manipulated in real time.",{"data":69954,"content":69955,"nodeType":860},{},[69956,69959,69967],{"data":69957,"marks":69958,"value":68635,"nodeType":864},{},[],{"data":69960,"content":69961,"nodeType":883},{"uri":16015},[69962],{"data":69963,"marks":69964,"value":69966,"nodeType":864},{},[69965],{"type":1455},"modern, cloud-native threat groups",{"data":69968,"marks":69969,"value":69970,"nodeType":864},{},[],", this lack of session-level visibility is their greatest advantage. They bypass the strong configuration and identity controls you’ve already implemented by simply stepping into the authorized stream. And by the time infrastructure-level signals suggest something is wrong, the attacker has already accomplished what they came for.",{"data":69972,"content":69973,"nodeType":1312},{},[69974],{"data":69975,"marks":69976,"value":69978,"nodeType":864},{},[69977],{"type":899},"Secure everything, still lose",{"data":69980,"content":69981,"nodeType":860},{},[69982],{"data":69983,"marks":69984,"value":69985,"nodeType":864},{},[],"At some point, this forces a hard realization: you can do everything “right” at the cloud and identity layers and still lose.",{"data":69987,"content":69988,"nodeType":860},{},[69989],{"data":69990,"marks":69991,"value":69992,"nodeType":864},{},[],"You can lock down infrastructure-as-code, tighten IAM policies, enforce conditional access, and pass every posture check you care about. But none of that changes where access actually happens. When users work in cloud services, they do it through a browser. And once a session is established, that browser session becomes the real control plane.",{"data":69994,"content":69995,"nodeType":860},{},[69996],{"data":69997,"marks":69998,"value":69999,"nodeType":864},{},[],"That’s the shift cloud security teams are running into. The problem isn’t that CSPM or CNAPP failed, it’s that they can’t see the full picture. Bridging the missing middle means treating the browser session itself as something you can inspect and defend.",{"data":70001,"content":70002,"nodeType":1005},{},[],{"data":70004,"content":70005,"nodeType":1009},{},[70006],{"data":70007,"marks":70008,"value":70010,"nodeType":864},{},[70009],{"type":899},"Why moving detection and response to the browser is the solution",{"data":70012,"content":70013,"nodeType":860},{},[70014,70018,70023],{"data":70015,"marks":70016,"value":70017,"nodeType":864},{},[],"First, ",{"data":70019,"marks":70020,"value":70022,"nodeType":864},{},[70021],{"type":899},"detection has to move into the browser",{"data":70024,"marks":70025,"value":70026,"nodeType":864},{},[],". Modern cloud attacks don’t announce themselves with known indicators or suspicious IPs; it’s all about behavior. A phishing kit rendering inside a login page. A session token being silently exfiltrated. A user interacting with a page that looks legitimate but isn’t. You only see those signals by inspecting the page, the scripts, and the user’s interaction, in real time, inside the tab, before any cloud API ever gets touched.",{"data":70028,"content":70029,"nodeType":860},{},[70030,70034,70039],{"data":70031,"marks":70032,"value":70033,"nodeType":864},{},[],"Second, ",{"data":70035,"marks":70036,"value":70038,"nodeType":864},{},[70037],{"type":899},"posture can’t stop at the IdP or cloud configuration.",{"data":70040,"marks":70041,"value":70042,"nodeType":864},{},[]," It’s not enough to enforce MFA and SSO at a handful of centrally managed apps and assume the rest of the estate follows suit. Shadow SaaS breaks that assumption immediately. Local accounts, duplicate identities, and MFA gaps undermine cloud access controls, even when your AWS or Azure configuration is otherwise airtight. If a sensitive app allows password-only access, that weakness propagates straight back into your cloud environment.",{"data":70044,"content":70045,"nodeType":860},{},[70046],{"data":70047,"marks":70048,"value":70049,"nodeType":864},{},[],"Finally, when something does go wrong, teams need more than a login timestamp and an IP address. They need to know what the user actually saw and did. Click-by-click browser session data is what allows responders to understand intent, scope impact accurately, and determine whether a session was abused or simply used.",{"data":70051,"content":70052,"nodeType":1312},{},[70053],{"data":70054,"marks":70055,"value":70057,"nodeType":864},{},[70056],{"type":899},"Visibility into the browser session holds the answers",{"data":70059,"content":70060,"nodeType":860},{},[70061],{"data":70062,"marks":70063,"value":70064,"nodeType":864},{},[],"If the browser session is where cloud access actually happens, then treating it as a black box is no longer viable.",{"data":70066,"content":70067,"nodeType":860},{},[70068],{"data":70069,"marks":70070,"value":70071,"nodeType":864},{},[],"This is where Push Security fits. Push is designed to cover the missing middle, not by replacing your existing cloud security stack, but by extending it into the one place it can’t reach on its own: the live browser session.",{"data":70073,"content":70074,"nodeType":860},{},[70075],{"data":70076,"marks":70077,"value":70078,"nodeType":864},{},[],"CSPM and CNAPP remain the right tools for securing cloud configuration and infrastructure. They tell you whether IAM policies are sane, resources are exposed, and guardrails are in place. Push addresses a different problem. It focuses on what happens once access is granted, when identity moves from configuration into motion.",{"data":70080,"content":70081,"nodeType":860},{},[70082],{"data":70083,"marks":70084,"value":70085,"nodeType":864},{},[],"Push does this by deploying a browser-native agent, like EDR operates at the host level. That agent gives defenders direct visibility into the application session itself like the page structure being rendered, the user’s interaction with it, and the behaviors attackers rely on when they hijack sessions in real time.",{"data":70087,"content":70090,"nodeType":996},{"target":70088},{"sys":70089},{"id":68814,"type":1001,"linkType":1002},[],{"data":70092,"content":70093,"nodeType":860},{},[70094],{"data":70095,"marks":70096,"value":70097,"nodeType":864},{},[],"That visibility changes how cloud access can be defended.",{"data":70099,"content":70100,"nodeType":941},{},[70101,70116,70131,70146],{"data":70102,"content":70103,"nodeType":945},{},[70104],{"data":70105,"content":70106,"nodeType":860},{},[70107,70112],{"data":70108,"marks":70109,"value":70111,"nodeType":864},{},[70110],{"type":899},"Real-time detection in the browser:",{"data":70113,"marks":70114,"value":70115,"nodeType":864},{},[]," Detect in-browser attacker techniques as they happen, left of boom. Phishing kits rendering inside login flows, session tokens being intercepted, credential submission into lookalike pages — Push observes these behaviors directly and can block them before any cloud API is touched or a console is reached.",{"data":70117,"content":70118,"nodeType":945},{},[70119],{"data":70120,"content":70121,"nodeType":860},{},[70122,70127],{"data":70123,"marks":70124,"value":70126,"nodeType":864},{},[70125],{"type":899},"Complete visibility into cloud access paths:",{"data":70128,"marks":70129,"value":70130,"nodeType":864},{},[]," Build an accurate inventory of how users are actually accessing cloud services. Push surfaces every application in use, including shadow SaaS, and shows which accounts are local, duplicated, missing MFA, or bypassing SSO — crucial visibility that falls between the cracks of application and identity provider. ",{"data":70132,"content":70133,"nodeType":945},{},[70134],{"data":70135,"content":70136,"nodeType":860},{},[70137,70142],{"data":70138,"marks":70139,"value":70141,"nodeType":864},{},[70140],{"type":899},"Active hardening at the point of access:",{"data":70143,"marks":70144,"value":70145,"nodeType":864},{},[]," Enforce secure login behavior across the entire application surface, not just centrally managed apps. Push can steer users toward using MFA and SSO and block risky credentials on unmanaged tools, closing identity gaps before they’re exploited.",{"data":70147,"content":70148,"nodeType":945},{},[70149],{"data":70150,"content":70151,"nodeType":860},{},[70152,70157],{"data":70153,"marks":70154,"value":70156,"nodeType":864},{},[70155],{"type":899},"Session-level context for rapid response:",{"data":70158,"marks":70159,"value":70160,"nodeType":864},{},[]," When something does go wrong, Push provides the missing ground truth. Instead of stitching together partial logs or relying on brittle app-level integrations, responders can see exactly what the user saw and did in the browser (from context generated directly from the browser session itself) making it possible to understand intent, assess scope accurately, and contain a compromised session quickly.",{"data":70162,"content":70163,"nodeType":1005},{},[],{"data":70165,"content":70166,"nodeType":1116},{},[70167],{"data":70168,"content":70169,"nodeType":860},{},[70170,70173,70180,70183,70190,70193,70200],{"data":70171,"marks":70172,"value":62048,"nodeType":864},{},[],{"data":70174,"content":70175,"nodeType":883},{"uri":16866},[70176],{"data":70177,"marks":70178,"value":62056,"nodeType":864},{},[70179],{"type":1455},{"data":70181,"marks":70182,"value":3731,"nodeType":864},{},[],{"data":70184,"content":70185,"nodeType":883},{"uri":16877},[70186],{"data":70187,"marks":70188,"value":62067,"nodeType":864},{},[70189],{"type":1455},{"data":70191,"marks":70192,"value":16887,"nodeType":864},{},[],{"data":70194,"content":70195,"nodeType":883},{"uri":1700},[70196],{"data":70197,"marks":70198,"value":16894,"nodeType":864},{},[70199],{"type":1455},{"data":70201,"marks":70202,"value":2924,"nodeType":864},{},[],{"data":70204,"content":70205,"nodeType":860},{},[70206],{"data":70207,"marks":70208,"value":21,"nodeType":864},{},[],"Why cloud security tools only give you part of the picture when it comes to modern attacks. ","2026-02-06T00:00:00.000Z",{"items":70212},[70213,70215],{"sys":70214,"name":13779},{"id":13778},{"sys":70216,"name":342},{"id":13775},{"items":70218},[70219],{"fullName":68485,"firstName":68486,"jobTitle":851,"profilePicture":70220},{"url":68488},"blog/push-plus-endpoint-security",{"json":70223},{"data":70224,"content":70225,"nodeType":856},{},[70226],{"data":70227,"content":70228,"nodeType":860},{},[70229],{"data":70230,"marks":70231,"value":70232,"nodeType":864},{},[],"One of the key questions we often hear is \"we've already got EDR, so why do we need to be in the browser too?\". Well, here's the answer!",{"id":52576,"publishedAt":70234},"2026-08-13T09:35:41.299Z",{"items":70236},[70237,70239],{"sys":70238,"name":13779},{"id":13778},{"sys":70240,"name":342},{"id":13775},{"items":70242},[70243,70245,70247,70249,70251,70253,70255,70257],{"sys":70244,"name":297,"slug":298,"tier":31},{"id":294},{"sys":70246,"name":279,"slug":280,"tier":31},{"id":276},{"sys":70248,"name":342,"slug":343,"tier":31},{"id":339},{"sys":70250,"name":377,"slug":378,"tier":45},{"id":374},{"sys":70252,"name":261,"slug":262,"tier":45},{"id":258},{"sys":70254,"name":571,"slug":572,"tier":45},{"id":568},{"sys":70256,"name":288,"slug":289,"tier":45},{"id":285},{"sys":70258,"name":315,"slug":316,"tier":45},{"id":312},"JhUSIdUT34jBz7baqPjVEhg0kgv0ylAjyUoc9hrf0Ok",{"id":70261,"title":68076,"authorsCollection":70262,"content":70266,"extension":228,"faqItemsCollection":71526,"faqTitle":59,"featured":6,"hashTags":59,"meta":71528,"metaTitle":71529,"ogImage":59,"postType":71530,"publishedDate":68078,"relatedBlogPostsCollection":71531,"slug":68079,"stem":73905,"subtitle":59,"summary":73906,"synopsis":68077,"sys":73917,"tagsCollection":73919,"topicsCollection":73925,"__hash__":73969},"blog/blog/taking-the-fight-to-attackers-top-features-of-2025.json",{"items":70263},[70264],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":59,"profilePicture":70265},{"url":853},{"json":70267,"links":71387},{"data":70268,"content":70269,"nodeType":856},{},[70270,70276,70282,70339,70345,70403,70408,70414,70420,70423,70429,70435,70441,70527,70542,70548,70585,70591,70597,70603,70633,70638,70665,70670,70676,70682,70712,70729,70732,70738,70744,70768,70774,70780,70786,70792,70798,70803,70816,70855,70860,70877,70880,70886,70892,70909,70915,70941,70958,70964,70981,70987,70993,71044,71050,71055,71068,71081,71098,71103,71120,71126,71129,71135,71141,71147,71153,71170,71176,71193,71198,71204,71234,71251,71254,71260,71266,71272,71289,71295,71308,71313,71319,71325,71342,71345,71351,71357,71363],{"data":70271,"content":70272,"nodeType":860},{},[70273],{"data":70274,"marks":70275,"value":66805,"nodeType":864},{},[],{"data":70277,"content":70278,"nodeType":860},{},[70279],{"data":70280,"marks":70281,"value":66812,"nodeType":864},{},[],{"data":70283,"content":70284,"nodeType":941},{},[70285,70303,70321],{"data":70286,"content":70287,"nodeType":945},{},[70288],{"data":70289,"content":70290,"nodeType":860},{},[70291,70294,70300],{"data":70292,"marks":70293,"value":66825,"nodeType":864},{},[],{"data":70295,"content":70296,"nodeType":883},{"uri":57747},[70297],{"data":70298,"marks":70299,"value":19538,"nodeType":864},{},[],{"data":70301,"marks":70302,"value":57756,"nodeType":864},{},[],{"data":70304,"content":70305,"nodeType":945},{},[70306],{"data":70307,"content":70308,"nodeType":860},{},[70309,70312,70318],{"data":70310,"marks":70311,"value":66844,"nodeType":864},{},[],{"data":70313,"content":70314,"nodeType":883},{"uri":57747},[70315],{"data":70316,"marks":70317,"value":19538,"nodeType":864},{},[],{"data":70319,"marks":70320,"value":57756,"nodeType":864},{},[],{"data":70322,"content":70323,"nodeType":945},{},[70324],{"data":70325,"content":70326,"nodeType":860},{},[70327,70330,70336],{"data":70328,"marks":70329,"value":66863,"nodeType":864},{},[],{"data":70331,"content":70332,"nodeType":883},{"uri":57769},[70333],{"data":70334,"marks":70335,"value":66870,"nodeType":864},{},[],{"data":70337,"marks":70338,"value":57756,"nodeType":864},{},[],{"data":70340,"content":70341,"nodeType":860},{},[70342],{"data":70343,"marks":70344,"value":66880,"nodeType":864},{},[],{"data":70346,"content":70347,"nodeType":941},{},[70348,70364,70387],{"data":70349,"content":70350,"nodeType":945},{},[70351],{"data":70352,"content":70353,"nodeType":860},{},[70354,70357,70361],{"data":70355,"marks":70356,"value":66893,"nodeType":864},{},[],{"data":70358,"marks":70359,"value":66898,"nodeType":864},{},[70360],{"type":899},{"data":70362,"marks":70363,"value":66902,"nodeType":864},{},[],{"data":70365,"content":70366,"nodeType":945},{},[70367],{"data":70368,"content":70369,"nodeType":860},{},[70370,70373,70377,70380,70384],{"data":70371,"marks":70372,"value":66912,"nodeType":864},{},[],{"data":70374,"marks":70375,"value":66917,"nodeType":864},{},[70376],{"type":899},{"data":70378,"marks":70379,"value":66921,"nodeType":864},{},[],{"data":70381,"marks":70382,"value":66926,"nodeType":864},{},[70383],{"type":899},{"data":70385,"marks":70386,"value":66930,"nodeType":864},{},[],{"data":70388,"content":70389,"nodeType":945},{},[70390],{"data":70391,"content":70392,"nodeType":860},{},[70393,70396,70400],{"data":70394,"marks":70395,"value":66940,"nodeType":864},{},[],{"data":70397,"marks":70398,"value":66945,"nodeType":864},{},[70399],{"type":899},{"data":70401,"marks":70402,"value":66949,"nodeType":864},{},[],{"data":70404,"content":70407,"nodeType":996},{"target":70405},{"sys":70406},{"id":66954,"type":1001,"linkType":1002},[],{"data":70409,"content":70410,"nodeType":860},{},[70411],{"data":70412,"marks":70413,"value":66962,"nodeType":864},{},[],{"data":70415,"content":70416,"nodeType":860},{},[70417],{"data":70418,"marks":70419,"value":66969,"nodeType":864},{},[],{"data":70421,"content":70422,"nodeType":1005},{},[],{"data":70424,"content":70425,"nodeType":1009},{},[70426],{"data":70427,"marks":70428,"value":66979,"nodeType":864},{},[],{"data":70430,"content":70431,"nodeType":1312},{},[70432],{"data":70433,"marks":70434,"value":66986,"nodeType":864},{},[],{"data":70436,"content":70437,"nodeType":860},{},[70438],{"data":70439,"marks":70440,"value":66993,"nodeType":864},{},[],{"data":70442,"content":70443,"nodeType":941},{},[70444,70468,70503],{"data":70445,"content":70446,"nodeType":945},{},[70447],{"data":70448,"content":70449,"nodeType":860},{},[70450,70454,70457,70465],{"data":70451,"marks":70452,"value":67007,"nodeType":864},{},[70453],{"type":899},{"data":70455,"marks":70456,"value":67011,"nodeType":864},{},[],{"data":70458,"content":70461,"nodeType":39736},{"target":70459},{"sys":70460},{"id":67016,"type":1001,"linkType":1002},[70462],{"data":70463,"marks":70464,"value":67021,"nodeType":864},{},[],{"data":70466,"marks":70467,"value":67025,"nodeType":864},{},[],{"data":70469,"content":70470,"nodeType":945},{},[70471],{"data":70472,"content":70473,"nodeType":860},{},[70474,70478,70481,70489,70492,70500],{"data":70475,"marks":70476,"value":67036,"nodeType":864},{},[70477],{"type":899},{"data":70479,"marks":70480,"value":67040,"nodeType":864},{},[],{"data":70482,"content":70485,"nodeType":39736},{"target":70483},{"sys":70484},{"id":67045,"type":1001,"linkType":1002},[70486],{"data":70487,"marks":70488,"value":441,"nodeType":864},{},[],{"data":70490,"marks":70491,"value":67053,"nodeType":864},{},[],{"data":70493,"content":70496,"nodeType":39736},{"target":70494},{"sys":70495},{"id":67058,"type":1001,"linkType":1002},[70497],{"data":70498,"marks":70499,"value":67063,"nodeType":864},{},[],{"data":70501,"marks":70502,"value":1774,"nodeType":864},{},[],{"data":70504,"content":70505,"nodeType":945},{},[70506],{"data":70507,"content":70508,"nodeType":860},{},[70509,70513,70516,70524],{"data":70510,"marks":70511,"value":67077,"nodeType":864},{},[70512],{"type":899},{"data":70514,"marks":70515,"value":67081,"nodeType":864},{},[],{"data":70517,"content":70520,"nodeType":39736},{"target":70518},{"sys":70519},{"id":67086,"type":1001,"linkType":1002},[70521],{"data":70522,"marks":70523,"value":67091,"nodeType":864},{},[],{"data":70525,"marks":70526,"value":67095,"nodeType":864},{},[],{"data":70528,"content":70529,"nodeType":860},{},[70530,70533,70539],{"data":70531,"marks":70532,"value":67102,"nodeType":864},{},[],{"data":70534,"content":70535,"nodeType":883},{"uri":67105},[70536],{"data":70537,"marks":70538,"value":67110,"nodeType":864},{},[],{"data":70540,"marks":70541,"value":67114,"nodeType":864},{},[],{"data":70543,"content":70544,"nodeType":860},{},[70545],{"data":70546,"marks":70547,"value":67121,"nodeType":864},{},[],{"data":70549,"content":70550,"nodeType":941},{},[70551,70560,70576],{"data":70552,"content":70553,"nodeType":945},{},[70554],{"data":70555,"content":70556,"nodeType":860},{},[70557],{"data":70558,"marks":70559,"value":67134,"nodeType":864},{},[],{"data":70561,"content":70562,"nodeType":945},{},[70563],{"data":70564,"content":70565,"nodeType":860},{},[70566,70569,70573],{"data":70567,"marks":70568,"value":67144,"nodeType":864},{},[],{"data":70570,"marks":70571,"value":67149,"nodeType":864},{},[70572],{"type":2246},{"data":70574,"marks":70575,"value":67153,"nodeType":864},{},[],{"data":70577,"content":70578,"nodeType":945},{},[70579],{"data":70580,"content":70581,"nodeType":860},{},[70582],{"data":70583,"marks":70584,"value":67163,"nodeType":864},{},[],{"data":70586,"content":70587,"nodeType":860},{},[70588],{"data":70589,"marks":70590,"value":67170,"nodeType":864},{},[],{"data":70592,"content":70593,"nodeType":1312},{},[70594],{"data":70595,"marks":70596,"value":67177,"nodeType":864},{},[],{"data":70598,"content":70599,"nodeType":860},{},[70600],{"data":70601,"marks":70602,"value":67184,"nodeType":864},{},[],{"data":70604,"content":70605,"nodeType":941},{},[70606,70615,70624],{"data":70607,"content":70608,"nodeType":945},{},[70609],{"data":70610,"content":70611,"nodeType":860},{},[70612],{"data":70613,"marks":70614,"value":67197,"nodeType":864},{},[],{"data":70616,"content":70617,"nodeType":945},{},[70618],{"data":70619,"content":70620,"nodeType":860},{},[70621],{"data":70622,"marks":70623,"value":67207,"nodeType":864},{},[],{"data":70625,"content":70626,"nodeType":945},{},[70627],{"data":70628,"content":70629,"nodeType":860},{},[70630],{"data":70631,"marks":70632,"value":67217,"nodeType":864},{},[],{"data":70634,"content":70637,"nodeType":996},{"target":70635},{"sys":70636},{"id":67222,"type":1001,"linkType":1002},[],{"data":70639,"content":70640,"nodeType":860},{},[70641,70644,70648,70651,70655,70658,70662],{"data":70642,"marks":70643,"value":67230,"nodeType":864},{},[],{"data":70645,"marks":70646,"value":67235,"nodeType":864},{},[70647],{"type":899},{"data":70649,"marks":70650,"value":3731,"nodeType":864},{},[],{"data":70652,"marks":70653,"value":67243,"nodeType":864},{},[70654],{"type":899},{"data":70656,"marks":70657,"value":2232,"nodeType":864},{},[],{"data":70659,"marks":70660,"value":65229,"nodeType":864},{},[70661],{"type":899},{"data":70663,"marks":70664,"value":67254,"nodeType":864},{},[],{"data":70666,"content":70669,"nodeType":996},{"target":70667},{"sys":70668},{"id":65484,"type":1001,"linkType":1002},[],{"data":70671,"content":70672,"nodeType":860},{},[70673],{"data":70674,"marks":70675,"value":67266,"nodeType":864},{},[],{"data":70677,"content":70678,"nodeType":860},{},[70679],{"data":70680,"marks":70681,"value":67273,"nodeType":864},{},[],{"data":70683,"content":70684,"nodeType":941},{},[70685,70694,70703],{"data":70686,"content":70687,"nodeType":945},{},[70688],{"data":70689,"content":70690,"nodeType":860},{},[70691],{"data":70692,"marks":70693,"value":67286,"nodeType":864},{},[],{"data":70695,"content":70696,"nodeType":945},{},[70697],{"data":70698,"content":70699,"nodeType":860},{},[70700],{"data":70701,"marks":70702,"value":67296,"nodeType":864},{},[],{"data":70704,"content":70705,"nodeType":945},{},[70706],{"data":70707,"content":70708,"nodeType":860},{},[70709],{"data":70710,"marks":70711,"value":67306,"nodeType":864},{},[],{"data":70713,"content":70714,"nodeType":860},{},[70715,70718,70726],{"data":70716,"marks":70717,"value":67313,"nodeType":864},{},[],{"data":70719,"content":70722,"nodeType":39736},{"target":70720},{"sys":70721},{"id":67318,"type":1001,"linkType":1002},[70723],{"data":70724,"marks":70725,"value":67323,"nodeType":864},{},[],{"data":70727,"marks":70728,"value":2924,"nodeType":864},{},[],{"data":70730,"content":70731,"nodeType":1005},{},[],{"data":70733,"content":70734,"nodeType":1009},{},[70735],{"data":70736,"marks":70737,"value":67336,"nodeType":864},{},[],{"data":70739,"content":70740,"nodeType":1312},{},[70741],{"data":70742,"marks":70743,"value":66986,"nodeType":864},{},[],{"data":70745,"content":70746,"nodeType":860},{},[70747,70750,70756,70759,70765],{"data":70748,"marks":70749,"value":67349,"nodeType":864},{},[],{"data":70751,"content":70752,"nodeType":883},{"uri":67352},[70753],{"data":70754,"marks":70755,"value":67357,"nodeType":864},{},[],{"data":70757,"marks":70758,"value":67361,"nodeType":864},{},[],{"data":70760,"content":70761,"nodeType":883},{"uri":67364},[70762],{"data":70763,"marks":70764,"value":67369,"nodeType":864},{},[],{"data":70766,"marks":70767,"value":67373,"nodeType":864},{},[],{"data":70769,"content":70770,"nodeType":860},{},[70771],{"data":70772,"marks":70773,"value":67380,"nodeType":864},{},[],{"data":70775,"content":70776,"nodeType":860},{},[70777],{"data":70778,"marks":70779,"value":67387,"nodeType":864},{},[],{"data":70781,"content":70782,"nodeType":860},{},[70783],{"data":70784,"marks":70785,"value":67394,"nodeType":864},{},[],{"data":70787,"content":70788,"nodeType":1312},{},[70789],{"data":70790,"marks":70791,"value":67177,"nodeType":864},{},[],{"data":70793,"content":70794,"nodeType":860},{},[70795],{"data":70796,"marks":70797,"value":67407,"nodeType":864},{},[],{"data":70799,"content":70802,"nodeType":996},{"target":70800},{"sys":70801},{"id":67412,"type":1001,"linkType":1002},[],{"data":70804,"content":70805,"nodeType":860},{},[70806,70809,70813],{"data":70807,"marks":70808,"value":67420,"nodeType":864},{},[],{"data":70810,"marks":70811,"value":65229,"nodeType":864},{},[70812],{"type":899},{"data":70814,"marks":70815,"value":67428,"nodeType":864},{},[],{"data":70817,"content":70818,"nodeType":941},{},[70819,70828,70837,70846],{"data":70820,"content":70821,"nodeType":945},{},[70822],{"data":70823,"content":70824,"nodeType":860},{},[70825],{"data":70826,"marks":70827,"value":67441,"nodeType":864},{},[],{"data":70829,"content":70830,"nodeType":945},{},[70831],{"data":70832,"content":70833,"nodeType":860},{},[70834],{"data":70835,"marks":70836,"value":67451,"nodeType":864},{},[],{"data":70838,"content":70839,"nodeType":945},{},[70840],{"data":70841,"content":70842,"nodeType":860},{},[70843],{"data":70844,"marks":70845,"value":67461,"nodeType":864},{},[],{"data":70847,"content":70848,"nodeType":945},{},[70849],{"data":70850,"content":70851,"nodeType":860},{},[70852],{"data":70853,"marks":70854,"value":67471,"nodeType":864},{},[],{"data":70856,"content":70859,"nodeType":996},{"target":70857},{"sys":70858},{"id":67476,"type":1001,"linkType":1002},[],{"data":70861,"content":70862,"nodeType":860},{},[70863,70866,70874],{"data":70864,"marks":70865,"value":67484,"nodeType":864},{},[],{"data":70867,"content":70870,"nodeType":39736},{"target":70868},{"sys":70869},{"id":52747,"type":1001,"linkType":1002},[70871],{"data":70872,"marks":70873,"value":67493,"nodeType":864},{},[],{"data":70875,"marks":70876,"value":2924,"nodeType":864},{},[],{"data":70878,"content":70879,"nodeType":1005},{},[],{"data":70881,"content":70882,"nodeType":1009},{},[70883],{"data":70884,"marks":70885,"value":67506,"nodeType":864},{},[],{"data":70887,"content":70888,"nodeType":1312},{},[70889],{"data":70890,"marks":70891,"value":66986,"nodeType":864},{},[],{"data":70893,"content":70894,"nodeType":860},{},[70895,70898,70906],{"data":70896,"marks":70897,"value":67519,"nodeType":864},{},[],{"data":70899,"content":70902,"nodeType":39736},{"target":70900},{"sys":70901},{"id":67524,"type":1001,"linkType":1002},[70903],{"data":70904,"marks":70905,"value":67529,"nodeType":864},{},[],{"data":70907,"marks":70908,"value":1774,"nodeType":864},{},[],{"data":70910,"content":70911,"nodeType":860},{},[70912],{"data":70913,"marks":70914,"value":67539,"nodeType":864},{},[],{"data":70916,"content":70917,"nodeType":860},{},[70918,70921,70929,70932,70938],{"data":70919,"marks":70920,"value":67546,"nodeType":864},{},[],{"data":70922,"content":70925,"nodeType":39736},{"target":70923},{"sys":70924},{"id":57022,"type":1001,"linkType":1002},[70926],{"data":70927,"marks":70928,"value":16018,"nodeType":864},{},[],{"data":70930,"marks":70931,"value":67558,"nodeType":864},{},[],{"data":70933,"content":70934,"nodeType":883},{"uri":57333},[70935],{"data":70936,"marks":70937,"value":29819,"nodeType":864},{},[],{"data":70939,"marks":70940,"value":67568,"nodeType":864},{},[],{"data":70942,"content":70943,"nodeType":860},{},[70944,70947,70955],{"data":70945,"marks":70946,"value":67575,"nodeType":864},{},[],{"data":70948,"content":70951,"nodeType":39736},{"target":70949},{"sys":70950},{"id":62097,"type":1001,"linkType":1002},[70952],{"data":70953,"marks":70954,"value":28735,"nodeType":864},{},[],{"data":70956,"marks":70957,"value":67587,"nodeType":864},{},[],{"data":70959,"content":70960,"nodeType":1312},{},[70961],{"data":70962,"marks":70963,"value":67177,"nodeType":864},{},[],{"data":70965,"content":70966,"nodeType":860},{},[70967,70970,70978],{"data":70968,"marks":70969,"value":67600,"nodeType":864},{},[],{"data":70971,"content":70974,"nodeType":39736},{"target":70972},{"sys":70973},{"id":67605,"type":1001,"linkType":1002},[70975],{"data":70976,"marks":70977,"value":67610,"nodeType":864},{},[],{"data":70979,"marks":70980,"value":67614,"nodeType":864},{},[],{"data":70982,"content":70983,"nodeType":860},{},[70984],{"data":70985,"marks":70986,"value":67621,"nodeType":864},{},[],{"data":70988,"content":70989,"nodeType":860},{},[70990],{"data":70991,"marks":70992,"value":67628,"nodeType":864},{},[],{"data":70994,"content":70995,"nodeType":941},{},[70996,71020],{"data":70997,"content":70998,"nodeType":945},{},[70999],{"data":71000,"content":71001,"nodeType":860},{},[71002,71006,71009,71017],{"data":71003,"marks":71004,"value":67642,"nodeType":864},{},[71005],{"type":899},{"data":71007,"marks":71008,"value":67646,"nodeType":864},{},[],{"data":71010,"content":71013,"nodeType":39736},{"target":71011},{"sys":71012},{"id":67651,"type":1001,"linkType":1002},[71014],{"data":71015,"marks":71016,"value":67656,"nodeType":864},{},[],{"data":71018,"marks":71019,"value":67660,"nodeType":864},{},[],{"data":71021,"content":71022,"nodeType":945},{},[71023],{"data":71024,"content":71025,"nodeType":860},{},[71026,71030,71033,71041],{"data":71027,"marks":71028,"value":67671,"nodeType":864},{},[71029],{"type":899},{"data":71031,"marks":71032,"value":67646,"nodeType":864},{},[],{"data":71034,"content":71037,"nodeType":39736},{"target":71035},{"sys":71036},{"id":67679,"type":1001,"linkType":1002},[71038],{"data":71039,"marks":71040,"value":67684,"nodeType":864},{},[],{"data":71042,"marks":71043,"value":67688,"nodeType":864},{},[],{"data":71045,"content":71046,"nodeType":860},{},[71047],{"data":71048,"marks":71049,"value":67695,"nodeType":864},{},[],{"data":71051,"content":71054,"nodeType":996},{"target":71052},{"sys":71053},{"id":67700,"type":1001,"linkType":1002},[],{"data":71056,"content":71057,"nodeType":860},{},[71058,71061,71065],{"data":71059,"marks":71060,"value":67708,"nodeType":864},{},[],{"data":71062,"marks":71063,"value":53134,"nodeType":864},{},[71064],{"type":899},{"data":71066,"marks":71067,"value":2924,"nodeType":864},{},[],{"data":71069,"content":71070,"nodeType":860},{},[71071,71074,71078],{"data":71072,"marks":71073,"value":2761,"nodeType":864},{},[],{"data":71075,"marks":71076,"value":53134,"nodeType":864},{},[71077],{"type":899},{"data":71079,"marks":71080,"value":67729,"nodeType":864},{},[],{"data":71082,"content":71083,"nodeType":860},{},[71084,71087,71095],{"data":71085,"marks":71086,"value":67736,"nodeType":864},{},[],{"data":71088,"content":71091,"nodeType":39736},{"target":71089},{"sys":71090},{"id":52935,"type":1001,"linkType":1002},[71092],{"data":71093,"marks":71094,"value":67745,"nodeType":864},{},[],{"data":71096,"marks":71097,"value":67749,"nodeType":864},{},[],{"data":71099,"content":71102,"nodeType":996},{"target":71100},{"sys":71101},{"id":67754,"type":1001,"linkType":1002},[],{"data":71104,"content":71105,"nodeType":860},{},[71106,71109,71117],{"data":71107,"marks":71108,"value":67762,"nodeType":864},{},[],{"data":71110,"content":71113,"nodeType":39736},{"target":71111},{"sys":71112},{"id":67767,"type":1001,"linkType":1002},[71114],{"data":71115,"marks":71116,"value":67772,"nodeType":864},{},[],{"data":71118,"marks":71119,"value":67776,"nodeType":864},{},[],{"data":71121,"content":71122,"nodeType":860},{},[71123],{"data":71124,"marks":71125,"value":67783,"nodeType":864},{},[],{"data":71127,"content":71128,"nodeType":1005},{},[],{"data":71130,"content":71131,"nodeType":1009},{},[71132],{"data":71133,"marks":71134,"value":67793,"nodeType":864},{},[],{"data":71136,"content":71137,"nodeType":1312},{},[71138],{"data":71139,"marks":71140,"value":66986,"nodeType":864},{},[],{"data":71142,"content":71143,"nodeType":860},{},[71144],{"data":71145,"marks":71146,"value":67806,"nodeType":864},{},[],{"data":71148,"content":71149,"nodeType":860},{},[71150],{"data":71151,"marks":71152,"value":67813,"nodeType":864},{},[],{"data":71154,"content":71155,"nodeType":860},{},[71156,71159,71167],{"data":71157,"marks":71158,"value":67820,"nodeType":864},{},[],{"data":71160,"content":71163,"nodeType":39736},{"target":71161},{"sys":71162},{"id":50825,"type":1001,"linkType":1002},[71164],{"data":71165,"marks":71166,"value":67829,"nodeType":864},{},[],{"data":71168,"marks":71169,"value":67833,"nodeType":864},{},[],{"data":71171,"content":71172,"nodeType":1312},{},[71173],{"data":71174,"marks":71175,"value":67177,"nodeType":864},{},[],{"data":71177,"content":71178,"nodeType":860},{},[71179,71182,71190],{"data":71180,"marks":71181,"value":67846,"nodeType":864},{},[],{"data":71183,"content":71186,"nodeType":39736},{"target":71184},{"sys":71185},{"id":53020,"type":1001,"linkType":1002},[71187],{"data":71188,"marks":71189,"value":67855,"nodeType":864},{},[],{"data":71191,"marks":71192,"value":67859,"nodeType":864},{},[],{"data":71194,"content":71197,"nodeType":996},{"target":71195},{"sys":71196},{"id":65179,"type":1001,"linkType":1002},[],{"data":71199,"content":71200,"nodeType":860},{},[71201],{"data":71202,"marks":71203,"value":67871,"nodeType":864},{},[],{"data":71205,"content":71206,"nodeType":941},{},[71207,71216,71225],{"data":71208,"content":71209,"nodeType":945},{},[71210],{"data":71211,"content":71212,"nodeType":860},{},[71213],{"data":71214,"marks":71215,"value":67884,"nodeType":864},{},[],{"data":71217,"content":71218,"nodeType":945},{},[71219],{"data":71220,"content":71221,"nodeType":860},{},[71222],{"data":71223,"marks":71224,"value":67894,"nodeType":864},{},[],{"data":71226,"content":71227,"nodeType":945},{},[71228],{"data":71229,"content":71230,"nodeType":860},{},[71231],{"data":71232,"marks":71233,"value":67904,"nodeType":864},{},[],{"data":71235,"content":71236,"nodeType":860},{},[71237,71240,71248],{"data":71238,"marks":71239,"value":67911,"nodeType":864},{},[],{"data":71241,"content":71244,"nodeType":39736},{"target":71242},{"sys":71243},{"id":53020,"type":1001,"linkType":1002},[71245],{"data":71246,"marks":71247,"value":67493,"nodeType":864},{},[],{"data":71249,"marks":71250,"value":2924,"nodeType":864},{},[],{"data":71252,"content":71253,"nodeType":1005},{},[],{"data":71255,"content":71256,"nodeType":1009},{},[71257],{"data":71258,"marks":71259,"value":67932,"nodeType":864},{},[],{"data":71261,"content":71262,"nodeType":1312},{},[71263],{"data":71264,"marks":71265,"value":66986,"nodeType":864},{},[],{"data":71267,"content":71268,"nodeType":860},{},[71269],{"data":71270,"marks":71271,"value":67945,"nodeType":864},{},[],{"data":71273,"content":71274,"nodeType":860},{},[71275,71278,71286],{"data":71276,"marks":71277,"value":67952,"nodeType":864},{},[],{"data":71279,"content":71282,"nodeType":39736},{"target":71280},{"sys":71281},{"id":67957,"type":1001,"linkType":1002},[71283],{"data":71284,"marks":71285,"value":67962,"nodeType":864},{},[],{"data":71287,"marks":71288,"value":67966,"nodeType":864},{},[],{"data":71290,"content":71291,"nodeType":1312},{},[71292],{"data":71293,"marks":71294,"value":67177,"nodeType":864},{},[],{"data":71296,"content":71297,"nodeType":860},{},[71298,71301,71305],{"data":71299,"marks":71300,"value":67979,"nodeType":864},{},[],{"data":71302,"marks":71303,"value":67984,"nodeType":864},{},[71304],{"type":899},{"data":71306,"marks":71307,"value":2924,"nodeType":864},{},[],{"data":71309,"content":71312,"nodeType":996},{"target":71310},{"sys":71311},{"id":67992,"type":1001,"linkType":1002},[],{"data":71314,"content":71315,"nodeType":860},{},[71316],{"data":71317,"marks":71318,"value":68000,"nodeType":864},{},[],{"data":71320,"content":71321,"nodeType":860},{},[71322],{"data":71323,"marks":71324,"value":68007,"nodeType":864},{},[],{"data":71326,"content":71327,"nodeType":860},{},[71328,71331,71339],{"data":71329,"marks":71330,"value":68014,"nodeType":864},{},[],{"data":71332,"content":71335,"nodeType":39736},{"target":71333},{"sys":71334},{"id":68019,"type":1001,"linkType":1002},[71336],{"data":71337,"marks":71338,"value":67323,"nodeType":864},{},[],{"data":71340,"marks":71341,"value":2924,"nodeType":864},{},[],{"data":71343,"content":71344,"nodeType":1005},{},[],{"data":71346,"content":71347,"nodeType":1009},{},[71348],{"data":71349,"marks":71350,"value":3578,"nodeType":864},{},[],{"data":71352,"content":71353,"nodeType":860},{},[71354],{"data":71355,"marks":71356,"value":68042,"nodeType":864},{},[],{"data":71358,"content":71359,"nodeType":860},{},[71360],{"data":71361,"marks":71362,"value":68049,"nodeType":864},{},[],{"data":71364,"content":71365,"nodeType":860},{},[71366,71369,71375,71378,71384],{"data":71367,"marks":71368,"value":68056,"nodeType":864},{},[],{"data":71370,"content":71371,"nodeType":883},{"uri":53388},[71372],{"data":71373,"marks":71374,"value":53393,"nodeType":864},{},[],{"data":71376,"marks":71377,"value":68066,"nodeType":864},{},[],{"data":71379,"content":71380,"nodeType":883},{"uri":40635},[71381],{"data":71382,"marks":71383,"value":2715,"nodeType":864},{},[],{"data":71385,"marks":71386,"value":2924,"nodeType":864},{},[],{"entries":71388},{"inline":71389,"hyperlink":71390,"block":71451},[],[71391,71395,71399,71403,71407,71411,71413,71417,71419,71421,71425,71429,71433,71435,71439,71441,71443,71447],{"sys":71392,"__typename":2059,"title":71393,"slug":71394},{"id":67016},"Introducing our guide to phishing detection evasion techniques","phishing-detection-evasion-launch",{"sys":71396,"__typename":2059,"title":71397,"slug":71398},{"id":67045},"Analysing a malvertising attack targeting business Google accounts intercepted by Push","analysing-a-malvertising-attack-targeting-business-google-accounts",{"sys":71400,"__typename":2059,"title":71401,"slug":71402},{"id":67058},"How Push stopped a high risk LinkedIn spear-phishing attack against a company exec","how-push-stopped-a-high-risk-linkedin-spear-phishing-attack",{"sys":71404,"__typename":2059,"title":71405,"slug":71406},{"id":67086},"Analyzing the latest Sneaky2FA Browser-in-the-Browser phishing page","analyzing-the-latest-sneaky2fa-phishing-page",{"sys":71408,"__typename":2059,"title":71409,"slug":71410},{"id":67318},"Introducing Push Detections: Equipping SecOps and IR teams to stop browser-based attacks","introducing-push-detections",{"sys":71412,"__typename":64143,"title":64159,"slug":64160,"articleId":64161},{"id":52747},{"sys":71414,"__typename":2059,"title":71415,"slug":71416},{"id":67524},"6 breaches in 5 months: Why attackers are targeting Jira with stolen credentials","why-attackers-are-targeting-jira-with-stolen-credentials",{"sys":71418,"__typename":2059,"title":57965,"slug":57968},{"id":57022},{"sys":71420,"__typename":2059,"title":62888,"slug":62891},{"id":62097},{"sys":71422,"__typename":2059,"title":71423,"slug":71424},{"id":67605},"Eliminate false positives with verified stolen credential detections using Push","verified-stolen-credential-detection",{"sys":71426,"__typename":2059,"title":71427,"slug":71428},{"id":67651},"Introducing Push password enforcement — for when weak passwords are still plaguing you","introducing-strong-password-enforcement",{"sys":71430,"__typename":2059,"title":71431,"slug":71432},{"id":67679},"No more hard simple problems: Enforce MFA on third-party apps with Push","enforce-mfa-on-third-party-apps",{"sys":71434,"__typename":64143,"title":64164,"slug":64165,"articleId":64166},{"id":52935},{"sys":71436,"__typename":2059,"title":71437,"slug":71438},{"id":67767},"Don’t let attackers find the keys to your kingdom in a personal password manager","stop-users-saving-corp-creds-into-personal-password-managers",{"sys":71440,"__typename":2059,"title":52055,"slug":52058},{"id":50825},{"sys":71442,"__typename":64143,"title":64184,"slug":64185,"articleId":64186},{"id":53020},{"sys":71444,"__typename":2059,"title":71445,"slug":71446},{"id":67957},"Scattered Spider: TTP evolution in 2025","scattered-spider-ttp-evolution-in-2025",{"sys":71448,"__typename":2059,"title":71449,"slug":71450},{"id":68019},"A simple, browser-based way to protect your help desk against social engineering","employee-identity-verification-codes-release",[71452,71477,71481,71488,71495,71499,71506,71512,71519],{"sys":71453,"__typename":1740,"content":71454,"name":71476,"title":59},{"id":66954},{"json":71455},{"nodeType":856,"data":71456,"content":71457},{},[71458],{"nodeType":860,"data":71459,"content":71460},{},[71461,71465,71473],{"nodeType":864,"value":71462,"marks":71463,"data":71464},"Learn more about these attacks and the rise of the Scattered Lapsus$ Hunters supergroup in our ",[],{},{"nodeType":883,"data":71466,"content":71468},{"uri":71467},"/blog/scattered-lapsus-hunters/",[71469],{"nodeType":864,"value":71470,"marks":71471,"data":71472},"recent blog post",[],{},{"nodeType":864,"value":2924,"marks":71474,"data":71475},[],{},"Scattered Lapsus$ Hunters blog promo",{"sys":71478,"__typename":12999,"title":71479,"arcadeDemoUrl":71480,"playText":13002},{"id":67222},"Detect and respond to browser-based attacks","https://demo.arcade.software/FDPVuWkgezE91MicpCx7?embed",{"sys":71482,"__typename":1724,"title":71483,"caption":59,"layoutMode":59,"file":71484},{"id":65484},"Detection details slideout w/ timeline etc. - KB 10136",{"url":71485,"width":71486,"height":71487},"https://images.ctfassets.net/y1cdw1ablpvd/6qMAmnkXcJpsp19n7YANTV/b89b76929cc68387121c60ee3c48b0f2/detection_enrichment_example.png",977,758,{"sys":71489,"__typename":1724,"title":71490,"caption":59,"layoutMode":59,"file":71491},{"id":67412},"Clickfix detection block page",{"url":71492,"width":71493,"height":71494},"https://images.ctfassets.net/y1cdw1ablpvd/5QM8JNSvpRk1y7eoYw7CLw/ae9e6aa8b27c067f88cfb600c57c0a34/malicious_copypaste_block_example.png",2568,1604,{"sys":71496,"__typename":12999,"title":71497,"arcadeDemoUrl":71498,"playText":13002},{"id":67476},"ClickFix Feature Release","https://demo.arcade.software/qhzGMAx2q3b6IRlHqBsB?embed",{"sys":71500,"__typename":1724,"title":71501,"caption":59,"layoutMode":59,"file":71502},{"id":67700},"MFA enforcement banner - KB 10121",{"url":71503,"width":71504,"height":71505},"https://images.ctfassets.net/y1cdw1ablpvd/1H45Qj9vCfyQTCMxs8ypU5/6eeb494d24a904058d5635f290569889/Screenshot_2024-12-09_at_1.58.57_PM.png",1438,785,{"sys":71507,"__typename":1724,"title":71508,"caption":59,"layoutMode":59,"file":71509},{"id":67754},"Password protection block screen for end-users - KB 10109",{"url":71510,"width":64977,"height":71511},"https://images.ctfassets.net/y1cdw1ablpvd/5y1AiJEoLP6BveEJwDKhAL/ba22c55dced3ec2842093000ea050fa7/protected_pwd_block_screen_branded_20260420.png",1622,{"sys":71513,"__typename":1724,"title":71514,"caption":59,"layoutMode":59,"file":71515},{"id":65179},"Extension enumeration - KB 10138",{"url":71516,"width":71517,"height":71518},"https://images.ctfassets.net/y1cdw1ablpvd/1dByBmqYgpC9KhPkZoUbGN/0d65ee5ce5abceed6e8538319d83d761/extension_data_table_20251216.png",1480,826,{"sys":71520,"__typename":1724,"title":71521,"caption":59,"layoutMode":59,"file":71522},{"id":67992},"Employee verification codes - Labs - for June 2025 release notes",{"url":71523,"width":71524,"height":71525},"https://images.ctfassets.net/y1cdw1ablpvd/4es73ojyk572RJHuSrAahL/91be55af18fbcfb5f2fc3067497c9746/employee_verification_code_annotated.png",472,241,{"items":71527},[],{},"Push features we built in 2025 to stop browser-based attacks","product-feature",{"items":71532},[71533,72361,73221],{"__typename":2059,"sys":71534,"content":71535,"title":57965,"synopsis":57966,"hashTags":59,"publishedDate":57967,"slug":57968,"tagsCollection":72351,"authorsCollection":72357},{"id":57022},{"json":71536},{"data":71537,"content":71538,"nodeType":856},{},[71539,71545,71551,71557,71560,71567,71573,71579,71584,71590,71595,71611,71617,71627,71630,71637,71643,71656,71662,71672,71677,71680,71687,71694,71699,71707,71723,71731,71737,71745,71760,71768,71774,71782,71808,71816,71822,71830,71846,71851,71859,71865,71873,71906,71909,71916,71924,71940,71948,71954,71962,71988,71993,72001,72007,72012,72015,72022,72030,72036,72087,72092,72095,72102,72110,72116,72121,72124,72131,72137,72143,72203,72209,72264,72270,72273,72280,72286,72292,72297,72300,72307,72313,72319,72325],{"data":71540,"content":71541,"nodeType":860},{},[71542],{"data":71543,"marks":71544,"value":57033,"nodeType":864},{},[],{"data":71546,"content":71547,"nodeType":860},{},[71548],{"data":71549,"marks":71550,"value":57040,"nodeType":864},{},[],{"data":71552,"content":71553,"nodeType":860},{},[71554],{"data":71555,"marks":71556,"value":57047,"nodeType":864},{},[],{"data":71558,"content":71559,"nodeType":1005},{},[],{"data":71561,"content":71562,"nodeType":1009},{},[71563],{"data":71564,"marks":71565,"value":57058,"nodeType":864},{},[71566],{"type":899},{"data":71568,"content":71569,"nodeType":860},{},[71570],{"data":71571,"marks":71572,"value":57065,"nodeType":864},{},[],{"data":71574,"content":71575,"nodeType":860},{},[71576],{"data":71577,"marks":71578,"value":57072,"nodeType":864},{},[],{"data":71580,"content":71583,"nodeType":996},{"target":71581},{"sys":71582},{"id":57077,"type":1001,"linkType":1002},[],{"data":71585,"content":71586,"nodeType":860},{},[71587],{"data":71588,"marks":71589,"value":57085,"nodeType":864},{},[],{"data":71591,"content":71594,"nodeType":996},{"target":71592},{"sys":71593},{"id":57090,"type":1001,"linkType":1002},[],{"data":71596,"content":71597,"nodeType":860},{},[71598,71601,71608],{"data":71599,"marks":71600,"value":57098,"nodeType":864},{},[],{"data":71602,"content":71603,"nodeType":883},{"uri":16553},[71604],{"data":71605,"marks":71606,"value":57106,"nodeType":864},{},[71607],{"type":1455},{"data":71609,"marks":71610,"value":57110,"nodeType":864},{},[],{"data":71612,"content":71613,"nodeType":860},{},[71614],{"data":71615,"marks":71616,"value":57117,"nodeType":864},{},[],{"data":71618,"content":71619,"nodeType":860},{},[71620,71623],{"data":71621,"marks":71622,"value":57124,"nodeType":864},{},[],{"data":71624,"marks":71625,"value":57129,"nodeType":864},{},[71626],{"type":899},{"data":71628,"content":71629,"nodeType":1005},{},[],{"data":71631,"content":71632,"nodeType":1009},{},[71633],{"data":71634,"marks":71635,"value":57140,"nodeType":864},{},[71636],{"type":899},{"data":71638,"content":71639,"nodeType":860},{},[71640],{"data":71641,"marks":71642,"value":57147,"nodeType":864},{},[],{"data":71644,"content":71645,"nodeType":860},{},[71646,71649,71653],{"data":71647,"marks":71648,"value":57154,"nodeType":864},{},[],{"data":71650,"marks":71651,"value":57159,"nodeType":864},{},[71652],{"type":899},{"data":71654,"marks":71655,"value":57163,"nodeType":864},{},[],{"data":71657,"content":71658,"nodeType":860},{},[71659],{"data":71660,"marks":71661,"value":57170,"nodeType":864},{},[],{"data":71663,"content":71664,"nodeType":860},{},[71665,71668],{"data":71666,"marks":71667,"value":57177,"nodeType":864},{},[],{"data":71669,"marks":71670,"value":57182,"nodeType":864},{},[71671],{"type":899},{"data":71673,"content":71676,"nodeType":996},{"target":71674},{"sys":71675},{"id":57187,"type":1001,"linkType":1002},[],{"data":71678,"content":71679,"nodeType":1005},{},[],{"data":71681,"content":71682,"nodeType":1009},{},[71683],{"data":71684,"marks":71685,"value":57199,"nodeType":864},{},[71686],{"type":899},{"data":71688,"content":71689,"nodeType":1312},{},[71690],{"data":71691,"marks":71692,"value":57207,"nodeType":864},{},[71693],{"type":899},{"data":71695,"content":71698,"nodeType":996},{"target":71696},{"sys":71697},{"id":57212,"type":1001,"linkType":1002},[],{"data":71700,"content":71701,"nodeType":860},{},[71702],{"data":71703,"marks":71704,"value":57222,"nodeType":864},{},[71705,71706],{"type":899},{"type":1455},{"data":71708,"content":71709,"nodeType":860},{},[71710,71713,71720],{"data":71711,"marks":71712,"value":57229,"nodeType":864},{},[],{"data":71714,"content":71715,"nodeType":883},{"uri":57232},[71716],{"data":71717,"marks":71718,"value":57238,"nodeType":864},{},[71719],{"type":1455},{"data":71721,"marks":71722,"value":57242,"nodeType":864},{},[],{"data":71724,"content":71725,"nodeType":860},{},[71726],{"data":71727,"marks":71728,"value":57251,"nodeType":864},{},[71729,71730],{"type":899},{"type":1455},{"data":71732,"content":71733,"nodeType":860},{},[71734],{"data":71735,"marks":71736,"value":57258,"nodeType":864},{},[],{"data":71738,"content":71739,"nodeType":860},{},[71740],{"data":71741,"marks":71742,"value":57267,"nodeType":864},{},[71743,71744],{"type":899},{"type":1455},{"data":71746,"content":71747,"nodeType":860},{},[71748,71751,71757],{"data":71749,"marks":71750,"value":57274,"nodeType":864},{},[],{"data":71752,"content":71753,"nodeType":883},{"uri":57277},[71754],{"data":71755,"marks":71756,"value":57282,"nodeType":864},{},[],{"data":71758,"marks":71759,"value":57286,"nodeType":864},{},[],{"data":71761,"content":71762,"nodeType":860},{},[71763],{"data":71764,"marks":71765,"value":57295,"nodeType":864},{},[71766,71767],{"type":899},{"type":1455},{"data":71769,"content":71770,"nodeType":860},{},[71771],{"data":71772,"marks":71773,"value":57302,"nodeType":864},{},[],{"data":71775,"content":71776,"nodeType":860},{},[71777],{"data":71778,"marks":71779,"value":57311,"nodeType":864},{},[71780,71781],{"type":899},{"type":1455},{"data":71783,"content":71784,"nodeType":860},{},[71785,71788,71795,71798,71805],{"data":71786,"marks":71787,"value":57318,"nodeType":864},{},[],{"data":71789,"content":71790,"nodeType":883},{"uri":3751},[71791],{"data":71792,"marks":71793,"value":57326,"nodeType":864},{},[71794],{"type":1455},{"data":71796,"marks":71797,"value":57330,"nodeType":864},{},[],{"data":71799,"content":71800,"nodeType":883},{"uri":57333},[71801],{"data":71802,"marks":71803,"value":29819,"nodeType":864},{},[71804],{"type":1455},{"data":71806,"marks":71807,"value":57342,"nodeType":864},{},[],{"data":71809,"content":71810,"nodeType":860},{},[71811],{"data":71812,"marks":71813,"value":57351,"nodeType":864},{},[71814,71815],{"type":899},{"type":1455},{"data":71817,"content":71818,"nodeType":860},{},[71819],{"data":71820,"marks":71821,"value":57358,"nodeType":864},{},[],{"data":71823,"content":71824,"nodeType":860},{},[71825],{"data":71826,"marks":71827,"value":57367,"nodeType":864},{},[71828,71829],{"type":899},{"type":1455},{"data":71831,"content":71832,"nodeType":860},{},[71833,71836,71843],{"data":71834,"marks":71835,"value":57374,"nodeType":864},{},[],{"data":71837,"content":71838,"nodeType":883},{"uri":57333},[71839],{"data":71840,"marks":71841,"value":29819,"nodeType":864},{},[71842],{"type":1455},{"data":71844,"marks":71845,"value":57385,"nodeType":864},{},[],{"data":71847,"content":71850,"nodeType":996},{"target":71848},{"sys":71849},{"id":57390,"type":1001,"linkType":1002},[],{"data":71852,"content":71853,"nodeType":860},{},[71854],{"data":71855,"marks":71856,"value":57400,"nodeType":864},{},[71857,71858],{"type":899},{"type":1455},{"data":71860,"content":71861,"nodeType":860},{},[71862],{"data":71863,"marks":71864,"value":57407,"nodeType":864},{},[],{"data":71866,"content":71867,"nodeType":860},{},[71868],{"data":71869,"marks":71870,"value":57416,"nodeType":864},{},[71871,71872],{"type":899},{"type":1455},{"data":71874,"content":71875,"nodeType":860},{},[71876,71879,71885,71888,71894,71897,71903],{"data":71877,"marks":71878,"value":57423,"nodeType":864},{},[],{"data":71880,"content":71881,"nodeType":883},{"uri":57426},[71882],{"data":71883,"marks":71884,"value":57431,"nodeType":864},{},[],{"data":71886,"marks":71887,"value":902,"nodeType":864},{},[],{"data":71889,"content":71890,"nodeType":883},{"uri":57437},[71891],{"data":71892,"marks":71893,"value":57442,"nodeType":864},{},[],{"data":71895,"marks":71896,"value":57446,"nodeType":864},{},[],{"data":71898,"content":71899,"nodeType":883},{"uri":23901},[71900],{"data":71901,"marks":71902,"value":57453,"nodeType":864},{},[],{"data":71904,"marks":71905,"value":57457,"nodeType":864},{},[],{"data":71907,"content":71908,"nodeType":1005},{},[],{"data":71910,"content":71911,"nodeType":1312},{},[71912],{"data":71913,"marks":71914,"value":57468,"nodeType":864},{},[71915],{"type":899},{"data":71917,"content":71918,"nodeType":860},{},[71919],{"data":71920,"marks":71921,"value":57477,"nodeType":864},{},[71922,71923],{"type":899},{"type":1455},{"data":71925,"content":71926,"nodeType":860},{},[71927,71930,71937],{"data":71928,"marks":71929,"value":57484,"nodeType":864},{},[],{"data":71931,"content":71932,"nodeType":883},{"uri":57487},[71933],{"data":71934,"marks":71935,"value":57493,"nodeType":864},{},[71936],{"type":1455},{"data":71938,"marks":71939,"value":57497,"nodeType":864},{},[],{"data":71941,"content":71942,"nodeType":860},{},[71943],{"data":71944,"marks":71945,"value":57506,"nodeType":864},{},[71946,71947],{"type":899},{"type":1455},{"data":71949,"content":71950,"nodeType":860},{},[71951],{"data":71952,"marks":71953,"value":57513,"nodeType":864},{},[],{"data":71955,"content":71956,"nodeType":860},{},[71957],{"data":71958,"marks":71959,"value":57522,"nodeType":864},{},[71960,71961],{"type":899},{"type":1455},{"data":71963,"content":71964,"nodeType":860},{},[71965,71968,71975,71978,71985],{"data":71966,"marks":71967,"value":57529,"nodeType":864},{},[],{"data":71969,"content":71970,"nodeType":883},{"uri":57532},[71971],{"data":71972,"marks":71973,"value":57538,"nodeType":864},{},[71974],{"type":1455},{"data":71976,"marks":71977,"value":57542,"nodeType":864},{},[],{"data":71979,"content":71980,"nodeType":883},{"uri":57545},[71981],{"data":71982,"marks":71983,"value":57551,"nodeType":864},{},[71984],{"type":1455},{"data":71986,"marks":71987,"value":57555,"nodeType":864},{},[],{"data":71989,"content":71992,"nodeType":996},{"target":71990},{"sys":71991},{"id":57560,"type":1001,"linkType":1002},[],{"data":71994,"content":71995,"nodeType":860},{},[71996],{"data":71997,"marks":71998,"value":57570,"nodeType":864},{},[71999,72000],{"type":899},{"type":1455},{"data":72002,"content":72003,"nodeType":860},{},[72004],{"data":72005,"marks":72006,"value":57577,"nodeType":864},{},[],{"data":72008,"content":72011,"nodeType":996},{"target":72009},{"sys":72010},{"id":57582,"type":1001,"linkType":1002},[],{"data":72013,"content":72014,"nodeType":1005},{},[],{"data":72016,"content":72017,"nodeType":1312},{},[72018],{"data":72019,"marks":72020,"value":694,"nodeType":864},{},[72021],{"type":899},{"data":72023,"content":72024,"nodeType":860},{},[72025],{"data":72026,"marks":72027,"value":57602,"nodeType":864},{},[72028,72029],{"type":899},{"type":1455},{"data":72031,"content":72032,"nodeType":860},{},[72033],{"data":72034,"marks":72035,"value":57609,"nodeType":864},{},[],{"data":72037,"content":72038,"nodeType":941},{},[72039,72052,72065],{"data":72040,"content":72041,"nodeType":945},{},[72042],{"data":72043,"content":72044,"nodeType":860},{},[72045,72049],{"data":72046,"marks":72047,"value":57623,"nodeType":864},{},[72048],{"type":899},{"data":72050,"marks":72051,"value":57627,"nodeType":864},{},[],{"data":72053,"content":72054,"nodeType":945},{},[72055],{"data":72056,"content":72057,"nodeType":860},{},[72058,72062],{"data":72059,"marks":72060,"value":57638,"nodeType":864},{},[72061],{"type":899},{"data":72063,"marks":72064,"value":57642,"nodeType":864},{},[],{"data":72066,"content":72067,"nodeType":945},{},[72068],{"data":72069,"content":72070,"nodeType":860},{},[72071,72075,72078,72084],{"data":72072,"marks":72073,"value":57653,"nodeType":864},{},[72074],{"type":899},{"data":72076,"marks":72077,"value":57657,"nodeType":864},{},[],{"data":72079,"content":72080,"nodeType":883},{"uri":16566},[72081],{"data":72082,"marks":72083,"value":57664,"nodeType":864},{},[],{"data":72085,"marks":72086,"value":57668,"nodeType":864},{},[],{"data":72088,"content":72091,"nodeType":996},{"target":72089},{"sys":72090},{"id":57673,"type":1001,"linkType":1002},[],{"data":72093,"content":72094,"nodeType":1005},{},[],{"data":72096,"content":72097,"nodeType":1312},{},[72098],{"data":72099,"marks":72100,"value":699,"nodeType":864},{},[72101],{"type":899},{"data":72103,"content":72104,"nodeType":860},{},[72105],{"data":72106,"marks":72107,"value":57693,"nodeType":864},{},[72108,72109],{"type":899},{"type":1455},{"data":72111,"content":72112,"nodeType":860},{},[72113],{"data":72114,"marks":72115,"value":57700,"nodeType":864},{},[],{"data":72117,"content":72120,"nodeType":996},{"target":72118},{"sys":72119},{"id":57705,"type":1001,"linkType":1002},[],{"data":72122,"content":72123,"nodeType":1005},{},[],{"data":72125,"content":72126,"nodeType":1009},{},[72127],{"data":72128,"marks":72129,"value":57717,"nodeType":864},{},[72130],{"type":899},{"data":72132,"content":72133,"nodeType":860},{},[72134],{"data":72135,"marks":72136,"value":57724,"nodeType":864},{},[],{"data":72138,"content":72139,"nodeType":860},{},[72140],{"data":72141,"marks":72142,"value":57731,"nodeType":864},{},[],{"data":72144,"content":72145,"nodeType":941},{},[72146,72165,72184],{"data":72147,"content":72148,"nodeType":945},{},[72149],{"data":72150,"content":72151,"nodeType":860},{},[72152,72155,72162],{"data":72153,"marks":72154,"value":57744,"nodeType":864},{},[],{"data":72156,"content":72157,"nodeType":883},{"uri":57747},[72158],{"data":72159,"marks":72160,"value":19538,"nodeType":864},{},[72161],{"type":1455},{"data":72163,"marks":72164,"value":57756,"nodeType":864},{},[],{"data":72166,"content":72167,"nodeType":945},{},[72168],{"data":72169,"content":72170,"nodeType":860},{},[72171,72174,72181],{"data":72172,"marks":72173,"value":57766,"nodeType":864},{},[],{"data":72175,"content":72176,"nodeType":883},{"uri":57769},[72177],{"data":72178,"marks":72179,"value":57775,"nodeType":864},{},[72180],{"type":1455},{"data":72182,"marks":72183,"value":57756,"nodeType":864},{},[],{"data":72185,"content":72186,"nodeType":945},{},[72187],{"data":72188,"content":72189,"nodeType":860},{},[72190,72193,72200],{"data":72191,"marks":72192,"value":57788,"nodeType":864},{},[],{"data":72194,"content":72195,"nodeType":883},{"uri":7170},[72196],{"data":72197,"marks":72198,"value":57796,"nodeType":864},{},[72199],{"type":1455},{"data":72201,"marks":72202,"value":57756,"nodeType":864},{},[],{"data":72204,"content":72205,"nodeType":860},{},[72206],{"data":72207,"marks":72208,"value":57806,"nodeType":864},{},[],{"data":72210,"content":72211,"nodeType":941},{},[72212,72225,72238,72251],{"data":72213,"content":72214,"nodeType":945},{},[72215],{"data":72216,"content":72217,"nodeType":860},{},[72218,72222],{"data":72219,"marks":72220,"value":57820,"nodeType":864},{},[72221],{"type":899},{"data":72223,"marks":72224,"value":57824,"nodeType":864},{},[],{"data":72226,"content":72227,"nodeType":945},{},[72228],{"data":72229,"content":72230,"nodeType":860},{},[72231,72235],{"data":72232,"marks":72233,"value":57835,"nodeType":864},{},[72234],{"type":899},{"data":72236,"marks":72237,"value":57839,"nodeType":864},{},[],{"data":72239,"content":72240,"nodeType":945},{},[72241],{"data":72242,"content":72243,"nodeType":860},{},[72244,72248],{"data":72245,"marks":72246,"value":57850,"nodeType":864},{},[72247],{"type":899},{"data":72249,"marks":72250,"value":57854,"nodeType":864},{},[],{"data":72252,"content":72253,"nodeType":945},{},[72254],{"data":72255,"content":72256,"nodeType":860},{},[72257,72261],{"data":72258,"marks":72259,"value":57865,"nodeType":864},{},[72260],{"type":899},{"data":72262,"marks":72263,"value":57869,"nodeType":864},{},[],{"data":72265,"content":72266,"nodeType":860},{},[72267],{"data":72268,"marks":72269,"value":57876,"nodeType":864},{},[],{"data":72271,"content":72272,"nodeType":1005},{},[],{"data":72274,"content":72275,"nodeType":1009},{},[72276],{"data":72277,"marks":72278,"value":57887,"nodeType":864},{},[72279],{"type":899},{"data":72281,"content":72282,"nodeType":860},{},[72283],{"data":72284,"marks":72285,"value":57894,"nodeType":864},{},[],{"data":72287,"content":72288,"nodeType":860},{},[72289],{"data":72290,"marks":72291,"value":57901,"nodeType":864},{},[],{"data":72293,"content":72296,"nodeType":996},{"target":72294},{"sys":72295},{"id":57906,"type":1001,"linkType":1002},[],{"data":72298,"content":72299,"nodeType":1005},{},[],{"data":72301,"content":72302,"nodeType":1009},{},[72303],{"data":72304,"marks":72305,"value":7533,"nodeType":864},{},[72306],{"type":899},{"data":72308,"content":72309,"nodeType":860},{},[72310],{"data":72311,"marks":72312,"value":57924,"nodeType":864},{},[],{"data":72314,"content":72315,"nodeType":860},{},[72316],{"data":72317,"marks":72318,"value":57931,"nodeType":864},{},[],{"data":72320,"content":72321,"nodeType":860},{},[72322],{"data":72323,"marks":72324,"value":57938,"nodeType":864},{},[],{"data":72326,"content":72327,"nodeType":860},{},[72328,72331,72338,72341,72348],{"data":72329,"marks":72330,"value":16863,"nodeType":864},{},[],{"data":72332,"content":72333,"nodeType":883},{"uri":16866},[72334],{"data":72335,"marks":72336,"value":16871,"nodeType":864},{},[72337],{"type":1455},{"data":72339,"marks":72340,"value":52968,"nodeType":864},{},[],{"data":72342,"content":72343,"nodeType":883},{"uri":1700},[72344],{"data":72345,"marks":72346,"value":16894,"nodeType":864},{},[72347],{"type":1455},{"data":72349,"marks":72350,"value":2924,"nodeType":864},{},[],{"items":72352},[72353,72355],{"sys":72354,"name":13779},{"id":13778},{"sys":72356,"name":342},{"id":13775},{"items":72358},[72359],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":72360},{"url":2740},{"__typename":2059,"sys":72362,"content":72363,"title":73207,"synopsis":73208,"hashTags":59,"publishedDate":73209,"slug":73210,"tagsCollection":73211,"authorsCollection":73217},{"id":39932},{"json":72364},{"data":72365,"content":72366,"nodeType":856},{},[72367,72375,72382,72389,72396,72408,72415,72421,72427,72430,72438,72445,72452,72458,72478,72485,72491,72498,72504,72511,72554,72560,72566,72573,72580,72583,72591,72611,72618,72624,72642,72648,72667,72674,72677,72685,72692,72736,72748,72751,72759,72776,72783,72799,72806,72813,72819,72826,72829,72837,72844,72897,72904,72907,72915,72921,72928,72935,72941,72948,72981,72988,72995,73001,73008,73014,73022,73039,73046,73079,73086,73119,73122,73130,73137,73143,73162,73169,73195,73201],{"data":72368,"content":72369,"nodeType":1009},{},[72370],{"data":72371,"marks":72372,"value":72374,"nodeType":864},{},[72373],{"type":899},"Introducing “ConsentFix” — a new kind of phishing attack",{"data":72376,"content":72377,"nodeType":860},{},[72378],{"data":72379,"marks":72380,"value":72381,"nodeType":864},{},[],"The Push browser agent recently detected and blocked a new attack technique seen targeting several Push customers. ",{"data":72383,"content":72384,"nodeType":860},{},[72385],{"data":72386,"marks":72387,"value":72388,"nodeType":864},{},[],"This is a new kind of browser-based attack technique that takes over user accounts with a simple copy and paste. If you’re already logged into the app in your browser, you don’t even need to supply creds, or pass an MFA check — meaning it effectively circumvents phishing-resistant auth like passkeys too.",{"data":72390,"content":72391,"nodeType":860},{},[72392],{"data":72393,"marks":72394,"value":72395,"nodeType":864},{},[],"This is so different from the AiTM phish kits we usually come up against that we felt it deserved a new name. ",{"data":72397,"content":72398,"nodeType":860},{},[72399,72404],{"data":72400,"marks":72401,"value":72403,"nodeType":864},{},[72402],{"type":899},"Enter: ConsentFix. ",{"data":72405,"marks":72406,"value":72407,"nodeType":864},{},[],"This attack shares a lot of similarities with ClickFix/FileFix, AiTM phishing, and OAuth Consent Phishing. You can think of this as a browser-native ClickFix attack that phishes an OAuth token on a target app by getting the victim to copy and paste a URL containing OAuth key material into a phishing page. ",{"data":72409,"content":72410,"nodeType":860},{},[72411],{"data":72412,"marks":72413,"value":72414,"nodeType":864},{},[],"The campaign we detected looks to be specifically targeting Microsoft accounts by abusing the Azure CLI OAuth app. Essentially, the attacker tricks the victim into logging into Azure CLI, by generating an OAuth authorization code — visible in a localhost URL — and then pasting that URL (including the code) into an attacker-controlled page. This then creates an OAuth connection between the victim’s Microsoft account and the attacker’s Azure CLI instance. ",{"data":72416,"content":72420,"nodeType":996},{"target":72417},{"sys":72418},{"id":72419,"type":1001,"linkType":1002},"5GTnqWIbmraz8HZeHMybrP",[],{"data":72422,"content":72426,"nodeType":996},{"target":72423},{"sys":72424},{"id":72425,"type":1001,"linkType":1002},"1lcjX5q3b1bsuhyOXKvJpW",[],{"data":72428,"content":72429,"nodeType":1005},{},[],{"data":72431,"content":72432,"nodeType":1009},{},[72433],{"data":72434,"marks":72435,"value":72437,"nodeType":864},{},[72436],{"type":899},"How ConsentFix works",{"data":72439,"content":72440,"nodeType":860},{},[72441],{"data":72442,"marks":72443,"value":72444,"nodeType":864},{},[],"In all of the examples we saw, the victim accessed a malicious or compromised webpage via Google Search. The vast majority of the sites we’ve seen associated with the campaign are legitimate, compromised websites with high domain reputation that are easily findable via search engines.",{"data":72446,"content":72447,"nodeType":860},{},[72448],{"data":72449,"marks":72450,"value":72451,"nodeType":864},{},[],"The attacker had injected a fake Cloudflare Turnstile into the compromised websites, requiring an email address to be supplied in order to proceed. ",{"data":72453,"content":72457,"nodeType":996},{"target":72454},{"sys":72455},{"id":72456,"type":1001,"linkType":1002},"39jEjeLqOYIkGc4o9w3MuX",[],{"data":72459,"content":72460,"nodeType":860},{},[72461,72465,72474],{"data":72462,"marks":72463,"value":72464,"nodeType":864},{},[],"This acted as a form of ",{"data":72466,"content":72468,"nodeType":883},{"uri":72467},"https://phishing-techniques.pushsecurity.com/techniques/conditional-loading/",[72469],{"data":72470,"marks":72471,"value":72473,"nodeType":864},{},[72472],{"type":1455},"conditional loading",{"data":72475,"marks":72476,"value":72477,"nodeType":864},{},[]," that would only continue if a valid email address and domain was supplied, designed to prevent the page from being analyzed by security bots, analysts, and low-value accounts that run the risk of exposing the campaign before the intended recipient(s) can be phished. ",{"data":72479,"content":72480,"nodeType":860},{},[72481],{"data":72482,"marks":72483,"value":72484,"nodeType":864},{},[],"If a domain not on the target list was provided, the victim was passed back to the original website and the attack did not progress to the next stage. Further, once the check has concluded per IP, the phishing page will no longer activate, even a different email is provided.  ",{"data":72486,"content":72490,"nodeType":996},{"target":72487},{"sys":72488},{"id":72489,"type":1001,"linkType":1002},"7ttmGnTzi9j87tBXfyFcOA",[],{"data":72492,"content":72493,"nodeType":860},{},[72494],{"data":72495,"marks":72496,"value":72497,"nodeType":864},{},[],"After entering an approved email address, the next stage was loaded, prompting the victim to complete a set of instructions on the page to continue.",{"data":72499,"content":72503,"nodeType":996},{"target":72500},{"sys":72501},{"id":72502,"type":1001,"linkType":1002},"2oHYNoMgAz6MdgLlcWjbaB",[],{"data":72505,"content":72506,"nodeType":860},{},[72507],{"data":72508,"marks":72509,"value":72510,"nodeType":864},{},[],"To complete the attack, the victim must:",{"data":72512,"content":72513,"nodeType":941},{},[72514,72524,72534,72544],{"data":72515,"content":72516,"nodeType":945},{},[72517],{"data":72518,"content":72519,"nodeType":860},{},[72520],{"data":72521,"marks":72522,"value":72523,"nodeType":864},{},[],"Click the “Sign In” button. This opens a new tab that loads a legitimate Microsoft URL associated with the user account/email used to access the page.",{"data":72525,"content":72526,"nodeType":945},{},[72527],{"data":72528,"content":72529,"nodeType":860},{},[72530],{"data":72531,"marks":72532,"value":72533,"nodeType":864},{},[],"If the user is already logged into Microsoft in their browser, they simply need to select their MS account from the dropdown. Otherwise, they will be required to login via the legitimate Microsoft login URL (no phishing takes place at this stage). ",{"data":72535,"content":72536,"nodeType":945},{},[72537],{"data":72538,"content":72539,"nodeType":860},{},[72540],{"data":72541,"marks":72542,"value":72543,"nodeType":864},{},[],"Once logged into legit Microsoft or the account is selected from the dropdown, the user is redirected to localhost, which generates a URL containing a code associated with the user’s Microsoft account. ",{"data":72545,"content":72546,"nodeType":945},{},[72547],{"data":72548,"content":72549,"nodeType":860},{},[72550],{"data":72551,"marks":72552,"value":72553,"nodeType":864},{},[],"To complete the phish, the victim copies the URL and pastes it onto the original page. ",{"data":72555,"content":72559,"nodeType":996},{"target":72556},{"sys":72557},{"id":72558,"type":1001,"linkType":1002},"7zendMbmCViGwtEpUQvq6y",[],{"data":72561,"content":72565,"nodeType":996},{"target":72562},{"sys":72563},{"id":72564,"type":1001,"linkType":1002},"1eZOs7hXi9FzCE92QEP6xh",[],{"data":72567,"content":72568,"nodeType":860},{},[72569],{"data":72570,"marks":72571,"value":72572,"nodeType":864},{},[],"Once the steps are completed, the victim has granted the attacker access to their Microsoft account via Azure CLI. ",{"data":72574,"content":72575,"nodeType":860},{},[72576],{"data":72577,"marks":72578,"value":72579,"nodeType":864},{},[],"At this point, the attacker has effective control of the victim’s Microsoft account, but without ever needing to phish a password, or pass an MFA check. In fact, if the user was already logged in to their Microsoft account (i.e. they had an active session) no login is required at all. ",{"data":72581,"content":72582,"nodeType":1005},{},[],{"data":72584,"content":72585,"nodeType":1009},{},[72586],{"data":72587,"marks":72588,"value":72590,"nodeType":864},{},[72589],{"type":899},"The next evolution of ClickFix?",{"data":72592,"content":72593,"nodeType":860},{},[72594,72598,72607],{"data":72595,"marks":72596,"value":72597,"nodeType":864},{},[],"When we presented ",{"data":72599,"content":72601,"nodeType":883},{"uri":72600},"https://pushsecurity.com/webinar/clickfix",[72602],{"data":72603,"marks":72604,"value":72606,"nodeType":864},{},[72605],{"type":1455},"our last webinar on ClickFix",{"data":72608,"marks":72609,"value":72610,"nodeType":864},{},[],", we predicted that the next evolution of the attack would happen entirely within the browser context. This is because any attack that touches the endpoint (a traditionally much better protected surface) is way more likely to be detected. And with many ClickFix attacks being used to deliver infostealer malware, these attacks are really trying to get back into the browser anyway — to steal credentials and sessions stored there. ",{"data":72612,"content":72613,"nodeType":860},{},[72614],{"data":72615,"marks":72616,"value":72617,"nodeType":864},{},[],"Let’s take a closer look at the page — if you follow Push research, you might be getting déjà vu. ",{"data":72619,"content":72623,"nodeType":996},{"target":72620},{"sys":72621},{"id":72622,"type":1001,"linkType":1002},"1vMZCJ92IxFdR1EzzCOOvb",[],{"data":72625,"content":72626,"nodeType":860},{},[72627,72631,72639],{"data":72628,"marks":72629,"value":72630,"nodeType":864},{},[],"We’ve seen this kind of embedded video player before (albeit a slicker looking one) that we blogged about as ",{"data":72632,"content":72633,"nodeType":883},{"uri":52377},[72634],{"data":72635,"marks":72636,"value":72638,"nodeType":864},{},[72637],{"type":1455},"the most advanced ClickFix we’d seen",{"data":72640,"marks":72641,"value":2924,"nodeType":864},{},[],{"data":72643,"content":72647,"nodeType":996},{"target":72644},{"sys":72645},{"id":72646,"type":1001,"linkType":1002},"ID7VKJNOZk729P5zBOBjZ",[],{"data":72649,"content":72650,"nodeType":860},{},[72651,72655,72663],{"data":72652,"marks":72653,"value":72654,"nodeType":864},{},[],"Another similarity with ClickFix campaigns we’ve investigated is the use of Google Search as a delivery vector. 4 in 5 ClickFix attacks intercepted by Push came via Google Search, with attackers using ",{"data":72656,"content":72658,"nodeType":883},{"uri":72657},"https://phishing-techniques.pushsecurity.com/techniques/malvertising/",[72659],{"data":72660,"marks":72661,"value":441,"nodeType":864},{},[72662],{"type":1455},{"data":72664,"marks":72665,"value":72666,"nodeType":864},{},[]," and either compromised or custom vibe-coded websites to intercept users as they browse the internet. ",{"data":72668,"content":72669,"nodeType":860},{},[72670],{"data":72671,"marks":72672,"value":72673,"nodeType":864},{},[],"So it seems highly likely that this is a kind of browser-native evolution of ClickFix that shares many elements with typical ClickFix attacks, and is probably used by the same groups of attackers.",{"data":72675,"content":72676,"nodeType":1005},{},[],{"data":72678,"content":72679,"nodeType":1009},{},[72680],{"data":72681,"marks":72682,"value":72684,"nodeType":864},{},[72683],{"type":899},"OAuth shenanigans via Azure CLI",{"data":72686,"content":72687,"nodeType":860},{},[72688],{"data":72689,"marks":72690,"value":72691,"nodeType":864},{},[],"The clever use of Azure CLI and OAuth consent abuse is another clever iteration on previous techniques. ",{"data":72693,"content":72694,"nodeType":860},{},[72695,72699,72708,72711,72719,72723,72732],{"data":72696,"marks":72697,"value":72698,"nodeType":864},{},[],"We’ve previously seen ",{"data":72700,"content":72702,"nodeType":883},{"uri":72701},"https://phishing-techniques.pushsecurity.com/techniques/consent-phishing/",[72703],{"data":72704,"marks":72705,"value":72707,"nodeType":864},{},[72706],{"type":1455},"consent phishing",{"data":72709,"marks":72710,"value":902,"nodeType":864},{},[],{"data":72712,"content":72714,"nodeType":883},{"uri":72713},"https://phishing-techniques.pushsecurity.com/techniques/device-code-phishing/",[72715],{"data":72716,"marks":72717,"value":18962,"nodeType":864},{},[72718],{"type":1455},{"data":72720,"marks":72721,"value":72722,"nodeType":864},{},[]," attacks where attackers have tricked victims into connecting malicious external apps into their tenant via OAuth, but this is becoming increasingly difficult in core enterprise cloud environments like Azure due to ",{"data":72724,"content":72726,"nodeType":883},{"uri":72725},"https://learn.microsoft.com/en-us/microsoft-365/admin/misc/user-consent?view=o365-worldwide",[72727],{"data":72728,"marks":72729,"value":72731,"nodeType":864},{},[72730],{"type":1455},"stricter default configs",{"data":72733,"marks":72734,"value":72735,"nodeType":864},{},[],". However, since Azure CLI is a first-party Microsoft app, it is implicitly trusted in Entra ID, and is excluded from these restrictions. ",{"data":72737,"content":72738,"nodeType":860},{},[72739,72743],{"data":72740,"marks":72741,"value":72742,"nodeType":864},{},[],"First-party apps like Azure CLI are trusted by default in all tenants, allowed to request permissions without admin approval, and cannot be deleted or blocked. They can also be granted special permissions, such as tenant-wide service permissions (without needing admin approval), use of legacy or undocumented graph scopes, internal scopes for Microsoft client operations, and permissions for Office/Entra admin functions. ",{"data":72744,"marks":72745,"value":72747,"nodeType":864},{},[72746],{"type":899},"This makes Azure CLI a prime target for attackers, and significantly more exploitable than when connecting a third-party app. ",{"data":72749,"content":72750,"nodeType":1005},{},[],{"data":72752,"content":72753,"nodeType":1009},{},[72754],{"data":72755,"marks":72756,"value":72758,"nodeType":864},{},[72757],{"type":899},"Advanced detection evasion techniques",{"data":72760,"content":72761,"nodeType":860},{},[72762,72766,72772],{"data":72763,"marks":72764,"value":72765,"nodeType":864},{},[],"This campaign features some of the most advanced ",{"data":72767,"content":72768,"nodeType":883},{"uri":14307},[72769],{"data":72770,"marks":72771,"value":19763,"nodeType":864},{},[],{"data":72773,"marks":72774,"value":72775,"nodeType":864},{},[]," we've seen in the wild. ",{"data":72777,"content":72778,"nodeType":860},{},[72779],{"data":72780,"marks":72781,"value":72782,"nodeType":864},{},[],"As well as the use of Google Search to deliver the lure, and bot protection to prevent security tools from analyzing the page, there were multiple layers of anti-analysis techniques to navigate.",{"data":72784,"content":72785,"nodeType":860},{},[72786,72790,72795],{"data":72787,"marks":72788,"value":72789,"nodeType":864},{},[],"We already mentioned the use of selective targeting based on email addresses and domain names. But all sites involved in the campaign also have synchronized IP blocking — meaning if you visit one site and are served one of the associated phishing pages, the phish will never be served again, ",{"data":72791,"marks":72792,"value":72794,"nodeType":864},{},[72793],{"type":899},"across any of the sites linked to the campaign",{"data":72796,"marks":72797,"value":72798,"nodeType":864},{},[],". When you visit any of the sites again, the phish won't trigger, and it can be browsed as normal. ",{"data":72800,"content":72801,"nodeType":860},{},[72802],{"data":72803,"marks":72804,"value":72805,"nodeType":864},{},[],"On the backend, there are multiple checks based on your IP and identifiers unique to your session. Unless all of the conditions are met, certain JavaScript packages won't be served — preventing full inspection of the page to detect malicious elements. ",{"data":72807,"content":72808,"nodeType":860},{},[72809],{"data":72810,"marks":72811,"value":72812,"nodeType":864},{},[],"If the conditions aren't met, the page may not load the Cloudflare Turnstile check at all, or will redirect you back to the site to continue browsing as normal.",{"data":72814,"content":72818,"nodeType":996},{"target":72815},{"sys":72816},{"id":72817,"type":1001,"linkType":1002},"5v0zDoscA6pYLBfkXrNtIH",[],{"data":72820,"content":72821,"nodeType":860},{},[72822],{"data":72823,"marks":72824,"value":72825,"nodeType":864},{},[],"All of these make it incredibly hard to detect and block these attacks ahead of time when relying on URL-based checks and traffic analysis.",{"data":72827,"content":72828,"nodeType":1005},{},[],{"data":72830,"content":72831,"nodeType":1009},{},[72832],{"data":72833,"marks":72834,"value":72836,"nodeType":864},{},[72835],{"type":899},"Key takeaways",{"data":72838,"content":72839,"nodeType":860},{},[72840],{"data":72841,"marks":72842,"value":72843,"nodeType":864},{},[],"ConsentFix is a dangerous evolution of ClickFix and consent phishing that is incredibly hard for traditional security tools to detect and block, as:",{"data":72845,"content":72846,"nodeType":941},{},[72847,72857,72867,72877,72887],{"data":72848,"content":72849,"nodeType":945},{},[72850],{"data":72851,"content":72852,"nodeType":860},{},[72853],{"data":72854,"marks":72855,"value":72856,"nodeType":864},{},[],"The attack happens entirely inside the browser context, removing one of the key detection opportunities for ClickFix (because it doesn’t touch the endpoint).",{"data":72858,"content":72859,"nodeType":945},{},[72860],{"data":72861,"content":72862,"nodeType":860},{},[72863],{"data":72864,"marks":72865,"value":72866,"nodeType":864},{},[],"Delivering the lure via a Google Search watering hole attack completely circumvents email-based anti-phishing controls.",{"data":72868,"content":72869,"nodeType":945},{},[72870],{"data":72871,"content":72872,"nodeType":860},{},[72873],{"data":72874,"marks":72875,"value":72876,"nodeType":864},{},[],"Targeting a first-party app like Azure CLI means that many of the mitigating controls available for third-party app integrations do not apply — making this attack way harder to prevent.",{"data":72878,"content":72879,"nodeType":945},{},[72880],{"data":72881,"content":72882,"nodeType":860},{},[72883],{"data":72884,"marks":72885,"value":72886,"nodeType":864},{},[],"Because there’s no login required, phishing-resistant authentication controls like passkeys have no impact on this attack. ",{"data":72888,"content":72889,"nodeType":945},{},[72890],{"data":72891,"content":72892,"nodeType":860},{},[72893],{"data":72894,"marks":72895,"value":72896,"nodeType":864},{},[],"The use of advanced detection evasion techniques makes this attack difficult to investigate, meaning these attacks are going undetected. ",{"data":72898,"content":72899,"nodeType":860},{},[72900],{"data":72901,"marks":72902,"value":72903,"nodeType":864},{},[],"We’re sure to see more examples of ConsentFix in future. We’ll be monitoring to see how attackers adapt in terms of integrating these capabilities with common as-a-Service offerings to make them more widespread, and whether the scope extends further beyond Microsoft / Azure CLI targets in the future to target other enterprise cloud ecosystems. ",{"data":72905,"content":72906,"nodeType":1005},{},[],{"data":72908,"content":72909,"nodeType":1009},{},[72910],{"data":72911,"marks":72912,"value":72914,"nodeType":864},{},[72913],{"type":899},"Recommendations",{"data":72916,"content":72920,"nodeType":996},{"target":72917},{"sys":72918},{"id":72919,"type":1001,"linkType":1002},"3aBCwdB2aNnLRxRN5RrshC",[],{"data":72922,"content":72923,"nodeType":860},{},[72924],{"data":72925,"marks":72926,"value":72927,"nodeType":864},{},[],"On the backend, exploitation of this attack will lead to login events being observed to the Microsoft Azure CLI app. It’s likely that any legitimate use of this will most likely be limited to system administrators and possibly developers. Therefore, logins outside of these groups will be inherently more suspicious.",{"data":72929,"content":72930,"nodeType":860},{},[72931],{"data":72932,"marks":72933,"value":72934,"nodeType":864},{},[],"Additionally, it’s possible that aspects of the logins themselves will be different between legitimate Azure CLI use and exploitation of this attack. For example, see the following logs from a lab environment. The login events with an application of  “Microsoft Azure CLI” and a resource of “Azure Resource Manager” was legitimate use of the Azure CLI using the powershell CLI framework. Conversely, the login event with the Resource of “Windows Azure Active Directory” was produced by logging in using the method used by the phishing kit.",{"data":72936,"content":72940,"nodeType":996},{"target":72937},{"sys":72938},{"id":72939,"type":1001,"linkType":1002},"6ie0nkk6XbgwidfwmiGwL4",[],{"data":72942,"content":72943,"nodeType":860},{},[72944],{"data":72945,"marks":72946,"value":72947,"nodeType":864},{},[],"There is no guarantee this can be used to differentiate between legitimate and malicious examples, but it’s another data point to consider. If searching logs you may wish to use the respective GUIDs for these:",{"data":72949,"content":72950,"nodeType":941},{},[72951,72966],{"data":72952,"content":72953,"nodeType":945},{},[72954],{"data":72955,"content":72956,"nodeType":860},{},[72957,72962],{"data":72958,"marks":72959,"value":72961,"nodeType":864},{},[72960],{"type":899},"Application ID",{"data":72963,"marks":72964,"value":72965,"nodeType":864},{},[]," = 04b07795-8ddb-461a-bbee-02f9e1bf7b46",{"data":72967,"content":72968,"nodeType":945},{},[72969],{"data":72970,"content":72971,"nodeType":860},{},[72972,72977],{"data":72973,"marks":72974,"value":72976,"nodeType":864},{},[72975],{"type":899},"Resource ID",{"data":72978,"marks":72979,"value":72980,"nodeType":864},{},[]," = 00000002-0000-0000-c000-000000000000",{"data":72982,"content":72983,"nodeType":860},{},[72984],{"data":72985,"marks":72986,"value":72987,"nodeType":864},{},[],"For interactive logins, like above, you cannot rely on looking for logins from suspicious IP addresses or locations. The login itself occurs from the victims browser directly to Microsoft, and so the IP addresses associated with these events will be the legitimate IP used by the target user, not by the threat actor. ",{"data":72989,"content":72990,"nodeType":860},{},[72991],{"data":72992,"marks":72993,"value":72994,"nodeType":864},{},[],"However, for non-interactive logins and other audit logs for actions taken, you may be able to uncover unusual IP addresses that differ from the original interactive login. For example, here are some non-interactive logins that were observed immediately after compromise that came from different IP addresses in both the US and Indonesia.",{"data":72996,"content":73000,"nodeType":996},{"target":72997},{"sys":72998},{"id":72999,"type":1001,"linkType":1002},"TD3YeWqgGIWIWM8FRHU4o",[],{"data":73002,"content":73003,"nodeType":860},{},[73004],{"data":73005,"marks":73006,"value":73007,"nodeType":864},{},[],"Interestingly, they differ in which resources they accessed, with one accessing the Windows Azure Active Directory resource ID like the interactive login, but two others accessing the Microsoft Intune Checkin resource ID. ",{"data":73009,"content":73013,"nodeType":996},{"target":73010},{"sys":73011},{"id":73012,"type":1001,"linkType":1002},"57PqDQiAiwzqkspVpROQXb",[],{"data":73015,"content":73016,"nodeType":1312},{},[73017],{"data":73018,"marks":73019,"value":73021,"nodeType":864},{},[73020],{"type":899},"IoCs",{"data":73023,"content":73024,"nodeType":860},{},[73025,73028,73035],{"data":73026,"marks":73027,"value":48437,"nodeType":864},{},[],{"data":73029,"content":73030,"nodeType":883},{"uri":14430},[73031],{"data":73032,"marks":73033,"value":14435,"nodeType":864},{},[73034],{"type":1455},{"data":73036,"marks":73037,"value":73038,"nodeType":864},{},[]," in the attack chain, often dynamically serving different URLs to site visitors. ",{"data":73040,"content":73041,"nodeType":860},{},[73042],{"data":73043,"marks":73044,"value":73045,"nodeType":864},{},[],"That said, the domains used to deliver the final phishing payload were:",{"data":73047,"content":73048,"nodeType":941},{},[73049,73059,73069],{"data":73050,"content":73051,"nodeType":945},{},[73052],{"data":73053,"content":73054,"nodeType":860},{},[73055],{"data":73056,"marks":73057,"value":73058,"nodeType":864},{},[],"hxxps://trustpointassurance.com/",{"data":73060,"content":73061,"nodeType":945},{},[73062],{"data":73063,"content":73064,"nodeType":860},{},[73065],{"data":73066,"marks":73067,"value":73068,"nodeType":864},{},[],"hxxps://fastwaycheck.com/",{"data":73070,"content":73071,"nodeType":945},{},[73072],{"data":73073,"content":73074,"nodeType":860},{},[73075],{"data":73076,"marks":73077,"value":73078,"nodeType":864},{},[],"hxxps://previewcentral.com",{"data":73080,"content":73081,"nodeType":860},{},[73082],{"data":73083,"marks":73084,"value":73085,"nodeType":864},{},[],"In addition, we recommend hunting for connections from the following IPs in Azure logs:",{"data":73087,"content":73088,"nodeType":941},{},[73089,73099,73109],{"data":73090,"content":73091,"nodeType":945},{},[73092],{"data":73093,"content":73094,"nodeType":860},{},[73095],{"data":73096,"marks":73097,"value":73098,"nodeType":864},{},[],"12.75.216.90",{"data":73100,"content":73101,"nodeType":945},{},[73102],{"data":73103,"content":73104,"nodeType":860},{},[73105],{"data":73106,"marks":73107,"value":73108,"nodeType":864},{},[],"182.3.36.223",{"data":73110,"content":73111,"nodeType":945},{},[73112],{"data":73113,"content":73114,"nodeType":860},{},[73115],{"data":73116,"marks":73117,"value":73118,"nodeType":864},{},[],"12.75.116.137",{"data":73120,"content":73121,"nodeType":1005},{},[],{"data":73123,"content":73124,"nodeType":1009},{},[73125],{"data":73126,"marks":73127,"value":73129,"nodeType":864},{},[73128],{"type":899},"How Push stopped the attack",{"data":73131,"content":73132,"nodeType":860},{},[73133],{"data":73134,"marks":73135,"value":73136,"nodeType":864},{},[],"Even though this was a brand new technique, Push intercepted this attack and shut it down before customers could interact with it. ",{"data":73138,"content":73142,"nodeType":996},{"target":73139},{"sys":73140},{"id":73141,"type":1001,"linkType":1002},"5YzpiQH974EYA5iPPZMXkV",[],{"data":73144,"content":73145,"nodeType":860},{},[73146,73150,73158],{"data":73147,"marks":73148,"value":73149,"nodeType":864},{},[],"Push doesn’t detect the redirect tricks or rely on outdated domain TI feeds. The reason we detect these attacks (which make it through all the other layers of phishing protection) is that Push sees what your users see. It doesn’t matter what ",{"data":73151,"content":73152,"nodeType":883},{"uri":14307},[73153],{"data":73154,"marks":73155,"value":73157,"nodeType":864},{},[73156],{"type":1455},"delivery channel or camouflage methods are used",{"data":73159,"marks":73160,"value":73161,"nodeType":864},{},[],", Push shuts the attack down in real time, as the user loads the malicious page in their web browser.",{"data":73163,"content":73164,"nodeType":860},{},[73165],{"data":73166,"marks":73167,"value":73168,"nodeType":864},{},[],"This isn’t all we do: Push’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":73170,"content":73171,"nodeType":860},{},[73172,73175,73182,73185,73192],{"data":73173,"marks":73174,"value":16863,"nodeType":864},{},[],{"data":73176,"content":73177,"nodeType":883},{"uri":16866},[73178],{"data":73179,"marks":73180,"value":16871,"nodeType":864},{},[73181],{"type":1455},{"data":73183,"marks":73184,"value":52968,"nodeType":864},{},[],{"data":73186,"content":73187,"nodeType":883},{"uri":1700},[73188],{"data":73189,"marks":73190,"value":16894,"nodeType":864},{},[73191],{"type":1455},{"data":73193,"marks":73194,"value":2924,"nodeType":864},{},[],{"data":73196,"content":73200,"nodeType":996},{"target":73197},{"sys":73198},{"id":73199,"type":1001,"linkType":1002},"6QzB0BlVC5mstXwXHvy2c3",[],{"data":73202,"content":73203,"nodeType":860},{},[73204],{"data":73205,"marks":73206,"value":21,"nodeType":864},{},[],"ConsentFix: Analyzing a browser-native ClickFix-style attack that hijacks OAuth consent grants","Analyzing \"ConsentFix\", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt. ","2025-12-11T00:00:00.000Z","consentfix",{"items":73212},[73213,73215],{"sys":73214,"name":13779},{"id":13778},{"sys":73216,"name":342},{"id":13775},{"items":73218},[73219],{"fullName":22309,"firstName":22310,"jobTitle":22311,"profilePicture":73220},{"url":22313},{"__typename":2059,"sys":73222,"content":73224,"title":73891,"synopsis":73892,"hashTags":59,"publishedDate":73893,"slug":73894,"tagsCollection":73895,"authorsCollection":73901},{"id":73223},"5CqV6e5wfHsfEVczkWSerZ",{"json":73225},{"data":73226,"content":73227,"nodeType":856},{},[73228,73234,73241,73248,73251,73259,73266,73273,73280,73376,73382,73388,73394,73401,73408,73427,73430,73438,73445,73452,73459,73502,73509,73554,73560,73567,73574,73577,73585,73592,73599,73606,73676,73682,73688,73720,73726,73745,73751,73758,73765,73771,73774,73782,73789,73822,73829,73832,73840,73847,73854,73880,73885],{"data":73229,"content":73233,"nodeType":996},{"target":73230},{"sys":73231},{"id":73232,"type":1001,"linkType":1002},"1axcGwWxeKxDMk8jOWhYT6",[],{"data":73235,"content":73236,"nodeType":860},{},[73237],{"data":73238,"marks":73239,"value":73240,"nodeType":864},{},[],"2025 saw a huge amount of attacker innovation when it comes to phishing attacks, as attackers continue to double down on identity-based techniques. The continual evolution of phishing means it remains one of the most effective methods available to attackers today — in fact, it’s arguably more effective than ever. ",{"data":73242,"content":73243,"nodeType":860},{},[73244],{"data":73245,"marks":73246,"value":73247,"nodeType":864},{},[],"Let’s take a closer look at the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026. ",{"data":73249,"content":73250,"nodeType":1005},{},[],{"data":73252,"content":73253,"nodeType":1009},{},[73254],{"data":73255,"marks":73256,"value":73258,"nodeType":864},{},[73257],{"type":899},"#1: Phishing goes omni-channel",{"data":73260,"content":73261,"nodeType":860},{},[73262],{"data":73263,"marks":73264,"value":73265,"nodeType":864},{},[],"We’ve been talking about the rise of non-email phishing for some time now, but 2025 was the year phishing truly went omni-channel. ",{"data":73267,"content":73268,"nodeType":860},{},[73269],{"data":73270,"marks":73271,"value":73272,"nodeType":864},{},[],"Although most of the industry’s data on phishing still comes from email security vendors and tools, the picture is starting to change. Roughly 1 in 3 phishing attacks detected by Push Security were delivered outside of email. ",{"data":73274,"content":73275,"nodeType":860},{},[73276],{"data":73277,"marks":73278,"value":73279,"nodeType":864},{},[],"There are many examples of phishing campaigns operated outside of email, with LinkedIn DMs and Google Search being the top channels we identified. Notable campaigns include:",{"data":73281,"content":73282,"nodeType":941},{},[73283,73305,73327],{"data":73284,"content":73285,"nodeType":945},{},[73286],{"data":73287,"content":73288,"nodeType":860},{},[73289,73292,73301],{"data":73290,"marks":73291,"value":21,"nodeType":864},{},[],{"data":73293,"content":73295,"nodeType":883},{"uri":73294},"https://pushsecurity.com/blog/how-push-stopped-a-high-risk-linkedin-spear-phishing-attack",[73296],{"data":73297,"marks":73298,"value":73300,"nodeType":864},{},[73299],{"type":1455},"A targeted campaign against tech company Exec’s",{"data":73302,"marks":73303,"value":73304,"nodeType":864},{},[]," delivered via compromised accounts on LinkedIn from other employees of the same organization, framed as an investment opportunity.",{"data":73306,"content":73307,"nodeType":945},{},[73308],{"data":73309,"content":73310,"nodeType":860},{},[73311,73314,73323],{"data":73312,"marks":73313,"value":21,"nodeType":864},{},[],{"data":73315,"content":73317,"nodeType":883},{"uri":73316},"https://pushsecurity.com/blog/new-phishing-campaign-identified-targeting-linkedin-users",[73318],{"data":73319,"marks":73320,"value":73322,"nodeType":864},{},[73321],{"type":1455},"A campaign posing as a South American investment fund",{"data":73324,"marks":73325,"value":73326,"nodeType":864},{},[]," offering the opportunity to join the fund. ",{"data":73328,"content":73329,"nodeType":945},{},[73330],{"data":73331,"content":73332,"nodeType":860},{},[73333,73337,73346,73350,73359,73363,73372],{"data":73334,"marks":73335,"value":73336,"nodeType":864},{},[],"Several malvertising campaigns capturing users searching for key search terms such as “",{"data":73338,"content":73340,"nodeType":883},{"uri":73339},"https://pushsecurity.com/blog/analysing-a-malvertising-attack-targeting-business-google-accounts",[73341],{"data":73342,"marks":73343,"value":73345,"nodeType":864},{},[73344],{"type":1455},"Google Ads",{"data":73347,"marks":73348,"value":73349,"nodeType":864},{},[],"”, “",{"data":73351,"content":73353,"nodeType":883},{"uri":73352},"https://pushsecurity.com/blog/analysing-a-sophisticated-google-malvertising-attack",[73354],{"data":73355,"marks":73356,"value":73358,"nodeType":864},{},[73357],{"type":1455},"TradingView",{"data":73360,"marks":73361,"value":73362,"nodeType":864},{},[],"” and “",{"data":73364,"content":73366,"nodeType":883},{"uri":73365},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers",[73367],{"data":73368,"marks":73369,"value":73371,"nodeType":864},{},[73370],{"type":1455},"Onfido",{"data":73373,"marks":73374,"value":73375,"nodeType":864},{},[],"”. ",{"data":73377,"content":73381,"nodeType":996},{"target":73378},{"sys":73379},{"id":73380,"type":1001,"linkType":1002},"3LjyZooaJQ83eJt8DRX9bP",[],{"data":73383,"content":73387,"nodeType":996},{"target":73384},{"sys":73385},{"id":73386,"type":1001,"linkType":1002},"644LdQYjRHerpKU5pCGv1n",[],{"data":73389,"content":73393,"nodeType":996},{"target":73390},{"sys":73391},{"id":73392,"type":1001,"linkType":1002},"3anCGk5A4AOVH1t9dr1xKp",[],{"data":73395,"content":73396,"nodeType":860},{},[73397],{"data":73398,"marks":73399,"value":73400,"nodeType":864},{},[],"Phishing via non-email channels has a number of advantages. With email being the best protected phishing vector, it sidesteps these controls entirely. There’s no need to build up your sender reputation, find ways to trick content analysis engines, or hope your message doesn’t end up in the spam folder.",{"data":73402,"content":73403,"nodeType":860},{},[73404],{"data":73405,"marks":73406,"value":73407,"nodeType":864},{},[],"In comparison, non-email vectors have practically no screening, your security team has no visibility, and users are less likely to anticipate possible phishing. It’s arguable that a company Exec is more likely to engage with a LinkedIn DM from a reputable account than a cold email. And social media apps do nothing to analyse messages for phishing links. (And because of the limitations of URL-based checks when it comes to today’s multi-stage phishing attacks, this would be extremely difficult even if they tried). ",{"data":73409,"content":73410,"nodeType":860},{},[73411,73415,73423],{"data":73412,"marks":73413,"value":73414,"nodeType":864},{},[],"Search engines also present a huge opportunity for attackers, whether they’re compromising existing, high reputation sites, spinning up malicious ads, or simply vibe coding their own SEO-optimized websites. This is an effective way to launch “watering hole” style attacks, casting a wide net to harvest credentials and account access that can be re-sold to other criminals for a fee, or leveraged by partners in the cybercriminal ecosystem as part of major cyber breaches (such as the recent attacks by the “",{"data":73416,"content":73418,"nodeType":883},{"uri":73417},"https://pushsecurity.com/blog/scattered-lapsus-hunters",[73419],{"data":73420,"marks":73421,"value":16018,"nodeType":864},{},[73422],{"type":1455},{"data":73424,"marks":73425,"value":73426,"nodeType":864},{},[],"” criminal collective, all of which began with identity-based initial access). ",{"data":73428,"content":73429,"nodeType":1005},{},[],{"data":73431,"content":73432,"nodeType":1009},{},[73433],{"data":73434,"marks":73435,"value":73437,"nodeType":864},{},[73436],{"type":899},"#2: Criminal PhaaS kits dominate",{"data":73439,"content":73440,"nodeType":860},{},[73441],{"data":73442,"marks":73443,"value":73444,"nodeType":864},{},[],"The vast majority of phishing attacks today use a reverse proxy. This means they are capable of bypassing most forms of MFA because a session is created and stolen in real time as part of the attack. There is no downside to this approach compared to the basic credential phishing that was the norm more than a decade ago.",{"data":73446,"content":73447,"nodeType":860},{},[73448],{"data":73449,"marks":73450,"value":73451,"nodeType":864},{},[],"These Attacker-in-the-Middle attacks are powered by criminal Phishing-as-a-Service (PhaaS) kits such as Tycoon, NakedPages, Sneaky2FA, Flowerstorm, Salty2FA, along with various Evilginx variations (nominally a tool for red teamers, but widely used by attackers). ",{"data":73453,"content":73454,"nodeType":860},{},[73455],{"data":73456,"marks":73457,"value":73458,"nodeType":864},{},[],"PhaaS kits are incredibly important to cybercrime because they make sophisticated and continuously evolving capabilities available to the criminal marketplace, lowering the barrier to entry for criminals running advanced phishing campaigns. This is not unique to phishing: Ransomware-as-a-Service, Credential Stuffing-as-a-Service, and many more for-hire tools and services exist for criminals to use for a fee. ",{"data":73460,"content":73461,"nodeType":860},{},[73462,73466,73475,73478,73485,73489,73498],{"data":73463,"marks":73464,"value":73465,"nodeType":864},{},[],"This competitive environment has fueled attacker innovation, resulting in an environment in which MFA-bypass is table stakes, phishing-resistant authentication is being circumvented through ",{"data":73467,"content":73469,"nodeType":883},{"uri":73468},"https://pushsecurity.com/blog/mfa-downgrade-attacks",[73470],{"data":73471,"marks":73472,"value":73474,"nodeType":864},{},[73473],{"type":1455},"downgrade attacks",{"data":73476,"marks":73477,"value":2232,"nodeType":864},{},[],{"data":73479,"content":73480,"nodeType":883},{"uri":14307},[73481],{"data":73482,"marks":73483,"value":19763,"nodeType":864},{},[73484],{"type":1455},{"data":73486,"marks":73487,"value":73488,"nodeType":864},{},[]," are being used to circumvent security tools — from email scanners, to web-crawling security tools, to web proxies analyzing network traffic. It also means that when new capabilities emerge — such as ",{"data":73490,"content":73492,"nodeType":883},{"uri":73491},"https://pushsecurity.com/blog/analyzing-the-latest-sneaky2fa-phishing-page",[73493],{"data":73494,"marks":73495,"value":73497,"nodeType":864},{},[73496],{"type":1455},"Browser-in-the-Browser",{"data":73499,"marks":73500,"value":73501,"nodeType":864},{},[]," — these are quickly integrated into a range of phishing kits. ",{"data":73503,"content":73504,"nodeType":860},{},[73505],{"data":73506,"marks":73507,"value":73508,"nodeType":864},{},[],"Some of the most prevalent detection evasion methods we’ve seen this year are:",{"data":73510,"content":73511,"nodeType":941},{},[73512,73522,73532],{"data":73513,"content":73514,"nodeType":945},{},[73515],{"data":73516,"content":73517,"nodeType":860},{},[73518],{"data":73519,"marks":73520,"value":73521,"nodeType":864},{},[],"Widespread use of bot protection. Every phishing page today comes with either a custom CAPTCHA or Cloudflare Turnstile (legitimate and fake versions) designed to block web-crawling security bots from being able to analyse phishing pages. ",{"data":73523,"content":73524,"nodeType":945},{},[73525],{"data":73526,"content":73527,"nodeType":860},{},[73528],{"data":73529,"marks":73530,"value":73531,"nodeType":864},{},[],"Extensive redirect chains between the initial link seeded out to the victim, and the actual malicious page hosting phishing content, designed to bury phishing sites among several legitimate pages. ",{"data":73533,"content":73534,"nodeType":945},{},[73535],{"data":73536,"content":73537,"nodeType":860},{},[73538,73542,73550],{"data":73539,"marks":73540,"value":73541,"nodeType":864},{},[],"Multi-stage page loading performed client-side via JavaScript. This means that pages are ",{"data":73543,"content":73544,"nodeType":883},{"uri":72467},[73545],{"data":73546,"marks":73547,"value":73549,"nodeType":864},{},[73548],{"type":1455},"conditionally loaded",{"data":73551,"marks":73552,"value":73553,"nodeType":864},{},[],", and if conditions aren’t met, malicious content isn’t served — so the page looks clean. This also means that most of the malicious activity is happening locally, without creating web requests that can be analysed by network traffic analysis tools (e.g. web proxies). ",{"data":73555,"content":73559,"nodeType":996},{"target":73556},{"sys":73557},{"id":73558,"type":1001,"linkType":1002},"5LLgjhCexTYd5OlHuptv3n",[],{"data":73561,"content":73562,"nodeType":860},{},[73563],{"data":73564,"marks":73565,"value":73566,"nodeType":864},{},[],"This contributes to an environment where phishing is going undetected for extended periods of time. Even when a page is flagged, it’s trivial for attackers to dynamically serve up different phishing pages from the same benign chain of URLs used in the attack. ",{"data":73568,"content":73569,"nodeType":860},{},[73570],{"data":73571,"marks":73572,"value":73573,"nodeType":864},{},[],"This is all to say that the old-school approach to URL blocking bad sites is becoming much harder and leaves you two steps behind attackers at all times.",{"data":73575,"content":73576,"nodeType":1005},{},[],{"data":73578,"content":73579,"nodeType":1009},{},[73580],{"data":73581,"marks":73582,"value":73584,"nodeType":864},{},[73583],{"type":899},"#3: Attackers find ways around phishing-resistant authentication (and other security controls)",{"data":73586,"content":73587,"nodeType":860},{},[73588],{"data":73589,"marks":73590,"value":73591,"nodeType":864},{},[],"We already mentioned that MFA downgrade has been an area of focus for security researchers and attackers. But phishing-resistant authentication methods (i.e. passkeys) remain effective so long as the phishing-resistant factor is the only possible login factor, and there are no backup methods enabled for the account. (Though because of the logistical issues of having just one factor, this is fairly uncommon.) ",{"data":73593,"content":73594,"nodeType":860},{},[73595],{"data":73596,"marks":73597,"value":73598,"nodeType":864},{},[],"Equally, access control policies can be applied on larger enterprise apps and cloud platforms to reduce the risk of unauthorized access (although these can be tricky to implement and maintain without error).",{"data":73600,"content":73601,"nodeType":860},{},[73602],{"data":73603,"marks":73604,"value":73605,"nodeType":864},{},[],"In any case, attackers are considering all eventualities and looking for alternative ways into accounts that are less well protected. This mainly involves attackers circumventing the standard authentication process, through techniques such as:",{"data":73607,"content":73608,"nodeType":941},{},[73609,73636,73661],{"data":73610,"content":73611,"nodeType":945},{},[73612],{"data":73613,"content":73614,"nodeType":860},{},[73615,73618,73627,73632],{"data":73616,"marks":73617,"value":21,"nodeType":864},{},[],{"data":73619,"content":73620,"nodeType":883},{"uri":50933},[73621],{"data":73622,"marks":73623,"value":73626,"nodeType":864},{},[73624,73625],{"type":1455},{"type":899},"Consent phishing",{"data":73628,"marks":73629,"value":73631,"nodeType":864},{},[73630],{"type":899},":",{"data":73633,"marks":73634,"value":73635,"nodeType":864},{},[]," Tricking victims into connecting malicious OAuth apps into their app tenant.",{"data":73637,"content":73638,"nodeType":945},{},[73639],{"data":73640,"content":73641,"nodeType":860},{},[73642,73645,73653,73657],{"data":73643,"marks":73644,"value":21,"nodeType":864},{},[],{"data":73646,"content":73647,"nodeType":883},{"uri":19347},[73648],{"data":73649,"marks":73650,"value":360,"nodeType":864},{},[73651,73652],{"type":1455},{"type":899},{"data":73654,"marks":73655,"value":13560,"nodeType":864},{},[73656],{"type":899},{"data":73658,"marks":73659,"value":73660,"nodeType":864},{},[],"The same as consent phishing, but authorizing through the device code flow designed for device logins that cannot support OAuth, by providing a substitute passcode. ",{"data":73662,"content":73663,"nodeType":945},{},[73664],{"data":73665,"content":73666,"nodeType":860},{},[73667,73672],{"data":73668,"marks":73669,"value":73671,"nodeType":864},{},[73670],{"type":899},"Malicious browser extensions: ",{"data":73673,"marks":73674,"value":73675,"nodeType":864},{},[],"Tricking victims into installing a malicious extension (or hijacking an existing one) to steal credentials and cookies from the browser. ",{"data":73677,"content":73681,"nodeType":996},{"target":73678},{"sys":73679},{"id":73680,"type":1001,"linkType":1002},"75lMjdJtq9APebTaF2hQ1b",[],{"data":73683,"content":73687,"nodeType":996},{"target":73684},{"sys":73685},{"id":73686,"type":1001,"linkType":1002},"4KWwlg8PsuyAud8i5tpWfH",[],{"data":73689,"content":73690,"nodeType":860},{},[73691,73695,73703,73707,73716],{"data":73692,"marks":73693,"value":73694,"nodeType":864},{},[],"Another technique that attackers are using to steal credentials and sessions is ",{"data":73696,"content":73698,"nodeType":883},{"uri":73697},"https://pushsecurity.com/blog/the-most-advanced-clickfix-yet",[73699],{"data":73700,"marks":73701,"value":315,"nodeType":864},{},[73702],{"type":1455},{"data":73704,"marks":73705,"value":73706,"nodeType":864},{},[],". ClickFix was the ",{"data":73708,"content":73710,"nodeType":883},{"uri":73709},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=36",[73711],{"data":73712,"marks":73713,"value":73715,"nodeType":864},{},[73714],{"type":1455},"top initial access vector detected by Microsoft last year",{"data":73717,"marks":73718,"value":73719,"nodeType":864},{},[],", involved in 47% of attacks. While not a traditional phishing attack, this sees attackers socially engineer users into running malicious code on their machine, typically deploying remote access tools and infostealer malware. Infostealers are then used to harvest credentials and cookies for initial access to various apps and services. ",{"data":73721,"content":73725,"nodeType":996},{"target":73722},{"sys":73723},{"id":73724,"type":1001,"linkType":1002},"4cC9GbPoKFmYUJgbkbeOLs",[],{"data":73727,"content":73728,"nodeType":860},{},[73729,73733,73741],{"data":73730,"marks":73731,"value":73732,"nodeType":864},{},[],"Push Security researchers have also discovered a brand new technique dubbed ",{"data":73734,"content":73736,"nodeType":883},{"uri":73735},"https://pushsecurity.com/blog/consentfix",[73737],{"data":73738,"marks":73739,"value":11731,"nodeType":864},{},[73740],{"type":1455},{"data":73742,"marks":73743,"value":73744,"nodeType":864},{},[]," — a browser-native version of ClickFix that results in an OAuth connection being established to the target app, simply by copying and pasting a legitimate URL containing OAuth key material. ",{"data":73746,"content":73750,"nodeType":996},{"target":73747},{"sys":73748},{"id":73749,"type":1001,"linkType":1002},"4bdqleePd53oK5v5uEUFbr",[],{"data":73752,"content":73753,"nodeType":860},{},[73754],{"data":73755,"marks":73756,"value":73757,"nodeType":864},{},[],"This is even more dangerous than ClickFix as it is entirely browser-native — removing the endpoint detection surface (and strong security controls like EDR) from the equation entirely. And in the particular case spotted by Push, the attackers targeted Azure CLI — a first-party Microsoft app that has special permissions and can’t be restricted like third-party apps. ",{"data":73759,"content":73760,"nodeType":860},{},[73761],{"data":73762,"marks":73763,"value":73764,"nodeType":864},{},[],"Really, there are lots of different techniques attackers can use to take over accounts on key business applications — it’s outdated to think of phishing as being locked in to passwords, MFA, and the standard authentication flow. ",{"data":73766,"content":73770,"nodeType":996},{"target":73767},{"sys":73768},{"id":73769,"type":1001,"linkType":1002},"74S97KkuFzI48UwXw3msTq",[],{"data":73772,"content":73773,"nodeType":1005},{},[],{"data":73775,"content":73776,"nodeType":1009},{},[73777],{"data":73778,"marks":73779,"value":73781,"nodeType":864},{},[73780],{"type":899},"Guidance for security teams in 2026",{"data":73783,"content":73784,"nodeType":860},{},[73785],{"data":73786,"marks":73787,"value":73788,"nodeType":864},{},[],"To tackle phishing in 2026, security teams need to change their threat model for phishing, and acknowledge that:",{"data":73790,"content":73791,"nodeType":941},{},[73792,73802,73812],{"data":73793,"content":73794,"nodeType":945},{},[73795],{"data":73796,"content":73797,"nodeType":860},{},[73798],{"data":73799,"marks":73800,"value":73801,"nodeType":864},{},[],"It’s not enough to protect email as your main anti-phishing surface",{"data":73803,"content":73804,"nodeType":945},{},[73805],{"data":73806,"content":73807,"nodeType":860},{},[73808],{"data":73809,"marks":73810,"value":73811,"nodeType":864},{},[],"Network and traffic monitoring tools aren’t keeping up with modern phishing pages",{"data":73813,"content":73814,"nodeType":945},{},[73815],{"data":73816,"content":73817,"nodeType":860},{},[73818],{"data":73819,"marks":73820,"value":73821,"nodeType":864},{},[],"Phishing-resistant authentication, even if perfectly implemented, doesn’t make you immune",{"data":73823,"content":73824,"nodeType":860},{},[73825],{"data":73826,"marks":73827,"value":73828,"nodeType":864},{},[],"Detection and response is key. But most organizations have significant visibility gaps.",{"data":73830,"content":73831,"nodeType":1005},{},[],{"data":73833,"content":73834,"nodeType":1009},{},[73835],{"data":73836,"marks":73837,"value":73839,"nodeType":864},{},[73838],{"type":899},"Solving the detection gap in the browser",{"data":73841,"content":73842,"nodeType":860},{},[73843],{"data":73844,"marks":73845,"value":73846,"nodeType":864},{},[],"One thing that these attacks have in common is that they all take place in the web browser, targeting users as they go about their work on the internet. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams.",{"data":73848,"content":73849,"nodeType":860},{},[73850],{"data":73851,"marks":73852,"value":73853,"nodeType":864},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":73855,"content":73856,"nodeType":860},{},[73857,73860,73867,73870,73877],{"data":73858,"marks":73859,"value":16863,"nodeType":864},{},[],{"data":73861,"content":73862,"nodeType":883},{"uri":16866},[73863],{"data":73864,"marks":73865,"value":16871,"nodeType":864},{},[73866],{"type":1455},{"data":73868,"marks":73869,"value":52968,"nodeType":864},{},[],{"data":73871,"content":73872,"nodeType":883},{"uri":1700},[73873],{"data":73874,"marks":73875,"value":16894,"nodeType":864},{},[73876],{"type":1455},{"data":73878,"marks":73879,"value":2924,"nodeType":864},{},[],{"data":73881,"content":73884,"nodeType":996},{"target":73882},{"sys":73883},{"id":73199,"type":1001,"linkType":1002},[],{"data":73886,"content":73887,"nodeType":860},{},[73888],{"data":73889,"marks":73890,"value":21,"nodeType":864},{},[],"2025’s top phishing trends — and what they mean for your 2026 security strategy","Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026. ","2025-12-15T00:00:00.000Z","2025-top-phishing-trends",{"items":73896},[73897,73899],{"sys":73898,"name":342},{"id":13775},{"sys":73900,"name":13779},{"id":13778},{"items":73902},[73903],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":73904},{"url":2740},"blog/taking-the-fight-to-attackers-top-features-of-2025",{"json":73907},{"data":73908,"content":73909,"nodeType":856},{},[73910],{"data":73911,"content":73912,"nodeType":860},{},[73913],{"data":73914,"marks":73915,"value":73916,"nodeType":864},{},[],"Here’s how real-world attacks and our own R&D informed what we built this year.",{"id":66794,"publishedAt":73918},"2026-08-13T09:35:11.859Z",{"items":73920},[73921,73923],{"sys":73922,"name":342},{"id":13775},{"sys":73924,"name":13779},{"id":13778},{"items":73926},[73927,73929,73931,73933,73935,73937,73939,73941,73943,73945,73947,73949,73951,73953,73955,73957,73959,73961,73963,73965,73967],{"sys":73928,"name":279,"slug":280,"tier":31},{"id":276},{"sys":73930,"name":413,"slug":414,"tier":31},{"id":410},{"sys":73932,"name":297,"slug":298,"tier":31},{"id":294},{"sys":73934,"name":519,"slug":520,"tier":31},{"id":516},{"sys":73936,"name":342,"slug":343,"tier":31},{"id":339},{"sys":73938,"name":642,"slug":643,"tier":31},{"id":639},{"sys":73940,"name":261,"slug":262,"tier":45},{"id":258},{"sys":73942,"name":315,"slug":316,"tier":45},{"id":312},{"sys":73944,"name":333,"slug":334,"tier":45},{"id":330},{"sys":73946,"name":571,"slug":572,"tier":45},{"id":568},{"sys":73948,"name":466,"slug":467,"tier":45},{"id":463},{"sys":73950,"name":511,"slug":512,"tier":45},{"id":508},{"sys":73952,"name":288,"slug":289,"tier":45},{"id":285},{"sys":73954,"name":395,"slug":396,"tier":45},{"id":392},{"sys":73956,"name":502,"slug":503,"tier":45},{"id":499},{"sys":73958,"name":457,"slug":458,"tier":45},{"id":454},{"sys":73960,"name":607,"slug":608,"tier":45},{"id":604},{"sys":73962,"name":422,"slug":423,"tier":45},{"id":419},{"sys":73964,"name":324,"slug":325,"tier":45},{"id":321},{"sys":73966,"name":440,"slug":441,"tier":45},{"id":437},{"sys":73968,"name":650,"slug":651,"tier":45},{"id":647},"PWDqfteh31QCBsZyOGrfwwzxqUSG34OMPlcKf1pr6SQ",{"id":73971,"title":73891,"authorsCollection":73972,"content":73977,"extension":228,"faqItemsCollection":74647,"faqTitle":59,"featured":6,"hashTags":59,"meta":74649,"metaTitle":74650,"ogImage":59,"postType":5726,"publishedDate":73893,"relatedBlogPostsCollection":74651,"slug":73894,"stem":76825,"subtitle":59,"summary":76826,"synopsis":73892,"sys":76837,"tagsCollection":76839,"topicsCollection":76845,"__hash__":76891},"blog/blog/2025-top-phishing-trends.json",{"items":73973},[73974],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":73975,"profilePicture":73976},[15231],{"url":2740},{"json":73978,"links":74558},{"data":73979,"content":73980,"nodeType":856},{},[73981,73986,73992,73998,74001,74008,74014,74020,74026,74106,74111,74116,74121,74127,74133,74149,74152,74159,74165,74171,74177,74213,74219,74259,74264,74270,74276,74279,74286,74292,74298,74304,74368,74373,74378,74404,74409,74425,74430,74436,74442,74447,74450,74457,74463,74493,74499,74502,74509,74515,74521,74547,74552],{"data":73982,"content":73985,"nodeType":996},{"target":73983},{"sys":73984},{"id":73232,"type":1001,"linkType":1002},[],{"data":73987,"content":73988,"nodeType":860},{},[73989],{"data":73990,"marks":73991,"value":73240,"nodeType":864},{},[],{"data":73993,"content":73994,"nodeType":860},{},[73995],{"data":73996,"marks":73997,"value":73247,"nodeType":864},{},[],{"data":73999,"content":74000,"nodeType":1005},{},[],{"data":74002,"content":74003,"nodeType":1009},{},[74004],{"data":74005,"marks":74006,"value":73258,"nodeType":864},{},[74007],{"type":899},{"data":74009,"content":74010,"nodeType":860},{},[74011],{"data":74012,"marks":74013,"value":73265,"nodeType":864},{},[],{"data":74015,"content":74016,"nodeType":860},{},[74017],{"data":74018,"marks":74019,"value":73272,"nodeType":864},{},[],{"data":74021,"content":74022,"nodeType":860},{},[74023],{"data":74024,"marks":74025,"value":73279,"nodeType":864},{},[],{"data":74027,"content":74028,"nodeType":941},{},[74029,74048,74067],{"data":74030,"content":74031,"nodeType":945},{},[74032],{"data":74033,"content":74034,"nodeType":860},{},[74035,74038,74045],{"data":74036,"marks":74037,"value":21,"nodeType":864},{},[],{"data":74039,"content":74040,"nodeType":883},{"uri":73294},[74041],{"data":74042,"marks":74043,"value":73300,"nodeType":864},{},[74044],{"type":1455},{"data":74046,"marks":74047,"value":73304,"nodeType":864},{},[],{"data":74049,"content":74050,"nodeType":945},{},[74051],{"data":74052,"content":74053,"nodeType":860},{},[74054,74057,74064],{"data":74055,"marks":74056,"value":21,"nodeType":864},{},[],{"data":74058,"content":74059,"nodeType":883},{"uri":73316},[74060],{"data":74061,"marks":74062,"value":73322,"nodeType":864},{},[74063],{"type":1455},{"data":74065,"marks":74066,"value":73326,"nodeType":864},{},[],{"data":74068,"content":74069,"nodeType":945},{},[74070],{"data":74071,"content":74072,"nodeType":860},{},[74073,74076,74083,74086,74093,74096,74103],{"data":74074,"marks":74075,"value":73336,"nodeType":864},{},[],{"data":74077,"content":74078,"nodeType":883},{"uri":73339},[74079],{"data":74080,"marks":74081,"value":73345,"nodeType":864},{},[74082],{"type":1455},{"data":74084,"marks":74085,"value":73349,"nodeType":864},{},[],{"data":74087,"content":74088,"nodeType":883},{"uri":73352},[74089],{"data":74090,"marks":74091,"value":73358,"nodeType":864},{},[74092],{"type":1455},{"data":74094,"marks":74095,"value":73362,"nodeType":864},{},[],{"data":74097,"content":74098,"nodeType":883},{"uri":73365},[74099],{"data":74100,"marks":74101,"value":73371,"nodeType":864},{},[74102],{"type":1455},{"data":74104,"marks":74105,"value":73375,"nodeType":864},{},[],{"data":74107,"content":74110,"nodeType":996},{"target":74108},{"sys":74109},{"id":73380,"type":1001,"linkType":1002},[],{"data":74112,"content":74115,"nodeType":996},{"target":74113},{"sys":74114},{"id":73386,"type":1001,"linkType":1002},[],{"data":74117,"content":74120,"nodeType":996},{"target":74118},{"sys":74119},{"id":73392,"type":1001,"linkType":1002},[],{"data":74122,"content":74123,"nodeType":860},{},[74124],{"data":74125,"marks":74126,"value":73400,"nodeType":864},{},[],{"data":74128,"content":74129,"nodeType":860},{},[74130],{"data":74131,"marks":74132,"value":73407,"nodeType":864},{},[],{"data":74134,"content":74135,"nodeType":860},{},[74136,74139,74146],{"data":74137,"marks":74138,"value":73414,"nodeType":864},{},[],{"data":74140,"content":74141,"nodeType":883},{"uri":73417},[74142],{"data":74143,"marks":74144,"value":16018,"nodeType":864},{},[74145],{"type":1455},{"data":74147,"marks":74148,"value":73426,"nodeType":864},{},[],{"data":74150,"content":74151,"nodeType":1005},{},[],{"data":74153,"content":74154,"nodeType":1009},{},[74155],{"data":74156,"marks":74157,"value":73437,"nodeType":864},{},[74158],{"type":899},{"data":74160,"content":74161,"nodeType":860},{},[74162],{"data":74163,"marks":74164,"value":73444,"nodeType":864},{},[],{"data":74166,"content":74167,"nodeType":860},{},[74168],{"data":74169,"marks":74170,"value":73451,"nodeType":864},{},[],{"data":74172,"content":74173,"nodeType":860},{},[74174],{"data":74175,"marks":74176,"value":73458,"nodeType":864},{},[],{"data":74178,"content":74179,"nodeType":860},{},[74180,74183,74190,74193,74200,74203,74210],{"data":74181,"marks":74182,"value":73465,"nodeType":864},{},[],{"data":74184,"content":74185,"nodeType":883},{"uri":73468},[74186],{"data":74187,"marks":74188,"value":73474,"nodeType":864},{},[74189],{"type":1455},{"data":74191,"marks":74192,"value":2232,"nodeType":864},{},[],{"data":74194,"content":74195,"nodeType":883},{"uri":14307},[74196],{"data":74197,"marks":74198,"value":19763,"nodeType":864},{},[74199],{"type":1455},{"data":74201,"marks":74202,"value":73488,"nodeType":864},{},[],{"data":74204,"content":74205,"nodeType":883},{"uri":73491},[74206],{"data":74207,"marks":74208,"value":73497,"nodeType":864},{},[74209],{"type":1455},{"data":74211,"marks":74212,"value":73501,"nodeType":864},{},[],{"data":74214,"content":74215,"nodeType":860},{},[74216],{"data":74217,"marks":74218,"value":73508,"nodeType":864},{},[],{"data":74220,"content":74221,"nodeType":941},{},[74222,74231,74240],{"data":74223,"content":74224,"nodeType":945},{},[74225],{"data":74226,"content":74227,"nodeType":860},{},[74228],{"data":74229,"marks":74230,"value":73521,"nodeType":864},{},[],{"data":74232,"content":74233,"nodeType":945},{},[74234],{"data":74235,"content":74236,"nodeType":860},{},[74237],{"data":74238,"marks":74239,"value":73531,"nodeType":864},{},[],{"data":74241,"content":74242,"nodeType":945},{},[74243],{"data":74244,"content":74245,"nodeType":860},{},[74246,74249,74256],{"data":74247,"marks":74248,"value":73541,"nodeType":864},{},[],{"data":74250,"content":74251,"nodeType":883},{"uri":72467},[74252],{"data":74253,"marks":74254,"value":73549,"nodeType":864},{},[74255],{"type":1455},{"data":74257,"marks":74258,"value":73553,"nodeType":864},{},[],{"data":74260,"content":74263,"nodeType":996},{"target":74261},{"sys":74262},{"id":73558,"type":1001,"linkType":1002},[],{"data":74265,"content":74266,"nodeType":860},{},[74267],{"data":74268,"marks":74269,"value":73566,"nodeType":864},{},[],{"data":74271,"content":74272,"nodeType":860},{},[74273],{"data":74274,"marks":74275,"value":73573,"nodeType":864},{},[],{"data":74277,"content":74278,"nodeType":1005},{},[],{"data":74280,"content":74281,"nodeType":1009},{},[74282],{"data":74283,"marks":74284,"value":73584,"nodeType":864},{},[74285],{"type":899},{"data":74287,"content":74288,"nodeType":860},{},[74289],{"data":74290,"marks":74291,"value":73591,"nodeType":864},{},[],{"data":74293,"content":74294,"nodeType":860},{},[74295],{"data":74296,"marks":74297,"value":73598,"nodeType":864},{},[],{"data":74299,"content":74300,"nodeType":860},{},[74301],{"data":74302,"marks":74303,"value":73605,"nodeType":864},{},[],{"data":74305,"content":74306,"nodeType":941},{},[74307,74331,74355],{"data":74308,"content":74309,"nodeType":945},{},[74310],{"data":74311,"content":74312,"nodeType":860},{},[74313,74316,74324,74328],{"data":74314,"marks":74315,"value":21,"nodeType":864},{},[],{"data":74317,"content":74318,"nodeType":883},{"uri":50933},[74319],{"data":74320,"marks":74321,"value":73626,"nodeType":864},{},[74322,74323],{"type":1455},{"type":899},{"data":74325,"marks":74326,"value":73631,"nodeType":864},{},[74327],{"type":899},{"data":74329,"marks":74330,"value":73635,"nodeType":864},{},[],{"data":74332,"content":74333,"nodeType":945},{},[74334],{"data":74335,"content":74336,"nodeType":860},{},[74337,74340,74348,74352],{"data":74338,"marks":74339,"value":21,"nodeType":864},{},[],{"data":74341,"content":74342,"nodeType":883},{"uri":19347},[74343],{"data":74344,"marks":74345,"value":360,"nodeType":864},{},[74346,74347],{"type":1455},{"type":899},{"data":74349,"marks":74350,"value":13560,"nodeType":864},{},[74351],{"type":899},{"data":74353,"marks":74354,"value":73660,"nodeType":864},{},[],{"data":74356,"content":74357,"nodeType":945},{},[74358],{"data":74359,"content":74360,"nodeType":860},{},[74361,74365],{"data":74362,"marks":74363,"value":73671,"nodeType":864},{},[74364],{"type":899},{"data":74366,"marks":74367,"value":73675,"nodeType":864},{},[],{"data":74369,"content":74372,"nodeType":996},{"target":74370},{"sys":74371},{"id":73680,"type":1001,"linkType":1002},[],{"data":74374,"content":74377,"nodeType":996},{"target":74375},{"sys":74376},{"id":73686,"type":1001,"linkType":1002},[],{"data":74379,"content":74380,"nodeType":860},{},[74381,74384,74391,74394,74401],{"data":74382,"marks":74383,"value":73694,"nodeType":864},{},[],{"data":74385,"content":74386,"nodeType":883},{"uri":73697},[74387],{"data":74388,"marks":74389,"value":315,"nodeType":864},{},[74390],{"type":1455},{"data":74392,"marks":74393,"value":73706,"nodeType":864},{},[],{"data":74395,"content":74396,"nodeType":883},{"uri":73709},[74397],{"data":74398,"marks":74399,"value":73715,"nodeType":864},{},[74400],{"type":1455},{"data":74402,"marks":74403,"value":73719,"nodeType":864},{},[],{"data":74405,"content":74408,"nodeType":996},{"target":74406},{"sys":74407},{"id":73724,"type":1001,"linkType":1002},[],{"data":74410,"content":74411,"nodeType":860},{},[74412,74415,74422],{"data":74413,"marks":74414,"value":73732,"nodeType":864},{},[],{"data":74416,"content":74417,"nodeType":883},{"uri":73735},[74418],{"data":74419,"marks":74420,"value":11731,"nodeType":864},{},[74421],{"type":1455},{"data":74423,"marks":74424,"value":73744,"nodeType":864},{},[],{"data":74426,"content":74429,"nodeType":996},{"target":74427},{"sys":74428},{"id":73749,"type":1001,"linkType":1002},[],{"data":74431,"content":74432,"nodeType":860},{},[74433],{"data":74434,"marks":74435,"value":73757,"nodeType":864},{},[],{"data":74437,"content":74438,"nodeType":860},{},[74439],{"data":74440,"marks":74441,"value":73764,"nodeType":864},{},[],{"data":74443,"content":74446,"nodeType":996},{"target":74444},{"sys":74445},{"id":73769,"type":1001,"linkType":1002},[],{"data":74448,"content":74449,"nodeType":1005},{},[],{"data":74451,"content":74452,"nodeType":1009},{},[74453],{"data":74454,"marks":74455,"value":73781,"nodeType":864},{},[74456],{"type":899},{"data":74458,"content":74459,"nodeType":860},{},[74460],{"data":74461,"marks":74462,"value":73788,"nodeType":864},{},[],{"data":74464,"content":74465,"nodeType":941},{},[74466,74475,74484],{"data":74467,"content":74468,"nodeType":945},{},[74469],{"data":74470,"content":74471,"nodeType":860},{},[74472],{"data":74473,"marks":74474,"value":73801,"nodeType":864},{},[],{"data":74476,"content":74477,"nodeType":945},{},[74478],{"data":74479,"content":74480,"nodeType":860},{},[74481],{"data":74482,"marks":74483,"value":73811,"nodeType":864},{},[],{"data":74485,"content":74486,"nodeType":945},{},[74487],{"data":74488,"content":74489,"nodeType":860},{},[74490],{"data":74491,"marks":74492,"value":73821,"nodeType":864},{},[],{"data":74494,"content":74495,"nodeType":860},{},[74496],{"data":74497,"marks":74498,"value":73828,"nodeType":864},{},[],{"data":74500,"content":74501,"nodeType":1005},{},[],{"data":74503,"content":74504,"nodeType":1009},{},[74505],{"data":74506,"marks":74507,"value":73839,"nodeType":864},{},[74508],{"type":899},{"data":74510,"content":74511,"nodeType":860},{},[74512],{"data":74513,"marks":74514,"value":73846,"nodeType":864},{},[],{"data":74516,"content":74517,"nodeType":860},{},[74518],{"data":74519,"marks":74520,"value":73853,"nodeType":864},{},[],{"data":74522,"content":74523,"nodeType":860},{},[74524,74527,74534,74537,74544],{"data":74525,"marks":74526,"value":16863,"nodeType":864},{},[],{"data":74528,"content":74529,"nodeType":883},{"uri":16866},[74530],{"data":74531,"marks":74532,"value":16871,"nodeType":864},{},[74533],{"type":1455},{"data":74535,"marks":74536,"value":52968,"nodeType":864},{},[],{"data":74538,"content":74539,"nodeType":883},{"uri":1700},[74540],{"data":74541,"marks":74542,"value":16894,"nodeType":864},{},[74543],{"type":1455},{"data":74545,"marks":74546,"value":2924,"nodeType":864},{},[],{"data":74548,"content":74551,"nodeType":996},{"target":74549},{"sys":74550},{"id":73199,"type":1001,"linkType":1002},[],{"data":74553,"content":74554,"nodeType":860},{},[74555],{"data":74556,"marks":74557,"value":21,"nodeType":864},{},[],{"entries":74559},{"hyperlink":74560,"inline":74561,"block":74562},[],[],[74563,74588,74594,74600,74606,74612,74618,74625,74631,74638,74644],{"sys":74564,"__typename":1740,"content":74565,"name":74587,"title":59},{"id":73232},{"json":74566},{"nodeType":856,"data":74567,"content":74568},{},[74569],{"nodeType":860,"data":74570,"content":74571},{},[74572,74576,74584],{"nodeType":864,"value":74573,"marks":74574,"data":74575},"We recently ran a webinar packed full of attack demo's, showcasing some of the most interesting attacks intercepted by Push in 2025. ",[],{},{"nodeType":883,"data":74577,"content":74579},{"uri":74578},"https://pushsecurity.com/webinar/phishing-2025-review",[74580],{"nodeType":864,"value":74581,"marks":74582,"data":74583},"You can now watch it on demand here!",[],{},{"nodeType":864,"value":21,"marks":74585,"data":74586},[],{},"Top phishing trends insight box 1",{"sys":74589,"__typename":1724,"title":74590,"caption":74590,"layoutMode":59,"file":74591},{"id":73380},"Fake private equity fund page hosted on Google Sites. ",{"url":74592,"width":1736,"height":74593},"https://images.ctfassets.net/y1cdw1ablpvd/2DbF1Lj4h5HVGrqDhlVlTF/9efa11f318206eb913d83c254746efb1/1.png",1200,{"sys":74595,"__typename":1724,"title":74596,"caption":74596,"layoutMode":59,"file":74597},{"id":73386},"Custom investment fund landing page hosted on Firebase.",{"url":74598,"width":1736,"height":74599},"https://images.ctfassets.net/y1cdw1ablpvd/2NH9muR2eBEPEybqQ8o0yu/ef66b40c7428790c9017181e17b33558/2.png",1080,{"sys":74601,"__typename":1724,"title":74602,"caption":74602,"layoutMode":59,"file":74603},{"id":73392},"Malvertising link for “Google Ads” taking the top Sponsored Results spot.",{"url":74604,"width":1736,"height":74605},"https://images.ctfassets.net/y1cdw1ablpvd/2gQcwHSyUKIoqlW1upRSzK/5ead4c9e6c1e6659be7d781ad85ed9ea/3.png",1205,{"sys":74607,"__typename":1724,"title":74608,"caption":74608,"layoutMode":59,"file":74609},{"id":73558},"Example of a typical phishing link chain incorporating legitimate websites before serving up a phishing page, as shown in the Push Security “Timelines” detection feature.",{"url":74610,"width":74611,"height":1736},"https://images.ctfassets.net/y1cdw1ablpvd/3WZkEAVsAH7PWtcoQJfDG1/03826279b5dd2bc11fbbf34f82c59136/4.png",1743,{"sys":74613,"__typename":1724,"title":74614,"caption":74614,"layoutMode":59,"file":74615},{"id":73680},"Consent phishing examples where an attacker tricks the victim into authorizing an attacker-controlled app with risky permissions.",{"url":74616,"width":1736,"height":74617},"https://images.ctfassets.net/y1cdw1ablpvd/2ZgY3mMKcE6IGpH55kOuL4/2a7e78e97654faa61cf8e8b002789b96/5.png",1367,{"sys":74619,"__typename":1724,"title":74620,"caption":74620,"layoutMode":59,"file":74621},{"id":73686},"Device code phishing targeting Salesforce, as seen in the Scattered Lapsus$ Hunters campaign. ",{"url":74622,"width":74623,"height":74624},"https://images.ctfassets.net/y1cdw1ablpvd/7uvYjRiqG4E7qj3PTmTZzW/3d3ed52d3157bf12a630e35eb2ae08d1/6.png",1488,950,{"sys":74626,"__typename":1724,"title":74627,"caption":74627,"layoutMode":59,"file":74628},{"id":73724},"ClickFix attacks prompt the victim to “fix” an issue on the webpage by running code locally on their machine.",{"url":74629,"width":1736,"height":74630},"https://images.ctfassets.net/y1cdw1ablpvd/1LXv96rhy5Sv6SBlJP0bJS/6fb6b49dcd2bdc003c2aa60ed271708f/7.png",1117,{"sys":74632,"__typename":1724,"title":74633,"caption":74633,"layoutMode":59,"file":74634},{"id":73749},"ConsentFix prompts victims to paste a URL containing an OAuth code, authorising a connection to the attacker’s OAuth app tenant. ",{"url":74635,"width":74636,"height":74637},"https://images.ctfassets.net/y1cdw1ablpvd/7IfG43sz0jRnrNiKsMwN8j/1373b7cd86fe969acad27ad956612ca0/8.png",1225,1135,{"sys":74639,"__typename":1724,"title":74640,"caption":74640,"layoutMode":59,"file":74641},{"id":73769},"There are lots of ways that attackers can achieve account takeover today via phishing / social engineering.",{"url":74642,"width":1736,"height":74643},"https://images.ctfassets.net/y1cdw1ablpvd/4Wz7gAJLWDyaGjj030ypH2/7a07f1e5c46cdebd2e395d0ceb412387/9.png",969,{"sys":74645,"__typename":1717,"type":1718,"ctaText":74646,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":74578},{"id":73199},"Learn how phishing evolved in 2025, showcasing the most sophisticated attacks and key trends uncovered by Push researchers",{"items":74648},[],{},"Analyzing 2025's top phishing trends",{"items":74652},[74653,75401,75997],{"__typename":2059,"sys":74654,"content":74655,"title":73207,"synopsis":73208,"hashTags":59,"publishedDate":73209,"slug":73210,"tagsCollection":75391,"authorsCollection":75397},{"id":39932},{"json":74656},{"data":74657,"content":74658,"nodeType":856},{},[74659,74666,74672,74678,74684,74694,74700,74705,74710,74713,74720,74726,74732,74737,74753,74759,74764,74770,74775,74781,74820,74825,74830,74836,74842,74845,74852,74868,74874,74879,74895,74900,74916,74922,74925,74932,74938,74974,74984,74987,74994,75009,75015,75028,75034,75040,75045,75051,75054,75061,75067,75115,75121,75124,75131,75136,75142,75148,75153,75159,75188,75194,75200,75205,75211,75216,75223,75239,75245,75275,75281,75311,75314,75321,75327,75332,75348,75354,75380,75385],{"data":74660,"content":74661,"nodeType":1009},{},[74662],{"data":74663,"marks":74664,"value":72374,"nodeType":864},{},[74665],{"type":899},{"data":74667,"content":74668,"nodeType":860},{},[74669],{"data":74670,"marks":74671,"value":72381,"nodeType":864},{},[],{"data":74673,"content":74674,"nodeType":860},{},[74675],{"data":74676,"marks":74677,"value":72388,"nodeType":864},{},[],{"data":74679,"content":74680,"nodeType":860},{},[74681],{"data":74682,"marks":74683,"value":72395,"nodeType":864},{},[],{"data":74685,"content":74686,"nodeType":860},{},[74687,74691],{"data":74688,"marks":74689,"value":72403,"nodeType":864},{},[74690],{"type":899},{"data":74692,"marks":74693,"value":72407,"nodeType":864},{},[],{"data":74695,"content":74696,"nodeType":860},{},[74697],{"data":74698,"marks":74699,"value":72414,"nodeType":864},{},[],{"data":74701,"content":74704,"nodeType":996},{"target":74702},{"sys":74703},{"id":72419,"type":1001,"linkType":1002},[],{"data":74706,"content":74709,"nodeType":996},{"target":74707},{"sys":74708},{"id":72425,"type":1001,"linkType":1002},[],{"data":74711,"content":74712,"nodeType":1005},{},[],{"data":74714,"content":74715,"nodeType":1009},{},[74716],{"data":74717,"marks":74718,"value":72437,"nodeType":864},{},[74719],{"type":899},{"data":74721,"content":74722,"nodeType":860},{},[74723],{"data":74724,"marks":74725,"value":72444,"nodeType":864},{},[],{"data":74727,"content":74728,"nodeType":860},{},[74729],{"data":74730,"marks":74731,"value":72451,"nodeType":864},{},[],{"data":74733,"content":74736,"nodeType":996},{"target":74734},{"sys":74735},{"id":72456,"type":1001,"linkType":1002},[],{"data":74738,"content":74739,"nodeType":860},{},[74740,74743,74750],{"data":74741,"marks":74742,"value":72464,"nodeType":864},{},[],{"data":74744,"content":74745,"nodeType":883},{"uri":72467},[74746],{"data":74747,"marks":74748,"value":72473,"nodeType":864},{},[74749],{"type":1455},{"data":74751,"marks":74752,"value":72477,"nodeType":864},{},[],{"data":74754,"content":74755,"nodeType":860},{},[74756],{"data":74757,"marks":74758,"value":72484,"nodeType":864},{},[],{"data":74760,"content":74763,"nodeType":996},{"target":74761},{"sys":74762},{"id":72489,"type":1001,"linkType":1002},[],{"data":74765,"content":74766,"nodeType":860},{},[74767],{"data":74768,"marks":74769,"value":72497,"nodeType":864},{},[],{"data":74771,"content":74774,"nodeType":996},{"target":74772},{"sys":74773},{"id":72502,"type":1001,"linkType":1002},[],{"data":74776,"content":74777,"nodeType":860},{},[74778],{"data":74779,"marks":74780,"value":72510,"nodeType":864},{},[],{"data":74782,"content":74783,"nodeType":941},{},[74784,74793,74802,74811],{"data":74785,"content":74786,"nodeType":945},{},[74787],{"data":74788,"content":74789,"nodeType":860},{},[74790],{"data":74791,"marks":74792,"value":72523,"nodeType":864},{},[],{"data":74794,"content":74795,"nodeType":945},{},[74796],{"data":74797,"content":74798,"nodeType":860},{},[74799],{"data":74800,"marks":74801,"value":72533,"nodeType":864},{},[],{"data":74803,"content":74804,"nodeType":945},{},[74805],{"data":74806,"content":74807,"nodeType":860},{},[74808],{"data":74809,"marks":74810,"value":72543,"nodeType":864},{},[],{"data":74812,"content":74813,"nodeType":945},{},[74814],{"data":74815,"content":74816,"nodeType":860},{},[74817],{"data":74818,"marks":74819,"value":72553,"nodeType":864},{},[],{"data":74821,"content":74824,"nodeType":996},{"target":74822},{"sys":74823},{"id":72558,"type":1001,"linkType":1002},[],{"data":74826,"content":74829,"nodeType":996},{"target":74827},{"sys":74828},{"id":72564,"type":1001,"linkType":1002},[],{"data":74831,"content":74832,"nodeType":860},{},[74833],{"data":74834,"marks":74835,"value":72572,"nodeType":864},{},[],{"data":74837,"content":74838,"nodeType":860},{},[74839],{"data":74840,"marks":74841,"value":72579,"nodeType":864},{},[],{"data":74843,"content":74844,"nodeType":1005},{},[],{"data":74846,"content":74847,"nodeType":1009},{},[74848],{"data":74849,"marks":74850,"value":72590,"nodeType":864},{},[74851],{"type":899},{"data":74853,"content":74854,"nodeType":860},{},[74855,74858,74865],{"data":74856,"marks":74857,"value":72597,"nodeType":864},{},[],{"data":74859,"content":74860,"nodeType":883},{"uri":72600},[74861],{"data":74862,"marks":74863,"value":72606,"nodeType":864},{},[74864],{"type":1455},{"data":74866,"marks":74867,"value":72610,"nodeType":864},{},[],{"data":74869,"content":74870,"nodeType":860},{},[74871],{"data":74872,"marks":74873,"value":72617,"nodeType":864},{},[],{"data":74875,"content":74878,"nodeType":996},{"target":74876},{"sys":74877},{"id":72622,"type":1001,"linkType":1002},[],{"data":74880,"content":74881,"nodeType":860},{},[74882,74885,74892],{"data":74883,"marks":74884,"value":72630,"nodeType":864},{},[],{"data":74886,"content":74887,"nodeType":883},{"uri":52377},[74888],{"data":74889,"marks":74890,"value":72638,"nodeType":864},{},[74891],{"type":1455},{"data":74893,"marks":74894,"value":2924,"nodeType":864},{},[],{"data":74896,"content":74899,"nodeType":996},{"target":74897},{"sys":74898},{"id":72646,"type":1001,"linkType":1002},[],{"data":74901,"content":74902,"nodeType":860},{},[74903,74906,74913],{"data":74904,"marks":74905,"value":72654,"nodeType":864},{},[],{"data":74907,"content":74908,"nodeType":883},{"uri":72657},[74909],{"data":74910,"marks":74911,"value":441,"nodeType":864},{},[74912],{"type":1455},{"data":74914,"marks":74915,"value":72666,"nodeType":864},{},[],{"data":74917,"content":74918,"nodeType":860},{},[74919],{"data":74920,"marks":74921,"value":72673,"nodeType":864},{},[],{"data":74923,"content":74924,"nodeType":1005},{},[],{"data":74926,"content":74927,"nodeType":1009},{},[74928],{"data":74929,"marks":74930,"value":72684,"nodeType":864},{},[74931],{"type":899},{"data":74933,"content":74934,"nodeType":860},{},[74935],{"data":74936,"marks":74937,"value":72691,"nodeType":864},{},[],{"data":74939,"content":74940,"nodeType":860},{},[74941,74944,74951,74954,74961,74964,74971],{"data":74942,"marks":74943,"value":72698,"nodeType":864},{},[],{"data":74945,"content":74946,"nodeType":883},{"uri":72701},[74947],{"data":74948,"marks":74949,"value":72707,"nodeType":864},{},[74950],{"type":1455},{"data":74952,"marks":74953,"value":902,"nodeType":864},{},[],{"data":74955,"content":74956,"nodeType":883},{"uri":72713},[74957],{"data":74958,"marks":74959,"value":18962,"nodeType":864},{},[74960],{"type":1455},{"data":74962,"marks":74963,"value":72722,"nodeType":864},{},[],{"data":74965,"content":74966,"nodeType":883},{"uri":72725},[74967],{"data":74968,"marks":74969,"value":72731,"nodeType":864},{},[74970],{"type":1455},{"data":74972,"marks":74973,"value":72735,"nodeType":864},{},[],{"data":74975,"content":74976,"nodeType":860},{},[74977,74980],{"data":74978,"marks":74979,"value":72742,"nodeType":864},{},[],{"data":74981,"marks":74982,"value":72747,"nodeType":864},{},[74983],{"type":899},{"data":74985,"content":74986,"nodeType":1005},{},[],{"data":74988,"content":74989,"nodeType":1009},{},[74990],{"data":74991,"marks":74992,"value":72758,"nodeType":864},{},[74993],{"type":899},{"data":74995,"content":74996,"nodeType":860},{},[74997,75000,75006],{"data":74998,"marks":74999,"value":72765,"nodeType":864},{},[],{"data":75001,"content":75002,"nodeType":883},{"uri":14307},[75003],{"data":75004,"marks":75005,"value":19763,"nodeType":864},{},[],{"data":75007,"marks":75008,"value":72775,"nodeType":864},{},[],{"data":75010,"content":75011,"nodeType":860},{},[75012],{"data":75013,"marks":75014,"value":72782,"nodeType":864},{},[],{"data":75016,"content":75017,"nodeType":860},{},[75018,75021,75025],{"data":75019,"marks":75020,"value":72789,"nodeType":864},{},[],{"data":75022,"marks":75023,"value":72794,"nodeType":864},{},[75024],{"type":899},{"data":75026,"marks":75027,"value":72798,"nodeType":864},{},[],{"data":75029,"content":75030,"nodeType":860},{},[75031],{"data":75032,"marks":75033,"value":72805,"nodeType":864},{},[],{"data":75035,"content":75036,"nodeType":860},{},[75037],{"data":75038,"marks":75039,"value":72812,"nodeType":864},{},[],{"data":75041,"content":75044,"nodeType":996},{"target":75042},{"sys":75043},{"id":72817,"type":1001,"linkType":1002},[],{"data":75046,"content":75047,"nodeType":860},{},[75048],{"data":75049,"marks":75050,"value":72825,"nodeType":864},{},[],{"data":75052,"content":75053,"nodeType":1005},{},[],{"data":75055,"content":75056,"nodeType":1009},{},[75057],{"data":75058,"marks":75059,"value":72836,"nodeType":864},{},[75060],{"type":899},{"data":75062,"content":75063,"nodeType":860},{},[75064],{"data":75065,"marks":75066,"value":72843,"nodeType":864},{},[],{"data":75068,"content":75069,"nodeType":941},{},[75070,75079,75088,75097,75106],{"data":75071,"content":75072,"nodeType":945},{},[75073],{"data":75074,"content":75075,"nodeType":860},{},[75076],{"data":75077,"marks":75078,"value":72856,"nodeType":864},{},[],{"data":75080,"content":75081,"nodeType":945},{},[75082],{"data":75083,"content":75084,"nodeType":860},{},[75085],{"data":75086,"marks":75087,"value":72866,"nodeType":864},{},[],{"data":75089,"content":75090,"nodeType":945},{},[75091],{"data":75092,"content":75093,"nodeType":860},{},[75094],{"data":75095,"marks":75096,"value":72876,"nodeType":864},{},[],{"data":75098,"content":75099,"nodeType":945},{},[75100],{"data":75101,"content":75102,"nodeType":860},{},[75103],{"data":75104,"marks":75105,"value":72886,"nodeType":864},{},[],{"data":75107,"content":75108,"nodeType":945},{},[75109],{"data":75110,"content":75111,"nodeType":860},{},[75112],{"data":75113,"marks":75114,"value":72896,"nodeType":864},{},[],{"data":75116,"content":75117,"nodeType":860},{},[75118],{"data":75119,"marks":75120,"value":72903,"nodeType":864},{},[],{"data":75122,"content":75123,"nodeType":1005},{},[],{"data":75125,"content":75126,"nodeType":1009},{},[75127],{"data":75128,"marks":75129,"value":72914,"nodeType":864},{},[75130],{"type":899},{"data":75132,"content":75135,"nodeType":996},{"target":75133},{"sys":75134},{"id":72919,"type":1001,"linkType":1002},[],{"data":75137,"content":75138,"nodeType":860},{},[75139],{"data":75140,"marks":75141,"value":72927,"nodeType":864},{},[],{"data":75143,"content":75144,"nodeType":860},{},[75145],{"data":75146,"marks":75147,"value":72934,"nodeType":864},{},[],{"data":75149,"content":75152,"nodeType":996},{"target":75150},{"sys":75151},{"id":72939,"type":1001,"linkType":1002},[],{"data":75154,"content":75155,"nodeType":860},{},[75156],{"data":75157,"marks":75158,"value":72947,"nodeType":864},{},[],{"data":75160,"content":75161,"nodeType":941},{},[75162,75175],{"data":75163,"content":75164,"nodeType":945},{},[75165],{"data":75166,"content":75167,"nodeType":860},{},[75168,75172],{"data":75169,"marks":75170,"value":72961,"nodeType":864},{},[75171],{"type":899},{"data":75173,"marks":75174,"value":72965,"nodeType":864},{},[],{"data":75176,"content":75177,"nodeType":945},{},[75178],{"data":75179,"content":75180,"nodeType":860},{},[75181,75185],{"data":75182,"marks":75183,"value":72976,"nodeType":864},{},[75184],{"type":899},{"data":75186,"marks":75187,"value":72980,"nodeType":864},{},[],{"data":75189,"content":75190,"nodeType":860},{},[75191],{"data":75192,"marks":75193,"value":72987,"nodeType":864},{},[],{"data":75195,"content":75196,"nodeType":860},{},[75197],{"data":75198,"marks":75199,"value":72994,"nodeType":864},{},[],{"data":75201,"content":75204,"nodeType":996},{"target":75202},{"sys":75203},{"id":72999,"type":1001,"linkType":1002},[],{"data":75206,"content":75207,"nodeType":860},{},[75208],{"data":75209,"marks":75210,"value":73007,"nodeType":864},{},[],{"data":75212,"content":75215,"nodeType":996},{"target":75213},{"sys":75214},{"id":73012,"type":1001,"linkType":1002},[],{"data":75217,"content":75218,"nodeType":1312},{},[75219],{"data":75220,"marks":75221,"value":73021,"nodeType":864},{},[75222],{"type":899},{"data":75224,"content":75225,"nodeType":860},{},[75226,75229,75236],{"data":75227,"marks":75228,"value":48437,"nodeType":864},{},[],{"data":75230,"content":75231,"nodeType":883},{"uri":14430},[75232],{"data":75233,"marks":75234,"value":14435,"nodeType":864},{},[75235],{"type":1455},{"data":75237,"marks":75238,"value":73038,"nodeType":864},{},[],{"data":75240,"content":75241,"nodeType":860},{},[75242],{"data":75243,"marks":75244,"value":73045,"nodeType":864},{},[],{"data":75246,"content":75247,"nodeType":941},{},[75248,75257,75266],{"data":75249,"content":75250,"nodeType":945},{},[75251],{"data":75252,"content":75253,"nodeType":860},{},[75254],{"data":75255,"marks":75256,"value":73058,"nodeType":864},{},[],{"data":75258,"content":75259,"nodeType":945},{},[75260],{"data":75261,"content":75262,"nodeType":860},{},[75263],{"data":75264,"marks":75265,"value":73068,"nodeType":864},{},[],{"data":75267,"content":75268,"nodeType":945},{},[75269],{"data":75270,"content":75271,"nodeType":860},{},[75272],{"data":75273,"marks":75274,"value":73078,"nodeType":864},{},[],{"data":75276,"content":75277,"nodeType":860},{},[75278],{"data":75279,"marks":75280,"value":73085,"nodeType":864},{},[],{"data":75282,"content":75283,"nodeType":941},{},[75284,75293,75302],{"data":75285,"content":75286,"nodeType":945},{},[75287],{"data":75288,"content":75289,"nodeType":860},{},[75290],{"data":75291,"marks":75292,"value":73098,"nodeType":864},{},[],{"data":75294,"content":75295,"nodeType":945},{},[75296],{"data":75297,"content":75298,"nodeType":860},{},[75299],{"data":75300,"marks":75301,"value":73108,"nodeType":864},{},[],{"data":75303,"content":75304,"nodeType":945},{},[75305],{"data":75306,"content":75307,"nodeType":860},{},[75308],{"data":75309,"marks":75310,"value":73118,"nodeType":864},{},[],{"data":75312,"content":75313,"nodeType":1005},{},[],{"data":75315,"content":75316,"nodeType":1009},{},[75317],{"data":75318,"marks":75319,"value":73129,"nodeType":864},{},[75320],{"type":899},{"data":75322,"content":75323,"nodeType":860},{},[75324],{"data":75325,"marks":75326,"value":73136,"nodeType":864},{},[],{"data":75328,"content":75331,"nodeType":996},{"target":75329},{"sys":75330},{"id":73141,"type":1001,"linkType":1002},[],{"data":75333,"content":75334,"nodeType":860},{},[75335,75338,75345],{"data":75336,"marks":75337,"value":73149,"nodeType":864},{},[],{"data":75339,"content":75340,"nodeType":883},{"uri":14307},[75341],{"data":75342,"marks":75343,"value":73157,"nodeType":864},{},[75344],{"type":1455},{"data":75346,"marks":75347,"value":73161,"nodeType":864},{},[],{"data":75349,"content":75350,"nodeType":860},{},[75351],{"data":75352,"marks":75353,"value":73168,"nodeType":864},{},[],{"data":75355,"content":75356,"nodeType":860},{},[75357,75360,75367,75370,75377],{"data":75358,"marks":75359,"value":16863,"nodeType":864},{},[],{"data":75361,"content":75362,"nodeType":883},{"uri":16866},[75363],{"data":75364,"marks":75365,"value":16871,"nodeType":864},{},[75366],{"type":1455},{"data":75368,"marks":75369,"value":52968,"nodeType":864},{},[],{"data":75371,"content":75372,"nodeType":883},{"uri":1700},[75373],{"data":75374,"marks":75375,"value":16894,"nodeType":864},{},[75376],{"type":1455},{"data":75378,"marks":75379,"value":2924,"nodeType":864},{},[],{"data":75381,"content":75384,"nodeType":996},{"target":75382},{"sys":75383},{"id":73199,"type":1001,"linkType":1002},[],{"data":75386,"content":75387,"nodeType":860},{},[75388],{"data":75389,"marks":75390,"value":21,"nodeType":864},{},[],{"items":75392},[75393,75395],{"sys":75394,"name":13779},{"id":13778},{"sys":75396,"name":342},{"id":13775},{"items":75398},[75399],{"fullName":22309,"firstName":22310,"jobTitle":22311,"profilePicture":75400},{"url":22313},{"__typename":2059,"sys":75402,"content":75403,"title":75983,"synopsis":75984,"hashTags":59,"publishedDate":75985,"slug":75986,"tagsCollection":75987,"authorsCollection":75993},{"id":39982},{"json":75404},{"data":75405,"content":75406,"nodeType":856},{},[75407,75414,75421,75428,75434,75441,75444,75452,75459,75466,75473,75479,75486,75492,75499,75505,75512,75518,75548,75555,75561,75568,75574,75581,75587,75594,75637,75640,75648,75655,75662,75669,75675,75678,75686,75693,75713,75719,75725,75731,75738,75744,75750,75770,75773,75781,75800,75806,75813,75831,75839,75846,75853,75860,75878,75886,75893,75899,75902,75909,75916,75923,75926,75933,75940,75946,75972,75977],{"data":75408,"content":75409,"nodeType":860},{},[75410],{"data":75411,"marks":75412,"value":75413,"nodeType":864},{},[],"We recently investigated a sophisticated phishing campaign targeting Google Workspace and Facebook Business accounts with Calendly-themed phishing lures, based around a fake job opportunity. ",{"data":75415,"content":75416,"nodeType":860},{},[75417],{"data":75418,"marks":75419,"value":75420,"nodeType":864},{},[],"We were first alerted to the campaign when a Push customer was hit with a highly targeted email-based attack, where the attacker used an Attacker-in-the-Middle (AiTM) phishing toolkit to target the customer’s Google Workspace account. ",{"data":75422,"content":75423,"nodeType":860},{},[75424],{"data":75425,"marks":75426,"value":75427,"nodeType":864},{},[],"In this case, Google was the customer’s primary enterprise IdP account, used to access native Google suite apps as well as SSO to downstream apps — effectively, the front door to their business IT stack. Despite this, the attacker’s MO was specifically the takeover of accounts used for the management of digital ads. ",{"data":75429,"content":75433,"nodeType":996},{"target":75430},{"sys":75431},{"id":75432,"type":1001,"linkType":1002},"5oivBCf1Fqvnq0GNCSko8f",[],{"data":75435,"content":75436,"nodeType":860},{},[75437],{"data":75438,"marks":75439,"value":75440,"nodeType":864},{},[],"In this blog post, we break down the various TTPs used by the attacker across the campaign, and consider why ad management platforms are being specifically targeted.  ",{"data":75442,"content":75443,"nodeType":1005},{},[],{"data":75445,"content":75446,"nodeType":1009},{},[75447],{"data":75448,"marks":75449,"value":75451,"nodeType":864},{},[75450],{"type":899},"Variant 1: Targeting Google Workspace with a sophisticated email phish ",{"data":75453,"content":75454,"nodeType":860},{},[75455],{"data":75456,"marks":75457,"value":75458,"nodeType":864},{},[],"The first phishing variant we analyzed began with a multi-stage phishing email lure, framed as a job opportunity for LVMH (Louis Vuitton Moët Hennessy), which oversees more than 75 brands across sectors like fashion, cosmetics, watches, and spirits. The specific delivery address is impersonating “Inside LVMH”, the talent acquisition and training arm of LVMH.  ",{"data":75460,"content":75461,"nodeType":860},{},[75462],{"data":75463,"marks":75464,"value":75465,"nodeType":864},{},[],"This lure is notable for multiple reasons. It is highly targeted, well-written, populated with information from the victim, and coming from what appears to be a legitimate employee of LVMH. Even if the victim was initially suspicious, searching for the recruiter’s name would appear to confirm their identity.  ",{"data":75467,"content":75468,"nodeType":860},{},[75469],{"data":75470,"marks":75471,"value":75472,"nodeType":864},{},[],"It is possible, even likely, that this interaction was operated using AI, using information scraped from the internet — but in any case, the outcome achieved is highly convincing. ",{"data":75474,"content":75478,"nodeType":996},{"target":75475},{"sys":75476},{"id":75477,"type":1001,"linkType":1002},"46BYpquURERbkhWc6C2Lpc",[],{"data":75480,"content":75481,"nodeType":860},{},[75482],{"data":75483,"marks":75484,"value":75485,"nodeType":864},{},[],"Only after the victim has responded to an initial email was the phishing link delivered under the guise of a Calendly link to book time for a call. ",{"data":75487,"content":75491,"nodeType":996},{"target":75488},{"sys":75489},{"id":75490,"type":1001,"linkType":1002},"37GBkfXGEdWvdQbMq65sad",[],{"data":75493,"content":75494,"nodeType":860},{},[75495],{"data":75496,"marks":75497,"value":75498,"nodeType":864},{},[],"Clicking the link takes the victim to an authentic-looking page impersonating a Calendly landing page.",{"data":75500,"content":75504,"nodeType":996},{"target":75501},{"sys":75502},{"id":75503,"type":1001,"linkType":1002},"1DwOPzK7mxsoJlEBp8cMpr",[],{"data":75506,"content":75507,"nodeType":860},{},[75508],{"data":75509,"marks":75510,"value":75511,"nodeType":864},{},[],"After completing the CAPTCHA check and selecting \"Continue with Google” the victim is redirected to an AiTM phishing page designed to capture Google Workspace credentials, with specific branding impersonating Calendly — making this visually distinct from most common Google-themed phishing pages. ",{"data":75513,"content":75517,"nodeType":996},{"target":75514},{"sys":75515},{"id":75516,"type":1001,"linkType":1002},"u1SY1uUX23sxfBYLpyaKb",[],{"data":75519,"content":75520,"nodeType":860},{},[75521,75525,75533,75537,75544],{"data":75522,"marks":75523,"value":75524,"nodeType":864},{},[],"This page uses ",{"data":75526,"content":75527,"nodeType":883},{"uri":72467},[75528],{"data":75529,"marks":75530,"value":75532,"nodeType":864},{},[75531],{"type":1455},"specific targeting parameters",{"data":75534,"marks":75535,"value":75536,"nodeType":864},{},[]," to ensure that only the intended recipient is able to access the page’s malicious functionality — a well-known ",{"data":75538,"content":75539,"nodeType":883},{"uri":14307},[75540],{"data":75541,"marks":75542,"value":14312,"nodeType":864},{},[75543],{"type":1455},{"data":75545,"marks":75546,"value":75547,"nodeType":864},{},[]," to prevent security analysts from being able to fully analyse the page (as malicious elements are not rendered until this check is completed). ",{"data":75549,"content":75550,"nodeType":860},{},[75551],{"data":75552,"marks":75553,"value":75554,"nodeType":864},{},[],"As you can see in the example below, attempts to use any email other than the intended victim’s email domain are blocked.   ",{"data":75556,"content":75560,"nodeType":996},{"target":75557},{"sys":75558},{"id":75559,"type":1001,"linkType":1002},"5m8LvVYjXz0zrITgTWqxio",[],{"data":75562,"content":75563,"nodeType":860},{},[75564],{"data":75565,"marks":75566,"value":75567,"nodeType":864},{},[],"Only entering an allowed email domain loads the password entry field. ",{"data":75569,"content":75573,"nodeType":996},{"target":75570},{"sys":75571},{"id":75572,"type":1001,"linkType":1002},"6KFRJSsgk2pB6x67kWdpws",[],{"data":75575,"content":75576,"nodeType":860},{},[75577],{"data":75578,"marks":75579,"value":75580,"nodeType":864},{},[],"We identified a number of pages that appear to be part of the same campaign. All these pages have the same visual style, Calendly-themed lure targeting Google Workspace accounts, and appear to match real employees of the respective companies being impersonated. ",{"data":75582,"content":75586,"nodeType":996},{"target":75583},{"sys":75584},{"id":75585,"type":1001,"linkType":1002},"zMkN1U5QlvIEcfOGmhBBf",[],{"data":75588,"content":75589,"nodeType":860},{},[75590],{"data":75591,"marks":75592,"value":75593,"nodeType":864},{},[],"The different pages include:",{"data":75595,"content":75596,"nodeType":941},{},[75597,75607,75617,75627],{"data":75598,"content":75599,"nodeType":945},{},[75600],{"data":75601,"content":75602,"nodeType":860},{},[75603],{"data":75604,"marks":75605,"value":75606,"nodeType":864},{},[],"A different visual match for the LVMH page.",{"data":75608,"content":75609,"nodeType":945},{},[75610],{"data":75611,"content":75612,"nodeType":860},{},[75613],{"data":75614,"marks":75615,"value":75616,"nodeType":864},{},[],"A Lego recruitment themed page.",{"data":75618,"content":75619,"nodeType":945},{},[75620],{"data":75621,"content":75622,"nodeType":860},{},[75623],{"data":75624,"marks":75625,"value":75626,"nodeType":864},{},[],"A Mastercard HR themed page.",{"data":75628,"content":75629,"nodeType":945},{},[75630],{"data":75631,"content":75632,"nodeType":860},{},[75633],{"data":75634,"marks":75635,"value":75636,"nodeType":864},{},[],"An Uber recruitment themed page.",{"data":75638,"content":75639,"nodeType":1005},{},[],{"data":75641,"content":75642,"nodeType":1009},{},[75643],{"data":75644,"marks":75645,"value":75647,"nodeType":864},{},[75646],{"type":899},"Variant 2: Targeting Facebook Business accounts",{"data":75649,"content":75650,"nodeType":860},{},[75651],{"data":75652,"marks":75653,"value":75654,"nodeType":864},{},[],"Upon further investigation, we found links to a second phishing page style that appears to be part of a longer campaign targeting Facebook accounts, dating back more than two years. ",{"data":75656,"content":75657,"nodeType":860},{},[75658],{"data":75659,"marks":75660,"value":75661,"nodeType":864},{},[],"In total, we identified 31 unique URLs associated with the same campaign, many of which were recycled over time to impersonate different brands. ",{"data":75663,"content":75664,"nodeType":860},{},[75665],{"data":75666,"marks":75667,"value":75668,"nodeType":864},{},[],"Since most of these pages appeared to be older (and no longer live) they could not be analysed further, beyond giving an indication of how the phishing campaign has evolved over time. ",{"data":75670,"content":75674,"nodeType":996},{"target":75671},{"sys":75672},{"id":75673,"type":1001,"linkType":1002},"5PFRI9XtNVdkpYiRoIYpF",[],{"data":75676,"content":75677,"nodeType":1005},{},[],{"data":75679,"content":75680,"nodeType":1009},{},[75681],{"data":75682,"marks":75683,"value":75685,"nodeType":864},{},[75684],{"type":899},"Variant 3: Targeting both Google and Facebook accounts",{"data":75687,"content":75688,"nodeType":860},{},[75689],{"data":75690,"marks":75691,"value":75692,"nodeType":864},{},[],"We also discovered a third, more recent variant targeting both Google and Facebook accounts with Calendly-styled pages.",{"data":75694,"content":75695,"nodeType":860},{},[75696,75700,75709],{"data":75697,"marks":75698,"value":75699,"nodeType":864},{},[],"This variant looks to leverage a Browser-in-the-Browser style pop-up window similar to the ",{"data":75701,"content":75703,"nodeType":883},{"uri":75702},"https://pushsecurity.com/blog/analyzing-the-latest-sneaky2fa-phishing-page/",[75704],{"data":75705,"marks":75706,"value":75708,"nodeType":864},{},[75707],{"type":1455},"Sneaky2FA attacks we reported on recently",{"data":75710,"marks":75711,"value":75712,"nodeType":864},{},[],". BITB allows the attacker to mask the phishing page URL by presenting a fake URL set by the attacker, inside a pop-up login window. ",{"data":75714,"content":75718,"nodeType":996},{"target":75715},{"sys":75716},{"id":75717,"type":1001,"linkType":1002},"7w4cmyqPvhxAFrokaK9CE1",[],{"data":75720,"content":75724,"nodeType":996},{"target":75721},{"sys":75722},{"id":75723,"type":1001,"linkType":1002},"6FUSNecz0BXLxJxoJTsALD",[],{"data":75726,"content":75730,"nodeType":996},{"target":75727},{"sys":75728},{"id":75729,"type":1001,"linkType":1002},"2zwFDrgsLuxi4Xv2q0nPFK",[],{"data":75732,"content":75733,"nodeType":860},{},[75734],{"data":75735,"marks":75736,"value":75737,"nodeType":864},{},[],"The attacker also implemented additional anti-analysis functionality, beyond the specific domain targeting we observed in the first page variant — the result of which meant the page IP blocked us from interacting with it further. ",{"data":75739,"content":75743,"nodeType":996},{"target":75740},{"sys":75741},{"id":75742,"type":1001,"linkType":1002},"3ZPdxi5cGZcn5hF1ISIUa7",[],{"data":75745,"content":75749,"nodeType":996},{"target":75746},{"sys":75747},{"id":75748,"type":1001,"linkType":1002},"3J5pmgNL9LevE1FdX4oksf",[],{"data":75751,"content":75752,"nodeType":860},{},[75753,75757,75766],{"data":75754,"marks":75755,"value":75756,"nodeType":864},{},[],"Often ",{"data":75758,"content":75760,"nodeType":883},{"uri":75759},"https://phishing-techniques.pushsecurity.com/techniques/anti-sandbox/",[75761],{"data":75762,"marks":75763,"value":75765,"nodeType":864},{},[75764],{"type":1455},"accessing dev tools",{"data":75767,"marks":75768,"value":75769,"nodeType":864},{},[]," on a page is enough to trigger this, specifically targeting security analysts and web-crawling security bots/tools. ",{"data":75771,"content":75772,"nodeType":1005},{},[],{"data":75774,"content":75775,"nodeType":1009},{},[75776],{"data":75777,"marks":75778,"value":75780,"nodeType":864},{},[75779],{"type":899},"Why are attackers targeting business ad management accounts?",{"data":75782,"content":75783,"nodeType":860},{},[75784,75788,75796],{"data":75785,"marks":75786,"value":75787,"nodeType":864},{},[],"The campaign shows signs of being a long-running, targeted initiative focused on compromising accounts responsible for managing digital ads on behalf of businesses. The attackers have demonstrated that they are continuing to iterate on their TTPs, introducing new page styles with increased sophistication, and new ",{"data":75789,"content":75791,"nodeType":883},{"uri":75790},"https://phishing-techniques.pushsecurity.com/#techniques-table",[75792],{"data":75793,"marks":75794,"value":19763,"nodeType":864},{},[75795],{"type":1455},{"data":75797,"marks":75798,"value":75799,"nodeType":864},{},[]," to defeat security analysis tools.  ",{"data":75801,"content":75805,"nodeType":996},{"target":75802},{"sys":75803},{"id":75804,"type":1001,"linkType":1002},"m5GsTsDb55T70MU2m72B1",[],{"data":75807,"content":75808,"nodeType":860},{},[75809],{"data":75810,"marks":75811,"value":75812,"nodeType":864},{},[],"We also discovered that Google recently issued a security warning specifically for agency organizations managing ads for a number of businesses, urging them to create security alerts whenever a new account is added to a Manager Account (MCC) used to view and manage multiple Google Ads accounts from a single view. ",{"data":75814,"content":75815,"nodeType":860},{},[75816,75820,75827],{"data":75817,"marks":75818,"value":75819,"nodeType":864},{},[],"With malvertising on the rise as an increasingly popular attack vector for the delivery of AITM phishing, malware downloads, and ",{"data":75821,"content":75822,"nodeType":883},{"uri":52377},[75823],{"data":75824,"marks":75825,"value":315,"nodeType":864},{},[75826],{"type":1455},{"data":75828,"marks":75829,"value":75830,"nodeType":864},{},[]," (4 in 5 ClickFix attacks intercepted by Push were delivered via Google Search), it makes sense that attackers are looking to increase their web of accounts from which to launch malicious ads. ",{"data":75832,"content":75833,"nodeType":1312},{},[75834],{"data":75835,"marks":75836,"value":75838,"nodeType":864},{},[75837],{"type":899},"Why are attackers turning to malvertising?",{"data":75840,"content":75841,"nodeType":860},{},[75842],{"data":75843,"marks":75844,"value":75845,"nodeType":864},{},[],"Malvertising attacks delivered over search engines (e.g. Google Search) and social media apps (Facebook, LinkedIn, etc.) are a great way to catch victims unawares while also evading typically email-based anti-phishing controls. ",{"data":75847,"content":75848,"nodeType":860},{},[75849],{"data":75850,"marks":75851,"value":75852,"nodeType":864},{},[],"The flipside of this is that malvertising attacks are less likely to be targeted than phishing delivered directly to the victim via a direct message (i.e. email, social media DM, instant messenger app, SMS, etc.). ",{"data":75854,"content":75855,"nodeType":860},{},[75856],{"data":75857,"marks":75858,"value":75859,"nodeType":864},{},[],"However, that isn’t to say that malvertising attacks can’t be targeted. For example, Google Ads can be targeted to searches coming from specific geographic locations, tailored to specific email domain matches, or specific device types (e.g. desktop, mobile, etc.). If you know where your target organization is located, you can tailor the ad to that location. Even more precise ad targeting can be achieved on social media platforms. ",{"data":75861,"content":75862,"nodeType":860},{},[75863,75867,75874],{"data":75864,"marks":75865,"value":75866,"nodeType":864},{},[],"Malvertising is an effective way to launch “watering hole” style attacks, casting a wide net to harvest credentials and account access that can be re-sold to other criminals for a fee, or leveraged by partners in the cybercriminal ecosystem as part of major cyber breaches (such as the recent attacks by the “",{"data":75868,"content":75869,"nodeType":883},{"uri":16015},[75870],{"data":75871,"marks":75872,"value":16018,"nodeType":864},{},[75873],{"type":1455},{"data":75875,"marks":75876,"value":75877,"nodeType":864},{},[],"” criminal collective, all of which began with identity-based initial access). For this reason, credentials and access are an increasingly profitable commodity for cyber criminals. ",{"data":75879,"content":75880,"nodeType":1312},{},[75881],{"data":75882,"marks":75883,"value":75885,"nodeType":864},{},[75884],{"type":899},"Additional considerations",{"data":75887,"content":75888,"nodeType":860},{},[75889],{"data":75890,"marks":75891,"value":75892,"nodeType":864},{},[],"As previously mentioned, compromising a Google Workspace account (particularly where it is the primary enterprise cloud platform used by the organization) provides comprehensive access to business apps, data, and functionality that can be exploited by attackers — effectively, it’s the access point to modern business IT. There’s a good chance that attackers establishing a foothold in this way would look to leverage this access further, or at least sell on that access to a criminal group looking to take the attack further. ",{"data":75894,"content":75898,"nodeType":996},{"target":75895},{"sys":75896},{"id":75897,"type":1001,"linkType":1002},"7jnQqRk0JuqEtrQ3HXy3f8",[],{"data":75900,"content":75901,"nodeType":1005},{},[],{"data":75903,"content":75904,"nodeType":1009},{},[75905],{"data":75906,"marks":75907,"value":73021,"nodeType":864},{},[75908],{"type":899},{"data":75910,"content":75911,"nodeType":860},{},[75912],{"data":75913,"marks":75914,"value":75915,"nodeType":864},{},[],"We have opted not to provide the domains associated with that campaign to preserve the privacy of the individuals being impersonated by the attacker. In many cases, their full name was included in the URL for the phishing page, while their name and profile picture (most likely scraped from LinkedIn) are also visible on the landing page. ",{"data":75917,"content":75918,"nodeType":860},{},[75919],{"data":75920,"marks":75921,"value":75922,"nodeType":864},{},[],"However, with the rate at which these domains were spun up and subsequently taken down (by the attacker or the site hosting the links) IoC-based detections for campaigns such as this are of limited value. ",{"data":75924,"content":75925,"nodeType":1005},{},[],{"data":75927,"content":75928,"nodeType":1009},{},[75929],{"data":75930,"marks":75931,"value":3578,"nodeType":864},{},[75932],{"type":899},{"data":75934,"content":75935,"nodeType":860},{},[75936],{"data":75937,"marks":75938,"value":75939,"nodeType":864},{},[],"Push researchers are continuously analysing and developing new detections based on the latest phishing kits and TTPs which enables us to stay two steps ahead of attackers.",{"data":75941,"content":75942,"nodeType":860},{},[75943],{"data":75944,"marks":75945,"value":57938,"nodeType":864},{},[],{"data":75947,"content":75948,"nodeType":860},{},[75949,75952,75959,75962,75969],{"data":75950,"marks":75951,"value":16863,"nodeType":864},{},[],{"data":75953,"content":75954,"nodeType":883},{"uri":16866},[75955],{"data":75956,"marks":75957,"value":16871,"nodeType":864},{},[75958],{"type":1455},{"data":75960,"marks":75961,"value":52968,"nodeType":864},{},[],{"data":75963,"content":75964,"nodeType":883},{"uri":1700},[75965],{"data":75966,"marks":75967,"value":16894,"nodeType":864},{},[75968],{"type":1455},{"data":75970,"marks":75971,"value":2924,"nodeType":864},{},[],{"data":75973,"content":75976,"nodeType":996},{"target":75974},{"sys":75975},{"id":73199,"type":1001,"linkType":1002},[],{"data":75978,"content":75979,"nodeType":860},{},[75980],{"data":75981,"marks":75982,"value":21,"nodeType":864},{},[],"Uncovering a Calendly-themed phishing campaign targeting business ad manager accounts","Investigating a phishing campaign targeting Google Ads Manager MCC accounts to propagate malvertising lures. ","2025-12-02T00:00:00.000Z","uncovering-a-calendly-themed-phishing-campaign",{"items":75988},[75989,75991],{"sys":75990,"name":13779},{"id":13778},{"sys":75992,"name":342},{"id":13775},{"items":75994},[75995],{"fullName":22309,"firstName":22310,"jobTitle":22311,"profilePicture":75996},{"url":22313},{"__typename":2059,"sys":75998,"content":75999,"title":57965,"synopsis":57966,"hashTags":59,"publishedDate":57967,"slug":57968,"tagsCollection":76815,"authorsCollection":76821},{"id":57022},{"json":76000},{"data":76001,"content":76002,"nodeType":856},{},[76003,76009,76015,76021,76024,76031,76037,76043,76048,76054,76059,76075,76081,76091,76094,76101,76107,76120,76126,76136,76141,76144,76151,76158,76163,76171,76187,76195,76201,76209,76224,76232,76238,76246,76272,76280,76286,76294,76310,76315,76323,76329,76337,76370,76373,76380,76388,76404,76412,76418,76426,76452,76457,76465,76471,76476,76479,76486,76494,76500,76551,76556,76559,76566,76574,76580,76585,76588,76595,76601,76607,76667,76673,76728,76734,76737,76744,76750,76756,76761,76764,76771,76777,76783,76789],{"data":76004,"content":76005,"nodeType":860},{},[76006],{"data":76007,"marks":76008,"value":57033,"nodeType":864},{},[],{"data":76010,"content":76011,"nodeType":860},{},[76012],{"data":76013,"marks":76014,"value":57040,"nodeType":864},{},[],{"data":76016,"content":76017,"nodeType":860},{},[76018],{"data":76019,"marks":76020,"value":57047,"nodeType":864},{},[],{"data":76022,"content":76023,"nodeType":1005},{},[],{"data":76025,"content":76026,"nodeType":1009},{},[76027],{"data":76028,"marks":76029,"value":57058,"nodeType":864},{},[76030],{"type":899},{"data":76032,"content":76033,"nodeType":860},{},[76034],{"data":76035,"marks":76036,"value":57065,"nodeType":864},{},[],{"data":76038,"content":76039,"nodeType":860},{},[76040],{"data":76041,"marks":76042,"value":57072,"nodeType":864},{},[],{"data":76044,"content":76047,"nodeType":996},{"target":76045},{"sys":76046},{"id":57077,"type":1001,"linkType":1002},[],{"data":76049,"content":76050,"nodeType":860},{},[76051],{"data":76052,"marks":76053,"value":57085,"nodeType":864},{},[],{"data":76055,"content":76058,"nodeType":996},{"target":76056},{"sys":76057},{"id":57090,"type":1001,"linkType":1002},[],{"data":76060,"content":76061,"nodeType":860},{},[76062,76065,76072],{"data":76063,"marks":76064,"value":57098,"nodeType":864},{},[],{"data":76066,"content":76067,"nodeType":883},{"uri":16553},[76068],{"data":76069,"marks":76070,"value":57106,"nodeType":864},{},[76071],{"type":1455},{"data":76073,"marks":76074,"value":57110,"nodeType":864},{},[],{"data":76076,"content":76077,"nodeType":860},{},[76078],{"data":76079,"marks":76080,"value":57117,"nodeType":864},{},[],{"data":76082,"content":76083,"nodeType":860},{},[76084,76087],{"data":76085,"marks":76086,"value":57124,"nodeType":864},{},[],{"data":76088,"marks":76089,"value":57129,"nodeType":864},{},[76090],{"type":899},{"data":76092,"content":76093,"nodeType":1005},{},[],{"data":76095,"content":76096,"nodeType":1009},{},[76097],{"data":76098,"marks":76099,"value":57140,"nodeType":864},{},[76100],{"type":899},{"data":76102,"content":76103,"nodeType":860},{},[76104],{"data":76105,"marks":76106,"value":57147,"nodeType":864},{},[],{"data":76108,"content":76109,"nodeType":860},{},[76110,76113,76117],{"data":76111,"marks":76112,"value":57154,"nodeType":864},{},[],{"data":76114,"marks":76115,"value":57159,"nodeType":864},{},[76116],{"type":899},{"data":76118,"marks":76119,"value":57163,"nodeType":864},{},[],{"data":76121,"content":76122,"nodeType":860},{},[76123],{"data":76124,"marks":76125,"value":57170,"nodeType":864},{},[],{"data":76127,"content":76128,"nodeType":860},{},[76129,76132],{"data":76130,"marks":76131,"value":57177,"nodeType":864},{},[],{"data":76133,"marks":76134,"value":57182,"nodeType":864},{},[76135],{"type":899},{"data":76137,"content":76140,"nodeType":996},{"target":76138},{"sys":76139},{"id":57187,"type":1001,"linkType":1002},[],{"data":76142,"content":76143,"nodeType":1005},{},[],{"data":76145,"content":76146,"nodeType":1009},{},[76147],{"data":76148,"marks":76149,"value":57199,"nodeType":864},{},[76150],{"type":899},{"data":76152,"content":76153,"nodeType":1312},{},[76154],{"data":76155,"marks":76156,"value":57207,"nodeType":864},{},[76157],{"type":899},{"data":76159,"content":76162,"nodeType":996},{"target":76160},{"sys":76161},{"id":57212,"type":1001,"linkType":1002},[],{"data":76164,"content":76165,"nodeType":860},{},[76166],{"data":76167,"marks":76168,"value":57222,"nodeType":864},{},[76169,76170],{"type":899},{"type":1455},{"data":76172,"content":76173,"nodeType":860},{},[76174,76177,76184],{"data":76175,"marks":76176,"value":57229,"nodeType":864},{},[],{"data":76178,"content":76179,"nodeType":883},{"uri":57232},[76180],{"data":76181,"marks":76182,"value":57238,"nodeType":864},{},[76183],{"type":1455},{"data":76185,"marks":76186,"value":57242,"nodeType":864},{},[],{"data":76188,"content":76189,"nodeType":860},{},[76190],{"data":76191,"marks":76192,"value":57251,"nodeType":864},{},[76193,76194],{"type":899},{"type":1455},{"data":76196,"content":76197,"nodeType":860},{},[76198],{"data":76199,"marks":76200,"value":57258,"nodeType":864},{},[],{"data":76202,"content":76203,"nodeType":860},{},[76204],{"data":76205,"marks":76206,"value":57267,"nodeType":864},{},[76207,76208],{"type":899},{"type":1455},{"data":76210,"content":76211,"nodeType":860},{},[76212,76215,76221],{"data":76213,"marks":76214,"value":57274,"nodeType":864},{},[],{"data":76216,"content":76217,"nodeType":883},{"uri":57277},[76218],{"data":76219,"marks":76220,"value":57282,"nodeType":864},{},[],{"data":76222,"marks":76223,"value":57286,"nodeType":864},{},[],{"data":76225,"content":76226,"nodeType":860},{},[76227],{"data":76228,"marks":76229,"value":57295,"nodeType":864},{},[76230,76231],{"type":899},{"type":1455},{"data":76233,"content":76234,"nodeType":860},{},[76235],{"data":76236,"marks":76237,"value":57302,"nodeType":864},{},[],{"data":76239,"content":76240,"nodeType":860},{},[76241],{"data":76242,"marks":76243,"value":57311,"nodeType":864},{},[76244,76245],{"type":899},{"type":1455},{"data":76247,"content":76248,"nodeType":860},{},[76249,76252,76259,76262,76269],{"data":76250,"marks":76251,"value":57318,"nodeType":864},{},[],{"data":76253,"content":76254,"nodeType":883},{"uri":3751},[76255],{"data":76256,"marks":76257,"value":57326,"nodeType":864},{},[76258],{"type":1455},{"data":76260,"marks":76261,"value":57330,"nodeType":864},{},[],{"data":76263,"content":76264,"nodeType":883},{"uri":57333},[76265],{"data":76266,"marks":76267,"value":29819,"nodeType":864},{},[76268],{"type":1455},{"data":76270,"marks":76271,"value":57342,"nodeType":864},{},[],{"data":76273,"content":76274,"nodeType":860},{},[76275],{"data":76276,"marks":76277,"value":57351,"nodeType":864},{},[76278,76279],{"type":899},{"type":1455},{"data":76281,"content":76282,"nodeType":860},{},[76283],{"data":76284,"marks":76285,"value":57358,"nodeType":864},{},[],{"data":76287,"content":76288,"nodeType":860},{},[76289],{"data":76290,"marks":76291,"value":57367,"nodeType":864},{},[76292,76293],{"type":899},{"type":1455},{"data":76295,"content":76296,"nodeType":860},{},[76297,76300,76307],{"data":76298,"marks":76299,"value":57374,"nodeType":864},{},[],{"data":76301,"content":76302,"nodeType":883},{"uri":57333},[76303],{"data":76304,"marks":76305,"value":29819,"nodeType":864},{},[76306],{"type":1455},{"data":76308,"marks":76309,"value":57385,"nodeType":864},{},[],{"data":76311,"content":76314,"nodeType":996},{"target":76312},{"sys":76313},{"id":57390,"type":1001,"linkType":1002},[],{"data":76316,"content":76317,"nodeType":860},{},[76318],{"data":76319,"marks":76320,"value":57400,"nodeType":864},{},[76321,76322],{"type":899},{"type":1455},{"data":76324,"content":76325,"nodeType":860},{},[76326],{"data":76327,"marks":76328,"value":57407,"nodeType":864},{},[],{"data":76330,"content":76331,"nodeType":860},{},[76332],{"data":76333,"marks":76334,"value":57416,"nodeType":864},{},[76335,76336],{"type":899},{"type":1455},{"data":76338,"content":76339,"nodeType":860},{},[76340,76343,76349,76352,76358,76361,76367],{"data":76341,"marks":76342,"value":57423,"nodeType":864},{},[],{"data":76344,"content":76345,"nodeType":883},{"uri":57426},[76346],{"data":76347,"marks":76348,"value":57431,"nodeType":864},{},[],{"data":76350,"marks":76351,"value":902,"nodeType":864},{},[],{"data":76353,"content":76354,"nodeType":883},{"uri":57437},[76355],{"data":76356,"marks":76357,"value":57442,"nodeType":864},{},[],{"data":76359,"marks":76360,"value":57446,"nodeType":864},{},[],{"data":76362,"content":76363,"nodeType":883},{"uri":23901},[76364],{"data":76365,"marks":76366,"value":57453,"nodeType":864},{},[],{"data":76368,"marks":76369,"value":57457,"nodeType":864},{},[],{"data":76371,"content":76372,"nodeType":1005},{},[],{"data":76374,"content":76375,"nodeType":1312},{},[76376],{"data":76377,"marks":76378,"value":57468,"nodeType":864},{},[76379],{"type":899},{"data":76381,"content":76382,"nodeType":860},{},[76383],{"data":76384,"marks":76385,"value":57477,"nodeType":864},{},[76386,76387],{"type":899},{"type":1455},{"data":76389,"content":76390,"nodeType":860},{},[76391,76394,76401],{"data":76392,"marks":76393,"value":57484,"nodeType":864},{},[],{"data":76395,"content":76396,"nodeType":883},{"uri":57487},[76397],{"data":76398,"marks":76399,"value":57493,"nodeType":864},{},[76400],{"type":1455},{"data":76402,"marks":76403,"value":57497,"nodeType":864},{},[],{"data":76405,"content":76406,"nodeType":860},{},[76407],{"data":76408,"marks":76409,"value":57506,"nodeType":864},{},[76410,76411],{"type":899},{"type":1455},{"data":76413,"content":76414,"nodeType":860},{},[76415],{"data":76416,"marks":76417,"value":57513,"nodeType":864},{},[],{"data":76419,"content":76420,"nodeType":860},{},[76421],{"data":76422,"marks":76423,"value":57522,"nodeType":864},{},[76424,76425],{"type":899},{"type":1455},{"data":76427,"content":76428,"nodeType":860},{},[76429,76432,76439,76442,76449],{"data":76430,"marks":76431,"value":57529,"nodeType":864},{},[],{"data":76433,"content":76434,"nodeType":883},{"uri":57532},[76435],{"data":76436,"marks":76437,"value":57538,"nodeType":864},{},[76438],{"type":1455},{"data":76440,"marks":76441,"value":57542,"nodeType":864},{},[],{"data":76443,"content":76444,"nodeType":883},{"uri":57545},[76445],{"data":76446,"marks":76447,"value":57551,"nodeType":864},{},[76448],{"type":1455},{"data":76450,"marks":76451,"value":57555,"nodeType":864},{},[],{"data":76453,"content":76456,"nodeType":996},{"target":76454},{"sys":76455},{"id":57560,"type":1001,"linkType":1002},[],{"data":76458,"content":76459,"nodeType":860},{},[76460],{"data":76461,"marks":76462,"value":57570,"nodeType":864},{},[76463,76464],{"type":899},{"type":1455},{"data":76466,"content":76467,"nodeType":860},{},[76468],{"data":76469,"marks":76470,"value":57577,"nodeType":864},{},[],{"data":76472,"content":76475,"nodeType":996},{"target":76473},{"sys":76474},{"id":57582,"type":1001,"linkType":1002},[],{"data":76477,"content":76478,"nodeType":1005},{},[],{"data":76480,"content":76481,"nodeType":1312},{},[76482],{"data":76483,"marks":76484,"value":694,"nodeType":864},{},[76485],{"type":899},{"data":76487,"content":76488,"nodeType":860},{},[76489],{"data":76490,"marks":76491,"value":57602,"nodeType":864},{},[76492,76493],{"type":899},{"type":1455},{"data":76495,"content":76496,"nodeType":860},{},[76497],{"data":76498,"marks":76499,"value":57609,"nodeType":864},{},[],{"data":76501,"content":76502,"nodeType":941},{},[76503,76516,76529],{"data":76504,"content":76505,"nodeType":945},{},[76506],{"data":76507,"content":76508,"nodeType":860},{},[76509,76513],{"data":76510,"marks":76511,"value":57623,"nodeType":864},{},[76512],{"type":899},{"data":76514,"marks":76515,"value":57627,"nodeType":864},{},[],{"data":76517,"content":76518,"nodeType":945},{},[76519],{"data":76520,"content":76521,"nodeType":860},{},[76522,76526],{"data":76523,"marks":76524,"value":57638,"nodeType":864},{},[76525],{"type":899},{"data":76527,"marks":76528,"value":57642,"nodeType":864},{},[],{"data":76530,"content":76531,"nodeType":945},{},[76532],{"data":76533,"content":76534,"nodeType":860},{},[76535,76539,76542,76548],{"data":76536,"marks":76537,"value":57653,"nodeType":864},{},[76538],{"type":899},{"data":76540,"marks":76541,"value":57657,"nodeType":864},{},[],{"data":76543,"content":76544,"nodeType":883},{"uri":16566},[76545],{"data":76546,"marks":76547,"value":57664,"nodeType":864},{},[],{"data":76549,"marks":76550,"value":57668,"nodeType":864},{},[],{"data":76552,"content":76555,"nodeType":996},{"target":76553},{"sys":76554},{"id":57673,"type":1001,"linkType":1002},[],{"data":76557,"content":76558,"nodeType":1005},{},[],{"data":76560,"content":76561,"nodeType":1312},{},[76562],{"data":76563,"marks":76564,"value":699,"nodeType":864},{},[76565],{"type":899},{"data":76567,"content":76568,"nodeType":860},{},[76569],{"data":76570,"marks":76571,"value":57693,"nodeType":864},{},[76572,76573],{"type":899},{"type":1455},{"data":76575,"content":76576,"nodeType":860},{},[76577],{"data":76578,"marks":76579,"value":57700,"nodeType":864},{},[],{"data":76581,"content":76584,"nodeType":996},{"target":76582},{"sys":76583},{"id":57705,"type":1001,"linkType":1002},[],{"data":76586,"content":76587,"nodeType":1005},{},[],{"data":76589,"content":76590,"nodeType":1009},{},[76591],{"data":76592,"marks":76593,"value":57717,"nodeType":864},{},[76594],{"type":899},{"data":76596,"content":76597,"nodeType":860},{},[76598],{"data":76599,"marks":76600,"value":57724,"nodeType":864},{},[],{"data":76602,"content":76603,"nodeType":860},{},[76604],{"data":76605,"marks":76606,"value":57731,"nodeType":864},{},[],{"data":76608,"content":76609,"nodeType":941},{},[76610,76629,76648],{"data":76611,"content":76612,"nodeType":945},{},[76613],{"data":76614,"content":76615,"nodeType":860},{},[76616,76619,76626],{"data":76617,"marks":76618,"value":57744,"nodeType":864},{},[],{"data":76620,"content":76621,"nodeType":883},{"uri":57747},[76622],{"data":76623,"marks":76624,"value":19538,"nodeType":864},{},[76625],{"type":1455},{"data":76627,"marks":76628,"value":57756,"nodeType":864},{},[],{"data":76630,"content":76631,"nodeType":945},{},[76632],{"data":76633,"content":76634,"nodeType":860},{},[76635,76638,76645],{"data":76636,"marks":76637,"value":57766,"nodeType":864},{},[],{"data":76639,"content":76640,"nodeType":883},{"uri":57769},[76641],{"data":76642,"marks":76643,"value":57775,"nodeType":864},{},[76644],{"type":1455},{"data":76646,"marks":76647,"value":57756,"nodeType":864},{},[],{"data":76649,"content":76650,"nodeType":945},{},[76651],{"data":76652,"content":76653,"nodeType":860},{},[76654,76657,76664],{"data":76655,"marks":76656,"value":57788,"nodeType":864},{},[],{"data":76658,"content":76659,"nodeType":883},{"uri":7170},[76660],{"data":76661,"marks":76662,"value":57796,"nodeType":864},{},[76663],{"type":1455},{"data":76665,"marks":76666,"value":57756,"nodeType":864},{},[],{"data":76668,"content":76669,"nodeType":860},{},[76670],{"data":76671,"marks":76672,"value":57806,"nodeType":864},{},[],{"data":76674,"content":76675,"nodeType":941},{},[76676,76689,76702,76715],{"data":76677,"content":76678,"nodeType":945},{},[76679],{"data":76680,"content":76681,"nodeType":860},{},[76682,76686],{"data":76683,"marks":76684,"value":57820,"nodeType":864},{},[76685],{"type":899},{"data":76687,"marks":76688,"value":57824,"nodeType":864},{},[],{"data":76690,"content":76691,"nodeType":945},{},[76692],{"data":76693,"content":76694,"nodeType":860},{},[76695,76699],{"data":76696,"marks":76697,"value":57835,"nodeType":864},{},[76698],{"type":899},{"data":76700,"marks":76701,"value":57839,"nodeType":864},{},[],{"data":76703,"content":76704,"nodeType":945},{},[76705],{"data":76706,"content":76707,"nodeType":860},{},[76708,76712],{"data":76709,"marks":76710,"value":57850,"nodeType":864},{},[76711],{"type":899},{"data":76713,"marks":76714,"value":57854,"nodeType":864},{},[],{"data":76716,"content":76717,"nodeType":945},{},[76718],{"data":76719,"content":76720,"nodeType":860},{},[76721,76725],{"data":76722,"marks":76723,"value":57865,"nodeType":864},{},[76724],{"type":899},{"data":76726,"marks":76727,"value":57869,"nodeType":864},{},[],{"data":76729,"content":76730,"nodeType":860},{},[76731],{"data":76732,"marks":76733,"value":57876,"nodeType":864},{},[],{"data":76735,"content":76736,"nodeType":1005},{},[],{"data":76738,"content":76739,"nodeType":1009},{},[76740],{"data":76741,"marks":76742,"value":57887,"nodeType":864},{},[76743],{"type":899},{"data":76745,"content":76746,"nodeType":860},{},[76747],{"data":76748,"marks":76749,"value":57894,"nodeType":864},{},[],{"data":76751,"content":76752,"nodeType":860},{},[76753],{"data":76754,"marks":76755,"value":57901,"nodeType":864},{},[],{"data":76757,"content":76760,"nodeType":996},{"target":76758},{"sys":76759},{"id":57906,"type":1001,"linkType":1002},[],{"data":76762,"content":76763,"nodeType":1005},{},[],{"data":76765,"content":76766,"nodeType":1009},{},[76767],{"data":76768,"marks":76769,"value":7533,"nodeType":864},{},[76770],{"type":899},{"data":76772,"content":76773,"nodeType":860},{},[76774],{"data":76775,"marks":76776,"value":57924,"nodeType":864},{},[],{"data":76778,"content":76779,"nodeType":860},{},[76780],{"data":76781,"marks":76782,"value":57931,"nodeType":864},{},[],{"data":76784,"content":76785,"nodeType":860},{},[76786],{"data":76787,"marks":76788,"value":57938,"nodeType":864},{},[],{"data":76790,"content":76791,"nodeType":860},{},[76792,76795,76802,76805,76812],{"data":76793,"marks":76794,"value":16863,"nodeType":864},{},[],{"data":76796,"content":76797,"nodeType":883},{"uri":16866},[76798],{"data":76799,"marks":76800,"value":16871,"nodeType":864},{},[76801],{"type":1455},{"data":76803,"marks":76804,"value":52968,"nodeType":864},{},[],{"data":76806,"content":76807,"nodeType":883},{"uri":1700},[76808],{"data":76809,"marks":76810,"value":16894,"nodeType":864},{},[76811],{"type":1455},{"data":76813,"marks":76814,"value":2924,"nodeType":864},{},[],{"items":76816},[76817,76819],{"sys":76818,"name":13779},{"id":13778},{"sys":76820,"name":342},{"id":13775},{"items":76822},[76823],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":76824},{"url":2740},"blog/2025-top-phishing-trends",{"json":76827},{"data":76828,"content":76829,"nodeType":856},{},[76830],{"data":76831,"content":76832,"nodeType":860},{},[76833],{"data":76834,"marks":76835,"value":76836,"nodeType":864},{},[],"Phishing attacks changed a lot through 2025. Here's the top trends from this year and what they mean for security teams heading into 2026. \n",{"id":73223,"publishedAt":76838},"2026-08-12T11:53:25.080Z",{"items":76840},[76841,76843],{"sys":76842,"name":342},{"id":13775},{"sys":76844,"name":13779},{"id":13778},{"items":76846},[76847,76849,76851,76853,76855,76857,76859,76861,76863,76865,76867,76869,76871,76873,76875,76877,76879,76881,76883,76885,76887,76889],{"sys":76848,"name":279,"slug":280,"tier":31},{"id":276},{"sys":76850,"name":413,"slug":414,"tier":31},{"id":410},{"sys":76852,"name":519,"slug":520,"tier":31},{"id":516},{"sys":76854,"name":642,"slug":643,"tier":31},{"id":639},{"sys":76856,"name":342,"slug":343,"tier":31},{"id":339},{"sys":76858,"name":261,"slug":262,"tier":45},{"id":258},{"sys":76860,"name":315,"slug":316,"tier":45},{"id":312},{"sys":76862,"name":324,"slug":325,"tier":45},{"id":321},{"sys":76864,"name":466,"slug":467,"tier":45},{"id":463},{"sys":76866,"name":511,"slug":512,"tier":45},{"id":508},{"sys":76868,"name":440,"slug":441,"tier":45},{"id":437},{"sys":76870,"name":563,"slug":564,"tier":45},{"id":560},{"sys":76872,"name":475,"slug":476,"tier":45},{"id":472},{"sys":76874,"name":607,"slug":608,"tier":45},{"id":604},{"sys":76876,"name":484,"slug":485,"tier":45},{"id":481},{"sys":76878,"name":360,"slug":361,"tier":45},{"id":357},{"sys":76880,"name":288,"slug":289,"tier":45},{"id":285},{"sys":76882,"name":422,"slug":423,"tier":45},{"id":419},{"sys":76884,"name":571,"slug":572,"tier":45},{"id":568},{"sys":76886,"name":431,"slug":432,"tier":45},{"id":428},{"sys":76888,"name":493,"slug":494,"tier":45},{"id":490},{"sys":76890,"name":404,"slug":405,"tier":45},{"id":401},"7YvVxDfBfBbYwky5xPf7erTDCzlAGNd3QktYmRe96W8",{"id":76893,"title":57965,"authorsCollection":76894,"content":76899,"extension":228,"faqItemsCollection":77888,"faqTitle":59,"featured":6,"hashTags":59,"meta":77890,"metaTitle":77891,"ogImage":59,"postType":59861,"publishedDate":57967,"relatedBlogPostsCollection":77892,"slug":57968,"stem":79681,"subtitle":59,"summary":79682,"synopsis":57966,"sys":79693,"tagsCollection":79695,"topicsCollection":79701,"__hash__":79733},"blog/blog/scattered-lapsus-hunters.json",{"items":76895},[76896],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":76897,"profilePicture":76898},[15231],{"url":2740},{"json":76900,"links":77715},{"data":76901,"content":76902,"nodeType":856},{},[76903,76909,76915,76921,76924,76931,76937,76943,76948,76954,76959,76975,76981,76991,76994,77001,77007,77020,77026,77036,77041,77044,77051,77058,77063,77071,77087,77095,77101,77109,77124,77132,77138,77146,77172,77180,77186,77194,77210,77215,77223,77229,77237,77270,77273,77280,77288,77304,77312,77318,77326,77352,77357,77365,77371,77376,77379,77386,77394,77400,77451,77456,77459,77466,77474,77480,77485,77488,77495,77501,77507,77567,77573,77628,77634,77637,77644,77650,77656,77661,77664,77671,77677,77683,77689],{"data":76904,"content":76905,"nodeType":860},{},[76906],{"data":76907,"marks":76908,"value":57033,"nodeType":864},{},[],{"data":76910,"content":76911,"nodeType":860},{},[76912],{"data":76913,"marks":76914,"value":57040,"nodeType":864},{},[],{"data":76916,"content":76917,"nodeType":860},{},[76918],{"data":76919,"marks":76920,"value":57047,"nodeType":864},{},[],{"data":76922,"content":76923,"nodeType":1005},{},[],{"data":76925,"content":76926,"nodeType":1009},{},[76927],{"data":76928,"marks":76929,"value":57058,"nodeType":864},{},[76930],{"type":899},{"data":76932,"content":76933,"nodeType":860},{},[76934],{"data":76935,"marks":76936,"value":57065,"nodeType":864},{},[],{"data":76938,"content":76939,"nodeType":860},{},[76940],{"data":76941,"marks":76942,"value":57072,"nodeType":864},{},[],{"data":76944,"content":76947,"nodeType":996},{"target":76945},{"sys":76946},{"id":57077,"type":1001,"linkType":1002},[],{"data":76949,"content":76950,"nodeType":860},{},[76951],{"data":76952,"marks":76953,"value":57085,"nodeType":864},{},[],{"data":76955,"content":76958,"nodeType":996},{"target":76956},{"sys":76957},{"id":57090,"type":1001,"linkType":1002},[],{"data":76960,"content":76961,"nodeType":860},{},[76962,76965,76972],{"data":76963,"marks":76964,"value":57098,"nodeType":864},{},[],{"data":76966,"content":76967,"nodeType":883},{"uri":16553},[76968],{"data":76969,"marks":76970,"value":57106,"nodeType":864},{},[76971],{"type":1455},{"data":76973,"marks":76974,"value":57110,"nodeType":864},{},[],{"data":76976,"content":76977,"nodeType":860},{},[76978],{"data":76979,"marks":76980,"value":57117,"nodeType":864},{},[],{"data":76982,"content":76983,"nodeType":860},{},[76984,76987],{"data":76985,"marks":76986,"value":57124,"nodeType":864},{},[],{"data":76988,"marks":76989,"value":57129,"nodeType":864},{},[76990],{"type":899},{"data":76992,"content":76993,"nodeType":1005},{},[],{"data":76995,"content":76996,"nodeType":1009},{},[76997],{"data":76998,"marks":76999,"value":57140,"nodeType":864},{},[77000],{"type":899},{"data":77002,"content":77003,"nodeType":860},{},[77004],{"data":77005,"marks":77006,"value":57147,"nodeType":864},{},[],{"data":77008,"content":77009,"nodeType":860},{},[77010,77013,77017],{"data":77011,"marks":77012,"value":57154,"nodeType":864},{},[],{"data":77014,"marks":77015,"value":57159,"nodeType":864},{},[77016],{"type":899},{"data":77018,"marks":77019,"value":57163,"nodeType":864},{},[],{"data":77021,"content":77022,"nodeType":860},{},[77023],{"data":77024,"marks":77025,"value":57170,"nodeType":864},{},[],{"data":77027,"content":77028,"nodeType":860},{},[77029,77032],{"data":77030,"marks":77031,"value":57177,"nodeType":864},{},[],{"data":77033,"marks":77034,"value":57182,"nodeType":864},{},[77035],{"type":899},{"data":77037,"content":77040,"nodeType":996},{"target":77038},{"sys":77039},{"id":57187,"type":1001,"linkType":1002},[],{"data":77042,"content":77043,"nodeType":1005},{},[],{"data":77045,"content":77046,"nodeType":1009},{},[77047],{"data":77048,"marks":77049,"value":57199,"nodeType":864},{},[77050],{"type":899},{"data":77052,"content":77053,"nodeType":1312},{},[77054],{"data":77055,"marks":77056,"value":57207,"nodeType":864},{},[77057],{"type":899},{"data":77059,"content":77062,"nodeType":996},{"target":77060},{"sys":77061},{"id":57212,"type":1001,"linkType":1002},[],{"data":77064,"content":77065,"nodeType":860},{},[77066],{"data":77067,"marks":77068,"value":57222,"nodeType":864},{},[77069,77070],{"type":899},{"type":1455},{"data":77072,"content":77073,"nodeType":860},{},[77074,77077,77084],{"data":77075,"marks":77076,"value":57229,"nodeType":864},{},[],{"data":77078,"content":77079,"nodeType":883},{"uri":57232},[77080],{"data":77081,"marks":77082,"value":57238,"nodeType":864},{},[77083],{"type":1455},{"data":77085,"marks":77086,"value":57242,"nodeType":864},{},[],{"data":77088,"content":77089,"nodeType":860},{},[77090],{"data":77091,"marks":77092,"value":57251,"nodeType":864},{},[77093,77094],{"type":899},{"type":1455},{"data":77096,"content":77097,"nodeType":860},{},[77098],{"data":77099,"marks":77100,"value":57258,"nodeType":864},{},[],{"data":77102,"content":77103,"nodeType":860},{},[77104],{"data":77105,"marks":77106,"value":57267,"nodeType":864},{},[77107,77108],{"type":899},{"type":1455},{"data":77110,"content":77111,"nodeType":860},{},[77112,77115,77121],{"data":77113,"marks":77114,"value":57274,"nodeType":864},{},[],{"data":77116,"content":77117,"nodeType":883},{"uri":57277},[77118],{"data":77119,"marks":77120,"value":57282,"nodeType":864},{},[],{"data":77122,"marks":77123,"value":57286,"nodeType":864},{},[],{"data":77125,"content":77126,"nodeType":860},{},[77127],{"data":77128,"marks":77129,"value":57295,"nodeType":864},{},[77130,77131],{"type":899},{"type":1455},{"data":77133,"content":77134,"nodeType":860},{},[77135],{"data":77136,"marks":77137,"value":57302,"nodeType":864},{},[],{"data":77139,"content":77140,"nodeType":860},{},[77141],{"data":77142,"marks":77143,"value":57311,"nodeType":864},{},[77144,77145],{"type":899},{"type":1455},{"data":77147,"content":77148,"nodeType":860},{},[77149,77152,77159,77162,77169],{"data":77150,"marks":77151,"value":57318,"nodeType":864},{},[],{"data":77153,"content":77154,"nodeType":883},{"uri":3751},[77155],{"data":77156,"marks":77157,"value":57326,"nodeType":864},{},[77158],{"type":1455},{"data":77160,"marks":77161,"value":57330,"nodeType":864},{},[],{"data":77163,"content":77164,"nodeType":883},{"uri":57333},[77165],{"data":77166,"marks":77167,"value":29819,"nodeType":864},{},[77168],{"type":1455},{"data":77170,"marks":77171,"value":57342,"nodeType":864},{},[],{"data":77173,"content":77174,"nodeType":860},{},[77175],{"data":77176,"marks":77177,"value":57351,"nodeType":864},{},[77178,77179],{"type":899},{"type":1455},{"data":77181,"content":77182,"nodeType":860},{},[77183],{"data":77184,"marks":77185,"value":57358,"nodeType":864},{},[],{"data":77187,"content":77188,"nodeType":860},{},[77189],{"data":77190,"marks":77191,"value":57367,"nodeType":864},{},[77192,77193],{"type":899},{"type":1455},{"data":77195,"content":77196,"nodeType":860},{},[77197,77200,77207],{"data":77198,"marks":77199,"value":57374,"nodeType":864},{},[],{"data":77201,"content":77202,"nodeType":883},{"uri":57333},[77203],{"data":77204,"marks":77205,"value":29819,"nodeType":864},{},[77206],{"type":1455},{"data":77208,"marks":77209,"value":57385,"nodeType":864},{},[],{"data":77211,"content":77214,"nodeType":996},{"target":77212},{"sys":77213},{"id":57390,"type":1001,"linkType":1002},[],{"data":77216,"content":77217,"nodeType":860},{},[77218],{"data":77219,"marks":77220,"value":57400,"nodeType":864},{},[77221,77222],{"type":899},{"type":1455},{"data":77224,"content":77225,"nodeType":860},{},[77226],{"data":77227,"marks":77228,"value":57407,"nodeType":864},{},[],{"data":77230,"content":77231,"nodeType":860},{},[77232],{"data":77233,"marks":77234,"value":57416,"nodeType":864},{},[77235,77236],{"type":899},{"type":1455},{"data":77238,"content":77239,"nodeType":860},{},[77240,77243,77249,77252,77258,77261,77267],{"data":77241,"marks":77242,"value":57423,"nodeType":864},{},[],{"data":77244,"content":77245,"nodeType":883},{"uri":57426},[77246],{"data":77247,"marks":77248,"value":57431,"nodeType":864},{},[],{"data":77250,"marks":77251,"value":902,"nodeType":864},{},[],{"data":77253,"content":77254,"nodeType":883},{"uri":57437},[77255],{"data":77256,"marks":77257,"value":57442,"nodeType":864},{},[],{"data":77259,"marks":77260,"value":57446,"nodeType":864},{},[],{"data":77262,"content":77263,"nodeType":883},{"uri":23901},[77264],{"data":77265,"marks":77266,"value":57453,"nodeType":864},{},[],{"data":77268,"marks":77269,"value":57457,"nodeType":864},{},[],{"data":77271,"content":77272,"nodeType":1005},{},[],{"data":77274,"content":77275,"nodeType":1312},{},[77276],{"data":77277,"marks":77278,"value":57468,"nodeType":864},{},[77279],{"type":899},{"data":77281,"content":77282,"nodeType":860},{},[77283],{"data":77284,"marks":77285,"value":57477,"nodeType":864},{},[77286,77287],{"type":899},{"type":1455},{"data":77289,"content":77290,"nodeType":860},{},[77291,77294,77301],{"data":77292,"marks":77293,"value":57484,"nodeType":864},{},[],{"data":77295,"content":77296,"nodeType":883},{"uri":57487},[77297],{"data":77298,"marks":77299,"value":57493,"nodeType":864},{},[77300],{"type":1455},{"data":77302,"marks":77303,"value":57497,"nodeType":864},{},[],{"data":77305,"content":77306,"nodeType":860},{},[77307],{"data":77308,"marks":77309,"value":57506,"nodeType":864},{},[77310,77311],{"type":899},{"type":1455},{"data":77313,"content":77314,"nodeType":860},{},[77315],{"data":77316,"marks":77317,"value":57513,"nodeType":864},{},[],{"data":77319,"content":77320,"nodeType":860},{},[77321],{"data":77322,"marks":77323,"value":57522,"nodeType":864},{},[77324,77325],{"type":899},{"type":1455},{"data":77327,"content":77328,"nodeType":860},{},[77329,77332,77339,77342,77349],{"data":77330,"marks":77331,"value":57529,"nodeType":864},{},[],{"data":77333,"content":77334,"nodeType":883},{"uri":57532},[77335],{"data":77336,"marks":77337,"value":57538,"nodeType":864},{},[77338],{"type":1455},{"data":77340,"marks":77341,"value":57542,"nodeType":864},{},[],{"data":77343,"content":77344,"nodeType":883},{"uri":57545},[77345],{"data":77346,"marks":77347,"value":57551,"nodeType":864},{},[77348],{"type":1455},{"data":77350,"marks":77351,"value":57555,"nodeType":864},{},[],{"data":77353,"content":77356,"nodeType":996},{"target":77354},{"sys":77355},{"id":57560,"type":1001,"linkType":1002},[],{"data":77358,"content":77359,"nodeType":860},{},[77360],{"data":77361,"marks":77362,"value":57570,"nodeType":864},{},[77363,77364],{"type":899},{"type":1455},{"data":77366,"content":77367,"nodeType":860},{},[77368],{"data":77369,"marks":77370,"value":57577,"nodeType":864},{},[],{"data":77372,"content":77375,"nodeType":996},{"target":77373},{"sys":77374},{"id":57582,"type":1001,"linkType":1002},[],{"data":77377,"content":77378,"nodeType":1005},{},[],{"data":77380,"content":77381,"nodeType":1312},{},[77382],{"data":77383,"marks":77384,"value":694,"nodeType":864},{},[77385],{"type":899},{"data":77387,"content":77388,"nodeType":860},{},[77389],{"data":77390,"marks":77391,"value":57602,"nodeType":864},{},[77392,77393],{"type":899},{"type":1455},{"data":77395,"content":77396,"nodeType":860},{},[77397],{"data":77398,"marks":77399,"value":57609,"nodeType":864},{},[],{"data":77401,"content":77402,"nodeType":941},{},[77403,77416,77429],{"data":77404,"content":77405,"nodeType":945},{},[77406],{"data":77407,"content":77408,"nodeType":860},{},[77409,77413],{"data":77410,"marks":77411,"value":57623,"nodeType":864},{},[77412],{"type":899},{"data":77414,"marks":77415,"value":57627,"nodeType":864},{},[],{"data":77417,"content":77418,"nodeType":945},{},[77419],{"data":77420,"content":77421,"nodeType":860},{},[77422,77426],{"data":77423,"marks":77424,"value":57638,"nodeType":864},{},[77425],{"type":899},{"data":77427,"marks":77428,"value":57642,"nodeType":864},{},[],{"data":77430,"content":77431,"nodeType":945},{},[77432],{"data":77433,"content":77434,"nodeType":860},{},[77435,77439,77442,77448],{"data":77436,"marks":77437,"value":57653,"nodeType":864},{},[77438],{"type":899},{"data":77440,"marks":77441,"value":57657,"nodeType":864},{},[],{"data":77443,"content":77444,"nodeType":883},{"uri":16566},[77445],{"data":77446,"marks":77447,"value":57664,"nodeType":864},{},[],{"data":77449,"marks":77450,"value":57668,"nodeType":864},{},[],{"data":77452,"content":77455,"nodeType":996},{"target":77453},{"sys":77454},{"id":57673,"type":1001,"linkType":1002},[],{"data":77457,"content":77458,"nodeType":1005},{},[],{"data":77460,"content":77461,"nodeType":1312},{},[77462],{"data":77463,"marks":77464,"value":699,"nodeType":864},{},[77465],{"type":899},{"data":77467,"content":77468,"nodeType":860},{},[77469],{"data":77470,"marks":77471,"value":57693,"nodeType":864},{},[77472,77473],{"type":899},{"type":1455},{"data":77475,"content":77476,"nodeType":860},{},[77477],{"data":77478,"marks":77479,"value":57700,"nodeType":864},{},[],{"data":77481,"content":77484,"nodeType":996},{"target":77482},{"sys":77483},{"id":57705,"type":1001,"linkType":1002},[],{"data":77486,"content":77487,"nodeType":1005},{},[],{"data":77489,"content":77490,"nodeType":1009},{},[77491],{"data":77492,"marks":77493,"value":57717,"nodeType":864},{},[77494],{"type":899},{"data":77496,"content":77497,"nodeType":860},{},[77498],{"data":77499,"marks":77500,"value":57724,"nodeType":864},{},[],{"data":77502,"content":77503,"nodeType":860},{},[77504],{"data":77505,"marks":77506,"value":57731,"nodeType":864},{},[],{"data":77508,"content":77509,"nodeType":941},{},[77510,77529,77548],{"data":77511,"content":77512,"nodeType":945},{},[77513],{"data":77514,"content":77515,"nodeType":860},{},[77516,77519,77526],{"data":77517,"marks":77518,"value":57744,"nodeType":864},{},[],{"data":77520,"content":77521,"nodeType":883},{"uri":57747},[77522],{"data":77523,"marks":77524,"value":19538,"nodeType":864},{},[77525],{"type":1455},{"data":77527,"marks":77528,"value":57756,"nodeType":864},{},[],{"data":77530,"content":77531,"nodeType":945},{},[77532],{"data":77533,"content":77534,"nodeType":860},{},[77535,77538,77545],{"data":77536,"marks":77537,"value":57766,"nodeType":864},{},[],{"data":77539,"content":77540,"nodeType":883},{"uri":57769},[77541],{"data":77542,"marks":77543,"value":57775,"nodeType":864},{},[77544],{"type":1455},{"data":77546,"marks":77547,"value":57756,"nodeType":864},{},[],{"data":77549,"content":77550,"nodeType":945},{},[77551],{"data":77552,"content":77553,"nodeType":860},{},[77554,77557,77564],{"data":77555,"marks":77556,"value":57788,"nodeType":864},{},[],{"data":77558,"content":77559,"nodeType":883},{"uri":7170},[77560],{"data":77561,"marks":77562,"value":57796,"nodeType":864},{},[77563],{"type":1455},{"data":77565,"marks":77566,"value":57756,"nodeType":864},{},[],{"data":77568,"content":77569,"nodeType":860},{},[77570],{"data":77571,"marks":77572,"value":57806,"nodeType":864},{},[],{"data":77574,"content":77575,"nodeType":941},{},[77576,77589,77602,77615],{"data":77577,"content":77578,"nodeType":945},{},[77579],{"data":77580,"content":77581,"nodeType":860},{},[77582,77586],{"data":77583,"marks":77584,"value":57820,"nodeType":864},{},[77585],{"type":899},{"data":77587,"marks":77588,"value":57824,"nodeType":864},{},[],{"data":77590,"content":77591,"nodeType":945},{},[77592],{"data":77593,"content":77594,"nodeType":860},{},[77595,77599],{"data":77596,"marks":77597,"value":57835,"nodeType":864},{},[77598],{"type":899},{"data":77600,"marks":77601,"value":57839,"nodeType":864},{},[],{"data":77603,"content":77604,"nodeType":945},{},[77605],{"data":77606,"content":77607,"nodeType":860},{},[77608,77612],{"data":77609,"marks":77610,"value":57850,"nodeType":864},{},[77611],{"type":899},{"data":77613,"marks":77614,"value":57854,"nodeType":864},{},[],{"data":77616,"content":77617,"nodeType":945},{},[77618],{"data":77619,"content":77620,"nodeType":860},{},[77621,77625],{"data":77622,"marks":77623,"value":57865,"nodeType":864},{},[77624],{"type":899},{"data":77626,"marks":77627,"value":57869,"nodeType":864},{},[],{"data":77629,"content":77630,"nodeType":860},{},[77631],{"data":77632,"marks":77633,"value":57876,"nodeType":864},{},[],{"data":77635,"content":77636,"nodeType":1005},{},[],{"data":77638,"content":77639,"nodeType":1009},{},[77640],{"data":77641,"marks":77642,"value":57887,"nodeType":864},{},[77643],{"type":899},{"data":77645,"content":77646,"nodeType":860},{},[77647],{"data":77648,"marks":77649,"value":57894,"nodeType":864},{},[],{"data":77651,"content":77652,"nodeType":860},{},[77653],{"data":77654,"marks":77655,"value":57901,"nodeType":864},{},[],{"data":77657,"content":77660,"nodeType":996},{"target":77658},{"sys":77659},{"id":57906,"type":1001,"linkType":1002},[],{"data":77662,"content":77663,"nodeType":1005},{},[],{"data":77665,"content":77666,"nodeType":1009},{},[77667],{"data":77668,"marks":77669,"value":7533,"nodeType":864},{},[77670],{"type":899},{"data":77672,"content":77673,"nodeType":860},{},[77674],{"data":77675,"marks":77676,"value":57924,"nodeType":864},{},[],{"data":77678,"content":77679,"nodeType":860},{},[77680],{"data":77681,"marks":77682,"value":57931,"nodeType":864},{},[],{"data":77684,"content":77685,"nodeType":860},{},[77686],{"data":77687,"marks":77688,"value":57938,"nodeType":864},{},[],{"data":77690,"content":77691,"nodeType":860},{},[77692,77695,77702,77705,77712],{"data":77693,"marks":77694,"value":16863,"nodeType":864},{},[],{"data":77696,"content":77697,"nodeType":883},{"uri":16866},[77698],{"data":77699,"marks":77700,"value":16871,"nodeType":864},{},[77701],{"type":1455},{"data":77703,"marks":77704,"value":52968,"nodeType":864},{},[],{"data":77706,"content":77707,"nodeType":883},{"uri":1700},[77708],{"data":77709,"marks":77710,"value":16894,"nodeType":864},{},[77711],{"type":1455},{"data":77713,"marks":77714,"value":2924,"nodeType":864},{},[],{"entries":77716},{"hyperlink":77717,"inline":77718,"block":77719},[],[],[77720,77734,77748,77755,77782,77796,77810,77835,77849,77863],{"sys":77721,"__typename":1740,"content":77722,"name":77733,"title":59},{"id":57077},{"json":77723},{"nodeType":856,"data":77724,"content":77725},{},[77726],{"nodeType":860,"data":77727,"content":77728},{},[77729],{"nodeType":864,"value":77730,"marks":77731,"data":77732},"The MGM hack resulted in a 36-hour outage, a $100M hit to its Q3 results, one-time cyber consulting fees in the region of $10M, and a class-action lawsuit later settled for $45M. Less is known about Caesars, except that a ransom of $15M was paid in an attempt to prevent stolen data being leaked online.",[],{},"SLH insight box 1",{"sys":77735,"__typename":1740,"content":77736,"name":77747,"title":59},{"id":57090},{"json":77737},{"nodeType":856,"data":77738,"content":77739},{},[77740],{"nodeType":860,"data":77741,"content":77742},{},[77743],{"nodeType":864,"value":77744,"marks":77745,"data":77746},"The Marks & Spencer ransomware breach resulted in online shopping services being taken offline, stores running low on products, £300M in lost profits, and almost £1B wiped off the company’s stock market valuation at one stage. Co-op proactively pulled the plug on their network to prevent further damage, lessening the impact to a still-sizeable £107m in lost profits.",[],{},"SLH insight box 2",{"sys":77749,"__typename":1724,"title":77750,"caption":77750,"layoutMode":59,"file":77751},{"id":57187},"Big picture view of Scattered Lapsus$ Hunters breaches since 2021.",{"url":77752,"width":77753,"height":77754},"https://images.ctfassets.net/y1cdw1ablpvd/415gvGUy6Ywr2zofY8Phpk/dc9a8461ef07c041fef4a7fb39d0a25b/Screenshot_2026-02-25_at_09.50.56.png",3414,1852,{"sys":77756,"__typename":1740,"content":77757,"name":77781,"title":59},{"id":57212},{"json":77758},{"nodeType":856,"data":77759,"content":77760},{},[77761],{"nodeType":860,"data":77762,"content":77763},{},[77764,77768,77777],{"nodeType":864,"value":77765,"marks":77766,"data":77767},"Stolen credentials were, and still are, one of the easiest ways in for an attacker. They're one of the most abundant resources available to attackers online, with billions leaked as a by-product of phishing, malware infections (infostealers), and data breaches, which are packaged up and resold to other criminals. Sure, ",[],{},{"nodeType":883,"data":77769,"content":77771},{"uri":77770},"https://pushsecurity.com/blog/verified-stolen-credential-detection/",[77772],{"nodeType":864,"value":77773,"marks":77774,"data":77776},"there’s a lot of noise in credential feeds",[77775],{"type":1455},{},{"nodeType":864,"value":77778,"marks":77779,"data":77780}," — but it only takes the attacker to get lucky once. And the steady stream of breaches are living proof of the MFA gaps waiting to be exploited.",[],{},"SLH insight box 3",{"sys":77783,"__typename":1740,"content":77784,"name":77795,"title":59},{"id":57390},{"json":77785},{"nodeType":856,"data":77786,"content":77787},{},[77788],{"nodeType":860,"data":77789,"content":77790},{},[77791],{"nodeType":864,"value":77792,"marks":77793,"data":77794},"A group calling themselves “The Crimson Collective” originally claimed the breach, with Scattered Lapsus$ Hunters becoming the main voice behind the breach at the extortion phase — showing just how interconnected the ecosystem of cybercriminals is.",[],{},"SLH insight box 10",{"sys":77797,"__typename":1740,"content":77798,"name":77809,"title":59},{"id":57560},{"json":77799},{"nodeType":856,"data":77800,"content":77801},{},[77802],{"nodeType":860,"data":77803,"content":77804},{},[77805],{"nodeType":864,"value":77806,"marks":77807,"data":77808},"An identical attack path was attempted against Co-op, but was detected early enough for the security team to pull the plug on their own network. This significantly reduced the disruption, although customer data was still taken by the attacker.",[],{},"SLH insight box 4",{"sys":77811,"__typename":1740,"content":77812,"name":77834,"title":59},{"id":57582},{"json":77813},{"nodeType":856,"data":77814,"content":77815},{},[77816],{"nodeType":860,"data":77817,"content":77818},{},[77819,77822,77830],{"nodeType":864,"value":21,"marks":77820,"data":77821},[],{},{"nodeType":883,"data":77823,"content":77824},{"uri":29089},[77825],{"nodeType":864,"value":77826,"marks":77827,"data":77829},"Jaguar’s Jira tenant was breached",[77828],{"type":1455},{},{"nodeType":864,"value":77831,"marks":77832,"data":77833}," by the “Scattered Lapsus$ Hunters” affiliated “HellCat” group earlier in 2025, which led to an alleged ~350GB of data being stolen. It is highly likely that this inside information from Jira (a platform storing huge amounts of business process information, architectural diagrams, and even improperly stored credentials and secrets) was leveraged in the later ransomware breach.",[],{},"SLH insight box 5",{"sys":77836,"__typename":1740,"content":77837,"name":77848,"title":59},{"id":57673},{"json":77838},{"nodeType":856,"data":77839,"content":77840},{},[77841],{"nodeType":860,"data":77842,"content":77843},{},[77844],{"nodeType":864,"value":77845,"marks":77846,"data":77847},"The Salesloft breach in fact originated from a developer’s GitHub account being phished, which enabled the attacker to pivot into AWS, steal access tokens, and pivot to downstream customer environments.",[],{},"SLH insight box 6",{"sys":77850,"__typename":1740,"content":77851,"name":77862,"title":59},{"id":57705},{"json":77852},{"nodeType":856,"data":77853,"content":77854},{},[77855],{"nodeType":860,"data":77856,"content":77857},{},[77858],{"nodeType":864,"value":77859,"marks":77860,"data":77861},"While the CyberHaven attacks were conducted by an unknown threat group, the MO of the attacker — pursuing financial gain, bypassing traditional defenses — is very much in-line with the Scattered Lapsus$ Hunters TTPs observed. ",[],{},"SLH insight box 7",{"sys":77864,"__typename":1740,"content":77865,"name":77887,"title":59},{"id":57906},{"json":77866},{"nodeType":856,"data":77867,"content":77868},{},[77869],{"nodeType":860,"data":77870,"content":77871},{},[77872,77876,77883],{"nodeType":864,"value":77873,"marks":77874,"data":77875},"One of the common threads from all of these breaches is the risk posed by ",[],{},{"nodeType":883,"data":77877,"content":77878},{"uri":57532},[77879],{"nodeType":864,"value":77880,"marks":77881,"data":77882},"help desk attacks",[],{},{"nodeType":864,"value":77884,"marks":77885,"data":77886},", but it’s easy to over-index here. Naturally, making it possible for help desk operators to reset MFA for all users (including accounts with dangerous privileges) is always going to be targeted — but is fairly easy to address in principle by requiring escalations for high-risk changes. What is more interesting is that the vast majority of the help desk attacks featured in this article involved a single provider that is now no longer contracted by a number of the victims.",[],{},"SLH insight box 8",{"items":77889},[],{},"Analyzing \"Scattered Lapsus$ Hunters\" breaches since 2021",{"items":77893},[77894,78555,79008],{"__typename":2059,"sys":77895,"content":77897,"title":78541,"synopsis":78542,"hashTags":59,"publishedDate":78543,"slug":78544,"tagsCollection":78545,"authorsCollection":78551},{"id":77896},"62Zyr35VUmijkpupWk3hoD",{"json":77898},{"data":77899,"content":77900,"nodeType":856},{},[77901,77917,77924,77927,77935,77942,77949,77969,77975,77982,77989,77996,78003,78006,78014,78021,78027,78034,78042,78049,78056,78062,78080,78086,78093,78100,78107,78113,78116,78124,78142,78149,78181,78188,78195,78201,78208,78215,78222,78225,78233,78249,78255,78262,78269,78275,78282,78289,78292,78300,78307,78327,78370,78377,78384,78391,78394,78402,78409,78416,78423,78426,78434,78441,78472,78492,78499,78502,78509,78516,78523],{"data":77902,"content":77903,"nodeType":860},{},[77904,77908,77913],{"data":77905,"marks":77906,"value":77907,"nodeType":864},{},[],"The view that \"the browser is the new endpoint\" and \"the new battleground for cyber attacks\" is becoming increasingly advocated by security leaders. But what does this ",{"data":77909,"marks":77910,"value":77912,"nodeType":864},{},[77911],{"type":2246},"actually",{"data":77914,"marks":77915,"value":77916,"nodeType":864},{},[]," mean for security teams? ",{"data":77918,"content":77919,"nodeType":860},{},[77920],{"data":77921,"marks":77922,"value":77923,"nodeType":864},{},[],"In this article, we’re cutting out the jargon to explore what a browser-based attack is, and what’s required for effective detection and response. ",{"data":77925,"content":77926,"nodeType":1005},{},[],{"data":77928,"content":77929,"nodeType":1009},{},[77930],{"data":77931,"marks":77932,"value":77934,"nodeType":864},{},[77933],{"type":899},"What is the goal of a browser-based attack?   ",{"data":77936,"content":77937,"nodeType":860},{},[77938],{"data":77939,"marks":77940,"value":77941,"nodeType":864},{},[],"First, it’s important to establish what the point of a browser-based attack is.",{"data":77943,"content":77944,"nodeType":860},{},[77945],{"data":77946,"marks":77947,"value":77948,"nodeType":864},{},[],"In most scenarios, attackers don’t think of themselves as attacking your web browser. Their end-goal is to compromise your business apps and data. That means going after the third-party apps and services that are now the backbone of business IT — and therefore the top target for attackers. ",{"data":77950,"content":77951,"nodeType":860},{},[77952,77956,77965],{"data":77953,"marks":77954,"value":77955,"nodeType":864},{},[],"The most common attack path today sees attackers log into third-party services, dump the data, and monetize it through extortion. You need only look at last year’s ",{"data":77957,"content":77959,"nodeType":883},{"uri":77958},"https://pushsecurity.com/blog/snowflake-retro?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[77960],{"data":77961,"marks":77962,"value":77964,"nodeType":864},{},[77963],{"type":1455},"Snowflake",{"data":77966,"marks":77967,"value":77968,"nodeType":864},{},[]," customer breaches or the still-ongoing Salesforce attacks to see the impact.",{"data":77970,"content":77974,"nodeType":996},{"target":77971},{"sys":77972},{"id":77973,"type":1001,"linkType":1002},"5agrVXzEdwALmew2F5SPDp",[],{"data":77976,"content":77977,"nodeType":860},{},[77978],{"data":77979,"marks":77980,"value":77981,"nodeType":864},{},[],"The most logical way to do this is by targeting users of those apps. And because of the changes to working practices, your users are more accessible than ever to external attackers.",{"data":77983,"content":77984,"nodeType":860},{},[77985],{"data":77986,"marks":77987,"value":77988,"nodeType":864},{},[],"Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content (at least, without significantly impeding their ability to do their jobs).",{"data":77990,"content":77991,"nodeType":860},{},[77992],{"data":77993,"marks":77994,"value":77995,"nodeType":864},{},[],"Given that the browser is the place where business apps are accessed and used, it makes sense that attacks are increasingly playing out there too. ",{"data":77997,"content":77998,"nodeType":860},{},[77999],{"data":78000,"marks":78001,"value":78002,"nodeType":864},{},[],"With that covered off, let’s take a closer look at the most prevalent browser-based attack techniques being used by attackers in the wild today.",{"data":78004,"content":78005,"nodeType":1005},{},[],{"data":78007,"content":78008,"nodeType":1009},{},[78009],{"data":78010,"marks":78011,"value":78013,"nodeType":864},{},[78012],{"type":899},"The 6 key browser-based attacks that security teams need to know about",{"data":78015,"content":78016,"nodeType":860},{},[78017],{"data":78018,"marks":78019,"value":78020,"nodeType":864},{},[],"Attacks that target users in their web browsers have seen an unprecedented rise in recent years. ",{"data":78022,"content":78026,"nodeType":996},{"target":78023},{"sys":78024},{"id":78025,"type":1001,"linkType":1002},"4ogNqZdObSIJXavHP44lom",[],{"data":78028,"content":78029,"nodeType":860},{},[78030],{"data":78031,"marks":78032,"value":78033,"nodeType":864},{},[],"Here's our breakdown of the top 6 browser-based attacks that should be on every security team's radar right now. ",{"data":78035,"content":78036,"nodeType":1312},{},[78037],{"data":78038,"marks":78039,"value":78041,"nodeType":864},{},[78040],{"type":899},"1. Phishing for credentials and sessions",{"data":78043,"content":78044,"nodeType":860},{},[78045],{"data":78046,"marks":78047,"value":78048,"nodeType":864},{},[],"The most direct way for an attacker to compromise a business application is to phish a user of that app. You might not necessarily think of phishing as a browser-based attack, but that’s exactly what it is today. ",{"data":78050,"content":78051,"nodeType":860},{},[78052],{"data":78053,"marks":78054,"value":78055,"nodeType":864},{},[],"Phishing tooling and infrastructure has evolved a lot in the past decade, while the changes to business IT means there are both many more vectors for phishing attack delivery, and apps and identities to target. Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration. ",{"data":78057,"content":78061,"nodeType":996},{"target":78058},{"sys":78059},{"id":78060,"type":1001,"linkType":1002},"3SrKOgpedLMQRpKIZqUQur",[],{"data":78063,"content":78064,"nodeType":860},{},[78065,78069,78077],{"data":78066,"marks":78067,"value":78068,"nodeType":864},{},[],"Whereas phishing was once entirely focused on credential theft, modern phishing attacks see the attacker intercept the victim’s session on the target app, using reverse-proxy Attacker-in-the-Middle kits that are the standard choice for attackers today. This means most forms of MFA can be bypassed, with the exception of passkeys (though attackers are finding ways to work around passkeys using ",{"data":78070,"content":78072,"nodeType":883},{"uri":78071},"https://pushsecurity.com/blog/mfa-downgrade-attacks/?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[78073],{"data":78074,"marks":78075,"value":73474,"nodeType":864},{},[78076],{"type":1455},{"data":78078,"marks":78079,"value":16213,"nodeType":864},{},[],{"data":78081,"content":78085,"nodeType":996},{"target":78082},{"sys":78083},{"id":78084,"type":1001,"linkType":1002},"2sOFEdAwQZjWOGzNAlGavb",[],{"data":78087,"content":78088,"nodeType":860},{},[78089],{"data":78090,"marks":78091,"value":78092,"nodeType":864},{},[],"There are other key differences to be aware of too. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques. The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",{"data":78094,"content":78095,"nodeType":860},{},[78096],{"data":78097,"marks":78098,"value":78099,"nodeType":864},{},[],"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution in 2025 with the rate that attackers refresh and rotate their phishing infrastructure. ",{"data":78101,"content":78102,"nodeType":860},{},[78103],{"data":78104,"marks":78105,"value":78106,"nodeType":864},{},[],"These changes make phishing more effective than ever, and increasingly difficult to detect and block without being able to observe and analyze web pages that a user interacts with in real time — something only possible with browser-level visibility. ",{"data":78108,"content":78112,"nodeType":996},{"target":78109},{"sys":78110},{"id":78111,"type":1001,"linkType":1002},"1II2kHyOZcShLsexx1TAgy",[],{"data":78114,"content":78115,"nodeType":1005},{},[],{"data":78117,"content":78118,"nodeType":1312},{},[78119],{"data":78120,"marks":78121,"value":78123,"nodeType":864},{},[78122],{"type":899},"2. Malicious copy and paste (aka. ClickFix, FileFix, etc.)",{"data":78125,"content":78126,"nodeType":860},{},[78127,78131,78139],{"data":78128,"marks":78129,"value":78130,"nodeType":864},{},[],"One of the biggest security trends in the past year has been the emergence of the attack technique known as ",{"data":78132,"content":78134,"nodeType":883},{"uri":78133},"https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/",[78135],{"data":78136,"marks":78137,"value":315,"nodeType":864},{},[78138],{"type":1455},{"data":78140,"marks":78141,"value":11546,"nodeType":864},{},[],{"data":78143,"content":78144,"nodeType":860},{},[78145],{"data":78146,"marks":78147,"value":78148,"nodeType":864},{},[],"Originally known as “Fake CAPTCHA”, these attacks attempt to trick users into running malicious commands on their device — typically by solving some form of verification challenge in the browser. ",{"data":78150,"content":78151,"nodeType":860},{},[78152,78156,78165,78169,78178],{"data":78153,"marks":78154,"value":78155,"nodeType":864},{},[],"In reality, by solving the challenge, the victim is actually copying malicious code from the page clipboard and running it on their device. It typically gives the victim instructions that involve clicking prompts and copying, pasting, and running commands directly in the Windows Run dialog box, Terminal, or PowerShell. Variants such as ",{"data":78157,"content":78159,"nodeType":883},{"uri":78158},"https://mrd0x.com/filefix-clickfix-alternative/",[78160],{"data":78161,"marks":78162,"value":78164,"nodeType":864},{},[78163],{"type":1455},"FileFix",{"data":78166,"marks":78167,"value":78168,"nodeType":864},{},[]," have also emerged which instead uses the File Explorer Address Bar to execute OS commands, while recent examples have seen this attack branch out to ",{"data":78170,"content":78172,"nodeType":883},{"uri":78171},"https://www.bleepingcomputer.com/news/security/fake-mac-fixes-trick-users-into-installing-new-shamos-infostealer/",[78173],{"data":78174,"marks":78175,"value":78177,"nodeType":864},{},[78176],{"type":1455},"Mac via the macOS terminal",{"data":78179,"marks":78180,"value":2924,"nodeType":864},{},[],{"data":78182,"content":78183,"nodeType":860},{},[78184],{"data":78185,"marks":78186,"value":78187,"nodeType":864},{},[],"Most commonly, these attacks are used to deliver infostealer malware, using stolen session cookies and credentials to access business apps and services. ",{"data":78189,"content":78190,"nodeType":860},{},[78191],{"data":78192,"marks":78193,"value":78194,"nodeType":864},{},[],"Like modern credential and session phishing, links to malicious pages are distributed over various delivery channels and using a variety of lures, including impersonating CAPTCHA, Cloudflare Turnstile, simulating an error loading a webpage, and many more. ",{"data":78196,"content":78200,"nodeType":996},{"target":78197},{"sys":78198},{"id":78199,"type":1001,"linkType":1002},"6O9YiOfhpGFCDsTil9F3On",[],{"data":78202,"content":78203,"nodeType":860},{},[78204],{"data":78205,"marks":78206,"value":78207,"nodeType":864},{},[],"The variance in lure, and differences between different versions of the same lure, can make it difficult to fingerprint and detect based on visual elements alone. Also, many of the same protections being used to obfuscate and prevent analysis of phishing pages also apply to ClickFix pages, making it equally challenging to detect and block them. ",{"data":78209,"content":78210,"nodeType":860},{},[78211],{"data":78212,"marks":78213,"value":78214,"nodeType":864},{},[],"This leaves most of the detection and blocking down to endpoint-layer controls around user-level code execution and malware running on a device. The quantity of ClickFix-related headlines in the news would indicate that endpoint controls are being routinely bypassed, or perhaps evaded altogether by targeting personal or BYOD devices. ",{"data":78216,"content":78217,"nodeType":860},{},[78218],{"data":78219,"marks":78220,"value":78221,"nodeType":864},{},[],"There is a significant opportunity to detect these attacks in the browser and stop them at the earliest opportunity, before they reach the endpoint. Every ClickFix attack and variant has a key action in common — malicious code is copied from the page’s clipboard. In some cases, this happens without any user interaction (where the only requirement on the user is to run code that has been silently copied behind the scenes), presenting a strong indicator of malicious behavior that can be observed in the browser. ",{"data":78223,"content":78224,"nodeType":1005},{},[],{"data":78226,"content":78227,"nodeType":1312},{},[78228],{"data":78229,"marks":78230,"value":78232,"nodeType":864},{},[78231],{"type":899},"3. Malicious OAuth integrations",{"data":78234,"content":78235,"nodeType":860},{},[78236,78240,78246],{"data":78237,"marks":78238,"value":78239,"nodeType":864},{},[],"Malicious OAuth integrations are another way for attackers to compromise an app by tricking a user into authorizing an integration with a malicious, attacker-controlled app, with the level of data access and functionality dictated by the scopes authorized in the request. This is also known as ",{"data":78241,"content":78242,"nodeType":883},{"uri":50933},[78243],{"data":78244,"marks":78245,"value":72707,"nodeType":864},{},[],{"data":78247,"marks":78248,"value":1774,"nodeType":864},{},[],{"data":78250,"content":78254,"nodeType":996},{"target":78251},{"sys":78252},{"id":78253,"type":1001,"linkType":1002},"5JaP4WSfFsFSbvaa9BQBOq",[],{"data":78256,"content":78257,"nodeType":860},{},[78258],{"data":78259,"marks":78260,"value":78261,"nodeType":864},{},[],"This is an effective way for attackers to bypass hardened authentication and access controls by sidestepping the typical login process to take over an account and compromise business apps. This includes phishing-resistant MFA methods like passkeys — since the standard login process does not apply. ",{"data":78263,"content":78264,"nodeType":860},{},[78265],{"data":78266,"marks":78267,"value":78268,"nodeType":864},{},[],"A variant of this attack has dominated the headlines recently with the ongoing Salesforce breaches. In this scenario, the attacker tricked the victim into authorizing an attacker-controlled OAuth app via the device code authorization flow in Salesforce, which requires the user to enter an 8-digit code in place of a password or MFA factor.",{"data":78270,"content":78274,"nodeType":996},{"target":78271},{"sys":78272},{"id":78273,"type":1001,"linkType":1002},"3odEFcUcpKN553gHh2P5yr",[],{"data":78276,"content":78277,"nodeType":860},{},[78278],{"data":78279,"marks":78280,"value":78281,"nodeType":864},{},[],"Preventing malicious OAuth grants being authorized requires tight in-app management of user permissions and tenant security settings. This is no mean feat when considering the 100s of apps in use across the modern enterprise, many of which are not centrally managed by IT and security teams (or in some cases, are completely unknown to them). Even then, you’re limited by the controls made available by the app vendor. In this case, Salesforce has announced planned changes to OAuth app authorization in order to improve security prompted by these attacks — but many more apps with insecure configs exist for attackers to take advantage of in future. ",{"data":78283,"content":78284,"nodeType":860},{},[78285],{"data":78286,"marks":78287,"value":78288,"nodeType":864},{},[],"However, unlike app-specific integrations, browser-based security tools are well positioned to observe OAuth grants across all apps accessed in the browser — even the ones the security team doesn’t manage or know about, or without needing to pay for the app’s special security add-on to get visibility.",{"data":78290,"content":78291,"nodeType":1005},{},[],{"data":78293,"content":78294,"nodeType":1312},{},[78295],{"data":78296,"marks":78297,"value":78299,"nodeType":864},{},[78298],{"type":899},"4. Malicious browser extensions",{"data":78301,"content":78302,"nodeType":860},{},[78303],{"data":78304,"marks":78305,"value":78306,"nodeType":864},{},[],"Malicious browser extensions are another way for attackers to compromise your business apps by observing and capturing logins as they happen, and/or extracting session cookies and credentials saved in the browser cache and password manager. ",{"data":78308,"content":78309,"nodeType":860},{},[78310,78314,78323],{"data":78311,"marks":78312,"value":78313,"nodeType":864},{},[],"Attackers do this by creating their own malicious extension and tricking your users into installing it, or taking over an existing extension to gain access to browsers where it is already installed (",{"data":78315,"content":78317,"nodeType":883},{"uri":78316},"https://secureannex.com/blog/buying-browser-extensions/",[78318],{"data":78319,"marks":78320,"value":78322,"nodeType":864},{},[78321],{"type":1455},"it’s very easy for attackers to buy and add malicious updates to existing extensions",{"data":78324,"marks":78325,"value":78326,"nodeType":864},{},[],", easily passing extension web store security checks). ",{"data":78328,"content":78329,"nodeType":860},{},[78330,78334,78342,78346,78355,78358,78367],{"data":78331,"marks":78332,"value":78333,"nodeType":864},{},[],"The news around extension-based compromises has been on the rise since the ",{"data":78335,"content":78336,"nodeType":883},{"uri":50913},[78337],{"data":78338,"marks":78339,"value":78341,"nodeType":864},{},[78340],{"type":1455},"Cyberhaven extension",{"data":78343,"marks":78344,"value":78345,"nodeType":864},{},[]," was hacked in December 2024, along with at least 35 other extensions. Since then, there has been regular reporting on data-stealing extensions ",{"data":78347,"content":78349,"nodeType":883},{"uri":78348},"https://www.bleepingcomputer.com/news/security/data-stealing-chrome-extensions-impersonate-fortinet-youtube-vpns/",[78350],{"data":78351,"marks":78352,"value":78354,"nodeType":864},{},[78353],{"type":1455},"impersonating legitimate brands",{"data":78356,"marks":78357,"value":2232,"nodeType":864},{},[],{"data":78359,"content":78361,"nodeType":883},{"uri":78360},"https://www.bleepingcomputer.com/news/security/chrome-extensions-with-6-million-installs-have-hidden-tracking-code/",[78362],{"data":78363,"marks":78364,"value":78366,"nodeType":864},{},[78365],{"type":1455},"impacting millions of users",{"data":78368,"marks":78369,"value":2924,"nodeType":864},{},[],{"data":78371,"content":78372,"nodeType":860},{},[78373],{"data":78374,"marks":78375,"value":78376,"nodeType":864},{},[],"Risky browser extension permissions include broad data access, the ability to modify website content, track user activity, capture screenshots, and manage tabs or network requests. Permissions like \"read and change all data on all websites\" or access to cookies and browsing history are particularly dangerous as they can be exploited for session hijacking, data theft, malware injection, or phishing.",{"data":78378,"content":78379,"nodeType":860},{},[78380],{"data":78381,"marks":78382,"value":78383,"nodeType":864},{},[],"Generally, your employees should not be randomly installing browser extensions unless pre-approved by your security team. The reality, however, is that many organizations have very little visibility of the extensions their employees are using, and the potential risk they’re exposed to as a result. ",{"data":78385,"content":78386,"nodeType":860},{},[78387],{"data":78388,"marks":78389,"value":78390,"nodeType":864},{},[],"To tackle malicious extensions, security tools operating in the browser can track the browser extensions deployed, highlight risky permissions, compare with known-malicious extensions, identify fraudulent/unofficial versions of a legitimate extension, and highlight other risky properties commonly associated with malicious extensions (e.g. “Developer” extensions). ",{"data":78392,"content":78393,"nodeType":1005},{},[],{"data":78395,"content":78396,"nodeType":1312},{},[78397],{"data":78398,"marks":78399,"value":78401,"nodeType":864},{},[78400],{"type":899},"5. Malicious file delivery",{"data":78403,"content":78404,"nodeType":860},{},[78405],{"data":78406,"marks":78407,"value":78408,"nodeType":864},{},[],"Malicious files have been a core part of malware delivery and credential theft for many years. Just as non-email channels like malvertising and drive-by attacks are used to deliver phishing and ClickFix lures, malicious files are also distributed through similar means — leaving malicious file detection to basic known-bad checks, sandbox analysis using a proxy (not that useful in the context of sandbox-aware malware) or runtime analysis on the endpoint. ",{"data":78410,"content":78411,"nodeType":860},{},[78412],{"data":78413,"marks":78414,"value":78415,"nodeType":864},{},[],"This doesn’t just have to be malicious executables directly dropping malware onto the device. File downloads can also contain additional links taking the user to malicious content. In fact, one of the most common types of downloadable content are HTML Applications (HTAs), commonly used to spawn local phishing pages to stealthily capture credentials. More recently, attackers have been weaponizing SVG files for a similar purpose, running as self-contained phishing pages that render fake login portals entirely client-side. ",{"data":78417,"content":78418,"nodeType":860},{},[78419],{"data":78420,"marks":78421,"value":78422,"nodeType":864},{},[],"Even if malicious content cannot always be flagged from surface-level inspection of a file, recording file downloads in the browser is a useful addition to endpoint-based malware protection, and provides another layer of defense against file downloads that perform client-side attacks, or redirect the user to malicious web-based content. ",{"data":78424,"content":78425,"nodeType":1005},{},[],{"data":78427,"content":78428,"nodeType":1312},{},[78429],{"data":78430,"marks":78431,"value":78433,"nodeType":864},{},[78432],{"type":899},"6. Stolen credentials and MFA gaps",{"data":78435,"content":78436,"nodeType":860},{},[78437],{"data":78438,"marks":78439,"value":78440,"nodeType":864},{},[],"This last one isn’t so much a browser-based attack, but it is a product of them. When credentials are stolen through phishing or infostealer malware they can be used to take over accounts missing MFA. ",{"data":78442,"content":78443,"nodeType":860},{},[78444,78448,78455,78459,78468],{"data":78445,"marks":78446,"value":78447,"nodeType":864},{},[],"This isn’t the most sophisticated attack, but it’s very effective. You need only look at last year’s ",{"data":78449,"content":78450,"nodeType":883},{"uri":77958},[78451],{"data":78452,"marks":78453,"value":77964,"nodeType":864},{},[78454],{"type":1455},{"data":78456,"marks":78457,"value":78458,"nodeType":864},{},[]," account compromises or the ",{"data":78460,"content":78462,"nodeType":883},{"uri":78461},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[78463],{"data":78464,"marks":78465,"value":78467,"nodeType":864},{},[78466],{"type":1455},"Jira",{"data":78469,"marks":78470,"value":78471,"nodeType":864},{},[]," attacks earlier this year to see how attackers harness stolen credentials at scale. ",{"data":78473,"content":78474,"nodeType":860},{},[78475,78479,78488],{"data":78476,"marks":78477,"value":78478,"nodeType":864},{},[],"With the modern enterprise using hundreds of apps, the likelihood that an app hasn’t been configured for mandatory MFA (if possible) is high. And even when an app has been configured for SSO and connected to your primary corporate identity, ",{"data":78480,"content":78482,"nodeType":883},{"uri":78481},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=sidebar",[78483],{"data":78484,"marks":78485,"value":78487,"nodeType":864},{},[78486],{"type":1455},"local “ghost logins” can continue to exist",{"data":78489,"marks":78490,"value":78491,"nodeType":864},{},[],", accepting passwords with no MFA required. Just having visibility of your primary Identity Provider accounts (e.g. Google, Microsoft, Okta) and SSO-connected apps doesn't give you a full picture of your identity surface.",{"data":78493,"content":78494,"nodeType":860},{},[78495],{"data":78496,"marks":78497,"value":78498,"nodeType":864},{},[],"Logins can also be observed in the browser — in fact, it’s as close to a universal source of truth as you’re going to get about how your employees are actually logging in, which apps they’re using, and whether MFA is present, enabling security teams to find and fix vulnerable logins before they can be exploited by attackers. ",{"data":78500,"content":78501,"nodeType":1005},{},[],{"data":78503,"content":78504,"nodeType":1009},{},[78505],{"data":78506,"marks":78507,"value":51911,"nodeType":864},{},[78508],{"type":899},{"data":78510,"content":78511,"nodeType":860},{},[78512],{"data":78513,"marks":78514,"value":78515,"nodeType":864},{},[],"Attacks are increasingly happening in the browser. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams. ",{"data":78517,"content":78518,"nodeType":860},{},[78519],{"data":78520,"marks":78521,"value":78522,"nodeType":864},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":78524,"content":78525,"nodeType":860},{},[78526,78530,78538],{"data":78527,"marks":78528,"value":78529,"nodeType":864},{},[],"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",{"data":78531,"content":78533,"nodeType":883},{"uri":78532},"https://pushsecurity.com/demo?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[78534],{"data":78535,"marks":78536,"value":16894,"nodeType":864},{},[78537],{"type":1455},{"data":78539,"marks":78540,"value":2924,"nodeType":864},{},[],"6 browser-based attacks every security team should be prepared for","What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.","2025-09-05T00:00:00.000Z","6-browser-based-attacks-every-security-team-should-be-prepared-for",{"items":78546},[78547,78549],{"sys":78548,"name":13779},{"id":13778},{"sys":78550,"name":342},{"id":13775},{"items":78552},[78553],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":78554},{"url":2740},{"__typename":2059,"sys":78556,"content":78558,"title":78994,"synopsis":78995,"hashTags":59,"publishedDate":78996,"slug":78997,"tagsCollection":78998,"authorsCollection":79004},{"id":78557},"4vPEPmjd8MOlARD7oXfOrj",{"json":78559},{"data":78560,"content":78561,"nodeType":856},{},[78562,78579,78595,78601,78608,78615,78618,78626,78644,78651,78657,78664,78670,78677,78683,78690,78696,78703,78709,78712,78720,78738,78744,78752,78772,78780,78812,78819,78827,78847,78855,78875,78881,78884,78891,78910,78917,78922,78925,78932,78948,78955,78962,78968],{"data":78563,"content":78564,"nodeType":860},{},[78565,78569,78576],{"data":78566,"marks":78567,"value":78568,"nodeType":864},{},[],"Push recently detected and blocked a high-risk LinkedIn phishing attack that demonstrated a number of crafty (and increasingly common) ",{"data":78570,"content":78571,"nodeType":883},{"uri":14307},[78572],{"data":78573,"marks":78574,"value":19763,"nodeType":864},{},[78575],{"type":1455},{"data":78577,"marks":78578,"value":11546,"nodeType":864},{},[],{"data":78580,"content":78581,"nodeType":860},{},[78582,78586,78591],{"data":78583,"marks":78584,"value":78585,"nodeType":864},{},[],"Phishing via LinkedIn is increasingly common, although it often goes undetected and unreported. This is to be expected when most of the industry’s data on phishing attacks comes from email security vendors and tools. In contrast to email-centric reporting, ",{"data":78587,"marks":78588,"value":78590,"nodeType":864},{},[78589],{"type":899},"34% of the phishing attacks intercepted by Push last month came through non-email channels",{"data":78592,"marks":78593,"value":78594,"nodeType":864},{},[]," like social media, IM platforms, malicious search engine ads, and in-app communications. ",{"data":78596,"content":78600,"nodeType":996},{"target":78597},{"sys":78598},{"id":78599,"type":1001,"linkType":1002},"7i8panfdFUqW9wqYkd9uDc",[],{"data":78602,"content":78603,"nodeType":860},{},[78604],{"data":78605,"marks":78606,"value":78607,"nodeType":864},{},[],"Phishing via LinkedIn is a great way to catch victims unawares and evade traditionally email-based anti-phishing controls. While often used for work and commonly accessed from corporate devices, it sits outside the purview of enterprise security tools, exploiting a visibility and control blind spot. ",{"data":78609,"content":78610,"nodeType":860},{},[78611],{"data":78612,"marks":78613,"value":78614,"nodeType":864},{},[],"Let’s break it down. ",{"data":78616,"content":78617,"nodeType":1005},{},[],{"data":78619,"content":78620,"nodeType":1009},{},[78621],{"data":78622,"marks":78623,"value":78625,"nodeType":864},{},[78624],{"type":899},"Phishing attack breakdown",{"data":78627,"content":78628,"nodeType":860},{},[78629,78633,78641],{"data":78630,"marks":78631,"value":78632,"nodeType":864},{},[],"The victim was sent a malicious link via LinkedIn DM relating to a fake investment opportunity for executives ",{"data":78634,"content":78636,"nodeType":883},{"uri":78635},"https://www.bleepingcomputer.com/news/security/linkedin-phishing-targets-finance-execs-with-fake-board-invites/",[78637],{"data":78638,"marks":78639,"value":78640,"nodeType":864},{},[],"to join the executive board of a newly created \"Common Wealth\" investment fund.",{"data":78642,"marks":78643,"value":1171,"nodeType":864},{},[],{"data":78645,"content":78646,"nodeType":860},{},[78647],{"data":78648,"marks":78649,"value":78650,"nodeType":864},{},[],"After clicking the link, they were redirected three times — via Google Search, and then payrails-canaccord[.]icu/(redacted) — before being sent to a custom landing page hosted on firebasestorage.googleapis[.]com/(redacted). ",{"data":78652,"content":78656,"nodeType":996},{"target":78653},{"sys":78654},{"id":78655,"type":1001,"linkType":1002},"65PeJOKzn6Ba7FDUQRae3Q",[],{"data":78658,"content":78659,"nodeType":860},{},[78660],{"data":78661,"marks":78662,"value":78663,"nodeType":864},{},[],"Upon clicking on one of the document links on the page, the victim is prompted to “view with Microsoft”. ",{"data":78665,"content":78669,"nodeType":996},{"target":78666},{"sys":78667},{"id":78668,"type":1001,"linkType":1002},"4f27KuwTRx1Do59rs3JoVl",[],{"data":78671,"content":78672,"nodeType":860},{},[78673],{"data":78674,"marks":78675,"value":78676,"nodeType":864},{},[],"The user is then met with a Cloudflare Turnstile gate challenge at login.kggpho[.]icu before the page will fully render, and malicious content is loaded. ",{"data":78678,"content":78682,"nodeType":996},{"target":78679},{"sys":78680},{"id":78681,"type":1001,"linkType":1002},"3lpVmLBZSocOSGdlCKhKnD",[],{"data":78684,"content":78685,"nodeType":860},{},[78686],{"data":78687,"marks":78688,"value":78689,"nodeType":864},{},[],"The Microsoft-impersonating AITM phishing page is then served to the victim. Entering credentials and completing the MFA check will result in their Microsoft session being stolen by the attacker. ",{"data":78691,"content":78695,"nodeType":996},{"target":78692},{"sys":78693},{"id":78694,"type":1001,"linkType":1002},"5FCa4EJwyux13K9KBT3nd4",[],{"data":78697,"content":78698,"nodeType":860},{},[78699],{"data":78700,"marks":78701,"value":78702,"nodeType":864},{},[],"You can see the full timeline of events in the Detection Timeline below. ",{"data":78704,"content":78708,"nodeType":996},{"target":78705},{"sys":78706},{"id":78707,"type":1001,"linkType":1002},"8lizkPJcGdZhtWFV2QEwQ",[],{"data":78710,"content":78711,"nodeType":1005},{},[],{"data":78713,"content":78714,"nodeType":1009},{},[78715],{"data":78716,"marks":78717,"value":78719,"nodeType":864},{},[78718],{"type":899},"Detection evasion techniques observed",{"data":78721,"content":78722,"nodeType":860},{},[78723,78727,78734],{"data":78724,"marks":78725,"value":78726,"nodeType":864},{},[],"The attacker used a number of ",{"data":78728,"content":78729,"nodeType":883},{"uri":14307},[78730],{"data":78731,"marks":78732,"value":19763,"nodeType":864},{},[78733],{"type":1455},{"data":78735,"marks":78736,"value":78737,"nodeType":864},{},[]," to prevent the phishing site being analysed and detected by security tools. ",{"data":78739,"content":78743,"nodeType":996},{"target":78740},{"sys":78741},{"id":78742,"type":1001,"linkType":1002},"7q9D1MREwTCCpnjvZZ5wk1",[],{"data":78745,"content":78746,"nodeType":1312},{},[78747],{"data":78748,"marks":78749,"value":78751,"nodeType":864},{},[78750],{"type":899},"LinkedIn delivery",{"data":78753,"content":78754,"nodeType":860},{},[78755,78759,78768],{"data":78756,"marks":78757,"value":78758,"nodeType":864},{},[],"As we mentioned above, sending phishing lures via ",{"data":78760,"content":78762,"nodeType":883},{"uri":78761},"https://phishing-techniques.pushsecurity.com/techniques/social-media/",[78763],{"data":78764,"marks":78765,"value":78767,"nodeType":864},{},[78766],{"type":1455},"social media apps",{"data":78769,"marks":78770,"value":78771,"nodeType":864},{},[]," like LinkedIn is a great way to reach employees in a place that they expect to be contacted by people outside of their organization. By evading the traditional phishing control point altogether (email) attackers significantly reduce the risk of interception. ",{"data":78773,"content":78774,"nodeType":1312},{},[78775],{"data":78776,"marks":78777,"value":78779,"nodeType":864},{},[78778],{"type":899},"Lengthy redirect chain through trusted sites",{"data":78781,"content":78782,"nodeType":860},{},[78783,78787,78795,78799,78808],{"data":78784,"marks":78785,"value":78786,"nodeType":864},{},[],"Attackers use ",{"data":78788,"content":78789,"nodeType":883},{"uri":14430},[78790],{"data":78791,"marks":78792,"value":78794,"nodeType":864},{},[78793],{"type":1455},"lengthy redirect chains",{"data":78796,"marks":78797,"value":78798,"nodeType":864},{},[]," in combination with hosting pages on ",{"data":78800,"content":78802,"nodeType":883},{"uri":78801},"https://phishing-techniques.pushsecurity.com/techniques/trusted-website-hosting/",[78803],{"data":78804,"marks":78805,"value":78807,"nodeType":864},{},[78806],{"type":1455},"legitimate, trusted sites",{"data":78809,"marks":78810,"value":78811,"nodeType":864},{},[]," (in this case Firebase, Google’s app development platform). This is a technique we see a lot, with various Google and Microsoft sites cropping up time and again, including Google Forms, Google Sites, Google Script, Google AMP, Microsoft Dynamics, SharePoint, Azure Front Door, and many more, all used by attackers as part of their phishing attacks. ",{"data":78813,"content":78814,"nodeType":860},{},[78815],{"data":78816,"marks":78817,"value":78818,"nodeType":864},{},[],"Legitimate services are less likely to be flagged by link analysis tools and effectively cloak the initial URL delivered to the victim to increase the chance of successful delivery of and access to the link, while many services are excluded from page scanning tools owing to their association with trusted domains. ",{"data":78820,"content":78821,"nodeType":1312},{},[78822],{"data":78823,"marks":78824,"value":78826,"nodeType":864},{},[78825],{"type":899},"Bot protection",{"data":78828,"content":78829,"nodeType":860},{},[78830,78834,78843],{"data":78831,"marks":78832,"value":78833,"nodeType":864},{},[],"Attackers are using common ",{"data":78835,"content":78837,"nodeType":883},{"uri":78836},"https://phishing-techniques.pushsecurity.com/techniques/bot-protection/",[78838],{"data":78839,"marks":78840,"value":78842,"nodeType":864},{},[78841],{"type":1455},"bot protection",{"data":78844,"marks":78845,"value":78846,"nodeType":864},{},[]," technologies like CAPTCHA and Cloudflare Turnstile to prevent security bots from accessing their web pages to be able to analyse them (and therefore block pages from being automatically flagged). This requires anyone visiting the page to pass a bot check/challenge before the page can be loaded, meaning the full page cannot be analysed by automated tools. ",{"data":78848,"content":78849,"nodeType":1312},{},[78850],{"data":78851,"marks":78852,"value":78854,"nodeType":864},{},[78853],{"type":899},"Page obfuscation",{"data":78856,"content":78857,"nodeType":860},{},[78858,78862,78871],{"data":78859,"marks":78860,"value":78861,"nodeType":864},{},[],"Phishing pages ",{"data":78863,"content":78865,"nodeType":883},{"uri":78864},"https://phishing-techniques.pushsecurity.com/techniques/page-obfuscation/",[78866],{"data":78867,"marks":78868,"value":78870,"nodeType":864},{},[78869],{"type":1455},"change and even randomize elements of the page",{"data":78872,"marks":78873,"value":78874,"nodeType":864},{},[]," to avoid static fingerprints and defeat comparison-based checks against real pages. This includes the page title, text, images, backgrounds, logos, favicons, etc. — all of which may be signatured components using web page analysis tools. These elements can even be embedded in an encoded form so it isn’t present in the initial HTML, and is instead dynamically set at runtime when loaded. As an example, you can see that the page randomly generated the tab header text.",{"data":78876,"content":78880,"nodeType":996},{"target":78877},{"sys":78878},{"id":78879,"type":1001,"linkType":1002},"2bbOZC9M4y69ACDy7bn209",[],{"data":78882,"content":78883,"nodeType":1005},{},[],{"data":78885,"content":78886,"nodeType":1009},{},[78887],{"data":78888,"marks":78889,"value":14297,"nodeType":864},{},[78890],{"type":899},{"data":78892,"content":78893,"nodeType":860},{},[78894,78898,78906],{"data":78895,"marks":78896,"value":78897,"nodeType":864},{},[],"We’re seeing ",{"data":78899,"content":78900,"nodeType":883},{"uri":52302},[78901],{"data":78902,"marks":78903,"value":78905,"nodeType":864},{},[78904],{"type":1455},"many phishing campaigns pivoting to social media apps like LinkedIn",{"data":78907,"marks":78908,"value":78909,"nodeType":864},{},[]," and organizations should be on guard against this attack vector, which is highly effective at evading common anti-phishing controls.  ",{"data":78911,"content":78912,"nodeType":860},{},[78913],{"data":78914,"marks":78915,"value":78916,"nodeType":864},{},[],"Just because the attack happens over LinkedIn doesn’t lessen the impact — these are corporate credentials and accounts being targeted, even if it is nominally a “personal” application. Taking over a core identity like a Microsoft or Google account can have wide-ranging consequences, putting data at risk in both core apps and any downstream apps that can be accessed via SSO from the compromised account. ",{"data":78918,"content":78921,"nodeType":996},{"target":78919},{"sys":78920},{"id":73199,"type":1001,"linkType":1002},[],{"data":78923,"content":78924,"nodeType":1005},{},[],{"data":78926,"content":78927,"nodeType":1009},{},[78928],{"data":78929,"marks":78930,"value":73129,"nodeType":864},{},[78931],{"type":899},{"data":78933,"content":78934,"nodeType":860},{},[78935,78938,78945],{"data":78936,"marks":78937,"value":73149,"nodeType":864},{},[],{"data":78939,"content":78940,"nodeType":883},{"uri":14307},[78941],{"data":78942,"marks":78943,"value":73157,"nodeType":864},{},[78944],{"type":1455},{"data":78946,"marks":78947,"value":73161,"nodeType":864},{},[],{"data":78949,"content":78950,"nodeType":860},{},[78951],{"data":78952,"marks":78953,"value":78954,"nodeType":864},{},[],"This isn’t all we do: Push’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, malicious OAuth grants, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":78956,"content":78957,"nodeType":860},{},[78958],{"data":78959,"marks":78960,"value":78961,"nodeType":864},{},[],"Check out the demo below to see Push detect and block this attack in real-time. ",{"data":78963,"content":78967,"nodeType":996},{"target":78964},{"sys":78965},{"id":78966,"type":1001,"linkType":1002},"5VsFECWlJ1HNGtC0jUcPjH",[],{"data":78969,"content":78970,"nodeType":860},{},[78971,78974,78981,78984,78991],{"data":78972,"marks":78973,"value":16863,"nodeType":864},{},[],{"data":78975,"content":78976,"nodeType":883},{"uri":16866},[78977],{"data":78978,"marks":78979,"value":16871,"nodeType":864},{},[78980],{"type":1455},{"data":78982,"marks":78983,"value":52968,"nodeType":864},{},[],{"data":78985,"content":78986,"nodeType":883},{"uri":1700},[78987],{"data":78988,"marks":78989,"value":16894,"nodeType":864},{},[78990],{"type":1455},{"data":78992,"marks":78993,"value":2924,"nodeType":864},{},[],"New phishing campaign identified targeting LinkedIn users","Diving into the latest sophisticated LinkedIn phishing campaign intercepted by Push. ","2025-10-30T00:00:00.000Z","new-phishing-campaign-identified-targeting-linkedin-users",{"items":78999},[79000,79002],{"sys":79001,"name":342},{"id":13775},{"sys":79003,"name":13779},{"id":13778},{"items":79005},[79006],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":79007},{"url":2740},{"__typename":2059,"sys":79009,"content":79011,"title":79667,"synopsis":79668,"hashTags":59,"publishedDate":79669,"slug":79670,"tagsCollection":79671,"authorsCollection":79677},{"id":79010},"7dqGkFzSMA00bIJ94rW4na",{"json":79012},{"data":79013,"content":79014,"nodeType":856},{},[79015,79022,79029,79035,79060,79080,79083,79091,79098,79105,79113,79133,79136,79144,79151,79157,79164,79170,79173,79181,79188,79195,79218,79225,79258,79265,79273,79292,79299,79305,79332,79363,79371,79378,79385,79418,79421,79429,79448,79455,79478,79485,79491,79494,79502,79509,79633,79636,79643,79650],{"data":79016,"content":79017,"nodeType":860},{},[79018],{"data":79019,"marks":79020,"value":79021,"nodeType":864},{},[],"As awareness grows around many MFA methods being “phishable” (i.e. not phishing resistant), passwordless authentication methods are being increasingly advocated. ",{"data":79023,"content":79024,"nodeType":860},{},[79025],{"data":79026,"marks":79027,"value":79028,"nodeType":864},{},[],"This is a good thing. The most commonly used MFA factors (like SMS codes, push notifications, and app-based OTP) are routinely bypassed, with modern reverse-proxy phishing kits the most common method. ",{"data":79030,"content":79034,"nodeType":996},{"target":79031},{"sys":79032},{"id":79033,"type":1001,"linkType":1002},"ImwzE2R9qaHaqlWn0GqIa",[],{"data":79036,"content":79037,"nodeType":860},{},[79038,79042,79047,79051,79056],{"data":79039,"marks":79040,"value":79041,"nodeType":864},{},[],"Often referred to as a “passkey”, passwordless authentication typically consists of a hardware security device that is built-into your laptop (e.g. the fingerprint sensor on a laptop) or something you plug into your device (e.g. a Yubikey). Because passkey-based logins are domain-bound, trying to use a passkey for ",{"data":79043,"marks":79044,"value":79046,"nodeType":864},{},[79045],{"type":1455},"microsoft.com",{"data":79048,"marks":79049,"value":79050,"nodeType":864},{},[]," on ",{"data":79052,"marks":79053,"value":79055,"nodeType":864},{},[79054],{"type":1455},"phishing.com",{"data":79057,"marks":79058,"value":79059,"nodeType":864},{},[]," simply won’t generate the correct value to pass the authentication check, even when proxied using an AitM kit. ",{"data":79061,"content":79062,"nodeType":860},{},[79063,79067,79077],{"data":79064,"marks":79065,"value":79066,"nodeType":864},{},[],"However, attackers have realized that even as these new phishing-resistant methods are starting to become used, most users still have alternative MFA methods active. The attacker can then do what’s called a ",{"data":79068,"content":79070,"nodeType":883},{"uri":79069},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_downgrade/description.md",[79071],{"data":79072,"marks":79073,"value":79076,"nodeType":864},{},[79074,79075],{"type":1455},{"type":899},"downgrade attack",{"data":79078,"marks":79079,"value":2924,"nodeType":864},{},[],{"data":79081,"content":79082,"nodeType":1005},{},[],{"data":79084,"content":79085,"nodeType":1009},{},[79086],{"data":79087,"marks":79088,"value":79090,"nodeType":864},{},[79089],{"type":899},"Downgrade attacks 101",{"data":79092,"content":79093,"nodeType":860},{},[79094],{"data":79095,"marks":79096,"value":79097,"nodeType":864},{},[],"When conducting an Attacker-in-the-Middle phishing attack, the attacker doesn’t need to relay 100% of the messages accurately. Instead, they can alter some of them. The app might ask the user “You need to MFA — do you want to use your passkey, or your backup authenticator code?”, but the phishing website might modify this page to say “You need to MFA — use your backup authenticator code” not giving you the option to use your secure passkey. This is called a downgrade attack.",{"data":79099,"content":79100,"nodeType":860},{},[79101],{"data":79102,"marks":79103,"value":79104,"nodeType":864},{},[],"This can also be applied to accounts that use SSO as the default login method. In this scenario, the phish kit can select a backup username and password option to allow the phishing attack to proceed.  ",{"data":79106,"content":79107,"nodeType":860},{},[79108],{"data":79109,"marks":79110,"value":79112,"nodeType":864},{},[79111],{"type":899},"So, you have a situation where even if a phishing-resistant login method exists, the presence of a less secure backup method means the account is still vulnerable to phishing attacks. ",{"data":79114,"content":79115,"nodeType":860},{},[79116,79120,79129],{"data":79117,"marks":79118,"value":79119,"nodeType":864},{},[],"These attacks are effective across a number of sites and login methods that support passkey-based logins, for example, Windows Hello, Okta FastPass, and Google Workspace. As an example, here’s a link to a ",{"data":79121,"content":79123,"nodeType":883},{"uri":79122},"https://github.com/yudasm/WHfB-o365-Phishlet",[79124],{"data":79125,"marks":79126,"value":79128,"nodeType":864},{},[79127],{"type":1455},"custom phishlet for Evilginx",{"data":79130,"marks":79131,"value":79132,"nodeType":864},{},[]," targeting Windows Hello for Business. A small caveat is that changes made by Microsoft have since broken this plugin, but we were able to write our own custom phishlet to achieve the same outcome. ",{"data":79134,"content":79135,"nodeType":1005},{},[],{"data":79137,"content":79138,"nodeType":1009},{},[79139],{"data":79140,"marks":79141,"value":79143,"nodeType":864},{},[79142],{"type":899},"MFA downgrade in action",{"data":79145,"content":79146,"nodeType":860},{},[79147],{"data":79148,"marks":79149,"value":79150,"nodeType":864},{},[],"Check out the video below to see an example of using Evilginx with a custom phishlet to downgrade authentication for a Microsoft account using Windows Hello. ",{"data":79152,"content":79156,"nodeType":996},{"target":79153},{"sys":79154},{"id":79155,"type":1001,"linkType":1002},"54I3YQ2gK26a8FIocQ3WYT",[],{"data":79158,"content":79159,"nodeType":860},{},[79160],{"data":79161,"marks":79162,"value":79163,"nodeType":864},{},[],"We’ve encountered similar functionality in criminal phishing platforms we’ve investigated such as Tycoon — in this case, targeting Google accounts. This snippet is notable in that it includes JavaScript to abuse UI features to bypass passkeys.",{"data":79165,"content":79169,"nodeType":996},{"target":79166},{"sys":79167},{"id":79168,"type":1001,"linkType":1002},"5Vya1VApSisr0000HuTLY2",[],{"data":79171,"content":79172,"nodeType":1005},{},[],{"data":79174,"content":79175,"nodeType":1009},{},[79176],{"data":79177,"marks":79178,"value":79180,"nodeType":864},{},[79179],{"type":899},"Mitigations (and challenges)",{"data":79182,"content":79183,"nodeType":860},{},[79184],{"data":79185,"marks":79186,"value":79187,"nodeType":864},{},[],"MFA downgrade is made possible by the existence of backup authentication methods. So the obvious solution is to remove backup/unused login and MFA methods from your accounts, ensuring you’re accessing apps using SSO from a hardened Identity Provider (IdP) account (e.g. Okta, Entra, Google Workspace). ",{"data":79189,"content":79190,"nodeType":860},{},[79191],{"data":79192,"marks":79193,"value":79194,"nodeType":864},{},[],"In the ideal world, you’d be:",{"data":79196,"content":79197,"nodeType":941},{},[79198,79208],{"data":79199,"content":79200,"nodeType":945},{},[79201],{"data":79202,"content":79203,"nodeType":860},{},[79204],{"data":79205,"marks":79206,"value":79207,"nodeType":864},{},[],"Using only one IdP account, which you access via passkey, with no backup methods.",{"data":79209,"content":79210,"nodeType":945},{},[79211],{"data":79212,"content":79213,"nodeType":860},{},[79214],{"data":79215,"marks":79216,"value":79217,"nodeType":864},{},[],"Accessing all business apps using SSO from your locked-down IdP account. ",{"data":79219,"content":79220,"nodeType":860},{},[79221],{"data":79222,"marks":79223,"value":79224,"nodeType":864},{},[],"The reality is way different, though. Because going totally passwordless is hard. It requires a large investment of time, money, and training for end-users. You’ll find many cautionary tales of companies starting on their passkey adoption journey and ultimately failing to make it a reality. This is largely because:",{"data":79226,"content":79227,"nodeType":941},{},[79228,79238,79248],{"data":79229,"content":79230,"nodeType":945},{},[79231],{"data":79232,"content":79233,"nodeType":860},{},[79234],{"data":79235,"marks":79236,"value":79237,"nodeType":864},{},[],"In environments with a mix of older and newer infrastructure, it can be challenging to get complete coverage. ",{"data":79239,"content":79240,"nodeType":945},{},[79241],{"data":79242,"content":79243,"nodeType":860},{},[79244],{"data":79245,"marks":79246,"value":79247,"nodeType":864},{},[],"Not every device comes with an in-built biometric identification method, so you need to use a second device — which employees may struggle with (especially when they lose it and aren’t familiar with how to regain account access).",{"data":79249,"content":79250,"nodeType":945},{},[79251],{"data":79252,"content":79253,"nodeType":860},{},[79254],{"data":79255,"marks":79256,"value":79257,"nodeType":864},{},[],"Most apps don’t allow you to log in directly with a passkey, meaning you need to SSO from your IdP account. But many apps don’t support every preferred SSO provider, and fail to provide SAML support, so there can be gaps.  ",{"data":79259,"content":79260,"nodeType":860},{},[79261],{"data":79262,"marks":79263,"value":79264,"nodeType":864},{},[],"And ultimately, because of the self-service, product-led growth fuelled nature of most online services today, it’s easy for users to slip back into using passwords — and hard for security teams to find and remove them (particularly if an app isn’t centrally managed). And the level of support that different apps provide users and administrators to secure how they access their services varies significantly. ",{"data":79266,"content":79267,"nodeType":1312},{},[79268],{"data":79269,"marks":79270,"value":79272,"nodeType":864},{},[79271],{"type":899},"Most apps make removing phishable authentication hard",{"data":79274,"content":79275,"nodeType":860},{},[79276,79280,79288],{"data":79277,"marks":79278,"value":79279,"nodeType":864},{},[],"While some providers are taking steps to go passwordless by default, which makes it easier to remove passwords (e.g. ",{"data":79281,"content":79283,"nodeType":883},{"uri":79282},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/introducing-password-removal-for-microsoft-accounts/2747280",[79284],{"data":79285,"marks":79286,"value":19538,"nodeType":864},{},[79287],{"type":1455},{"data":79289,"marks":79290,"value":79291,"nodeType":864},{},[]," recently made a big deal of its desire to get rid of passwords), the quality of identity security management functionality varies significantly from app to app. ",{"data":79293,"content":79294,"nodeType":860},{},[79295],{"data":79296,"marks":79297,"value":79298,"nodeType":864},{},[],"Many apps default to the most recently used or strongest login method, but very few automatically lock you in to using the strongest method available. Most of the time, these kinds of controls also need to be configured in the app — which can be challenging if your security team doesn’t manage it (or simply isn’t aware of it). ",{"data":79300,"content":79304,"nodeType":996},{"target":79301},{"sys":79302},{"id":79303,"type":1001,"linkType":1002},"4X9MR0CbSMltOmw767XNOm",[],{"data":79306,"content":79307,"nodeType":860},{},[79308,79312,79317,79321,79328],{"data":79309,"marks":79310,"value":79311,"nodeType":864},{},[],"Finally, configuring MFA is often an additive process — you start by adding a phone number, then you add an authenticator app or a passkey. Just like we find that most accounts with SSO ",{"data":79313,"marks":79314,"value":79316,"nodeType":864},{},[79315],{"type":899},"also",{"data":79318,"marks":79319,"value":79320,"nodeType":864},{},[]," have a password login configured (also known as ",{"data":79322,"content":79323,"nodeType":883},{"uri":57333},[79324],{"data":79325,"marks":79326,"value":29819,"nodeType":864},{},[79327],{"type":1455},{"data":79329,"marks":79330,"value":79331,"nodeType":864},{},[],"), most accounts with MFA typically have multiple methods attached to their account. ",{"data":79333,"content":79334,"nodeType":860},{},[79335,79339,79347,79350,79359],{"data":79336,"marks":79337,"value":79338,"nodeType":864},{},[],"The result is that even if you can successfully lock down a handful of apps, many more will continue to be susceptible to phishing attacks using commonly available downgrade functionality. And as attackers diversify the apps they target (such as these recent examples targeting ",{"data":79340,"content":79342,"nodeType":883},{"uri":79341},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/",[79343],{"data":79344,"marks":79345,"value":73371,"nodeType":864},{},[79346],{"type":1455},{"data":79348,"marks":79349,"value":902,"nodeType":864},{},[],{"data":79351,"content":79353,"nodeType":883},{"uri":79352},"https://pushsecurity.com/blog/dissecting-a-recent-mailchimp-phishing-attack/",[79354],{"data":79355,"marks":79356,"value":79358,"nodeType":864},{},[79357],{"type":1455},"MailChimp",{"data":79360,"marks":79361,"value":79362,"nodeType":864},{},[],"), this becomes increasingly likely. ",{"data":79364,"content":79365,"nodeType":1312},{},[79366],{"data":79367,"marks":79368,"value":79370,"nodeType":864},{},[79369],{"type":899},"Conditional access is a useful mitigation if configured properly, but only on apps which support it",{"data":79372,"content":79373,"nodeType":860},{},[79374],{"data":79375,"marks":79376,"value":79377,"nodeType":864},{},[],"Conditional access policies are a useful last line of defense against account takeover attacks by denying logins that don't meet certain criteria, even if they user is able to authenticate. In larger IdP platforms that typically support more granular conditional access policies, this is a useful addition when configured correctly. However, many apps simply don't support conditional access, so will be vulnerable to attackers targeting them directly (as opposed to first logging into e.g. Microsoft or Google, and then accessing downstream apps via SSO). ",{"data":79379,"content":79380,"nodeType":860},{},[79381],{"data":79382,"marks":79383,"value":79384,"nodeType":864},{},[],"That said, locking down your core IdP platforms with robust conditional access should be a top priority for security teams. Useful policies that should be configured include:",{"data":79386,"content":79387,"nodeType":941},{},[79388,79398,79408],{"data":79389,"content":79390,"nodeType":945},{},[79391],{"data":79392,"content":79393,"nodeType":860},{},[79394],{"data":79395,"marks":79396,"value":79397,"nodeType":864},{},[],"Limiting logins to domain-joined devices.",{"data":79399,"content":79400,"nodeType":945},{},[79401],{"data":79402,"content":79403,"nodeType":860},{},[79404],{"data":79405,"marks":79406,"value":79407,"nodeType":864},{},[],"Set phishing-resistant MFA as required. ",{"data":79409,"content":79410,"nodeType":945},{},[79411],{"data":79412,"content":79413,"nodeType":860},{},[79414],{"data":79415,"marks":79416,"value":79417,"nodeType":864},{},[],"(Where possible) limit logins to trusted IP ranges. ",{"data":79419,"content":79420,"nodeType":1005},{},[],{"data":79422,"content":79423,"nodeType":1009},{},[79424],{"data":79425,"marks":79426,"value":79428,"nodeType":864},{},[79427],{"type":899},"Tackling MFA downgrade with Push Security",{"data":79430,"content":79431,"nodeType":860},{},[79432,79436,79444],{"data":79433,"marks":79434,"value":79435,"nodeType":864},{},[],"Phishing-resistant authentication methods like passkeys are key to the future of enterprise identity security, but organizations need to recognize that adopting passkeys isn’t a silver bullet. Ensuring that passkeys are the only authentication method supported by your business apps is no mean feat, considering ",{"data":79437,"content":79438,"nodeType":883},{"uri":25338},[79439],{"data":79440,"marks":79441,"value":79443,"nodeType":864},{},[79442],{"type":1455},"most organizations are using hundreds of them",{"data":79445,"marks":79446,"value":79447,"nodeType":864},{},[]," — all with their own specific ways of handling and administering identities. ",{"data":79449,"content":79450,"nodeType":860},{},[79451],{"data":79452,"marks":79453,"value":79454,"nodeType":864},{},[],"That’s why we support a layered defense, providing last-mile protection by:",{"data":79456,"content":79457,"nodeType":941},{},[79458,79468],{"data":79459,"content":79460,"nodeType":945},{},[79461],{"data":79462,"content":79463,"nodeType":860},{},[79464],{"data":79465,"marks":79466,"value":79467,"nodeType":864},{},[],"Intercepting and blocking phishing attacks in the browser to prevent AiTM attacks using downgrade techniques.",{"data":79469,"content":79470,"nodeType":945},{},[79471],{"data":79472,"content":79473,"nodeType":860},{},[79474],{"data":79475,"marks":79476,"value":79477,"nodeType":864},{},[],"Identifying backup MFA and login methods across the business apps your employees use, so they can be removed (individually or through app-level configuration changes).",{"data":79479,"content":79480,"nodeType":860},{},[79481],{"data":79482,"marks":79483,"value":79484,"nodeType":864},{},[],"Here’s how it works.",{"data":79486,"content":79490,"nodeType":996},{"target":79487},{"sys":79488},{"id":79489,"type":1001,"linkType":1002},"2uvItnfaOQZHa4a9BIIhRn",[],{"data":79492,"content":79493,"nodeType":1005},{},[],{"data":79495,"content":79496,"nodeType":1009},{},[79497],{"data":79498,"marks":79499,"value":79501,"nodeType":864},{},[79500],{"type":899},"Further reading",{"data":79503,"content":79504,"nodeType":860},{},[79505],{"data":79506,"marks":79507,"value":79508,"nodeType":864},{},[],"MFA downgrade is just one method of getting into an otherwise locked-down account. Attackers are also finding ways to bypass the standard authentication process entirely, through: ",{"data":79510,"content":79511,"nodeType":941},{},[79512,79546,79579,79599],{"data":79513,"content":79514,"nodeType":945},{},[79515],{"data":79516,"content":79517,"nodeType":860},{},[79518,79521,79530,79534,79543],{"data":79519,"marks":79520,"value":21,"nodeType":864},{},[],{"data":79522,"content":79524,"nodeType":883},{"uri":79523},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/app_specific_password_phishing/description.md",[79525],{"data":79526,"marks":79527,"value":79529,"nodeType":864},{},[79528],{"type":1455},"App-specific password phishing",{"data":79531,"marks":79532,"value":79533,"nodeType":864},{},[],", where attackers can abuse functionality designed to enable users to log into apps that don’t support modern authentication. (",{"data":79535,"content":79537,"nodeType":883},{"uri":79536},"https://pushsecurity.com/blog/app-specific-password-phishing/",[79538],{"data":79539,"marks":79540,"value":79542,"nodeType":864},{},[79541],{"type":1455},"Read the article for more information here",{"data":79544,"marks":79545,"value":49943,"nodeType":864},{},[],{"data":79547,"content":79548,"nodeType":945},{},[79549],{"data":79550,"content":79551,"nodeType":860},{},[79552,79555,79562,79566,79575],{"data":79553,"marks":79554,"value":21,"nodeType":864},{},[],{"data":79556,"content":79557,"nodeType":883},{"uri":50933},[79558],{"data":79559,"marks":79560,"value":73626,"nodeType":864},{},[79561],{"type":1455},{"data":79563,"marks":79564,"value":79565,"nodeType":864},{},[],", which sees the victim accept OAuth scopes for an attacker-controlled app integration granting access to the account without needing to directly compromise it. (",{"data":79567,"content":79569,"nodeType":883},{"uri":79568},"https://pushsecurity.com/blog/how-consent-phishing-is-evolving/",[79570],{"data":79571,"marks":79572,"value":79574,"nodeType":864},{},[79573],{"type":1455},"You can read more about recent examples here",{"data":79576,"marks":79577,"value":79578,"nodeType":864},{},[],".) ",{"data":79580,"content":79581,"nodeType":945},{},[79582],{"data":79583,"content":79584,"nodeType":860},{},[79585,79588,79595],{"data":79586,"marks":79587,"value":21,"nodeType":864},{},[],{"data":79589,"content":79590,"nodeType":883},{"uri":19347},[79591],{"data":79592,"marks":79593,"value":360,"nodeType":864},{},[79594],{"type":1455},{"data":79596,"marks":79597,"value":79598,"nodeType":864},{},[],", functionally very similar to consent phishing but involving the victim entering a code for authorization. ",{"data":79600,"content":79601,"nodeType":945},{},[79602],{"data":79603,"content":79604,"nodeType":860},{},[79605,79608,79617,79621,79630],{"data":79606,"marks":79607,"value":21,"nodeType":864},{},[],{"data":79609,"content":79611,"nodeType":883},{"uri":79610},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/cross-idp_impersonation/description.md",[79612],{"data":79613,"marks":79614,"value":79616,"nodeType":864},{},[79615],{"type":1455},"Cross-IdP impersonation",{"data":79618,"marks":79619,"value":79620,"nodeType":864},{},[],", which sees the attacker register a new IdP connected to the victim’s email account that can be used to access connected apps via SSO without directly compromising the primary IdP. (",{"data":79622,"content":79624,"nodeType":883},{"uri":79623},"https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/",[79625],{"data":79626,"marks":79627,"value":79629,"nodeType":864},{},[79628],{"type":1455},"You can read more about this here",{"data":79631,"marks":79632,"value":1560,"nodeType":864},{},[],{"data":79634,"content":79635,"nodeType":1005},{},[],{"data":79637,"content":79638,"nodeType":1009},{},[79639],{"data":79640,"marks":79641,"value":40614,"nodeType":864},{},[79642],{"type":899},{"data":79644,"content":79645,"nodeType":860},{},[79646],{"data":79647,"marks":79648,"value":79649,"nodeType":864},{},[],"Push Security’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use, like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more.",{"data":79651,"content":79652,"nodeType":860},{},[79653,79657,79664],{"data":79654,"marks":79655,"value":79656,"nodeType":864},{},[],"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":79658,"content":79659,"nodeType":883},{"uri":14401},[79660],{"data":79661,"marks":79662,"value":16894,"nodeType":864},{},[79663],{"type":1455},{"data":79665,"marks":79666,"value":2924,"nodeType":864},{},[],"MFA downgrade: How attackers are getting around phishing-resistant authentication","MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.","2025-07-21T00:00:00.000Z","mfa-downgrade-attacks",{"items":79672},[79673,79675],{"sys":79674,"name":342},{"id":13775},{"sys":79676,"name":13779},{"id":13778},{"items":79678},[79679],{"fullName":22309,"firstName":22310,"jobTitle":22311,"profilePicture":79680},{"url":22313},"blog/scattered-lapsus-hunters",{"json":79683},{"data":79684,"content":79685,"nodeType":856},{},[79686],{"data":79687,"content":79688,"nodeType":860},{},[79689],{"data":79690,"marks":79691,"value":79692,"nodeType":864},{},[],"In this blog post, we’ll be taking a closer look at the breaches linked to Scattered Lapsus$ Hunters, the evolution of TTPs that makes them so successful, and how they’re shaping the current and next generation of cyber criminals.",{"id":57022,"publishedAt":79694},"2026-08-12T11:53:35.368Z",{"items":79696},[79697,79699],{"sys":79698,"name":13779},{"id":13778},{"sys":79700,"name":342},{"id":13775},{"items":79702},[79703,79705,79707,79709,79711,79713,79715,79717,79719,79721,79723,79725,79727,79729,79731],{"sys":79704,"name":279,"slug":280,"tier":31},{"id":276},{"sys":79706,"name":413,"slug":414,"tier":31},{"id":410},{"sys":79708,"name":642,"slug":643,"tier":31},{"id":639},{"sys":79710,"name":650,"slug":651,"tier":45},{"id":647},{"sys":79712,"name":261,"slug":262,"tier":45},{"id":258},{"sys":79714,"name":404,"slug":405,"tier":45},{"id":401},{"sys":79716,"name":537,"slug":538,"tier":45},{"id":534},{"sys":79718,"name":333,"slug":334,"tier":45},{"id":330},{"sys":79720,"name":607,"slug":608,"tier":45},{"id":604},{"sys":79722,"name":484,"slug":485,"tier":45},{"id":481},{"sys":79724,"name":288,"slug":289,"tier":45},{"id":285},{"sys":79726,"name":422,"slug":423,"tier":45},{"id":419},{"sys":79728,"name":571,"slug":572,"tier":45},{"id":568},{"sys":79730,"name":528,"slug":529,"tier":45},{"id":525},{"sys":79732,"name":395,"slug":396,"tier":45},{"id":392},"cPGKjifHC8Xc0ke0Qls0IvBKrqcQS7B54QT7CK7Q1JI",{"id":79735,"title":65699,"authorsCollection":79736,"content":79740,"extension":228,"faqItemsCollection":80420,"faqTitle":59,"featured":6,"hashTags":59,"meta":80422,"metaTitle":80423,"ogImage":59,"postType":64991,"publishedDate":65701,"relatedBlogPostsCollection":80424,"slug":65702,"stem":81463,"subtitle":59,"summary":81464,"synopsis":65700,"sys":81475,"tagsCollection":81477,"topicsCollection":81481,"__hash__":81491},"blog/blog/product-release-november-2025.json",{"items":79737},[79738],{"fullName":64440,"firstName":64441,"jobTitle":64442,"socialLinks":59,"profilePicture":79739},{"url":64444},{"json":79741,"links":80365},{"data":79742,"content":79743,"nodeType":856},{},[79744,79750,79816,79822,79828,79848,79868,79898,79903,79920,79926,79932,79938,79965,79970,79987,79993,80006,80012,80032,80038,80044,80064,80077,80082,80088,80094,80107,80113,80161,80167,80172,80189,80195,80208,80214,80235,80255,80261,80267,80359],{"data":79745,"content":79746,"nodeType":1009},{},[79747],{"data":79748,"marks":79749,"value":64455,"nodeType":864},{},[],{"data":79751,"content":79752,"nodeType":941},{},[79753,79762,79771,79780,79789,79798,79807],{"data":79754,"content":79755,"nodeType":945},{},[79756],{"data":79757,"content":79758,"nodeType":860},{},[79759],{"data":79760,"marks":79761,"value":65020,"nodeType":864},{},[],{"data":79763,"content":79764,"nodeType":945},{},[79765],{"data":79766,"content":79767,"nodeType":860},{},[79768],{"data":79769,"marks":79770,"value":65030,"nodeType":864},{},[],{"data":79772,"content":79773,"nodeType":945},{},[79774],{"data":79775,"content":79776,"nodeType":860},{},[79777],{"data":79778,"marks":79779,"value":65040,"nodeType":864},{},[],{"data":79781,"content":79782,"nodeType":945},{},[79783],{"data":79784,"content":79785,"nodeType":860},{},[79786],{"data":79787,"marks":79788,"value":65050,"nodeType":864},{},[],{"data":79790,"content":79791,"nodeType":945},{},[79792],{"data":79793,"content":79794,"nodeType":860},{},[79795],{"data":79796,"marks":79797,"value":65060,"nodeType":864},{},[],{"data":79799,"content":79800,"nodeType":945},{},[79801],{"data":79802,"content":79803,"nodeType":860},{},[79804],{"data":79805,"marks":79806,"value":65070,"nodeType":864},{},[],{"data":79808,"content":79809,"nodeType":945},{},[79810],{"data":79811,"content":79812,"nodeType":860},{},[79813],{"data":79814,"marks":79815,"value":64518,"nodeType":864},{},[],{"data":79817,"content":79818,"nodeType":1009},{},[79819],{"data":79820,"marks":79821,"value":65020,"nodeType":864},{},[],{"data":79823,"content":79824,"nodeType":860},{},[79825],{"data":79826,"marks":79827,"value":65092,"nodeType":864},{},[],{"data":79829,"content":79830,"nodeType":860},{},[79831,79834,79838,79841,79845],{"data":79832,"marks":79833,"value":65099,"nodeType":864},{},[],{"data":79835,"marks":79836,"value":65104,"nodeType":864},{},[79837],{"type":899},{"data":79839,"marks":79840,"value":65108,"nodeType":864},{},[],{"data":79842,"marks":79843,"value":65113,"nodeType":864},{},[79844],{"type":899},{"data":79846,"marks":79847,"value":65117,"nodeType":864},{},[],{"data":79849,"content":79850,"nodeType":860},{},[79851,79854,79858,79861,79865],{"data":79852,"marks":79853,"value":65124,"nodeType":864},{},[],{"data":79855,"marks":79856,"value":288,"nodeType":864},{},[79857],{"type":899},{"data":79859,"marks":79860,"value":65132,"nodeType":864},{},[],{"data":79862,"marks":79863,"value":65137,"nodeType":864},{},[79864],{"type":899},{"data":79866,"marks":79867,"value":65141,"nodeType":864},{},[],{"data":79869,"content":79870,"nodeType":941},{},[79871,79880,79889],{"data":79872,"content":79873,"nodeType":945},{},[79874],{"data":79875,"content":79876,"nodeType":860},{},[79877],{"data":79878,"marks":79879,"value":65154,"nodeType":864},{},[],{"data":79881,"content":79882,"nodeType":945},{},[79883],{"data":79884,"content":79885,"nodeType":860},{},[79886],{"data":79887,"marks":79888,"value":65164,"nodeType":864},{},[],{"data":79890,"content":79891,"nodeType":945},{},[79892],{"data":79893,"content":79894,"nodeType":860},{},[79895],{"data":79896,"marks":79897,"value":65174,"nodeType":864},{},[],{"data":79899,"content":79902,"nodeType":996},{"target":79900},{"sys":79901},{"id":65179,"type":1001,"linkType":1002},[],{"data":79904,"content":79905,"nodeType":860},{},[79906,79909,79917],{"data":79907,"marks":79908,"value":21,"nodeType":864},{},[],{"data":79910,"content":79913,"nodeType":39736},{"target":79911},{"sys":79912},{"id":53020,"type":1001,"linkType":1002},[79914],{"data":79915,"marks":79916,"value":40614,"nodeType":864},{},[],{"data":79918,"marks":79919,"value":21,"nodeType":864},{},[],{"data":79921,"content":79922,"nodeType":1009},{},[79923],{"data":79924,"marks":79925,"value":65030,"nodeType":864},{},[],{"data":79927,"content":79928,"nodeType":860},{},[79929],{"data":79930,"marks":79931,"value":65210,"nodeType":864},{},[],{"data":79933,"content":79934,"nodeType":860},{},[79935],{"data":79936,"marks":79937,"value":65217,"nodeType":864},{},[],{"data":79939,"content":79940,"nodeType":860},{},[79941,79944,79948,79951,79955,79958,79962],{"data":79942,"marks":79943,"value":65224,"nodeType":864},{},[],{"data":79945,"marks":79946,"value":65229,"nodeType":864},{},[79947],{"type":899},{"data":79949,"marks":79950,"value":65233,"nodeType":864},{},[],{"data":79952,"marks":79953,"value":64560,"nodeType":864},{},[79954],{"type":899},{"data":79956,"marks":79957,"value":65241,"nodeType":864},{},[],{"data":79959,"marks":79960,"value":1334,"nodeType":864},{},[79961],{"type":899},{"data":79963,"marks":79964,"value":65249,"nodeType":864},{},[],{"data":79966,"content":79969,"nodeType":996},{"target":79967},{"sys":79968},{"id":65254,"type":1001,"linkType":1002},[],{"data":79971,"content":79972,"nodeType":860},{},[79973,79976,79984],{"data":79974,"marks":79975,"value":21,"nodeType":864},{},[],{"data":79977,"content":79980,"nodeType":39736},{"target":79978},{"sys":79979},{"id":64656,"type":1001,"linkType":1002},[79981],{"data":79982,"marks":79983,"value":40614,"nodeType":864},{},[],{"data":79985,"marks":79986,"value":21,"nodeType":864},{},[],{"data":79988,"content":79989,"nodeType":1009},{},[79990],{"data":79991,"marks":79992,"value":65040,"nodeType":864},{},[],{"data":79994,"content":79995,"nodeType":860},{},[79996,79999,80003],{"data":79997,"marks":79998,"value":65285,"nodeType":864},{},[],{"data":80000,"marks":80001,"value":65290,"nodeType":864},{},[80002],{"type":899},{"data":80004,"marks":80005,"value":65294,"nodeType":864},{},[],{"data":80007,"content":80008,"nodeType":860},{},[80009],{"data":80010,"marks":80011,"value":65301,"nodeType":864},{},[],{"data":80013,"content":80014,"nodeType":860},{},[80015,80018,80022,80025,80029],{"data":80016,"marks":80017,"value":65308,"nodeType":864},{},[],{"data":80019,"marks":80020,"value":65290,"nodeType":864},{},[80021],{"type":899},{"data":80023,"marks":80024,"value":65316,"nodeType":864},{},[],{"data":80026,"marks":80027,"value":65321,"nodeType":864},{},[80028],{"type":899},{"data":80030,"marks":80031,"value":64828,"nodeType":864},{},[],{"data":80033,"content":80034,"nodeType":1009},{},[80035],{"data":80036,"marks":80037,"value":65331,"nodeType":864},{},[],{"data":80039,"content":80040,"nodeType":860},{},[80041],{"data":80042,"marks":80043,"value":65338,"nodeType":864},{},[],{"data":80045,"content":80046,"nodeType":860},{},[80047,80050,80054,80057,80061],{"data":80048,"marks":80049,"value":65345,"nodeType":864},{},[],{"data":80051,"marks":80052,"value":65104,"nodeType":864},{},[80053],{"type":899},{"data":80055,"marks":80056,"value":65353,"nodeType":864},{},[],{"data":80058,"marks":80059,"value":65358,"nodeType":864},{},[80060],{"type":899},{"data":80062,"marks":80063,"value":2924,"nodeType":864},{},[],{"data":80065,"content":80066,"nodeType":860},{},[80067,80070,80074],{"data":80068,"marks":80069,"value":65368,"nodeType":864},{},[],{"data":80071,"marks":80072,"value":65373,"nodeType":864},{},[80073],{"type":899},{"data":80075,"marks":80076,"value":65377,"nodeType":864},{},[],{"data":80078,"content":80081,"nodeType":996},{"target":80079},{"sys":80080},{"id":65382,"type":1001,"linkType":1002},[],{"data":80083,"content":80084,"nodeType":1009},{},[80085],{"data":80086,"marks":80087,"value":65060,"nodeType":864},{},[],{"data":80089,"content":80090,"nodeType":860},{},[80091],{"data":80092,"marks":80093,"value":65396,"nodeType":864},{},[],{"data":80095,"content":80096,"nodeType":860},{},[80097,80100,80104],{"data":80098,"marks":80099,"value":65403,"nodeType":864},{},[],{"data":80101,"marks":80102,"value":65408,"nodeType":864},{},[80103],{"type":899},{"data":80105,"marks":80106,"value":65412,"nodeType":864},{},[],{"data":80108,"content":80109,"nodeType":860},{},[80110],{"data":80111,"marks":80112,"value":65419,"nodeType":864},{},[],{"data":80114,"content":80115,"nodeType":941},{},[80116,80125,80134,80143,80152],{"data":80117,"content":80118,"nodeType":945},{},[80119],{"data":80120,"content":80121,"nodeType":860},{},[80122],{"data":80123,"marks":80124,"value":65432,"nodeType":864},{},[],{"data":80126,"content":80127,"nodeType":945},{},[80128],{"data":80129,"content":80130,"nodeType":860},{},[80131],{"data":80132,"marks":80133,"value":65442,"nodeType":864},{},[],{"data":80135,"content":80136,"nodeType":945},{},[80137],{"data":80138,"content":80139,"nodeType":860},{},[80140],{"data":80141,"marks":80142,"value":65452,"nodeType":864},{},[],{"data":80144,"content":80145,"nodeType":945},{},[80146],{"data":80147,"content":80148,"nodeType":860},{},[80149],{"data":80150,"marks":80151,"value":65462,"nodeType":864},{},[],{"data":80153,"content":80154,"nodeType":945},{},[80155],{"data":80156,"content":80157,"nodeType":860},{},[80158],{"data":80159,"marks":80160,"value":65472,"nodeType":864},{},[],{"data":80162,"content":80163,"nodeType":860},{},[80164],{"data":80165,"marks":80166,"value":65479,"nodeType":864},{},[],{"data":80168,"content":80171,"nodeType":996},{"target":80169},{"sys":80170},{"id":65484,"type":1001,"linkType":1002},[],{"data":80173,"content":80174,"nodeType":860},{},[80175,80178,80186],{"data":80176,"marks":80177,"value":21,"nodeType":864},{},[],{"data":80179,"content":80182,"nodeType":39736},{"target":80180},{"sys":80181},{"id":65496,"type":1001,"linkType":1002},[80183],{"data":80184,"marks":80185,"value":40614,"nodeType":864},{},[],{"data":80187,"marks":80188,"value":21,"nodeType":864},{},[],{"data":80190,"content":80191,"nodeType":1009},{},[80192],{"data":80193,"marks":80194,"value":65070,"nodeType":864},{},[],{"data":80196,"content":80197,"nodeType":860},{},[80198,80201,80205],{"data":80199,"marks":80200,"value":65516,"nodeType":864},{},[],{"data":80202,"marks":80203,"value":53250,"nodeType":864},{},[80204],{"type":899},{"data":80206,"marks":80207,"value":65524,"nodeType":864},{},[],{"data":80209,"content":80210,"nodeType":860},{},[80211],{"data":80212,"marks":80213,"value":65531,"nodeType":864},{},[],{"data":80215,"content":80216,"nodeType":941},{},[80217,80226],{"data":80218,"content":80219,"nodeType":945},{},[80220],{"data":80221,"content":80222,"nodeType":860},{},[80223],{"data":80224,"marks":80225,"value":65544,"nodeType":864},{},[],{"data":80227,"content":80228,"nodeType":945},{},[80229],{"data":80230,"content":80231,"nodeType":860},{},[80232],{"data":80233,"marks":80234,"value":65554,"nodeType":864},{},[],{"data":80236,"content":80237,"nodeType":860},{},[80238,80241,80245,80248,80252],{"data":80239,"marks":80240,"value":53314,"nodeType":864},{},[],{"data":80242,"marks":80243,"value":53250,"nodeType":864},{},[80244],{"type":899},{"data":80246,"marks":80247,"value":65568,"nodeType":864},{},[],{"data":80249,"marks":80250,"value":65573,"nodeType":864},{},[80251],{"type":899},{"data":80253,"marks":80254,"value":2924,"nodeType":864},{},[],{"data":80256,"content":80257,"nodeType":1009},{},[80258],{"data":80259,"marks":80260,"value":64518,"nodeType":864},{},[],{"data":80262,"content":80263,"nodeType":860},{},[80264],{"data":80265,"marks":80266,"value":64860,"nodeType":864},{},[],{"data":80268,"content":80269,"nodeType":941},{},[80270,80301,80321,80330,80350],{"data":80271,"content":80272,"nodeType":945},{},[80273],{"data":80274,"content":80275,"nodeType":860},{},[80276,80279,80287,80290,80298],{"data":80277,"marks":80278,"value":65601,"nodeType":864},{},[],{"data":80280,"content":80283,"nodeType":39736},{"target":80281},{"sys":80282},{"id":65606,"type":1001,"linkType":1002},[80284],{"data":80285,"marks":80286,"value":65611,"nodeType":864},{},[],{"data":80288,"marks":80289,"value":902,"nodeType":864},{},[],{"data":80291,"content":80294,"nodeType":39736},{"target":80292},{"sys":80293},{"id":65619,"type":1001,"linkType":1002},[80295],{"data":80296,"marks":80297,"value":65624,"nodeType":864},{},[],{"data":80299,"marks":80300,"value":65628,"nodeType":864},{},[],{"data":80302,"content":80303,"nodeType":945},{},[80304],{"data":80305,"content":80306,"nodeType":860},{},[80307,80310,80318],{"data":80308,"marks":80309,"value":65638,"nodeType":864},{},[],{"data":80311,"content":80314,"nodeType":39736},{"target":80312},{"sys":80313},{"id":65643,"type":1001,"linkType":1002},[80315],{"data":80316,"marks":80317,"value":40614,"nodeType":864},{},[],{"data":80319,"marks":80320,"value":2924,"nodeType":864},{},[],{"data":80322,"content":80323,"nodeType":945},{},[80324],{"data":80325,"content":80326,"nodeType":860},{},[80327],{"data":80328,"marks":80329,"value":65660,"nodeType":864},{},[],{"data":80331,"content":80332,"nodeType":945},{},[80333],{"data":80334,"content":80335,"nodeType":860},{},[80336,80339,80347],{"data":80337,"marks":80338,"value":65670,"nodeType":864},{},[],{"data":80340,"content":80343,"nodeType":39736},{"target":80341},{"sys":80342},{"id":65675,"type":1001,"linkType":1002},[80344],{"data":80345,"marks":80346,"value":40614,"nodeType":864},{},[],{"data":80348,"marks":80349,"value":2924,"nodeType":864},{},[],{"data":80351,"content":80352,"nodeType":945},{},[80353],{"data":80354,"content":80355,"nodeType":860},{},[80356],{"data":80357,"marks":80358,"value":65692,"nodeType":864},{},[],{"data":80360,"content":80361,"nodeType":860},{},[80362],{"data":80363,"marks":80364,"value":21,"nodeType":864},{},[],{"entries":80366},{"inline":80367,"hyperlink":80368,"block":80399},[],[80369,80371,80373,80378,80383,80388,80394],{"sys":80370,"__typename":64143,"title":64184,"slug":64185,"articleId":64186},{"id":53020},{"sys":80372,"__typename":2059,"title":64950,"slug":64951},{"id":64656},{"sys":80374,"__typename":64143,"title":80375,"slug":80376,"articleId":80377},{"id":65496},"How does Push enrich detections with domain analysis data?","how-does-push-enrich-detections-with-domain-analysis-data",10136,{"sys":80379,"__typename":64143,"title":80380,"slug":80381,"articleId":80382},{"id":65606},"How do I create an exception for MFA findings?","how-do-i-create-an-exception-for-mfa-findings",10140,{"sys":80384,"__typename":64143,"title":80385,"slug":80386,"articleId":80387},{"id":65619},"How do I create an exception for reused password findings?","how-do-i-create-an-exception-for-reused-password-findings",10139,{"sys":80389,"__typename":80390,"linkedFromParent":59,"title":80391,"slug":80392,"audience":80393},{"id":65643},"DocumentationPage","Connect to SIEM or SOAR","connect-to-siem-or-soar","administrators",{"sys":80395,"__typename":64143,"title":80396,"slug":80397,"articleId":80398},{"id":65675},"Can I automatically remove licenses from inactive employees?","can-i-automatically-remove-licenses-from-inactive-employees",10143,[80400,80403,80410,80417],{"sys":80401,"__typename":1724,"title":71514,"caption":59,"layoutMode":59,"file":80402},{"id":65179},{"url":71516,"width":71517,"height":71518},{"sys":80404,"__typename":1724,"title":80405,"caption":59,"layoutMode":59,"file":80406},{"id":65254},"Clickfix detection example - KB 10141",{"url":80407,"width":80408,"height":80409},"https://images.ctfassets.net/y1cdw1ablpvd/5oWnKQFQqPdcsh93DCXji0/14d90366c354312349e5a664e2a0821a/clickfix_example_detection_20251009.png",1940,1696,{"sys":80411,"__typename":1724,"title":80412,"caption":59,"layoutMode":59,"file":80413},{"id":65382},"My team - Settings - docs - Administering Push",{"url":80414,"width":80415,"height":80416},"https://images.ctfassets.net/y1cdw1ablpvd/6TN6jkKngLWXBSe80jte2k/05a740c839e8eae4989622f4c9c2198b/org_page_settings_20250929.png",1980,1232,{"sys":80418,"__typename":1724,"title":71483,"caption":59,"layoutMode":59,"file":80419},{"id":65484},{"url":71485,"width":71486,"height":71487},{"items":80421},[],{},"Push Security new product features for November 2025",{"items":80425},[80426,80980],{"__typename":2059,"sys":80427,"content":80429,"title":80968,"synopsis":80969,"hashTags":59,"publishedDate":80970,"slug":80971,"tagsCollection":80972,"authorsCollection":80976},{"id":80428},"5QZCp0CTUoF0V7yZ8WnQrr",{"json":80430},{"data":80431,"content":80432,"nodeType":856},{},[80433,80440,80513,80519,80533,80581,80622,80628,80645,80651,80673,80700,80706,80723,80729,80736,80743,80767,80785,80792,80808,80815,80860,80866,80872,80879,80895,80913,80920,80927,80950],{"data":80434,"content":80435,"nodeType":1009},{},[80436],{"data":80437,"marks":80438,"value":80439,"nodeType":864},{},[],"What’s new this month:",{"data":80441,"content":80442,"nodeType":941},{},[80443,80453,80463,80473,80483,80493,80503],{"data":80444,"content":80445,"nodeType":945},{},[80446],{"data":80447,"content":80448,"nodeType":860},{},[80449],{"data":80450,"marks":80451,"value":80452,"nodeType":864},{},[],"Attack timeline, screenshots & classifications for Detections",{"data":80454,"content":80455,"nodeType":945},{},[80456],{"data":80457,"content":80458,"nodeType":860},{},[80459],{"data":80460,"marks":80461,"value":80462,"nodeType":864},{},[],"Block cloned login pages",{"data":80464,"content":80465,"nodeType":945},{},[80466],{"data":80467,"content":80468,"nodeType":860},{},[80469],{"data":80470,"marks":80471,"value":80472,"nodeType":864},{},[],"Block URL schema obfuscation",{"data":80474,"content":80475,"nodeType":945},{},[80476],{"data":80477,"content":80478,"nodeType":860},{},[80479],{"data":80480,"marks":80481,"value":80482,"nodeType":864},{},[],"Identify browsers synced to personal profiles",{"data":80484,"content":80485,"nodeType":945},{},[80486],{"data":80487,"content":80488,"nodeType":860},{},[80489],{"data":80490,"marks":80491,"value":80492,"nodeType":864},{},[],"Enhanced dashboard",{"data":80494,"content":80495,"nodeType":945},{},[80496],{"data":80497,"content":80498,"nodeType":860},{},[80499],{"data":80500,"marks":80501,"value":80502,"nodeType":864},{},[],"Configure a custom data retention period",{"data":80504,"content":80505,"nodeType":945},{},[80506],{"data":80507,"content":80508,"nodeType":860},{},[80509],{"data":80510,"marks":80511,"value":80512,"nodeType":864},{},[],"Debug logs for SIEM & webhooks integrations",{"data":80514,"content":80515,"nodeType":1009},{},[80516],{"data":80517,"marks":80518,"value":80452,"nodeType":864},{},[],{"data":80520,"content":80521,"nodeType":860},{},[80522,80526,80530],{"data":80523,"marks":80524,"value":80525,"nodeType":864},{},[],"You can now get deeper context and telemetry to investigate attacks that Push intercepts in the browser using these recently released enrichments for Push’s ",{"data":80527,"marks":80528,"value":64544,"nodeType":864},{},[80529],{"type":899},{"data":80531,"marks":80532,"value":73631,"nodeType":864},{},[],{"data":80534,"content":80535,"nodeType":941},{},[80536,80551,80566],{"data":80537,"content":80538,"nodeType":945},{},[80539],{"data":80540,"content":80541,"nodeType":860},{},[80542,80547],{"data":80543,"marks":80544,"value":80546,"nodeType":864},{},[80545],{"type":899},"Timeline:",{"data":80548,"marks":80549,"value":80550,"nodeType":864},{},[]," An attack timeline of where a phishing link originated, how a user interacted with the page, and how Push responded.",{"data":80552,"content":80553,"nodeType":945},{},[80554],{"data":80555,"content":80556,"nodeType":860},{},[80557,80562],{"data":80558,"marks":80559,"value":80561,"nodeType":864},{},[80560],{"type":899},"Screenshots:",{"data":80563,"marks":80564,"value":80565,"nodeType":864},{},[]," Optional screenshots of the suspicious page, to quickly triage detections.",{"data":80567,"content":80568,"nodeType":945},{},[80569],{"data":80570,"content":80571,"nodeType":860},{},[80572,80577],{"data":80573,"marks":80574,"value":80576,"nodeType":864},{},[80575],{"type":899},"Blast radius:",{"data":80578,"marks":80579,"value":80580,"nodeType":864},{},[]," A view of the impact of this attack and whether other apps are also compromised or at risk as a result.",{"data":80582,"content":80583,"nodeType":860},{},[80584,80588,80593,80596,80601,80605,80610,80614,80619],{"data":80585,"marks":80586,"value":80587,"nodeType":864},{},[],"You can also now classify a detection to record the outcome of your investigation. Options include: ",{"data":80589,"marks":80590,"value":80592,"nodeType":864},{},[80591],{"type":899},"true positive",{"data":80594,"marks":80595,"value":3731,"nodeType":864},{},[],{"data":80597,"marks":80598,"value":80600,"nodeType":864},{},[80599],{"type":899},"benign true positive",{"data":80602,"marks":80603,"value":80604,"nodeType":864},{},[]," (such as a detection triggered by a phishing simulation exercise), and ",{"data":80606,"marks":80607,"value":80609,"nodeType":864},{},[80608],{"type":899},"false positive",{"data":80611,"marks":80612,"value":80613,"nodeType":864},{},[],". The default state is ",{"data":80615,"marks":80616,"value":80618,"nodeType":864},{},[80617],{"type":899},"not classified",{"data":80620,"marks":80621,"value":2924,"nodeType":864},{},[],{"data":80623,"content":80627,"nodeType":996},{"target":80624},{"sys":80625},{"id":80626,"type":1001,"linkType":1002},"2IMRHDY5ShjsquyaW7hB5M",[],{"data":80629,"content":80630,"nodeType":860},{},[80631,80634,80642],{"data":80632,"marks":80633,"value":21,"nodeType":864},{},[],{"data":80635,"content":80638,"nodeType":39736},{"target":80636},{"sys":80637},{"id":67318,"type":1001,"linkType":1002},[80639],{"data":80640,"marks":80641,"value":40614,"nodeType":864},{},[],{"data":80643,"marks":80644,"value":21,"nodeType":864},{},[],{"data":80646,"content":80647,"nodeType":1009},{},[80648],{"data":80649,"marks":80650,"value":80462,"nodeType":864},{},[],{"data":80652,"content":80653,"nodeType":860},{},[80654,80658,80662,80665,80669],{"data":80655,"marks":80656,"value":80657,"nodeType":864},{},[],"You can now ",{"data":80659,"marks":80660,"value":1503,"nodeType":864},{},[80661],{"type":899},{"data":80663,"marks":80664,"value":52968,"nodeType":864},{},[],{"data":80666,"marks":80667,"value":1397,"nodeType":864},{},[80668],{"type":899},{"data":80670,"marks":80671,"value":80672,"nodeType":864},{},[]," employees when Push detects that they’re visiting a cloned login page.",{"data":80674,"content":80675,"nodeType":860},{},[80676,80680,80684,80688,80692,80696],{"data":80677,"marks":80678,"value":67243,"nodeType":864},{},[80679],{"type":899},{"data":80681,"marks":80682,"value":80683,"nodeType":864},{},[],", which you can configure on the ",{"data":80685,"marks":80686,"value":64560,"nodeType":864},{},[80687],{"type":899},{"data":80689,"marks":80690,"value":80691,"nodeType":864},{},[]," page of the Push admin console, has become a highly effective and low false-positive control. We recommend that you move to using ",{"data":80693,"marks":80694,"value":1397,"nodeType":864},{},[80695],{"type":899},{"data":80697,"marks":80698,"value":80699,"nodeType":864},{},[]," mode for your organization — if you’re not already!",{"data":80701,"content":80705,"nodeType":996},{"target":80702},{"sys":80703},{"id":80704,"type":1001,"linkType":1002},"4auXExHqaYtu44zTFGh47s",[],{"data":80707,"content":80708,"nodeType":860},{},[80709,80712,80720],{"data":80710,"marks":80711,"value":21,"nodeType":864},{},[],{"data":80713,"content":80716,"nodeType":39736},{"target":80714},{"sys":80715},{"id":52703,"type":1001,"linkType":1002},[80717],{"data":80718,"marks":80719,"value":40614,"nodeType":864},{},[],{"data":80721,"marks":80722,"value":21,"nodeType":864},{},[],{"data":80724,"content":80725,"nodeType":1009},{},[80726],{"data":80727,"marks":80728,"value":80482,"nodeType":864},{},[],{"data":80730,"content":80731,"nodeType":860},{},[80732],{"data":80733,"marks":80734,"value":80735,"nodeType":864},{},[],"The Push browser extension can now identify the email address that’s used to log in to a browser, as well as whether browser sync is enabled.",{"data":80737,"content":80738,"nodeType":860},{},[80739],{"data":80740,"marks":80741,"value":80742,"nodeType":864},{},[],"Using this data, you can see whether any employees are signed in to work browsers with non-company identities and syncing their browsers, which can result in work credentials being synced to personal profiles. ",{"data":80744,"content":80745,"nodeType":860},{},[80746,80750,80755,80759,80763],{"data":80747,"marks":80748,"value":80749,"nodeType":864},{},[],"To find this data, go to the Push admin console and view the ",{"data":80751,"marks":80752,"value":80754,"nodeType":864},{},[80753],{"type":899},"Browsers",{"data":80756,"marks":80757,"value":80758,"nodeType":864},{},[]," page under ",{"data":80760,"marks":80761,"value":65137,"nodeType":864},{},[80762],{"type":899},{"data":80764,"marks":80765,"value":80766,"nodeType":864},{},[]," in the left toolbar.",{"data":80768,"content":80769,"nodeType":860},{},[80770,80773,80782],{"data":80771,"marks":80772,"value":21,"nodeType":864},{},[],{"data":80774,"content":80778,"nodeType":39736},{"target":80775},{"sys":80776},{"id":80777,"type":1001,"linkType":1002},"2IS6Dbz1fnJZrDfrMSTFQd",[80779],{"data":80780,"marks":80781,"value":40614,"nodeType":864},{},[],{"data":80783,"marks":80784,"value":21,"nodeType":864},{},[],{"data":80786,"content":80787,"nodeType":1009},{},[80788],{"data":80789,"marks":80790,"value":80791,"nodeType":864},{},[],"Enhanced dashboard for easier monitoring",{"data":80793,"content":80794,"nodeType":860},{},[80795,80799,80804],{"data":80796,"marks":80797,"value":80798,"nodeType":864},{},[],"We’ve improved the data and design of the Push admin console ",{"data":80800,"marks":80801,"value":80803,"nodeType":864},{},[80802],{"type":899},"Dashboard",{"data":80805,"marks":80806,"value":80807,"nodeType":864},{},[]," so you can keep track of the important developments in your environment.",{"data":80809,"content":80810,"nodeType":860},{},[80811],{"data":80812,"marks":80813,"value":80814,"nodeType":864},{},[],"A few of the changes:",{"data":80816,"content":80817,"nodeType":941},{},[80818,80836,80850],{"data":80819,"content":80820,"nodeType":945},{},[80821],{"data":80822,"content":80823,"nodeType":860},{},[80824,80828,80832],{"data":80825,"marks":80826,"value":80827,"nodeType":864},{},[],"A snapshot of recent ",{"data":80829,"marks":80830,"value":64544,"nodeType":864},{},[80831],{"type":899},{"data":80833,"marks":80834,"value":80835,"nodeType":864},{},[]," activity",{"data":80837,"content":80838,"nodeType":945},{},[80839],{"data":80840,"content":80841,"nodeType":860},{},[80842,80846],{"data":80843,"marks":80844,"value":80845,"nodeType":864},{},[],"An overview of all events on the platform, including activity related to ",{"data":80847,"marks":80848,"value":64560,"nodeType":864},{},[80849],{"type":899},{"data":80851,"content":80852,"nodeType":945},{},[80853],{"data":80854,"content":80855,"nodeType":860},{},[80856],{"data":80857,"marks":80858,"value":80859,"nodeType":864},{},[],"Performance improvements so the page load is fast for even very large deployments",{"data":80861,"content":80865,"nodeType":996},{"target":80862},{"sys":80863},{"id":80864,"type":1001,"linkType":1002},"4kqqwOPsN7VhLeQdrV15bH",[],{"data":80867,"content":80868,"nodeType":1009},{},[80869],{"data":80870,"marks":80871,"value":80502,"nodeType":864},{},[],{"data":80873,"content":80874,"nodeType":860},{},[80875],{"data":80876,"marks":80877,"value":80878,"nodeType":864},{},[],"You can now configure how long activity data will be retained in Push by configuring a data retention period. ",{"data":80880,"content":80881,"nodeType":860},{},[80882,80886,80891],{"data":80883,"marks":80884,"value":80885,"nodeType":864},{},[],"From the admin console, go to ",{"data":80887,"marks":80888,"value":80890,"nodeType":864},{},[80889],{"type":899},"Settings > Organization > Data retention",{"data":80892,"marks":80893,"value":80894,"nodeType":864},{},[]," and select the data retention period in years.",{"data":80896,"content":80897,"nodeType":860},{},[80898,80901,80910],{"data":80899,"marks":80900,"value":21,"nodeType":864},{},[],{"data":80902,"content":80906,"nodeType":39736},{"target":80903},{"sys":80904},{"id":80905,"type":1001,"linkType":1002},"4esJSEUrMN2hpbghIkXjDG",[80907],{"data":80908,"marks":80909,"value":40614,"nodeType":864},{},[],{"data":80911,"marks":80912,"value":21,"nodeType":864},{},[],{"data":80914,"content":80915,"nodeType":1009},{},[80916],{"data":80917,"marks":80918,"value":80919,"nodeType":864},{},[],"Easier debugging for webhook or integration error messages",{"data":80921,"content":80922,"nodeType":860},{},[80923],{"data":80924,"marks":80925,"value":80926,"nodeType":864},{},[],"We’ve added a debug log to make it easier to see what’s not working when you receive an error related to your Push webhooks or SIEM integrations.",{"data":80928,"content":80929,"nodeType":860},{},[80930,80934,80939,80942,80947],{"data":80931,"marks":80932,"value":80933,"nodeType":864},{},[],"You can access the debug log by opening the details slideout in the Push admin console for the webhook or integration you’ve created. Go to ",{"data":80935,"marks":80936,"value":80938,"nodeType":864},{},[80937],{"type":899},"Settings > Webhooks",{"data":80940,"marks":80941,"value":52968,"nodeType":864},{},[],{"data":80943,"marks":80944,"value":80946,"nodeType":864},{},[80945],{"type":899},"Settings > Integrations",{"data":80948,"marks":80949,"value":2924,"nodeType":864},{},[],{"data":80951,"content":80952,"nodeType":860},{},[80953,80956,80965],{"data":80954,"marks":80955,"value":21,"nodeType":864},{},[],{"data":80957,"content":80961,"nodeType":39736},{"target":80958},{"sys":80959},{"id":80960,"type":1001,"linkType":1002},"2naceBODKDL3iw72wrce6E",[80962],{"data":80963,"marks":80964,"value":40614,"nodeType":864},{},[],{"data":80966,"marks":80967,"value":21,"nodeType":864},{},[],"Product release: September 2025","Here’s what’s new on the Push platform for September 2025.","2025-09-08T00:00:00.000Z","product-release-september-2025",{"items":80973},[80974],{"sys":80975,"name":65708},{"id":65707},{"items":80977},[80978],{"fullName":64440,"firstName":64441,"jobTitle":64442,"profilePicture":80979},{"url":64444},{"__typename":2059,"sys":80981,"content":80983,"title":81451,"synopsis":81452,"hashTags":59,"publishedDate":81453,"slug":81454,"tagsCollection":81455,"authorsCollection":81459},{"id":80982},"20xOvhmIKW7E0e1g5q7D2h",{"json":80984},{"data":80985,"content":80986,"nodeType":856},{},[80987,80993,81066,81072,81088,81095,81101,81119,81125,81141,81148,81155,81179,81184,81190,81204,81211,81217,81234,81240,81256,81263,81270,81276,81294,81300,81315,81322,81328,81344,81350,81381,81396,81402,81418,81424,81439,81445],{"data":80988,"content":80989,"nodeType":1009},{},[80990],{"data":80991,"marks":80992,"value":64455,"nodeType":864},{},[],{"data":80994,"content":80995,"nodeType":941},{},[80996,81006,81016,81026,81036,81046,81056],{"data":80997,"content":80998,"nodeType":945},{},[80999],{"data":81000,"content":81001,"nodeType":860},{},[81002],{"data":81003,"marks":81004,"value":81005,"nodeType":864},{},[],"Streamline investigations with Detections page",{"data":81007,"content":81008,"nodeType":945},{},[81009],{"data":81010,"content":81011,"nodeType":860},{},[81012],{"data":81013,"marks":81014,"value":81015,"nodeType":864},{},[],"New Labs feature: Employee verification codes",{"data":81017,"content":81018,"nodeType":945},{},[81019],{"data":81020,"content":81021,"nodeType":860},{},[81022],{"data":81023,"marks":81024,"value":81025,"nodeType":864},{},[],"Enforce strong passwords with in-browser guardrails",{"data":81027,"content":81028,"nodeType":945},{},[81029],{"data":81030,"content":81031,"nodeType":860},{},[81032],{"data":81033,"marks":81034,"value":81035,"nodeType":864},{},[],"Merge related employee records",{"data":81037,"content":81038,"nodeType":945},{},[81039],{"data":81040,"content":81041,"nodeType":860},{},[81042],{"data":81043,"marks":81044,"value":81045,"nodeType":864},{},[],"Customize your webhook events",{"data":81047,"content":81048,"nodeType":945},{},[81049],{"data":81050,"content":81051,"nodeType":860},{},[81052],{"data":81053,"marks":81054,"value":81055,"nodeType":864},{},[],"Create rules for phishing tool detection and MFA enforcement",{"data":81057,"content":81058,"nodeType":945},{},[81059],{"data":81060,"content":81061,"nodeType":860},{},[81062],{"data":81063,"marks":81064,"value":81065,"nodeType":864},{},[],"New integration for Microsoft Sentinel",{"data":81067,"content":81068,"nodeType":1009},{},[81069],{"data":81070,"marks":81071,"value":81005,"nodeType":864},{},[],{"data":81073,"content":81074,"nodeType":860},{},[81075,81079,81084],{"data":81076,"marks":81077,"value":81078,"nodeType":864},{},[],"You can now receive and triage detections in the Push admin console (or get them via the Push REST API, webhooks or ChatOps), giving you a ",{"data":81080,"marks":81081,"value":81083,"nodeType":864},{},[81082],{"type":899},"single view of all the security events that Push has detected",{"data":81085,"marks":81086,"value":81087,"nodeType":864},{},[],", such as AiTM phishing, stolen creds, or blocked URLs being visited by employees.",{"data":81089,"content":81090,"nodeType":860},{},[81091],{"data":81092,"marks":81093,"value":81094,"nodeType":864},{},[]," Use the additional telemetry about each detection, such as timestamp, detection URL, type of phishkit detected, Push response action, etc., to understand how to triage the incident. ",{"data":81096,"content":81100,"nodeType":996},{"target":81097},{"sys":81098},{"id":81099,"type":1001,"linkType":1002},"53BOccCQ72Yo3oCSUWVFXn",[],{"data":81102,"content":81103,"nodeType":860},{},[81104,81107,81116],{"data":81105,"marks":81106,"value":21,"nodeType":864},{},[],{"data":81108,"content":81112,"nodeType":39736},{"target":81109},{"sys":81110},{"id":81111,"type":1001,"linkType":1002},"6jbLw9Wi2JuddCXL6ncrCV",[81113],{"data":81114,"marks":81115,"value":40614,"nodeType":864},{},[],{"data":81117,"marks":81118,"value":21,"nodeType":864},{},[],{"data":81120,"content":81121,"nodeType":1009},{},[81122],{"data":81123,"marks":81124,"value":81015,"nodeType":864},{},[],{"data":81126,"content":81127,"nodeType":860},{},[81128,81132,81137],{"data":81129,"marks":81130,"value":81131,"nodeType":864},{},[],"Employees can now get a 6-digit verification code via the Push browser extension that you can use to ",{"data":81133,"marks":81134,"value":81136,"nodeType":864},{},[81135],{"type":899},"validate that your help desk is speaking to someone from your organization",{"data":81138,"marks":81139,"value":81140,"nodeType":864},{},[],".  ",{"data":81142,"content":81143,"nodeType":860},{},[81144],{"data":81145,"marks":81146,"value":81147,"nodeType":864},{},[],"The verification code is the same for all employees at a given organization, and resets every 24 hours. If your help desk needs to verify that they’re speaking to an employee, they can ask them to open the details tray for their Push extension and verify the code.",{"data":81149,"content":81150,"nodeType":860},{},[81151],{"data":81152,"marks":81153,"value":81154,"nodeType":864},{},[],"Employee verification codes is a Labs feature, which means it’s available on an early-access basis and we're particularly interested in hearing from you if this is a problem you're interested in solving using Push. ",{"data":81156,"content":81157,"nodeType":860},{},[81158,81162,81166,81170,81175],{"data":81159,"marks":81160,"value":81161,"nodeType":864},{},[],"You can enable Labs features by going to the ",{"data":81163,"marks":81164,"value":53319,"nodeType":864},{},[81165],{"type":899},{"data":81167,"marks":81168,"value":81169,"nodeType":864},{},[]," page of the Push admin console and choosing the ",{"data":81171,"marks":81172,"value":81174,"nodeType":864},{},[81173],{"type":899},"Labs",{"data":81176,"marks":81177,"value":81178,"nodeType":864},{},[]," tab.",{"data":81180,"content":81183,"nodeType":996},{"target":81181},{"sys":81182},{"id":67992,"type":1001,"linkType":1002},[],{"data":81185,"content":81186,"nodeType":1009},{},[81187],{"data":81188,"marks":81189,"value":81025,"nodeType":864},{},[],{"data":81191,"content":81192,"nodeType":860},{},[81193,81197,81201],{"data":81194,"marks":81195,"value":81196,"nodeType":864},{},[],"Prompt your employees to change an insecure password using Push’s new in-browser guardrail, ",{"data":81198,"marks":81199,"value":53112,"nodeType":864},{},[81200],{"type":899},{"data":81202,"marks":81203,"value":1774,"nodeType":864},{},[],{"data":81205,"content":81206,"nodeType":860},{},[81207],{"data":81208,"marks":81209,"value":81210,"nodeType":864},{},[],"You can select which password security issues you want to remediate, and which apps you want to target using the configuration rules for this control. Then, when Push observes a password issue, it will automatically display a banner to end-users prompting them to change their password.",{"data":81212,"content":81216,"nodeType":996},{"target":81213},{"sys":81214},{"id":81215,"type":1001,"linkType":1002},"6ZcsdzYPxLAE1K170mQPHE",[],{"data":81218,"content":81219,"nodeType":860},{},[81220,81223,81231],{"data":81221,"marks":81222,"value":21,"nodeType":864},{},[],{"data":81224,"content":81227,"nodeType":39736},{"target":81225},{"sys":81226},{"id":52973,"type":1001,"linkType":1002},[81228],{"data":81229,"marks":81230,"value":40614,"nodeType":864},{},[],{"data":81232,"marks":81233,"value":21,"nodeType":864},{},[],{"data":81235,"content":81236,"nodeType":1009},{},[81237],{"data":81238,"marks":81239,"value":81035,"nodeType":864},{},[],{"data":81241,"content":81242,"nodeType":860},{},[81243,81247,81252],{"data":81244,"marks":81245,"value":81246,"nodeType":864},{},[],"If you have employees using multiple email addresses, you can ",{"data":81248,"marks":81249,"value":81251,"nodeType":864},{},[81250],{"type":899},"now merge those records in the Push platform",{"data":81253,"marks":81254,"value":81255,"nodeType":864},{},[]," so they can be treated as a single employee. ",{"data":81257,"content":81258,"nodeType":860},{},[81259],{"data":81260,"marks":81261,"value":81262,"nodeType":864},{},[],"A common use case for merging employee records is when you have employees with a user account and an administrator account. By merging records in cases like this, you can resolve incorrect shared account findings and correct your license usage so only the primary employee record consumes a license. ",{"data":81264,"content":81265,"nodeType":860},{},[81266],{"data":81267,"marks":81268,"value":81269,"nodeType":864},{},[],"You can also merge records programmatically via the Push REST API. This is helpful if you have a predictable pattern for usernames you're mapping.",{"data":81271,"content":81275,"nodeType":996},{"target":81272},{"sys":81273},{"id":81274,"type":1001,"linkType":1002},"3xcEqhSUZ1VmZTsgSOS4xH",[],{"data":81277,"content":81278,"nodeType":860},{},[81279,81282,81291],{"data":81280,"marks":81281,"value":21,"nodeType":864},{},[],{"data":81283,"content":81287,"nodeType":39736},{"target":81284},{"sys":81285},{"id":81286,"type":1001,"linkType":1002},"3RIMjhmhJcHC2V7Lkrhvj2",[81288],{"data":81289,"marks":81290,"value":40614,"nodeType":864},{},[],{"data":81292,"marks":81293,"value":21,"nodeType":864},{},[],{"data":81295,"content":81296,"nodeType":1009},{},[81297],{"data":81298,"marks":81299,"value":81045,"nodeType":864},{},[],{"data":81301,"content":81302,"nodeType":860},{},[81303,81306,81311],{"data":81304,"marks":81305,"value":80657,"nodeType":864},{},[],{"data":81307,"marks":81308,"value":81310,"nodeType":864},{},[81309],{"type":899},"select which events you want when creating a webhook",{"data":81312,"marks":81313,"value":81314,"nodeType":864},{},[]," in the Push platform. For example, if you want to build an automation around specific Push events or send only Push detection alerts to your SIEM, you can elect to send just those events to your configured destinations. ",{"data":81316,"content":81317,"nodeType":860},{},[81318],{"data":81319,"marks":81320,"value":81321,"nodeType":864},{},[],"You can select which events you want to consume when configuring a new webhook via the Push admin console.",{"data":81323,"content":81327,"nodeType":996},{"target":81324},{"sys":81325},{"id":81326,"type":1001,"linkType":1002},"755nABuK9KGdHHwWNqDtmS",[],{"data":81329,"content":81330,"nodeType":860},{},[81331,81334,81341],{"data":81332,"marks":81333,"value":21,"nodeType":864},{},[],{"data":81335,"content":81337,"nodeType":883},{"uri":81336},"https://pushsecurity.redoc.ly/webhooks-v1",[81338],{"data":81339,"marks":81340,"value":40614,"nodeType":864},{},[],{"data":81342,"marks":81343,"value":21,"nodeType":864},{},[],{"data":81345,"content":81346,"nodeType":1009},{},[81347],{"data":81348,"marks":81349,"value":81055,"nodeType":864},{},[],{"data":81351,"content":81352,"nodeType":860},{},[81353,81357,81362,81366,81371,81374,81378],{"data":81354,"marks":81355,"value":81356,"nodeType":864},{},[],"We’re continuing to ",{"data":81358,"marks":81359,"value":81361,"nodeType":864},{},[81360],{"type":899},"add configuration rule capabilities to security controls",{"data":81363,"marks":81364,"value":81365,"nodeType":864},{},[]," in the Push platform, including for ",{"data":81367,"marks":81368,"value":81370,"nodeType":864},{},[81369],{"type":899},"phishing tool detection",{"data":81372,"marks":81373,"value":902,"nodeType":864},{},[],{"data":81375,"marks":81376,"value":53104,"nodeType":864},{},[81377],{"type":899},{"data":81379,"marks":81380,"value":1774,"nodeType":864},{},[],{"data":81382,"content":81383,"nodeType":860},{},[81384,81388,81392],{"data":81385,"marks":81386,"value":81387,"nodeType":864},{},[],"With these config rules, you can scope a control to specific employees or employee groups, and carve out exemptions if you like. You can also set the control to apply to specific apps, or set the ",{"data":81389,"marks":81390,"value":64686,"nodeType":864},{},[81391],{"type":899},{"data":81393,"marks":81394,"value":81395,"nodeType":864},{},[]," (e.g. Monitor, Warn, or Block), where applicable.",{"data":81397,"content":81401,"nodeType":996},{"target":81398},{"sys":81399},{"id":81400,"type":1001,"linkType":1002},"2eKYcSet4tkd6UEffzdaaa",[],{"data":81403,"content":81404,"nodeType":860},{},[81405,81408,81415],{"data":81406,"marks":81407,"value":21,"nodeType":864},{},[],{"data":81409,"content":81411,"nodeType":883},{"uri":81410},"/help/10121/#how-to-create-a-configuration-rule",[81412],{"data":81413,"marks":81414,"value":40614,"nodeType":864},{},[],{"data":81416,"marks":81417,"value":21,"nodeType":864},{},[],{"data":81419,"content":81420,"nodeType":1009},{},[81421],{"data":81422,"marks":81423,"value":81065,"nodeType":864},{},[],{"data":81425,"content":81426,"nodeType":860},{},[81427,81431,81435],{"data":81428,"marks":81429,"value":81430,"nodeType":864},{},[],"Push now offers a Microsoft Sentinel integration to make it easier to send Push data to your Sentinel SIEM. You can start setting up your integration by going to ",{"data":81432,"marks":81433,"value":80946,"nodeType":864},{},[81434],{"type":899},{"data":81436,"marks":81437,"value":81438,"nodeType":864},{},[]," in the Push admin console and selecting the Sentinel tile.",{"data":81440,"content":81444,"nodeType":996},{"target":81441},{"sys":81442},{"id":81443,"type":1001,"linkType":1002},"5l5TIPvbOoNgauV7gUj7fy",[],{"data":81446,"content":81447,"nodeType":860},{},[81448],{"data":81449,"marks":81450,"value":21,"nodeType":864},{},[],"Product release: June 2025","Here’s what’s new on the Push platform for June 2025.","2025-06-09T00:00:00.000Z","product-release-june-2025",{"items":81456},[81457],{"sys":81458,"name":65708},{"id":65707},{"items":81460},[81461],{"fullName":64440,"firstName":64441,"jobTitle":64442,"profilePicture":81462},{"url":64444},"blog/product-release-november-2025",{"json":81465},{"data":81466,"content":81467,"nodeType":856},{},[81468],{"data":81469,"content":81470,"nodeType":860},{},[81471],{"data":81472,"marks":81473,"value":81474,"nodeType":864},{},[],"Browser extension visibility, ClickFix detection, RBAC and more.",{"id":64997,"publishedAt":81476},"2026-08-13T09:34:58.995Z",{"items":81478},[81479],{"sys":81480,"name":65708},{"id":65707},{"items":81482},[81483,81485,81487,81489],{"sys":81484,"name":297,"slug":298,"tier":31},{"id":294},{"sys":81486,"name":288,"slug":289,"tier":45},{"id":285},{"sys":81488,"name":315,"slug":316,"tier":45},{"id":312},{"sys":81490,"name":598,"slug":599,"tier":45},{"id":595},"4b_JWlgpJmPkxAfNXEHJpjVo5NMVhKC04Re6Yh_q2RA",{"id":81493,"title":78541,"authorsCollection":81494,"content":81499,"extension":228,"faqItemsCollection":82106,"faqTitle":59,"featured":6,"hashTags":59,"meta":82108,"metaTitle":82109,"ogImage":82110,"postType":5726,"publishedDate":78543,"relatedBlogPostsCollection":82112,"slug":78544,"stem":84509,"subtitle":59,"summary":84510,"synopsis":78542,"sys":84521,"tagsCollection":84523,"topicsCollection":84529,"__hash__":84577},"blog/blog/6-browser-based-attacks-every-security-team-should-be-prepared-for.json",{"items":81495},[81496],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":81497,"profilePicture":81498},[15231],{"url":2740},{"json":81500,"links":82052},{"data":81501,"content":81502,"nodeType":856},{},[81503,81516,81522,81525,81532,81538,81544,81560,81565,81571,81577,81583,81589,81592,81599,81605,81610,81616,81623,81629,81635,81640,81656,81661,81667,81673,81679,81684,81687,81694,81710,81716,81742,81748,81754,81759,81765,81771,81777,81780,81787,81802,81807,81813,81819,81824,81830,81836,81839,81846,81852,81868,81904,81910,81916,81922,81925,81932,81938,81944,81950,81953,81960,81966,81992,82008,82014,82017,82024,82030,82036],{"data":81504,"content":81505,"nodeType":860},{},[81506,81509,81513],{"data":81507,"marks":81508,"value":77907,"nodeType":864},{},[],{"data":81510,"marks":81511,"value":77912,"nodeType":864},{},[81512],{"type":2246},{"data":81514,"marks":81515,"value":77916,"nodeType":864},{},[],{"data":81517,"content":81518,"nodeType":860},{},[81519],{"data":81520,"marks":81521,"value":77923,"nodeType":864},{},[],{"data":81523,"content":81524,"nodeType":1005},{},[],{"data":81526,"content":81527,"nodeType":1009},{},[81528],{"data":81529,"marks":81530,"value":77934,"nodeType":864},{},[81531],{"type":899},{"data":81533,"content":81534,"nodeType":860},{},[81535],{"data":81536,"marks":81537,"value":77941,"nodeType":864},{},[],{"data":81539,"content":81540,"nodeType":860},{},[81541],{"data":81542,"marks":81543,"value":77948,"nodeType":864},{},[],{"data":81545,"content":81546,"nodeType":860},{},[81547,81550,81557],{"data":81548,"marks":81549,"value":77955,"nodeType":864},{},[],{"data":81551,"content":81552,"nodeType":883},{"uri":77958},[81553],{"data":81554,"marks":81555,"value":77964,"nodeType":864},{},[81556],{"type":1455},{"data":81558,"marks":81559,"value":77968,"nodeType":864},{},[],{"data":81561,"content":81564,"nodeType":996},{"target":81562},{"sys":81563},{"id":77973,"type":1001,"linkType":1002},[],{"data":81566,"content":81567,"nodeType":860},{},[81568],{"data":81569,"marks":81570,"value":77981,"nodeType":864},{},[],{"data":81572,"content":81573,"nodeType":860},{},[81574],{"data":81575,"marks":81576,"value":77988,"nodeType":864},{},[],{"data":81578,"content":81579,"nodeType":860},{},[81580],{"data":81581,"marks":81582,"value":77995,"nodeType":864},{},[],{"data":81584,"content":81585,"nodeType":860},{},[81586],{"data":81587,"marks":81588,"value":78002,"nodeType":864},{},[],{"data":81590,"content":81591,"nodeType":1005},{},[],{"data":81593,"content":81594,"nodeType":1009},{},[81595],{"data":81596,"marks":81597,"value":78013,"nodeType":864},{},[81598],{"type":899},{"data":81600,"content":81601,"nodeType":860},{},[81602],{"data":81603,"marks":81604,"value":78020,"nodeType":864},{},[],{"data":81606,"content":81609,"nodeType":996},{"target":81607},{"sys":81608},{"id":78025,"type":1001,"linkType":1002},[],{"data":81611,"content":81612,"nodeType":860},{},[81613],{"data":81614,"marks":81615,"value":78033,"nodeType":864},{},[],{"data":81617,"content":81618,"nodeType":1312},{},[81619],{"data":81620,"marks":81621,"value":78041,"nodeType":864},{},[81622],{"type":899},{"data":81624,"content":81625,"nodeType":860},{},[81626],{"data":81627,"marks":81628,"value":78048,"nodeType":864},{},[],{"data":81630,"content":81631,"nodeType":860},{},[81632],{"data":81633,"marks":81634,"value":78055,"nodeType":864},{},[],{"data":81636,"content":81639,"nodeType":996},{"target":81637},{"sys":81638},{"id":78060,"type":1001,"linkType":1002},[],{"data":81641,"content":81642,"nodeType":860},{},[81643,81646,81653],{"data":81644,"marks":81645,"value":78068,"nodeType":864},{},[],{"data":81647,"content":81648,"nodeType":883},{"uri":78071},[81649],{"data":81650,"marks":81651,"value":73474,"nodeType":864},{},[81652],{"type":1455},{"data":81654,"marks":81655,"value":16213,"nodeType":864},{},[],{"data":81657,"content":81660,"nodeType":996},{"target":81658},{"sys":81659},{"id":78084,"type":1001,"linkType":1002},[],{"data":81662,"content":81663,"nodeType":860},{},[81664],{"data":81665,"marks":81666,"value":78092,"nodeType":864},{},[],{"data":81668,"content":81669,"nodeType":860},{},[81670],{"data":81671,"marks":81672,"value":78099,"nodeType":864},{},[],{"data":81674,"content":81675,"nodeType":860},{},[81676],{"data":81677,"marks":81678,"value":78106,"nodeType":864},{},[],{"data":81680,"content":81683,"nodeType":996},{"target":81681},{"sys":81682},{"id":78111,"type":1001,"linkType":1002},[],{"data":81685,"content":81686,"nodeType":1005},{},[],{"data":81688,"content":81689,"nodeType":1312},{},[81690],{"data":81691,"marks":81692,"value":78123,"nodeType":864},{},[81693],{"type":899},{"data":81695,"content":81696,"nodeType":860},{},[81697,81700,81707],{"data":81698,"marks":81699,"value":78130,"nodeType":864},{},[],{"data":81701,"content":81702,"nodeType":883},{"uri":78133},[81703],{"data":81704,"marks":81705,"value":315,"nodeType":864},{},[81706],{"type":1455},{"data":81708,"marks":81709,"value":11546,"nodeType":864},{},[],{"data":81711,"content":81712,"nodeType":860},{},[81713],{"data":81714,"marks":81715,"value":78148,"nodeType":864},{},[],{"data":81717,"content":81718,"nodeType":860},{},[81719,81722,81729,81732,81739],{"data":81720,"marks":81721,"value":78155,"nodeType":864},{},[],{"data":81723,"content":81724,"nodeType":883},{"uri":78158},[81725],{"data":81726,"marks":81727,"value":78164,"nodeType":864},{},[81728],{"type":1455},{"data":81730,"marks":81731,"value":78168,"nodeType":864},{},[],{"data":81733,"content":81734,"nodeType":883},{"uri":78171},[81735],{"data":81736,"marks":81737,"value":78177,"nodeType":864},{},[81738],{"type":1455},{"data":81740,"marks":81741,"value":2924,"nodeType":864},{},[],{"data":81743,"content":81744,"nodeType":860},{},[81745],{"data":81746,"marks":81747,"value":78187,"nodeType":864},{},[],{"data":81749,"content":81750,"nodeType":860},{},[81751],{"data":81752,"marks":81753,"value":78194,"nodeType":864},{},[],{"data":81755,"content":81758,"nodeType":996},{"target":81756},{"sys":81757},{"id":78199,"type":1001,"linkType":1002},[],{"data":81760,"content":81761,"nodeType":860},{},[81762],{"data":81763,"marks":81764,"value":78207,"nodeType":864},{},[],{"data":81766,"content":81767,"nodeType":860},{},[81768],{"data":81769,"marks":81770,"value":78214,"nodeType":864},{},[],{"data":81772,"content":81773,"nodeType":860},{},[81774],{"data":81775,"marks":81776,"value":78221,"nodeType":864},{},[],{"data":81778,"content":81779,"nodeType":1005},{},[],{"data":81781,"content":81782,"nodeType":1312},{},[81783],{"data":81784,"marks":81785,"value":78232,"nodeType":864},{},[81786],{"type":899},{"data":81788,"content":81789,"nodeType":860},{},[81790,81793,81799],{"data":81791,"marks":81792,"value":78239,"nodeType":864},{},[],{"data":81794,"content":81795,"nodeType":883},{"uri":50933},[81796],{"data":81797,"marks":81798,"value":72707,"nodeType":864},{},[],{"data":81800,"marks":81801,"value":1774,"nodeType":864},{},[],{"data":81803,"content":81806,"nodeType":996},{"target":81804},{"sys":81805},{"id":78253,"type":1001,"linkType":1002},[],{"data":81808,"content":81809,"nodeType":860},{},[81810],{"data":81811,"marks":81812,"value":78261,"nodeType":864},{},[],{"data":81814,"content":81815,"nodeType":860},{},[81816],{"data":81817,"marks":81818,"value":78268,"nodeType":864},{},[],{"data":81820,"content":81823,"nodeType":996},{"target":81821},{"sys":81822},{"id":78273,"type":1001,"linkType":1002},[],{"data":81825,"content":81826,"nodeType":860},{},[81827],{"data":81828,"marks":81829,"value":78281,"nodeType":864},{},[],{"data":81831,"content":81832,"nodeType":860},{},[81833],{"data":81834,"marks":81835,"value":78288,"nodeType":864},{},[],{"data":81837,"content":81838,"nodeType":1005},{},[],{"data":81840,"content":81841,"nodeType":1312},{},[81842],{"data":81843,"marks":81844,"value":78299,"nodeType":864},{},[81845],{"type":899},{"data":81847,"content":81848,"nodeType":860},{},[81849],{"data":81850,"marks":81851,"value":78306,"nodeType":864},{},[],{"data":81853,"content":81854,"nodeType":860},{},[81855,81858,81865],{"data":81856,"marks":81857,"value":78313,"nodeType":864},{},[],{"data":81859,"content":81860,"nodeType":883},{"uri":78316},[81861],{"data":81862,"marks":81863,"value":78322,"nodeType":864},{},[81864],{"type":1455},{"data":81866,"marks":81867,"value":78326,"nodeType":864},{},[],{"data":81869,"content":81870,"nodeType":860},{},[81871,81874,81881,81884,81891,81894,81901],{"data":81872,"marks":81873,"value":78333,"nodeType":864},{},[],{"data":81875,"content":81876,"nodeType":883},{"uri":50913},[81877],{"data":81878,"marks":81879,"value":78341,"nodeType":864},{},[81880],{"type":1455},{"data":81882,"marks":81883,"value":78345,"nodeType":864},{},[],{"data":81885,"content":81886,"nodeType":883},{"uri":78348},[81887],{"data":81888,"marks":81889,"value":78354,"nodeType":864},{},[81890],{"type":1455},{"data":81892,"marks":81893,"value":2232,"nodeType":864},{},[],{"data":81895,"content":81896,"nodeType":883},{"uri":78360},[81897],{"data":81898,"marks":81899,"value":78366,"nodeType":864},{},[81900],{"type":1455},{"data":81902,"marks":81903,"value":2924,"nodeType":864},{},[],{"data":81905,"content":81906,"nodeType":860},{},[81907],{"data":81908,"marks":81909,"value":78376,"nodeType":864},{},[],{"data":81911,"content":81912,"nodeType":860},{},[81913],{"data":81914,"marks":81915,"value":78383,"nodeType":864},{},[],{"data":81917,"content":81918,"nodeType":860},{},[81919],{"data":81920,"marks":81921,"value":78390,"nodeType":864},{},[],{"data":81923,"content":81924,"nodeType":1005},{},[],{"data":81926,"content":81927,"nodeType":1312},{},[81928],{"data":81929,"marks":81930,"value":78401,"nodeType":864},{},[81931],{"type":899},{"data":81933,"content":81934,"nodeType":860},{},[81935],{"data":81936,"marks":81937,"value":78408,"nodeType":864},{},[],{"data":81939,"content":81940,"nodeType":860},{},[81941],{"data":81942,"marks":81943,"value":78415,"nodeType":864},{},[],{"data":81945,"content":81946,"nodeType":860},{},[81947],{"data":81948,"marks":81949,"value":78422,"nodeType":864},{},[],{"data":81951,"content":81952,"nodeType":1005},{},[],{"data":81954,"content":81955,"nodeType":1312},{},[81956],{"data":81957,"marks":81958,"value":78433,"nodeType":864},{},[81959],{"type":899},{"data":81961,"content":81962,"nodeType":860},{},[81963],{"data":81964,"marks":81965,"value":78440,"nodeType":864},{},[],{"data":81967,"content":81968,"nodeType":860},{},[81969,81972,81979,81982,81989],{"data":81970,"marks":81971,"value":78447,"nodeType":864},{},[],{"data":81973,"content":81974,"nodeType":883},{"uri":77958},[81975],{"data":81976,"marks":81977,"value":77964,"nodeType":864},{},[81978],{"type":1455},{"data":81980,"marks":81981,"value":78458,"nodeType":864},{},[],{"data":81983,"content":81984,"nodeType":883},{"uri":78461},[81985],{"data":81986,"marks":81987,"value":78467,"nodeType":864},{},[81988],{"type":1455},{"data":81990,"marks":81991,"value":78471,"nodeType":864},{},[],{"data":81993,"content":81994,"nodeType":860},{},[81995,81998,82005],{"data":81996,"marks":81997,"value":78478,"nodeType":864},{},[],{"data":81999,"content":82000,"nodeType":883},{"uri":78481},[82001],{"data":82002,"marks":82003,"value":78487,"nodeType":864},{},[82004],{"type":1455},{"data":82006,"marks":82007,"value":78491,"nodeType":864},{},[],{"data":82009,"content":82010,"nodeType":860},{},[82011],{"data":82012,"marks":82013,"value":78498,"nodeType":864},{},[],{"data":82015,"content":82016,"nodeType":1005},{},[],{"data":82018,"content":82019,"nodeType":1009},{},[82020],{"data":82021,"marks":82022,"value":51911,"nodeType":864},{},[82023],{"type":899},{"data":82025,"content":82026,"nodeType":860},{},[82027],{"data":82028,"marks":82029,"value":78515,"nodeType":864},{},[],{"data":82031,"content":82032,"nodeType":860},{},[82033],{"data":82034,"marks":82035,"value":78522,"nodeType":864},{},[],{"data":82037,"content":82038,"nodeType":860},{},[82039,82042,82049],{"data":82040,"marks":82041,"value":78529,"nodeType":864},{},[],{"data":82043,"content":82044,"nodeType":883},{"uri":78532},[82045],{"data":82046,"marks":82047,"value":16894,"nodeType":864},{},[82048],{"type":1455},{"data":82050,"marks":82051,"value":2924,"nodeType":864},{},[],{"entries":82053},{"hyperlink":82054,"inline":82055,"block":82056},[],[],[82057,82064,82072,82078,82085,82090,82096,82101],{"sys":82058,"__typename":1724,"title":82059,"caption":82059,"layoutMode":59,"file":82060},{"id":77973},"Attacks have shifted from targeting local networks to internet services, accessed through employee web browsers.",{"url":82061,"width":82062,"height":82063},"https://images.ctfassets.net/y1cdw1ablpvd/2TRbV3HLZRt0pjgxPAPUOY/5dbeec4b4ac16a3b450e1eff2add6266/1.png",1174,482,{"sys":82065,"__typename":1724,"title":82066,"caption":82067,"layoutMode":59,"file":82068},{"id":78025},"Browser-based attacks like AITM phishing, ClickFix, and consent phishing have seen an unprecedented rise in recent years.","Browser-based attacks like AITM phishing, ClickFix, and consent phishing are the fastest-growing threats of 2025. ",{"url":82069,"width":82070,"height":82071},"https://images.ctfassets.net/y1cdw1ablpvd/1eCBgB8nNDu5955f1BwFO6/b80d5cb43c7acd75e1a670d4ae22b2ec/Browser-based_attacks_graphic__1_.png",2012,1272,{"sys":82073,"__typename":1724,"title":82074,"caption":82074,"layoutMode":59,"file":82075},{"id":78060},"Phishing is now multi- and cross-channel, targeting a vast range of cloud and SaaS apps using flexible AitM toolkits — but all roads inevitably lead to the browser.",{"url":82076,"width":1736,"height":82077},"https://images.ctfassets.net/y1cdw1ablpvd/1Fq4iSo4ssD0bdINZ4M31q/28d89ce5b8af767b37d2acb54a1c78cf/2.png",1003,{"sys":82079,"__typename":1724,"title":82080,"caption":82080,"layoutMode":59,"file":82081},{"id":78084},"AitM kits proxy information to the real site in order to complete the login process, passing MFA checks to steal the user’s session. ",{"url":82082,"width":82083,"height":82084},"https://images.ctfassets.net/y1cdw1ablpvd/Yo8TuzfyNcBWOIl34X1dS/2381e4e671039ddf61d03ef44fa45138/3.png",1064,458,{"sys":82086,"__typename":1717,"type":1718,"ctaText":82087,"buttonLabel":82088,"buttonColour":1721,"buttonUrl":82089},{"id":78111},"Learn more about how phishing attacks have evolved and why they're so effective at evading detection controls.","Get the Whitepaper","https://pushsecurity.com/resources/phishing-evolution",{"sys":82091,"__typename":1724,"title":82092,"caption":82092,"layoutMode":59,"file":82093},{"id":78199},"Examples of ClickFix lures used by attackers in the wild.",{"url":82094,"width":1736,"height":82095},"https://images.ctfassets.net/y1cdw1ablpvd/3VSQ6bEHXlk0yJRal4R4oD/d3d6d281acfe22361a7d36719c4b0fa9/4.png",1955,{"sys":82097,"__typename":1724,"title":82098,"caption":82098,"layoutMode":59,"file":82099},{"id":78253},"Consent phishing examples, where an attacker tricks the victim into authorizing an attacker-controlled app with risky permissions.",{"url":82100,"width":1736,"height":74617},"https://images.ctfassets.net/y1cdw1ablpvd/1Yx10JvyaLHI2DzhAjDgE0/886e807035dc8d005b9a6c84919a5a3f/5.png",{"sys":82102,"__typename":1724,"title":82103,"caption":82103,"layoutMode":59,"file":82104},{"id":78273},"The ongoing Salesforce attacks involve malicious OAuth apps being granted access to the victim’s Salesforce tenant. ",{"url":82105,"width":74623,"height":74624},"https://images.ctfassets.net/y1cdw1ablpvd/5JA9n2l57OlYE3jIcsYKv2/d7f1dcf15542f2df4045df1c3c61ba2e/6.png",{"items":82107},[],{},"6 browser-based attacks security teams need to know about",{"url":82111},"https://images.ctfassets.net/y1cdw1ablpvd/42Id6vr4wOWFp4RH6MqFoJ/54bfaf4a392fcbeda9bf795b09a9bef3/Bleeping_Thumbnail__Article_Header_.png",{"items":82113},[82114,83113,83721],{"__typename":2059,"sys":82115,"content":82116,"title":71409,"synopsis":83101,"hashTags":59,"publishedDate":83102,"slug":71410,"tagsCollection":83103,"authorsCollection":83109},{"id":67318},{"json":82117},{"data":82118,"content":82119,"nodeType":856},{},[82120,82127,82139,82151,82163,82175,82181,82201,82208,82223,82230,82236,82239,82247,82254,82261,82268,82274,82277,82285,82292,82312,82319,82326,82333,82340,82346,82353,82360,82367,82396,82403,82421,82428,82435,82455,82475,82495,82501,82508,82524,82531,82538,82545,82564,82572,82579,82586,82589,82597,82604,82611,82618,82661,82667,82674,82689,82778,82784,82791,82798,82861,82868,82875,82882,82888,82895,82902,82909,82915,82922,82929,82936,82942,82962,82969,82976,83019,83025,83028,83036,83060,83063,83070,83077,83084],{"data":82121,"content":82122,"nodeType":860},{},[82123],{"data":82124,"marks":82125,"value":82126,"nodeType":864},{},[],"Oh, look! A time capsule from 2010. Wonder what’s inside … ",{"data":82128,"content":82129,"nodeType":860},{},[82130,82135],{"data":82131,"marks":82132,"value":82134,"nodeType":864},{},[82133],{"type":899},"Listening to:",{"data":82136,"marks":82137,"value":82138,"nodeType":864},{},[]," “Like a G6” by Far East Movement (on a Nokia C7 — hey, it even had a touchscreen).",{"data":82140,"content":82141,"nodeType":860},{},[82142,82147],{"data":82143,"marks":82144,"value":82146,"nodeType":864},{},[82145],{"type":899},"Major news event:",{"data":82148,"marks":82149,"value":82150,"nodeType":864},{},[]," Eyjafjallajökull volcano erupts in Iceland, disrupting air travel.",{"data":82152,"content":82153,"nodeType":860},{},[82154,82159],{"data":82155,"marks":82156,"value":82158,"nodeType":864},{},[82157],{"type":899},"Worried about:",{"data":82160,"marks":82161,"value":82162,"nodeType":864},{},[]," Exploitable Flash browser plugins and static HTML phishing sites.",{"data":82164,"content":82165,"nodeType":860},{},[82166,82171],{"data":82167,"marks":82168,"value":82170,"nodeType":864},{},[82169],{"type":899},"How to be a hero?",{"data":82172,"marks":82173,"value":82174,"nodeType":864},{},[]," Roll out the latest AV, implement a web proxy, and add a “report phishing” button to your email solution.",{"data":82176,"content":82180,"nodeType":996},{"target":82177},{"sys":82178},{"id":82179,"type":1001,"linkType":1002},"54xYbMs0ii96xb2jgQVX9m",[],{"data":82182,"content":82183,"nodeType":860},{},[82184,82188,82197],{"data":82185,"marks":82186,"value":82187,"nodeType":864},{},[],"We’re halfway through 2025, and the time capsule for this year may need to be an XL when it comes to ",{"data":82189,"content":82191,"nodeType":883},{"uri":82190},"https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/",[82192],{"data":82193,"marks":82194,"value":82196,"nodeType":864},{},[82195],{"type":1455},"how much has happened",{"data":82198,"marks":82199,"value":82200,"nodeType":864},{},[]," in the world of browser-based attacks. (Yet fittingly, Drake’s “Nokia” is a pop hit.)",{"data":82202,"content":82203,"nodeType":860},{},[82204],{"data":82205,"marks":82206,"value":82207,"nodeType":864},{},[],"While at least we don’t have to worry about Flash anymore, the browser is now the new battleground, and workforce identities are the most common target. Security teams are struggling with approaches and tools that attackers have outpaced.",{"data":82209,"content":82210,"nodeType":860},{},[82211,82215,82219],{"data":82212,"marks":82213,"value":82214,"nodeType":864},{},[],"In this article, we’ll cover how browser-based attacks have evolved, and how Push is taking a new approach with the release of our ",{"data":82216,"marks":82217,"value":64544,"nodeType":864},{},[82218],{"type":899},{"data":82220,"marks":82221,"value":82222,"nodeType":864},{},[]," capabilities, now generally available to all customers.",{"data":82224,"content":82225,"nodeType":860},{},[82226],{"data":82227,"marks":82228,"value":82229,"nodeType":864},{},[],"Push Detections use real-time telemetry to help you understand context, user behavior, and attacker techniques, and then respond — a modern tool for modern browser-based attacks.",{"data":82231,"content":82235,"nodeType":996},{"target":82232},{"sys":82233},{"id":82234,"type":1001,"linkType":1002},"2ULDSj85bXtT2OgpXKBHtB",[],{"data":82237,"content":82238,"nodeType":1005},{},[],{"data":82240,"content":82241,"nodeType":1009},{},[82242],{"data":82243,"marks":82244,"value":82246,"nodeType":864},{},[82245],{"type":899},"The old world vs. the new world",{"data":82248,"content":82249,"nodeType":860},{},[82250],{"data":82251,"marks":82252,"value":82253,"nodeType":864},{},[],"In the early 2010s, the typical attack path involved sending a user an email with a link to a static HTML webpage (most commonly a generic Exchange Web Access clone) that tricked them into giving you Active Directory creds. These could be used to log in to an exposed remote desktop service or the victim’s mailbox, giving the attacker a foothold to install malware. Anyone who’s done “red teaming 101” will recognize this scenario. ",{"data":82255,"content":82256,"nodeType":860},{},[82257],{"data":82258,"marks":82259,"value":82260,"nodeType":864},{},[],"A compromised identity was once just part of a system compromise. That meant the scope of detection and response was focused on the organization’s Active Directory domain, correlated with endpoint and network logs. ",{"data":82262,"content":82263,"nodeType":860},{},[82264],{"data":82265,"marks":82266,"value":82267,"nodeType":864},{},[],"But now, identity attacks happen beyond traditional on-premises networks, impacting cloud identities that are created, used, and attacked in the browser. What was once the familiar backbone of business IT — internal apps and thick clients — has been replaced with a sprawling cloud and SaaS ecosystem that can be targeted directly via identity, without touching the endpoint. ",{"data":82269,"content":82273,"nodeType":996},{"target":82270},{"sys":82271},{"id":82272,"type":1001,"linkType":1002},"2F2p4eTMCHo3LfNQJZeGWB",[],{"data":82275,"content":82276,"nodeType":1005},{},[],{"data":82278,"content":82279,"nodeType":1009},{},[82280],{"data":82281,"marks":82282,"value":82284,"nodeType":864},{},[82283],{"type":899},"Why detection and response hasn’t kept up with threat evolution",{"data":82286,"content":82287,"nodeType":860},{},[82288],{"data":82289,"marks":82290,"value":82291,"nodeType":864},{},[],"This shift in attacker TTPs is forcing a change in how we handle detection and response. ",{"data":82293,"content":82294,"nodeType":860},{},[82295,82299,82308],{"data":82296,"marks":82297,"value":82298,"nodeType":864},{},[],"But a lot of organizations are still applying the same old playbooks to this new world where identity attacks are the ",{"data":82300,"content":82302,"nodeType":883},{"uri":82301},"https://pushsecurity.com/resources/2024-identity-attacks",[82303],{"data":82304,"marks":82305,"value":82307,"nodeType":864},{},[82306],{"type":1455},"leading cause of breaches",{"data":82309,"marks":82310,"value":82311,"nodeType":864},{},[],", with uneven outcomes. ",{"data":82313,"content":82314,"nodeType":860},{},[82315],{"data":82316,"marks":82317,"value":82318,"nodeType":864},{},[],"This isn’t because of a lack of effort or skill on the part of security teams. It’s a reflection of the tools that have been available. ",{"data":82320,"content":82321,"nodeType":860},{},[82322],{"data":82323,"marks":82324,"value":82325,"nodeType":864},{},[],"Let’s look at some of the ways detection and response hasn’t kept up with the evolution of browser-borne threats in this new landscape.",{"data":82327,"content":82328,"nodeType":1312},{},[82329],{"data":82330,"marks":82331,"value":82332,"nodeType":864},{},[],"Incomplete identity visibility ",{"data":82334,"content":82335,"nodeType":860},{},[82336],{"data":82337,"marks":82338,"value":82339,"nodeType":864},{},[],"Today’s cloud identity providers see a fraction of the overall logins your users make to online apps, compared to the comprehensive visibility of Active Directory in the old world. You don’t know where users are logging in, how they’re logging in, or whether these logins are securely using phishing-resistant methods.",{"data":82341,"content":82345,"nodeType":996},{"target":82342},{"sys":82343},{"id":82344,"type":1001,"linkType":1002},"1SUYueQct7dtWwLh3AaAtA",[],{"data":82347,"content":82348,"nodeType":860},{},[82349],{"data":82350,"marks":82351,"value":82352,"nodeType":864},{},[],"This means that identity attacks are routinely bypassing preventative, account hygiene-based controls, putting the strain on detection and response. ",{"data":82354,"content":82355,"nodeType":1312},{},[82356],{"data":82357,"marks":82358,"value":82359,"nodeType":864},{},[],"Limited detection coverage ",{"data":82361,"content":82362,"nodeType":860},{},[82363],{"data":82364,"marks":82365,"value":82366,"nodeType":864},{},[],"Email and network security tools got pretty good at intercepting old-school phishing attacks like the ones from our proverbial time capsule: static HTML pages delivered over email that could be intercepted and analyzed when entering the mailbox or being loaded by the user. ",{"data":82368,"content":82369,"nodeType":860},{},[82370,82374,82383,82387,82391],{"data":82371,"marks":82372,"value":82373,"nodeType":864},{},[],"But with modern phishing attacks dynamically obfuscating the code that loads the web page, implementing custom bot protection, and using runtime anti-analysis features, they’re ",{"data":82375,"content":82376,"nodeType":883},{"uri":13094},[82377],{"data":82378,"marks":82379,"value":82382,"nodeType":864},{},[82380,82381],{"type":1455},{"type":899},"increasingly difficult to detect",{"data":82384,"marks":82385,"value":1171,"nodeType":864},{},[82386],{"type":899},{"data":82388,"marks":82389,"value":82390,"nodeType":864},{},[],"using conventional tools",{"data":82392,"marks":82393,"value":82395,"nodeType":864},{},[82394],{"type":899},".   ",{"data":82397,"content":82398,"nodeType":860},{},[82399],{"data":82400,"marks":82401,"value":82402,"nodeType":864},{},[],"Of course, email-based detections aren’t much use if attackers are using legitimate services to camouflage their links, or bypassing email altogether by switching to alternative delivery channels like messaging apps (such as Slack and Teams), as well as public services like LinkedIn and Reddit. ",{"data":82404,"content":82405,"nodeType":860},{},[82406,82410,82417],{"data":82407,"marks":82408,"value":82409,"nodeType":864},{},[],"More recently, groups like ",{"data":82411,"content":82412,"nodeType":883},{"uri":82190},[82413],{"data":82414,"marks":82415,"value":67962,"nodeType":864},{},[82416],{"type":1455},{"data":82418,"marks":82419,"value":82420,"nodeType":864},{},[]," have even been seen using malvertising techniques, delivering phishing links masquerading as paid Google ads.",{"data":82422,"content":82423,"nodeType":1312},{},[82424],{"data":82425,"marks":82426,"value":82427,"nodeType":864},{},[],"Inadequate security logs",{"data":82429,"content":82430,"nodeType":860},{},[82431],{"data":82432,"marks":82433,"value":82434,"nodeType":864},{},[],"If you fail to spot the attack pre-account takeover, you’re reliant on being able to detect and investigate suspicious or malicious activity resulting from the compromise. ",{"data":82436,"content":82437,"nodeType":860},{},[82438,82442,82451],{"data":82439,"marks":82440,"value":82441,"nodeType":864},{},[],"This was more straightforward (if not easy) when you had the luxury of a ",{"data":82443,"content":82445,"nodeType":883},{"uri":82444},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[82446],{"data":82447,"marks":82448,"value":82450,"nodeType":864},{},[82449],{"type":1455},"typical on-prem network to fall back",{"data":82452,"marks":82453,"value":82454,"nodeType":864},{},[]," on. But with cloud exploitation taking place in a matter of minutes, you don’t get much warning — and your endpoint and network-based alarms can’t help you. ",{"data":82456,"content":82457,"nodeType":860},{},[82458,82462,82471],{"data":82459,"marks":82460,"value":82461,"nodeType":864},{},[],"The situation is further complicated by the fact that you simply don’t have the logs you need because of the huge variability in how cloud and SaaS services provide logs (with many ",{"data":82463,"content":82465,"nodeType":883},{"uri":82464},"https://pushsecurity.com/blog/minimum-viable-identity-security/#id-enable-security-teams-to-detect-and-respond-to-identity-attacks",[82466],{"data":82467,"marks":82468,"value":82470,"nodeType":864},{},[82469],{"type":1455},"failing to provide security logs",{"data":82472,"marks":82473,"value":82474,"nodeType":864},{},[]," with relevant data points at all). So chances are you’re flying blind when it comes to large chunks of your business app suite. ",{"data":82476,"content":82477,"nodeType":860},{},[82478,82482,82491],{"data":82479,"marks":82480,"value":82481,"nodeType":864},{},[],"Ultimately, you’re stuck with what you can observe — typically network traffic. But ",{"data":82483,"content":82485,"nodeType":883},{"uri":82484},"https://pushsecurity.com/blog/the-web-proxy-is-dead-long-live-the-browser-extension/",[82486],{"data":82487,"marks":82488,"value":82490,"nodeType":864},{},[82489],{"type":1455},"even with a TLS-terminating proxy",{"data":82492,"marks":82493,"value":82494,"nodeType":864},{},[],", extracting fine-grained identity data points isn’t really achievable. You’re looking from the outside-in at malicious activity that’s happening in the user’s browser and trying to infer what happened.  ",{"data":82496,"content":82500,"nodeType":996},{"target":82497},{"sys":82498},{"id":82499,"type":1001,"linkType":1002},"7FMdHtbE63GMCavObETf3O",[],{"data":82502,"content":82503,"nodeType":1312},{},[82504],{"data":82505,"marks":82506,"value":82507,"nodeType":864},{},[],"Spotty control enforcement",{"data":82509,"content":82510,"nodeType":860},{},[82511,82515,82520],{"data":82512,"marks":82513,"value":82514,"nodeType":864},{},[],"And in the case that you do identify that a user clicked a malicious link and ",{"data":82516,"marks":82517,"value":82519,"nodeType":864},{},[82518],{"type":2246},"maybe ",{"data":82521,"marks":82522,"value":82523,"nodeType":864},{},[],"entered their credentials into the page — now what? ",{"data":82525,"content":82526,"nodeType":860},{},[82527],{"data":82528,"marks":82529,"value":82530,"nodeType":864},{},[],"You can reset the account in the affected app, ideally terminating active sessions — which may or may not be possible, depending on the app. This might take a while if you don’t centrally manage the app, and involve some painful emergency phone calls to employees. ",{"data":82532,"content":82533,"nodeType":860},{},[82534],{"data":82535,"marks":82536,"value":82537,"nodeType":864},{},[],"What about apps where the same password is reused? ",{"data":82539,"content":82540,"nodeType":860},{},[82541],{"data":82542,"marks":82543,"value":82544,"nodeType":864},{},[],"Or if it’s an IdP account used for SSO, what about the other apps that might be accessible now? ",{"data":82546,"content":82547,"nodeType":860},{},[82548,82552,82560],{"data":82549,"marks":82550,"value":82551,"nodeType":864},{},[],"If the attacker has created stealthy backdoors that persist through credential changes (like ",{"data":82553,"content":82554,"nodeType":883},{"uri":57333},[82555],{"data":82556,"marks":82557,"value":82559,"nodeType":864},{},[82558],{"type":1455},"creating an API key or a malicious OAuth integration",{"data":82561,"marks":82562,"value":82563,"nodeType":864},{},[],") they could still be lurking in your environment.",{"data":82565,"content":82566,"nodeType":860},{},[82567],{"data":82568,"marks":82569,"value":82571,"nodeType":864},{},[82570],{"type":899},"Suddenly, you’re not dealing with one possible control point, you’re dealing with several. ",{"data":82573,"content":82574,"nodeType":860},{},[82575],{"data":82576,"marks":82577,"value":82578,"nodeType":864},{},[],"And if you can’t trace the attack back to a source — because your email solution missed it, or it didn’t come via email, how can you triage the impact to other users? ",{"data":82580,"content":82581,"nodeType":860},{},[82582],{"data":82583,"marks":82584,"value":82585,"nodeType":864},{},[],"It’s no wonder that security teams are struggling to adapt. ",{"data":82587,"content":82588,"nodeType":1005},{},[],{"data":82590,"content":82591,"nodeType":1009},{},[82592],{"data":82593,"marks":82594,"value":82596,"nodeType":864},{},[82595],{"type":899},"How Push is solving modern identity investigations in the browser",{"data":82598,"content":82599,"nodeType":860},{},[82600],{"data":82601,"marks":82602,"value":82603,"nodeType":864},{},[],"The good news? We’ve seen this phenomenon play out before: In the early 2010s, in fact, when AV evolved into EDR. What was the big innovation then? Getting inside the data stream, in real time, and detecting and responding from a much higher-fidelity source of telemetry.",{"data":82605,"content":82606,"nodeType":860},{},[82607],{"data":82608,"marks":82609,"value":82610,"nodeType":864},{},[],"This time around, security teams need tools that take them inside the browser layer.",{"data":82612,"content":82613,"nodeType":860},{},[82614],{"data":82615,"marks":82616,"value":82617,"nodeType":864},{},[],"This approach gives you the right vantage point to defend against and investigate browser-based identity attacks, providing access to:",{"data":82619,"content":82620,"nodeType":941},{},[82621,82631,82641,82651],{"data":82622,"content":82623,"nodeType":945},{},[82624],{"data":82625,"content":82626,"nodeType":860},{},[82627],{"data":82628,"marks":82629,"value":82630,"nodeType":864},{},[],"Full decrypted HTTP traffic — not just DNS and TCP/IP metadata",{"data":82632,"content":82633,"nodeType":945},{},[82634],{"data":82635,"content":82636,"nodeType":860},{},[82637],{"data":82638,"marks":82639,"value":82640,"nodeType":864},{},[],"Full user interaction tracing — every click, keystroke, or DOM change",{"data":82642,"content":82643,"nodeType":945},{},[82644],{"data":82645,"content":82646,"nodeType":860},{},[82647],{"data":82648,"marks":82649,"value":82650,"nodeType":864},{},[],"Full inspection at every layer of execution, not just the initial HTML served",{"data":82652,"content":82653,"nodeType":945},{},[82654],{"data":82655,"content":82656,"nodeType":860},{},[82657],{"data":82658,"marks":82659,"value":82660,"nodeType":864},{},[],"Full access to browser APIs, to correlate with browser history, local storage, cookies, etc.",{"data":82662,"content":82666,"nodeType":996},{"target":82663},{"sys":82664},{"id":82665,"type":1001,"linkType":1002},"5qt0s8e1TIEUxhU1GzFO63",[],{"data":82668,"content":82669,"nodeType":860},{},[82670],{"data":82671,"marks":82672,"value":82673,"nodeType":864},{},[],"With this data, teams have the information they need to respond to and investigate browser-based attacks. But to become valuable, this data needs a translation layer that turns it from raw logs into actionable information.",{"data":82675,"content":82676,"nodeType":860},{},[82677,82681,82685],{"data":82678,"marks":82679,"value":82680,"nodeType":864},{},[],"That’s where Push’s ",{"data":82682,"marks":82683,"value":64544,"nodeType":864},{},[82684],{"type":899},{"data":82686,"marks":82687,"value":82688,"nodeType":864},{},[]," capability comes in. With it, you can:",{"data":82690,"content":82691,"nodeType":941},{},[82692,82728,82738,82748,82758,82768],{"data":82693,"content":82694,"nodeType":945},{},[82695],{"data":82696,"content":82697,"nodeType":860},{},[82698,82702,82711,82715,82724],{"data":82699,"marks":82700,"value":82701,"nodeType":864},{},[],"Get alerted in your platform of choice (via the Push admin console, ",{"data":82703,"content":82705,"nodeType":883},{"uri":82704},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/send-webhook-events-to-slack/",[82706],{"data":82707,"marks":82708,"value":82710,"nodeType":864},{},[82709],{"type":1455},"Slack integration",{"data":82712,"marks":82713,"value":82714,"nodeType":864},{},[],", or your ",{"data":82716,"content":82718,"nodeType":883},{"uri":82717},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/",[82719],{"data":82720,"marks":82721,"value":82723,"nodeType":864},{},[82722],{"type":1455},"SIEM/SOAR",{"data":82725,"marks":82726,"value":82727,"nodeType":864},{},[]," of choice) whenever Push detects a browser-based attack, such as AiTM phishing or a cloned login page.",{"data":82729,"content":82730,"nodeType":945},{},[82731],{"data":82732,"content":82733,"nodeType":860},{},[82734],{"data":82735,"marks":82736,"value":82737,"nodeType":864},{},[],"Review a curated timeline of the incident: Where a phishing link originated; whether a user entered their credentials on the page; what kind of phishkit was used; and whether the attack was blocked by Push.",{"data":82739,"content":82740,"nodeType":945},{},[82741],{"data":82742,"content":82743,"nodeType":860},{},[82744],{"data":82745,"marks":82746,"value":82747,"nodeType":864},{},[],"See all the other impacted accounts and apps that shared a password with the phished account so you can remediate them.",{"data":82749,"content":82750,"nodeType":945},{},[82751],{"data":82752,"content":82753,"nodeType":860},{},[82754],{"data":82755,"marks":82756,"value":82757,"nodeType":864},{},[],"See a screenshot captured by the Push browser extension of the phishing page, so you can see exactly what the user saw before the page disappears.",{"data":82759,"content":82760,"nodeType":945},{},[82761],{"data":82762,"content":82763,"nodeType":860},{},[82764],{"data":82765,"marks":82766,"value":82767,"nodeType":864},{},[],"Get additional context from urlscan.io about the domains connected to the incident, helping you understand whether a domain has been reported as malicious by other users, when it was registered, and how many times it’s been scanned.",{"data":82769,"content":82770,"nodeType":945},{},[82771],{"data":82772,"content":82773,"nodeType":860},{},[82774],{"data":82775,"marks":82776,"value":82777,"nodeType":864},{},[],"Interrogate and send this telemetry to your SIEM for you to operationalize it as part of SecOps workflows and hunt across events for similar incident characteristics.",{"data":82779,"content":82783,"nodeType":996},{"target":82780},{"sys":82781},{"id":82782,"type":1001,"linkType":1002},"5iPYWpPx4IZ2M1DykQiWsN",[],{"data":82785,"content":82786,"nodeType":1312},{},[82787],{"data":82788,"marks":82789,"value":82790,"nodeType":864},{},[],"Browser context",{"data":82792,"content":82793,"nodeType":860},{},[82794],{"data":82795,"marks":82796,"value":82797,"nodeType":864},{},[],"With Push, there’s no more: ",{"data":82799,"content":82800,"nodeType":941},{},[82801,82811,82821,82831,82841,82851],{"data":82802,"content":82803,"nodeType":945},{},[82804],{"data":82805,"content":82806,"nodeType":860},{},[82807],{"data":82808,"marks":82809,"value":82810,"nodeType":864},{},[],"Waiting (and hoping) that a browser-based attack gets recognized and reported by a user.",{"data":82812,"content":82813,"nodeType":945},{},[82814],{"data":82815,"content":82816,"nodeType":860},{},[82817],{"data":82818,"marks":82819,"value":82820,"nodeType":864},{},[],"Guesswork as to exactly what happened on the phishing page. ",{"data":82822,"content":82823,"nodeType":945},{},[82824],{"data":82825,"content":82826,"nodeType":860},{},[82827],{"data":82828,"marks":82829,"value":82830,"nodeType":864},{},[],"Struggling to get your hands on a live version of the page to see if it was actually malicious and getting thwarted because the attacker used a one-time phishing link. ",{"data":82832,"content":82833,"nodeType":945},{},[82834],{"data":82835,"content":82836,"nodeType":860},{},[82837],{"data":82838,"marks":82839,"value":82840,"nodeType":864},{},[],"Manually tracing the attack to see if it arrived by email so you can quarantine the messages. ",{"data":82842,"content":82843,"nodeType":945},{},[82844],{"data":82845,"content":82846,"nodeType":860},{},[82847],{"data":82848,"marks":82849,"value":82850,"nodeType":864},{},[],"Trawling through voluminous proxy logs for scraps of information (who else visited the link; where did it originate; etc.).",{"data":82852,"content":82853,"nodeType":945},{},[82854],{"data":82855,"content":82856,"nodeType":860},{},[82857],{"data":82858,"marks":82859,"value":82860,"nodeType":864},{},[],"Spending precious time on urlscan or VirusTotal to get basic context on a domain or IP address. ",{"data":82862,"content":82863,"nodeType":860},{},[82864],{"data":82865,"marks":82866,"value":82867,"nodeType":864},{},[],"Instead, Push gives you all the information you need in one place to investigate and respond. ",{"data":82869,"content":82870,"nodeType":860},{},[82871],{"data":82872,"marks":82873,"value":82874,"nodeType":864},{},[],"The foundation for these detections is the Push browser agent, which can be silently installed in all major browsers in your environment to begin streaming information about a user’s entire identity footprint. ",{"data":82876,"content":82877,"nodeType":860},{},[82878],{"data":82879,"marks":82880,"value":82881,"nodeType":864},{},[],"This valuable telemetry, combined with Push’s out-of-the-box controls and detections, gives you a seat on the user’s side of the equation, capturing reliable information about network requests, scripts loaded by a malicious website, and what a user clicked and navigated to: the ingredients for showing you how a browser-based attack unfolded, start to finish.",{"data":82883,"content":82887,"nodeType":996},{"target":82884},{"sys":82885},{"id":82886,"type":1001,"linkType":1002},"7ylgcaNDrxYhw7bULixM1C",[],{"data":82889,"content":82890,"nodeType":860},{},[82891],{"data":82892,"marks":82893,"value":82894,"nodeType":864},{},[],"Push raises a detection when it observes a phishing attack or when a user attempts to visit a blocked URL. You can view detections in the Push admin console, or send them to your SIEM or SOAR for correlation and analysis.",{"data":82896,"content":82897,"nodeType":1312},{},[82898],{"data":82899,"marks":82900,"value":82901,"nodeType":864},{},[],"Screenshot capture",{"data":82903,"content":82904,"nodeType":860},{},[82905],{"data":82906,"marks":82907,"value":82908,"nodeType":864},{},[],"The Push extension can also capture a screenshot at the time of a detection firing. This means security teams can see the visual characteristics of the page even if it’s since been taken down (and no more looking at bot protection screens like Cloudflare Turnstile on urlscan). ",{"data":82910,"content":82914,"nodeType":996},{"target":82911},{"sys":82912},{"id":82913,"type":1001,"linkType":1002},"58HPrc7wImm3mLxPK0yJOG",[],{"data":82916,"content":82917,"nodeType":1312},{},[82918],{"data":82919,"marks":82920,"value":82921,"nodeType":864},{},[],"Blast radius analysis for all impacted accounts & apps",{"data":82923,"content":82924,"nodeType":860},{},[82925],{"data":82926,"marks":82927,"value":82928,"nodeType":864},{},[],"With Push’s knowledge of your workforce identities — based on observing logins in the browser that use corporate credentials — the platform can also provide an analysis of the blast radius of an attack by showing you where other accounts and apps are impacted or at risk.",{"data":82930,"content":82931,"nodeType":860},{},[82932],{"data":82933,"marks":82934,"value":82935,"nodeType":864},{},[],"This information helps you understand the true impact of an incident so you can remediate all affected accounts.",{"data":82937,"content":82941,"nodeType":996},{"target":82938},{"sys":82939},{"id":82940,"type":1001,"linkType":1002},"77e8XMl2Rb0p7ZrG2wmURO",[],{"data":82943,"content":82944,"nodeType":860},{},[82945,82949,82958],{"data":82946,"marks":82947,"value":82948,"nodeType":864},{},[],"Push is able to provide this blast radius analysis by ",{"data":82950,"content":82952,"nodeType":883},{"uri":82951},"https://pushsecurity.com/help/10043/#how-push-securely-analyzes-passwords",[82953],{"data":82954,"marks":82955,"value":82957,"nodeType":864},{},[82956],{"type":1455},"securely fingerprinting users’ passwords",{"data":82959,"marks":82960,"value":82961,"nodeType":864},{},[]," when a login is observed; analyzing them for security posture issues such as missing MFA, or stolen, weak, or reused passwords; and then raising that relevant context for a given detection.",{"data":82963,"content":82964,"nodeType":1312},{},[82965],{"data":82966,"marks":82967,"value":82968,"nodeType":864},{},[],"Correlated context from urlscan.io",{"data":82970,"content":82971,"nodeType":860},{},[82972],{"data":82973,"marks":82974,"value":82975,"nodeType":864},{},[],"Finally, through an integration with urlscan.io, Push is able to provide additional context about the domains involved in a detection event, including:",{"data":82977,"content":82978,"nodeType":941},{},[82979,82989,82999,83009],{"data":82980,"content":82981,"nodeType":945},{},[82982],{"data":82983,"content":82984,"nodeType":860},{},[82985],{"data":82986,"marks":82987,"value":82988,"nodeType":864},{},[],"When they were created",{"data":82990,"content":82991,"nodeType":945},{},[82992],{"data":82993,"content":82994,"nodeType":860},{},[82995],{"data":82996,"marks":82997,"value":82998,"nodeType":864},{},[],"How many times they have previously been scanned",{"data":83000,"content":83001,"nodeType":945},{},[83002],{"data":83003,"content":83004,"nodeType":860},{},[83005],{"data":83006,"marks":83007,"value":83008,"nodeType":864},{},[],"When they were last scanned",{"data":83010,"content":83011,"nodeType":945},{},[83012],{"data":83013,"content":83014,"nodeType":860},{},[83015],{"data":83016,"marks":83017,"value":83018,"nodeType":864},{},[],"If urlscan has marked them as suspicious",{"data":83020,"content":83024,"nodeType":996},{"target":83021},{"sys":83022},{"id":83023,"type":1001,"linkType":1002},"2AKpAk65XdmaGBfe2V4qZ5",[],{"data":83026,"content":83027,"nodeType":1005},{},[],{"data":83029,"content":83030,"nodeType":1009},{},[83031],{"data":83032,"marks":83033,"value":83035,"nodeType":864},{},[83034],{"type":899},"Check out our latest webinar for practical guidance in real-world scenarios",{"data":83037,"content":83038,"nodeType":860},{},[83039,83043,83052,83055],{"data":83040,"marks":83041,"value":83042,"nodeType":864},{},[],"For practical advice and applied examples of how to use Push data in incident response — as well as some bonus examples of automated response and remediation use cases — ",{"data":83044,"content":83046,"nodeType":883},{"uri":83045},"https://pushsecurity.com/webinar/identity-detection-response",[83047],{"data":83048,"marks":83049,"value":83051,"nodeType":864},{},[83050],{"type":1455},"join us live on August 13 for our webinar",{"data":83053,"marks":83054,"value":3731,"nodeType":864},{},[],{"data":83056,"marks":83057,"value":83059,"nodeType":864},{},[83058],{"type":899},"“Identity attacks have changed — have your IR playbooks?”",{"data":83061,"content":83062,"nodeType":1005},{},[],{"data":83064,"content":83065,"nodeType":1009},{},[83066],{"data":83067,"marks":83068,"value":3578,"nodeType":864},{},[83069],{"type":899},{"data":83071,"content":83072,"nodeType":860},{},[83073],{"data":83074,"marks":83075,"value":83076,"nodeType":864},{},[],"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying, and session hijacking using stolen session tokens. ",{"data":83078,"content":83079,"nodeType":860},{},[83080],{"data":83081,"marks":83082,"value":83083,"nodeType":864},{},[],"You can also use Push to find and fix identity vulnerabilities across every app that your employees use, including ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more.",{"data":83085,"content":83086,"nodeType":860},{},[83087,83090,83098],{"data":83088,"marks":83089,"value":79656,"nodeType":864},{},[],{"data":83091,"content":83092,"nodeType":883},{"uri":14401},[83093],{"data":83094,"marks":83095,"value":83097,"nodeType":864},{},[83096],{"type":1455},"request a demo.",{"data":83099,"marks":83100,"value":21,"nodeType":864},{},[],"We’re launching a new Detections capability, enabling security teams to more effectively investigate and triage alerts, and build more effective workflows. ","2025-07-29T00:00:00.000Z",{"items":83104},[83105,83107],{"sys":83106,"name":342},{"id":13775},{"sys":83108,"name":13779},{"id":13778},{"items":83110},[83111],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":83112},{"url":853},{"__typename":2059,"sys":83114,"content":83116,"title":83707,"synopsis":83708,"hashTags":59,"publishedDate":83709,"slug":83710,"tagsCollection":83711,"authorsCollection":83717},{"id":83115},"5y6UUG3mMTu1dFhtKO0AUT",{"json":83117},{"data":83118,"content":83119,"nodeType":856},{},[83120,83127,83134,83154,83161,83181,83188,83191,83199,83206,83213,83219,83226,83271,83313,83321,83328,83348,83386,83392,83399,83405,83412,83420,83450,83456,83459,83466,83486,83506,83536,83541,83544,83552,83559,83652,83655,83662,83679,83685,83691],{"data":83121,"content":83122,"nodeType":860},{},[83123],{"data":83124,"marks":83125,"value":83126,"nodeType":864},{},[],"Everything we do at Push is research-driven. Our detections for phishing attacks were created through hands-on analysis of phishing kits that our customers have been targeted with. This gives us a steady supply of all manner of modern Attacker-in-the-Middle phishing kits to analyze — from the classic Evilginx-style phish kit to professionalized criminal as-a-Service infrastructure. ",{"data":83128,"content":83129,"nodeType":860},{},[83130],{"data":83131,"marks":83132,"value":83133,"nodeType":864},{},[],"In our most recent phish kit teardown, we encountered a standard reverse-proxy clone of a Microsoft login page — nothing unusual at first glance. But increasingly, a lot of the innovation comes outside of the phishing page itself. ",{"data":83135,"content":83136,"nodeType":860},{},[83137,83141,83150],{"data":83138,"marks":83139,"value":83140,"nodeType":864},{},[],"The art in detection evasion comes from being able to successfully deliver the page to a user and have them open the page without it being intercepted by an email security, proxy scanner, URL TI feed, or web analysis tool. To achieve this, the attacker found a way to redirect from a legitimate ",{"data":83142,"content":83144,"nodeType":883},{"uri":83143},"http://outlook.office.com",[83145],{"data":83146,"marks":83147,"value":83149,"nodeType":864},{},[83148],{"type":1455},"outlook.office.com",{"data":83151,"marks":83152,"value":83153,"nodeType":864},{},[]," link to a phishing website. ",{"data":83155,"content":83156,"nodeType":860},{},[83157],{"data":83158,"marks":83159,"value":83160,"nodeType":864},{},[],"This is essentially an open redirect vulnerability — maybe not the classic example where someone has forgotten to do input sanitization on their website, but the outcome is the same.",{"data":83162,"content":83163,"nodeType":860},{},[83164,83168,83177],{"data":83165,"marks":83166,"value":83167,"nodeType":864},{},[],"Central to our analysis was the use of our timelines feature, ",{"data":83169,"content":83171,"nodeType":883},{"uri":83170},"https://pushsecurity.com/blog/introducing-push-detections/",[83172],{"data":83173,"marks":83174,"value":83176,"nodeType":864},{},[83175],{"type":1455},"part of our latest Detections feature release",{"data":83178,"marks":83179,"value":83180,"nodeType":864},{},[],". I’m not going to talk in any detail about this, but the TL;DR is that it allows us to trace back the entire chain of browsing activity leading up to a detection — showing the full (sometimes lengthy) redirect chain from the initial link delivery source to the actual phishing page, tabs opened and closed, popup windows, forms submitted, passwords entered, and more. ",{"data":83182,"content":83183,"nodeType":860},{},[83184],{"data":83185,"marks":83186,"value":83187,"nodeType":864},{},[],"First, let’s go through the steps of my investigation before looking at the findings (and the implications for phishing detection evasion techniques). ",{"data":83189,"content":83190,"nodeType":1005},{},[],{"data":83192,"content":83193,"nodeType":1009},{},[83194],{"data":83195,"marks":83196,"value":83198,"nodeType":864},{},[83197],{"type":899},"Investigation walkthrough",{"data":83200,"content":83201,"nodeType":860},{},[83202],{"data":83203,"marks":83204,"value":83205,"nodeType":864},{},[],"As I opened with, there was nothing especially notable about the phishing page itself — a standard reverse-proxy AitM page designed to intercept the user’s session as they authenticate, bypassing MFA in the process. ",{"data":83207,"content":83208,"nodeType":860},{},[83209],{"data":83210,"marks":83211,"value":83212,"nodeType":864},{},[],"This was not targeted delivery — employees from several customers were impacted. I’ve included an example of how one user arrived at the site below.",{"data":83214,"content":83218,"nodeType":996},{"target":83215},{"sys":83216},{"id":83217,"type":1001,"linkType":1002},"51MnOL9XqQDkllK2Jer4S9",[],{"data":83220,"content":83221,"nodeType":860},{},[83222],{"data":83223,"marks":83224,"value":83225,"nodeType":864},{},[],"This one stood out to me for a few reasons. ",{"data":83227,"content":83228,"nodeType":941},{},[83229,83239,83261],{"data":83230,"content":83231,"nodeType":945},{},[83232],{"data":83233,"content":83234,"nodeType":860},{},[83235],{"data":83236,"marks":83237,"value":83238,"nodeType":864},{},[],"The user had accessed the malicious link from Google search. They searched “Office 265\" (a typo presumably), clicked a link, and were taken to an Office login page.",{"data":83240,"content":83241,"nodeType":945},{},[83242],{"data":83243,"content":83244,"nodeType":860},{},[83245,83249,83257],{"data":83246,"marks":83247,"value":83248,"nodeType":864},{},[],"The Outlook link had a number of Google Ads tracking parameters attached, meaning they clicked an ad, not an organic link — making this a ",{"data":83250,"content":83252,"nodeType":883},{"uri":83251},"https://pushsecurity.github.io/phishing-techniques/techniques/malvertising/",[83253],{"data":83254,"marks":83255,"value":441,"nodeType":864},{},[83256],{"type":1455},{"data":83258,"marks":83259,"value":83260,"nodeType":864},{},[]," attack. ",{"data":83262,"content":83263,"nodeType":945},{},[83264],{"data":83265,"content":83266,"nodeType":860},{},[83267],{"data":83268,"marks":83269,"value":83270,"nodeType":864},{},[],"Another domain — bluegraintours[.]com — was in the URL path, after which they were redirected to the Microsoft-impersonating phishing site (login-microsoftonline[.]offirmtm[.]com ...). ",{"data":83272,"content":83273,"nodeType":860},{},[83274,83278,83287,83291,83298,83302,83309],{"data":83275,"marks":83276,"value":83277,"nodeType":864},{},[],"This got me wondering — how did they get ",{"data":83279,"content":83281,"nodeType":883},{"uri":83280},"http://office.com",[83282],{"data":83283,"marks":83284,"value":83286,"nodeType":864},{},[83285],{"type":1455},"office.com",{"data":83288,"marks":83289,"value":83290,"nodeType":864},{},[]," to redirect to the phishing site, and why was the bluegraintours domain in the path of an ",{"data":83292,"content":83293,"nodeType":883},{"uri":83280},[83294],{"data":83295,"marks":83296,"value":83286,"nodeType":864},{},[83297],{"type":1455},{"data":83299,"marks":83300,"value":83301,"nodeType":864},{},[]," link? There was no indication that an actual phishing email was interacted with, it seemed to all happen directly from the legitimate ",{"data":83303,"content":83304,"nodeType":883},{"uri":83280},[83305],{"data":83306,"marks":83307,"value":83286,"nodeType":864},{},[83308],{"type":1455},{"data":83310,"marks":83311,"value":83312,"nodeType":864},{},[]," link. ",{"data":83314,"content":83315,"nodeType":1312},{},[83316],{"data":83317,"marks":83318,"value":83320,"nodeType":864},{},[83319],{"type":899},"Redirecting to a malicious login page via ADFS",{"data":83322,"content":83323,"nodeType":860},{},[83324],{"data":83325,"marks":83326,"value":83327,"nodeType":864},{},[],"From memory, I knew that the tenant name can appear in the URL when you’re accessing a specific Microsoft tenant for your organization — essentially a domain-specific landing page. ",{"data":83329,"content":83330,"nodeType":860},{},[83331,83335,83344],{"data":83332,"marks":83333,"value":83334,"nodeType":864},{},[],"It turns out the attacker had set up a custom Microsoft tenant with ",{"data":83336,"content":83338,"nodeType":883},{"uri":83337},"https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/ad-fs-overview",[83339],{"data":83340,"marks":83341,"value":83343,"nodeType":864},{},[83342],{"type":1455},"Active Directory Federation Services (ADFS)",{"data":83345,"marks":83346,"value":83347,"nodeType":864},{},[]," configured. If you’re not familiar, ADFS is an SSO solution that is often used to connect on-premises Active Directory with cloud services like Microsoft 365 or Azure Active Directory. This means Microsoft will perform the redirect to the custom malicious domain. ",{"data":83349,"content":83350,"nodeType":860},{},[83351,83355,83364,83368,83377,83381],{"data":83352,"marks":83353,"value":83354,"nodeType":864},{},[],"This is strikingly similar to ",{"data":83356,"content":83358,"nodeType":883},{"uri":83357},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/samljacking/description.md",[83359],{"data":83360,"marks":83361,"value":83363,"nodeType":864},{},[83362],{"type":1455},"SAMLjacking",{"data":83365,"marks":83366,"value":83367,"nodeType":864},{},[],", a technique I’ve ",{"data":83369,"content":83371,"nodeType":883},{"uri":83370},"https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/",[83372],{"data":83373,"marks":83374,"value":83376,"nodeType":864},{},[83375],{"type":1455},"blogged about previously",{"data":83378,"marks":83379,"value":83380,"nodeType":864},{},[]," which allows you to change the identity provider domain that an application’s users authenticate through. Attackers can change this link to their phishing page that proxies the legitimate site to phish users through legitimate sign-in links — ",{"data":83382,"marks":83383,"value":83385,"nodeType":864},{},[83384],{"type":899},"so I guess that makes this ADFSjacking?",{"data":83387,"content":83391,"nodeType":996},{"target":83388},{"sys":83389},{"id":83390,"type":1001,"linkType":1002},"3BXyDhMC69355gLRqyIwQP",[],{"data":83393,"content":83394,"nodeType":860},{},[83395],{"data":83396,"marks":83397,"value":83398,"nodeType":864},{},[],"I had initially assumed that bluegraintours was a legitimate website that had been compromised by the attacker and used as a redirect, which is pretty common behavior for threat groups. However, it turns out that it’s actually a fake website that the attackers have probably vibe-coded. ",{"data":83400,"content":83404,"nodeType":996},{"target":83401},{"sys":83402},{"id":83403,"type":1001,"linkType":1002},"1hnWJ0jgsPqRELDqUeFzf3",[],{"data":83406,"content":83407,"nodeType":860},{},[83408],{"data":83409,"marks":83410,"value":83411,"nodeType":864},{},[],"It’s worth noting that this isn’t something that the phishing victim would see as part of the attack — it’s purely used as an invisible redirect. This is most likely to be an attempt to mask the nature of the domain for domain categorization purposes, which is typical for proxy-based solutions to prevent users from browsing to unapproved things — this way, automated scanners will classify it as a travel blog. ",{"data":83413,"content":83414,"nodeType":1312},{},[83415],{"data":83416,"marks":83417,"value":83419,"nodeType":864},{},[83418],{"type":899},"Conditional loading interrupted the page analysis",{"data":83421,"content":83422,"nodeType":860},{},[83423,83427,83435,83439,83446],{"data":83424,"marks":83425,"value":83426,"nodeType":864},{},[],"While the user was taken to the phishing page at the end of the chain, ",{"data":83428,"content":83430,"nodeType":883},{"uri":83429},"https://pushsecurity.github.io/phishing-techniques/techniques/conditional-loading/",[83431],{"data":83432,"marks":83433,"value":72473,"nodeType":864},{},[83434],{"type":1455},{"data":83436,"marks":83437,"value":83438,"nodeType":864},{},[]," restrictions prevented us from recreating the full attack flow when loading the initial link clicked by the user. This happens when certain conditions of the page load aren’t met. Because the kit decides I’m not a valid target, I’m redirected back to ",{"data":83440,"content":83441,"nodeType":883},{"uri":83280},[83442],{"data":83443,"marks":83444,"value":83286,"nodeType":864},{},[83445],{"type":1455},{"data":83447,"marks":83448,"value":83449,"nodeType":864},{},[],". However, we were able to skip ahead and bypass the conditional loading to access the phishing server directly. ",{"data":83451,"content":83455,"nodeType":996},{"target":83452},{"sys":83453},{"id":83454,"type":1001,"linkType":1002},"68rW6CHJOJ2u3mCc08lGvZ",[],{"data":83457,"content":83458,"nodeType":1005},{},[],{"data":83460,"content":83461,"nodeType":1009},{},[83462],{"data":83463,"marks":83464,"value":72836,"nodeType":864},{},[83465],{"type":899},{"data":83467,"content":83468,"nodeType":860},{},[83469,83473,83482],{"data":83470,"marks":83471,"value":83472,"nodeType":864},{},[],"While this isn’t a vulnerability per se, the ability for attackers to add their own Microsoft ADFS server to host their phishing page and have Microsoft redirect to it is a concerning development that will make URL-based detections even more challenging than they already are. ",{"data":83474,"content":83476,"nodeType":883},{"uri":83475},"https://pushsecurity.github.io/phishing-techniques/techniques/trusted-website-hosting/",[83477],{"data":83478,"marks":83479,"value":83481,"nodeType":864},{},[83480],{"type":1455},"Hosting phishing links on trusted third-party websites",{"data":83483,"marks":83484,"value":83485,"nodeType":864},{},[]," is a highly effective way of both bypassing URL-based detections and implementing layers of obfuscation in their phishing delivery chain that can break automated analysis tools.  ",{"data":83487,"content":83488,"nodeType":860},{},[83489,83493,83502],{"data":83490,"marks":83491,"value":83492,"nodeType":864},{},[],"This is basically the equivalent to ",{"data":83494,"content":83496,"nodeType":883},{"uri":83495},"http://outlook.com",[83497],{"data":83498,"marks":83499,"value":83501,"nodeType":864},{},[83500],{"type":1455},"Outlook.com",{"data":83503,"marks":83504,"value":83505,"nodeType":864},{},[]," having an open redirect vulnerability, which would be a huge deal in the eyes of most security practitioners. In practice, it’s a little harder for the average attacker to make use of this, but anyone that is willing to create a Microsoft tenant and set up ADFS could create similar phishing infrastructure  — which only requires passing a credit card check. ",{"data":83507,"content":83508,"nodeType":860},{},[83509,83513,83520,83524,83532],{"data":83510,"marks":83511,"value":83512,"nodeType":864},{},[],"The other notable component to this attack is the use of ",{"data":83514,"content":83515,"nodeType":883},{"uri":83251},[83516],{"data":83517,"marks":83518,"value":441,"nodeType":864},{},[83519],{"type":1455},{"data":83521,"marks":83522,"value":83523,"nodeType":864},{},[]," as the lure delivery channel. This is a trend we spotted recently with ",{"data":83525,"content":83526,"nodeType":883},{"uri":79341},[83527],{"data":83528,"marks":83529,"value":83531,"nodeType":864},{},[83530],{"type":1455},"Scattered Spider’s use of Onfido-based malvertising lures",{"data":83533,"marks":83534,"value":83535,"nodeType":864},{},[],". Malvertising is a great way for attackers to sidestep phishing controls placed at the email layer (where the majority are) and, as in this case, can create a highly-convincing and difficult-to-spot phishing scenario.  ",{"data":83537,"content":83540,"nodeType":996},{"target":83538},{"sys":83539},{"id":73199,"type":1001,"linkType":1002},[],{"data":83542,"content":83543,"nodeType":1005},{},[],{"data":83545,"content":83546,"nodeType":1009},{},[83547],{"data":83548,"marks":83549,"value":83551,"nodeType":864},{},[83550],{"type":899},"Detection recommendations",{"data":83553,"content":83554,"nodeType":860},{},[83555],{"data":83556,"marks":83557,"value":83558,"nodeType":864},{},[],"There are a couple of tool-agnostic hardening options that can used to limit exposure to the specifics of this attack:",{"data":83560,"content":83561,"nodeType":941},{},[83562,83572,83593],{"data":83563,"content":83564,"nodeType":945},{},[83565],{"data":83566,"content":83567,"nodeType":860},{},[83568],{"data":83569,"marks":83570,"value":83571,"nodeType":864},{},[],"Monitoring for ADFS redirects in proxy logs that could be malicious, i.e. login.microsoftonline.com redirecting to another domain with /adfs/ls/ in the path. Many organizations do not use ADFS, while those that do should be able to filter legitimate ones to their legitimate domain relatively easily. ",{"data":83573,"content":83574,"nodeType":945},{},[83575],{"data":83576,"content":83577,"nodeType":860},{},[83578,83582,83589],{"data":83579,"marks":83580,"value":83581,"nodeType":864},{},[],"Monitoring for Google redirects to ",{"data":83583,"content":83584,"nodeType":883},{"uri":83280},[83585],{"data":83586,"marks":83587,"value":83286,"nodeType":864},{},[83588],{"type":1455},{"data":83590,"marks":83591,"value":83592,"nodeType":864},{},[]," with Google ad parameters for more specific detection of malvertising + ADFS hijacking as in this example. ",{"data":83594,"content":83595,"nodeType":945},{},[83596],{"data":83597,"content":83598,"nodeType":860},{},[83599,83603,83612,83615,83624,83627,83636,83639,83648],{"data":83600,"marks":83601,"value":83602,"nodeType":864},{},[],"Deploying ad blockers to all of your browsers to stop malvertising attacks — though this only serves to tackle one of the several possible delivery vectors, such as links delivered using ",{"data":83604,"content":83606,"nodeType":883},{"uri":83605},"https://pushsecurity.github.io/phishing-techniques/techniques/email-legitimate-app/",[83607],{"data":83608,"marks":83609,"value":83611,"nodeType":864},{},[83610],{"type":1455},"legitimate third-party services",{"data":83613,"marks":83614,"value":3731,"nodeType":864},{},[],{"data":83616,"content":83618,"nodeType":883},{"uri":83617},"https://pushsecurity.github.io/phishing-techniques/techniques/social-media/",[83619],{"data":83620,"marks":83621,"value":83623,"nodeType":864},{},[83622],{"type":1455},"social media",{"data":83625,"marks":83626,"value":3731,"nodeType":864},{},[],{"data":83628,"content":83630,"nodeType":883},{"uri":83629},"https://pushsecurity.github.io/phishing-techniques/techniques/instant-messenger/",[83631],{"data":83632,"marks":83633,"value":83635,"nodeType":864},{},[83634],{"type":1455},"instant messenger",{"data":83637,"marks":83638,"value":16887,"nodeType":864},{},[],{"data":83640,"content":83642,"nodeType":883},{"uri":83641},"https://pushsecurity.github.io/phishing-techniques/techniques/email-attachment/",[83643],{"data":83644,"marks":83645,"value":83647,"nodeType":864},{},[83646],{"type":1455},"email attachment",{"data":83649,"marks":83650,"value":83651,"nodeType":864},{},[],". (This is one of the limitations of focusing on specific delivery mechanisms — attackers have more to choose from than ever before. It’s not just an email problem). ",{"data":83653,"content":83654,"nodeType":1005},{},[],{"data":83656,"content":83657,"nodeType":1009},{},[83658],{"data":83659,"marks":83660,"value":3578,"nodeType":864},{},[83661],{"type":899},{"data":83663,"content":83664,"nodeType":860},{},[83665,83669,83675],{"data":83666,"marks":83667,"value":83668,"nodeType":864},{},[],"Push doesn’t detect the redirect tricks, or relies on outdated domain TI feeds. It doesn’t matter what ",{"data":83670,"content":83671,"nodeType":883},{"uri":14307},[83672],{"data":83673,"marks":83674,"value":73157,"nodeType":864},{},[],{"data":83676,"marks":83677,"value":83678,"nodeType":864},{},[],", Push detects and blocks attacks by identifying the attack in real time, as the user loads the page in their web browser.",{"data":83680,"content":83681,"nodeType":860},{},[83682],{"data":83683,"marks":83684,"value":83076,"nodeType":864},{},[],{"data":83686,"content":83687,"nodeType":860},{},[83688],{"data":83689,"marks":83690,"value":83083,"nodeType":864},{},[],{"data":83692,"content":83693,"nodeType":860},{},[83694,83697,83704],{"data":83695,"marks":83696,"value":79656,"nodeType":864},{},[],{"data":83698,"content":83699,"nodeType":883},{"uri":14401},[83700],{"data":83701,"marks":83702,"value":83097,"nodeType":864},{},[83703],{"type":1455},{"data":83705,"marks":83706,"value":21,"nodeType":864},{},[],"How attackers are using Active Directory Federation Services to phish with legit office.com links","Push recently identified a novel phishing attack using Active Directory Federation Services to get Microsoft to send victims to a phishing site.","2025-08-12T00:00:00.000Z","phishing-with-active-directory-federation-services",{"items":83712},[83713,83715],{"sys":83714,"name":342},{"id":13775},{"sys":83716,"name":13779},{"id":13778},{"items":83718},[83719],{"fullName":22309,"firstName":22310,"jobTitle":22311,"profilePicture":83720},{"url":22313},{"__typename":2059,"sys":83722,"content":83724,"title":84495,"synopsis":84496,"hashTags":59,"publishedDate":84497,"slug":84498,"tagsCollection":84499,"authorsCollection":84505},{"id":83723},"31m73YMGdCyqVmjHulBwER",{"json":83725},{"data":83726,"content":83727,"nodeType":856},{},[83728,83735,83768,83775,83781,83788,83819,83826,83832,83835,83843,83850,83857,83913,83931,83943,83950,83956,83959,83967,83983,83989,83996,84002,84009,84047,84052,84055,84063,84070,84077,84198,84204,84234,84241,84244,84252,84259,84266,84308,84336,84343,84418,84424,84427,84434,84441,84461,84464,84472,84479],{"data":83729,"content":83730,"nodeType":860},{},[83731],{"data":83732,"marks":83733,"value":83734,"nodeType":864},{},[],"Until recently, the cyber attacker methodology behind the biggest breaches of the last decade or so has been pretty consistent:",{"data":83736,"content":83737,"nodeType":941},{},[83738,83748,83758],{"data":83739,"content":83740,"nodeType":945},{},[83741],{"data":83742,"content":83743,"nodeType":860},{},[83744],{"data":83745,"marks":83746,"value":83747,"nodeType":864},{},[],"Compromise an endpoint via software exploit, or social engineering a user to run malware on their device; ",{"data":83749,"content":83750,"nodeType":945},{},[83751],{"data":83752,"content":83753,"nodeType":860},{},[83754],{"data":83755,"marks":83756,"value":83757,"nodeType":864},{},[],"Find ways to move laterally inside the network and compromise privileged identities;",{"data":83759,"content":83760,"nodeType":945},{},[83761],{"data":83762,"content":83763,"nodeType":860},{},[83764],{"data":83765,"marks":83766,"value":83767,"nodeType":864},{},[],"Repeat as needed until you can execute your desired attack — usually stealing data from file shares, deploying ransomware, or both. ",{"data":83769,"content":83770,"nodeType":860},{},[83771],{"data":83772,"marks":83773,"value":83774,"nodeType":864},{},[],"But attacks have fundamentally changed as networks have evolved. With the SaaS-ification of enterprise IT, core business systems aren’t locally deployed and centrally managed in the way they used to be. Instead, they’re logged into over the internet, via a web browser.",{"data":83776,"content":83780,"nodeType":996},{"target":83777},{"sys":83778},{"id":83779,"type":1001,"linkType":1002},"4h4hUYAghbZavOwjRTnBe2",[],{"data":83782,"content":83783,"nodeType":860},{},[83784],{"data":83785,"marks":83786,"value":83787,"nodeType":864},{},[],"Under the shared responsibility model, the part that’s left to the business consuming a SaaS service is mostly constrained to how they manage identities — the vehicle by which the app is accessed and used by the workforce. It’s no surprise that this has become the soft underbelly in the crosshairs of attackers. ",{"data":83789,"content":83790,"nodeType":860},{},[83791,83795,83803,83807,83816],{"data":83792,"marks":83793,"value":83794,"nodeType":864},{},[],"We’ve seen this time and again in the biggest breaches of recent years, with the highlights including the massive ",{"data":83796,"content":83797,"nodeType":883},{"uri":3751},[83798],{"data":83799,"marks":83800,"value":83802,"nodeType":864},{},[83801],{"type":1455},"Snowflake campaign in 2024",{"data":83804,"marks":83805,"value":83806,"nodeType":864},{},[]," and the ",{"data":83808,"content":83810,"nodeType":883},{"uri":83809},"https://pushsecurity.com/blog/key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/",[83811],{"data":83812,"marks":83813,"value":83815,"nodeType":864},{},[83814],{"type":1455},"2025 crime wave attributed to Scattered Spider",{"data":83817,"marks":83818,"value":82395,"nodeType":864},{},[],{"data":83820,"content":83821,"nodeType":860},{},[83822],{"data":83823,"marks":83824,"value":83825,"nodeType":864},{},[],"These attacks are so successful because while attackers have moved with the changes to enterprise IT, security hasn’t really kept up. ",{"data":83827,"content":83831,"nodeType":996},{"target":83828},{"sys":83829},{"id":83830,"type":1001,"linkType":1002},"xH0ZqgKQXCRRZGYVs6xt6",[],{"data":83833,"content":83834,"nodeType":1005},{},[],{"data":83836,"content":83837,"nodeType":1009},{},[83838],{"data":83839,"marks":83840,"value":83842,"nodeType":864},{},[83841],{"type":899},"The browser is the new battleground — and a security blind spot",{"data":83844,"content":83845,"nodeType":860},{},[83846],{"data":83847,"marks":83848,"value":83849,"nodeType":864},{},[],"Taking over workforce identities is the first objective for attackers looking to target an organization, and the browser is the place where the attacks against users happen. This is because it’s where these digital identities are created and used — and their credentials and sessions live. This is what the attacker wants to get their hands on. ",{"data":83851,"content":83852,"nodeType":860},{},[83853],{"data":83854,"marks":83855,"value":83856,"nodeType":864},{},[],"Stolen credentials can be used as part of targeted attacks or in broader credential stuffing (cycling known username and credential pairs against various apps and platforms), while stolen session tokens can be used to log in directly to an active session, bypassing the authentication process. ",{"data":83858,"content":83859,"nodeType":860},{},[83860,83864,83869,83872,83877,83880,83885,83888,83893,83896,83901,83905,83909],{"data":83861,"marks":83862,"value":83863,"nodeType":864},{},[],"There are a few different techniques that attackers can use to get access to these identities. Attackers harvest stolen credentials from various places — ",{"data":83865,"marks":83866,"value":83868,"nodeType":864},{},[83867],{"type":899},"data breach dumps",{"data":83870,"marks":83871,"value":3731,"nodeType":864},{},[],{"data":83873,"marks":83874,"value":83876,"nodeType":864},{},[83875],{"type":899},"mass",{"data":83878,"marks":83879,"value":1171,"nodeType":864},{},[],{"data":83881,"marks":83882,"value":83884,"nodeType":864},{},[83883],{"type":899},"credential",{"data":83886,"marks":83887,"value":1171,"nodeType":864},{},[],{"data":83889,"marks":83890,"value":83892,"nodeType":864},{},[83891],{"type":899},"phishing campaigns,",{"data":83894,"marks":83895,"value":1171,"nodeType":864},{},[],{"data":83897,"marks":83898,"value":83900,"nodeType":864},{},[83899],{"type":899},"infostealer logs",{"data":83902,"marks":83903,"value":83904,"nodeType":864},{},[],", even ",{"data":83906,"marks":83907,"value":59242,"nodeType":864},{},[83908],{"type":899},{"data":83910,"marks":83911,"value":83912,"nodeType":864},{},[]," that they’ve tricked an employee into installing. In fact, the cyber crime ecosystem itself has shifted on its axis to cater to this, with hackers specifically taking on the role of harvesting credentials and establishing account access for others to exploit. ",{"data":83914,"content":83915,"nodeType":860},{},[83916,83920,83927],{"data":83917,"marks":83918,"value":83919,"nodeType":864},{},[],"The high-profile ",{"data":83921,"content":83922,"nodeType":883},{"uri":3751},[83923],{"data":83924,"marks":83925,"value":77964,"nodeType":864},{},[83926],{"type":1455},{"data":83928,"marks":83929,"value":83930,"nodeType":864},{},[]," breaches in 2024 signalled a watershed moment in the shift to identity-driven breaches, where attackers logged into accounts across hundreds of customer tenants using stolen credentials. One of the primary sources of the stolen credentials used in the attacks were infostealer logs dating back to 2020 — breached passwords that hadn’t been rotated or mitigated with MFA. ",{"data":83932,"content":83933,"nodeType":860},{},[83934,83938],{"data":83935,"marks":83936,"value":83937,"nodeType":864},{},[],"Infostealers are notable because they’re an endpoint malware attack designed to harvest credentials and session tokens (often from the browser) to enable the attacker to then log into those services… through their own web browser. ",{"data":83939,"marks":83940,"value":83942,"nodeType":864},{},[83941],{"type":899},"So, even today’s endpoint attacks are seeing the attacker pivot back into the browser in order to get to identities — the key to the online apps and services where exploitable data and functionality now resides. ",{"data":83944,"content":83945,"nodeType":860},{},[83946],{"data":83947,"marks":83948,"value":83949,"nodeType":864},{},[],"The problem here is that this is a blind spot for the security tools we’re currently reliant upon — which don’t have the fine-grained visibility required. This is very similar to the challenge that the industry faced prior to the introduction of EDR in the 2010s — the main sources of data are looking from the outside-in, lacking the process-level visibility and context to be able to detect and stop attacks as they happen.",{"data":83951,"content":83955,"nodeType":996},{"target":83952},{"sys":83953},{"id":83954,"type":1001,"linkType":1002},"2qoMH6qCNJc7it7sTuKl4F",[],{"data":83957,"content":83958,"nodeType":1005},{},[],{"data":83960,"content":83961,"nodeType":1009},{},[83962],{"data":83963,"marks":83964,"value":83966,"nodeType":864},{},[83965],{"type":899},"Identity is the prize, browser is the platform — and phishing is the weapon of choice",{"data":83968,"content":83969,"nodeType":860},{},[83970,83974,83979],{"data":83971,"marks":83972,"value":83973,"nodeType":864},{},[],"But the technique that’s STILL driving the most impactful identity-driven breaches? ",{"data":83975,"marks":83976,"value":83978,"nodeType":864},{},[83977],{"type":899},"It’s phishing",{"data":83980,"marks":83981,"value":83982,"nodeType":864},{},[],". Phishing for credentials, sessions, OAuth consent, authorization codes. Phishing via email, instant messenger, social media, malicious Google ads… it all happens in, or leads to, the browser. ",{"data":83984,"content":83988,"nodeType":996},{"target":83985},{"sys":83986},{"id":83987,"type":1001,"linkType":1002},"6Gsd3G0sOibNxgVLimb2wV",[],{"data":83990,"content":83991,"nodeType":860},{},[83992],{"data":83993,"marks":83994,"value":83995,"nodeType":864},{},[],"And modern phishing attacks are more effective than ever. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques to block email and network security tools from intercepting them. Probably the most common example today is the use of bot protection (think CAPTCHA or Cloudflare Turnstile), using legitimate anti-spam features to block security tools. ",{"data":83997,"content":84001,"nodeType":996},{"target":83998},{"sys":83999},{"id":84000,"type":1001,"linkType":1002},"6M1My4lSKItu6Qdv4hO1RA",[],{"data":84003,"content":84004,"nodeType":860},{},[84005],{"data":84006,"marks":84007,"value":84008,"nodeType":864},{},[],"The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom CAPTCHA, and using runtime anti-analysis features, making them increasingly difficult to detect. The ways in which links are delivered has also increased in sophistication, with more delivery channels (as we showed above) and the use of legitimate SaaS services for camouflage. ",{"data":84010,"content":84011,"nodeType":860},{},[84012,84016,84021,84025,84030,84034,84043],{"data":84013,"marks":84014,"value":84015,"nodeType":864},{},[],"And the latest trends indicate that attackers are responding to increasingly hardened IdP/SSO configuration by exploiting alternative phishing techniques that ",{"data":84017,"marks":84018,"value":84020,"nodeType":864},{},[84019],{"type":899},"circumvent MFA and passkeys",{"data":84022,"marks":84023,"value":84024,"nodeType":864},{},[],", most commonly by ",{"data":84026,"marks":84027,"value":84029,"nodeType":864},{},[84028],{"type":899},"downgrading to a phishable backup authentication method",{"data":84031,"marks":84032,"value":84033,"nodeType":864},{},[]," — which you can see in action below, and ",{"data":84035,"content":84037,"nodeType":883},{"uri":84036},"https://pushsecurity.com/blog/mfa-downgrade-attacks/",[84038],{"data":84039,"marks":84040,"value":84042,"nodeType":864},{},[84041],{"type":1455},"read more about here",{"data":84044,"marks":84045,"value":84046,"nodeType":864},{},[],".  ",{"data":84048,"content":84051,"nodeType":996},{"target":84049},{"sys":84050},{"id":79155,"type":1001,"linkType":1002},[],{"data":84053,"content":84054,"nodeType":1005},{},[],{"data":84056,"content":84057,"nodeType":1009},{},[84058],{"data":84059,"marks":84060,"value":84062,"nodeType":864},{},[84061],{"type":899},"Identities are the lowest-hanging fruit for attackers to aim for",{"data":84064,"content":84065,"nodeType":860},{},[84066],{"data":84067,"marks":84068,"value":84069,"nodeType":864},{},[],"The goal of the modern attacker, and the easiest way into your business’s digital environment, is to compromise identities. Whether you’re dealing with phishing attacks, malicious browser extensions, or infostealer malware, the objective remains the same — account takeover. ",{"data":84071,"content":84072,"nodeType":860},{},[84073],{"data":84074,"marks":84075,"value":84076,"nodeType":864},{},[],"Organizations are dealing with a vast and vulnerable attack surface consisting of:",{"data":84078,"content":84079,"nodeType":941},{},[84080,84101,84122,84142],{"data":84081,"content":84082,"nodeType":945},{},[84083],{"data":84084,"content":84085,"nodeType":860},{},[84086,84089,84097],{"data":84087,"marks":84088,"value":21,"nodeType":864},{},[],{"data":84090,"content":84091,"nodeType":883},{"uri":25338},[84092],{"data":84093,"marks":84094,"value":84096,"nodeType":864},{},[84095],{"type":1455},"Hundreds of applications, with thousands of accounts",{"data":84098,"marks":84099,"value":84100,"nodeType":864},{},[]," spread across the app estate.",{"data":84102,"content":84103,"nodeType":945},{},[84104],{"data":84105,"content":84106,"nodeType":860},{},[84107,84111,84119],{"data":84108,"marks":84109,"value":84110,"nodeType":864},{},[],"Accounts vulnerable to MFA-bypass phishing kits, because they are using a login method that is not phishing-resistant, or because ",{"data":84112,"content":84113,"nodeType":883},{"uri":84036},[84114],{"data":84115,"marks":84116,"value":84118,"nodeType":864},{},[84117],{"type":1455},"the login method can be downgraded",{"data":84120,"marks":84121,"value":2924,"nodeType":864},{},[],{"data":84123,"content":84124,"nodeType":945},{},[84125],{"data":84126,"content":84127,"nodeType":860},{},[84128,84132,84139],{"data":84129,"marks":84130,"value":84131,"nodeType":864},{},[],"Accounts with a weak, reused, or breached password and no MFA altogether (usually the result of a forgotten-about ",{"data":84133,"content":84134,"nodeType":883},{"uri":57333},[84135],{"data":84136,"marks":84137,"value":62634,"nodeType":864},{},[84138],{"type":1455},{"data":84140,"marks":84141,"value":49943,"nodeType":864},{},[],{"data":84143,"content":84144,"nodeType":945},{},[84145],{"data":84146,"content":84147,"nodeType":860},{},[84148,84152,84161,84164,84172,84176,84183,84186,84194],{"data":84149,"marks":84150,"value":84151,"nodeType":864},{},[],"Bypassing the authentication process entirely to evade otherwise phishing-resistant authentication methods, by abusing features like ",{"data":84153,"content":84155,"nodeType":883},{"uri":84154},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_keys/description.md",[84156],{"data":84157,"marks":84158,"value":84160,"nodeType":864},{},[84159],{"type":1455},"API key creation",{"data":84162,"marks":84163,"value":3731,"nodeType":864},{},[],{"data":84165,"content":84166,"nodeType":883},{"uri":79523},[84167],{"data":84168,"marks":84169,"value":84171,"nodeType":864},{},[84170],{"type":1455},"app-specific passwords",{"data":84173,"marks":84174,"value":84175,"nodeType":864},{},[],", OAuth ",{"data":84177,"content":84178,"nodeType":883},{"uri":50933},[84179],{"data":84180,"marks":84181,"value":72707,"nodeType":864},{},[84182],{"type":1455},{"data":84184,"marks":84185,"value":3731,"nodeType":864},{},[],{"data":84187,"content":84188,"nodeType":883},{"uri":79610},[84189],{"data":84190,"marks":84191,"value":84193,"nodeType":864},{},[84192],{"type":1455},"cross-IdP impersonation",{"data":84195,"marks":84196,"value":84197,"nodeType":864},{},[],", and more.  ",{"data":84199,"content":84203,"nodeType":996},{"target":84200},{"sys":84201},{"id":84202,"type":1001,"linkType":1002},"3WFzina1t5j6bDlTlGQA0l",[],{"data":84205,"content":84206,"nodeType":860},{},[84207,84211,84219,84223,84230],{"data":84208,"marks":84209,"value":84210,"nodeType":864},{},[],"A key driver of identity vulnerability is the ",{"data":84212,"content":84213,"nodeType":883},{"uri":18920},[84214],{"data":84215,"marks":84216,"value":84218,"nodeType":864},{},[84217],{"type":1455},"huge variance in the configurability of accounts per application",{"data":84220,"marks":84221,"value":84222,"nodeType":864},{},[],", with different levels of centralized visibility and security control of identities provided — for example, while one app can be locked down to only accept SSO logins via SAML and automatically remove any unused passwords, another provides no control or visibility of login method or MFA status (another big driver of the ",{"data":84224,"content":84225,"nodeType":883},{"uri":3751},[84226],{"data":84227,"marks":84228,"value":77964,"nodeType":864},{},[84229],{"type":1455},{"data":84231,"marks":84232,"value":84233,"nodeType":864},{},[]," breaches last year). Unfortunately, as a by-product of product-led growth and something that is compounded by every new SaaS startup that hits the market, this situation doesn’t look like it’s going to change anytime soon. ",{"data":84235,"content":84236,"nodeType":860},{},[84237],{"data":84238,"marks":84239,"value":84240,"nodeType":864},{},[],"The end result is that identities are misconfigured, invisible to the security team, and routinely exploited by commodity attacker tooling. It’s no surprise that they’re the primary target for attackers today. ",{"data":84242,"content":84243,"nodeType":1005},{},[],{"data":84245,"content":84246,"nodeType":1009},{},[84247],{"data":84248,"marks":84249,"value":84251,"nodeType":864},{},[84250],{"type":899},"The solution: The browser as a telemetry source and control point",{"data":84253,"content":84254,"nodeType":860},{},[84255],{"data":84256,"marks":84257,"value":84258,"nodeType":864},{},[],"Because identity attacks play out in the browser, it’s the perfect place for security teams to observe, intercept, and shut down these attacks. ",{"data":84260,"content":84261,"nodeType":860},{},[84262],{"data":84263,"marks":84264,"value":84265,"nodeType":864},{},[],"The browser has a number of advantages over the different places where identity can be observed and protected, because:",{"data":84267,"content":84268,"nodeType":941},{},[84269,84279,84289],{"data":84270,"content":84271,"nodeType":945},{},[84272],{"data":84273,"content":84274,"nodeType":860},{},[84275],{"data":84276,"marks":84277,"value":84278,"nodeType":864},{},[],"You aren’t limited to the apps and identities directly connected to your IdP (a fraction of your workforce identity sprawl). ",{"data":84280,"content":84281,"nodeType":945},{},[84282],{"data":84283,"content":84284,"nodeType":860},{},[84285],{"data":84286,"marks":84287,"value":84288,"nodeType":864},{},[],"You aren’t limited to the apps that you know about and manage centrally — you can observe every login that passes through the browser.",{"data":84290,"content":84291,"nodeType":945},{},[84292],{"data":84293,"content":84294,"nodeType":860},{},[84295,84299,84304],{"data":84296,"marks":84297,"value":84298,"nodeType":864},{},[],"You can observe all the properties of a login, including the login method, MFA method, etc. You’d otherwise need API access to ",{"data":84300,"marks":84301,"value":84303,"nodeType":864},{},[84302],{"type":2246},"maybe",{"data":84305,"marks":84306,"value":84307,"nodeType":864},{},[]," get this information (depending on whether an API is provided and whether this specific data can be interrogated, also not standard for many apps). ",{"data":84309,"content":84310,"nodeType":860},{},[84311,84315,84320,84324,84332],{"data":84312,"marks":84313,"value":84314,"nodeType":864},{},[],"It’s obvious with all that we’ve covered so far that fixing every identity vulnerability is an ominous task — the SaaS ecosystem itself is working against you. ",{"data":84316,"marks":84317,"value":84319,"nodeType":864},{},[84318],{"type":899},"This is why detecting and responding to identity attacks is essential. ",{"data":84321,"marks":84322,"value":84323,"nodeType":864},{},[],"Because identity compromise almost always involves phishing or social engineering a user to perform an action in their browser (with some exceptions — like the ",{"data":84325,"content":84326,"nodeType":883},{"uri":57532},[84327],{"data":84328,"marks":84329,"value":84331,"nodeType":864},{},[84330],{"type":1455},"Scattered Spider-related help desk attacks",{"data":84333,"marks":84334,"value":84335,"nodeType":864},{},[]," seen recently), it’s also the perfect place to monitor for and intercept attacks. ",{"data":84337,"content":84338,"nodeType":860},{},[84339],{"data":84340,"marks":84341,"value":84342,"nodeType":864},{},[],"In the browser, you gather deep, contextualized information about page behavior and user inputs that can be used to detect and shut down risky scenarios in real time. Take the example of phishing pages. Because Push operates in the browser, it sees everything:",{"data":84344,"content":84345,"nodeType":941},{},[84346,84356,84366,84376,84398,84408],{"data":84347,"content":84348,"nodeType":945},{},[84349],{"data":84350,"content":84351,"nodeType":860},{},[84352],{"data":84353,"marks":84354,"value":84355,"nodeType":864},{},[],"The page layout.",{"data":84357,"content":84358,"nodeType":945},{},[84359],{"data":84360,"content":84361,"nodeType":860},{},[84362],{"data":84363,"marks":84364,"value":84365,"nodeType":864},{},[],"Where the user came from (through the whole redirect chain).",{"data":84367,"content":84368,"nodeType":945},{},[84369],{"data":84370,"content":84371,"nodeType":860},{},[84372],{"data":84373,"marks":84374,"value":84375,"nodeType":864},{},[],"Page interaction events — e.g. tabs opened and closed, popup windows, forms submitted, etc.",{"data":84377,"content":84378,"nodeType":945},{},[84379],{"data":84380,"content":84381,"nodeType":860},{},[84382,84386,84394],{"data":84383,"marks":84384,"value":84385,"nodeType":864},{},[],"The password they enter ",{"data":84387,"content":84388,"nodeType":883},{"uri":82951},[84389],{"data":84390,"marks":84391,"value":84393,"nodeType":864},{},[84392],{"type":1455},"(as a salted, abbreviated hash)",{"data":84395,"marks":84396,"value":84397,"nodeType":864},{},[],", and whether a password was typed or copied, and where from.",{"data":84399,"content":84400,"nodeType":945},{},[84401],{"data":84402,"content":84403,"nodeType":860},{},[84404],{"data":84405,"marks":84406,"value":84407,"nodeType":864},{},[],"What scripts are running on the page and whether they are potentially malicious.",{"data":84409,"content":84410,"nodeType":945},{},[84411],{"data":84412,"content":84413,"nodeType":860},{},[84414],{"data":84415,"marks":84416,"value":84417,"nodeType":864},{},[],"Where credentials are being sent.",{"data":84419,"content":84423,"nodeType":996},{"target":84420},{"sys":84421},{"id":84422,"type":1001,"linkType":1002},"6kQejVS63FQ6Oy8nIm6UlV",[],{"data":84425,"content":84426,"nodeType":1005},{},[],{"data":84428,"content":84429,"nodeType":1009},{},[84430],{"data":84431,"marks":84432,"value":51911,"nodeType":864},{},[84433],{"type":899},{"data":84435,"content":84436,"nodeType":860},{},[84437],{"data":84438,"marks":84439,"value":84440,"nodeType":864},{},[],"Identity attacks are the biggest unsolved problem facing security teams today and the leading cause of security breaches. At the same time, the browser presents security teams with all the tools they need to prevent, detect, and respond to identity-based attacks — proactively by finding and fixing identity vulnerabilities, and reactively by detecting and blocking attacks against users in real time. ",{"data":84442,"content":84443,"nodeType":860},{},[84444,84448,84457],{"data":84445,"marks":84446,"value":84447,"nodeType":864},{},[],"Organizations need to move past the old ways of doing identity security — relying on MFA attestations, identity management dashboards, and ",{"data":84449,"content":84451,"nodeType":883},{"uri":84450},"https://pushsecurity.com/blog/three-reasons-why-browser-is-best-for-stopping-phishing-attacks/",[84452],{"data":84453,"marks":84454,"value":84456,"nodeType":864},{},[84455],{"type":1455},"legacy email and network anti-phishing tools",{"data":84458,"marks":84459,"value":84460,"nodeType":864},{},[],". And there’s no better place to stop these attacks than in the browser. ",{"data":84462,"content":84463,"nodeType":1005},{},[],{"data":84465,"content":84466,"nodeType":1009},{},[84467],{"data":84468,"marks":84469,"value":84471,"nodeType":864},{},[84470],{"type":899},"Find out more",{"data":84473,"content":84474,"nodeType":860},{},[84475],{"data":84476,"marks":84477,"value":84478,"nodeType":864},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks identity attacks like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more.",{"data":84480,"content":84481,"nodeType":860},{},[84482,84485,84492],{"data":84483,"marks":84484,"value":78529,"nodeType":864},{},[],{"data":84486,"content":84487,"nodeType":883},{"uri":1700},[84488],{"data":84489,"marks":84490,"value":16894,"nodeType":864},{},[84491],{"type":1455},{"data":84493,"marks":84494,"value":2924,"nodeType":864},{},[],"How the browser became the main cyber battleground","How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.","2025-08-15T00:00:00.000Z","how-the-browser-became-the-main-cyber-battleground",{"items":84500},[84501,84503],{"sys":84502,"name":342},{"id":13775},{"sys":84504,"name":13779},{"id":13778},{"items":84506},[84507],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":84508},{"url":2740},"blog/6-browser-based-attacks-every-security-team-should-be-prepared-for",{"json":84511},{"data":84512,"content":84513,"nodeType":856},{},[84514],{"data":84515,"content":84516,"nodeType":860},{},[84517],{"data":84518,"marks":84519,"value":84520,"nodeType":864},{},[],"What security teams need to know about the browser-based attack techniques that are the leading cause of breaches today.",{"id":77896,"publishedAt":84522},"2026-08-12T11:53:52.135Z",{"items":84524},[84525,84527],{"sys":84526,"name":13779},{"id":13778},{"sys":84528,"name":342},{"id":13775},{"items":84530},[84531,84533,84535,84537,84539,84541,84543,84545,84547,84549,84551,84553,84555,84557,84559,84561,84563,84565,84567,84569,84571,84573,84575],{"sys":84532,"name":279,"slug":280,"tier":31},{"id":276},{"sys":84534,"name":413,"slug":414,"tier":31},{"id":410},{"sys":84536,"name":297,"slug":298,"tier":31},{"id":294},{"sys":84538,"name":519,"slug":520,"tier":31},{"id":516},{"sys":84540,"name":342,"slug":343,"tier":31},{"id":339},{"sys":84542,"name":642,"slug":643,"tier":31},{"id":639},{"sys":84544,"name":261,"slug":262,"tier":45},{"id":258},{"sys":84546,"name":315,"slug":316,"tier":45},{"id":312},{"sys":84548,"name":571,"slug":572,"tier":45},{"id":568},{"sys":84550,"name":324,"slug":325,"tier":45},{"id":321},{"sys":84552,"name":466,"slug":467,"tier":45},{"id":463},{"sys":84554,"name":484,"slug":485,"tier":45},{"id":481},{"sys":84556,"name":288,"slug":289,"tier":45},{"id":285},{"sys":84558,"name":448,"slug":449,"tier":45},{"id":445},{"sys":84560,"name":333,"slug":334,"tier":45},{"id":330},{"sys":84562,"name":395,"slug":396,"tier":45},{"id":392},{"sys":84564,"name":422,"slug":423,"tier":45},{"id":419},{"sys":84566,"name":475,"slug":476,"tier":45},{"id":472},{"sys":84568,"name":360,"slug":361,"tier":45},{"id":357},{"sys":84570,"name":607,"slug":608,"tier":45},{"id":604},{"sys":84572,"name":511,"slug":512,"tier":45},{"id":508},{"sys":84574,"name":502,"slug":503,"tier":45},{"id":499},{"sys":84576,"name":457,"slug":458,"tier":45},{"id":454},"WL7qIr1ZFM800qYp8iPSNtZRoMC9xxn2kj9zNtQfvf4",{"id":84579,"title":84495,"authorsCollection":84580,"content":84585,"extension":228,"faqItemsCollection":85310,"faqTitle":59,"featured":6,"hashTags":59,"meta":85312,"metaTitle":85313,"ogImage":59,"postType":5726,"publishedDate":84497,"relatedBlogPostsCollection":85314,"slug":84498,"stem":87088,"subtitle":59,"summary":87089,"synopsis":84496,"sys":87099,"tagsCollection":87101,"topicsCollection":87107,"__hash__":87159},"blog/blog/how-the-browser-became-the-main-cyber-battleground.json",{"items":84581},[84582],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":84583,"profilePicture":84584},[15231],{"url":2740},{"json":84586,"links":85258},{"data":84587,"content":84588,"nodeType":856},{},[84589,84595,84625,84631,84636,84642,84668,84674,84679,84682,84689,84695,84701,84749,84765,84775,84781,84786,84789,84796,84809,84814,84820,84825,84831,84861,84866,84869,84876,84882,84888,84997,85002,85028,85034,85037,85044,85050,85056,85093,85116,85122,85189,85194,85197,85204,85210,85226,85229,85236,85242],{"data":84590,"content":84591,"nodeType":860},{},[84592],{"data":84593,"marks":84594,"value":83734,"nodeType":864},{},[],{"data":84596,"content":84597,"nodeType":941},{},[84598,84607,84616],{"data":84599,"content":84600,"nodeType":945},{},[84601],{"data":84602,"content":84603,"nodeType":860},{},[84604],{"data":84605,"marks":84606,"value":83747,"nodeType":864},{},[],{"data":84608,"content":84609,"nodeType":945},{},[84610],{"data":84611,"content":84612,"nodeType":860},{},[84613],{"data":84614,"marks":84615,"value":83757,"nodeType":864},{},[],{"data":84617,"content":84618,"nodeType":945},{},[84619],{"data":84620,"content":84621,"nodeType":860},{},[84622],{"data":84623,"marks":84624,"value":83767,"nodeType":864},{},[],{"data":84626,"content":84627,"nodeType":860},{},[84628],{"data":84629,"marks":84630,"value":83774,"nodeType":864},{},[],{"data":84632,"content":84635,"nodeType":996},{"target":84633},{"sys":84634},{"id":83779,"type":1001,"linkType":1002},[],{"data":84637,"content":84638,"nodeType":860},{},[84639],{"data":84640,"marks":84641,"value":83787,"nodeType":864},{},[],{"data":84643,"content":84644,"nodeType":860},{},[84645,84648,84655,84658,84665],{"data":84646,"marks":84647,"value":83794,"nodeType":864},{},[],{"data":84649,"content":84650,"nodeType":883},{"uri":3751},[84651],{"data":84652,"marks":84653,"value":83802,"nodeType":864},{},[84654],{"type":1455},{"data":84656,"marks":84657,"value":83806,"nodeType":864},{},[],{"data":84659,"content":84660,"nodeType":883},{"uri":83809},[84661],{"data":84662,"marks":84663,"value":83815,"nodeType":864},{},[84664],{"type":1455},{"data":84666,"marks":84667,"value":82395,"nodeType":864},{},[],{"data":84669,"content":84670,"nodeType":860},{},[84671],{"data":84672,"marks":84673,"value":83825,"nodeType":864},{},[],{"data":84675,"content":84678,"nodeType":996},{"target":84676},{"sys":84677},{"id":83830,"type":1001,"linkType":1002},[],{"data":84680,"content":84681,"nodeType":1005},{},[],{"data":84683,"content":84684,"nodeType":1009},{},[84685],{"data":84686,"marks":84687,"value":83842,"nodeType":864},{},[84688],{"type":899},{"data":84690,"content":84691,"nodeType":860},{},[84692],{"data":84693,"marks":84694,"value":83849,"nodeType":864},{},[],{"data":84696,"content":84697,"nodeType":860},{},[84698],{"data":84699,"marks":84700,"value":83856,"nodeType":864},{},[],{"data":84702,"content":84703,"nodeType":860},{},[84704,84707,84711,84714,84718,84721,84725,84728,84732,84735,84739,84742,84746],{"data":84705,"marks":84706,"value":83863,"nodeType":864},{},[],{"data":84708,"marks":84709,"value":83868,"nodeType":864},{},[84710],{"type":899},{"data":84712,"marks":84713,"value":3731,"nodeType":864},{},[],{"data":84715,"marks":84716,"value":83876,"nodeType":864},{},[84717],{"type":899},{"data":84719,"marks":84720,"value":1171,"nodeType":864},{},[],{"data":84722,"marks":84723,"value":83884,"nodeType":864},{},[84724],{"type":899},{"data":84726,"marks":84727,"value":1171,"nodeType":864},{},[],{"data":84729,"marks":84730,"value":83892,"nodeType":864},{},[84731],{"type":899},{"data":84733,"marks":84734,"value":1171,"nodeType":864},{},[],{"data":84736,"marks":84737,"value":83900,"nodeType":864},{},[84738],{"type":899},{"data":84740,"marks":84741,"value":83904,"nodeType":864},{},[],{"data":84743,"marks":84744,"value":59242,"nodeType":864},{},[84745],{"type":899},{"data":84747,"marks":84748,"value":83912,"nodeType":864},{},[],{"data":84750,"content":84751,"nodeType":860},{},[84752,84755,84762],{"data":84753,"marks":84754,"value":83919,"nodeType":864},{},[],{"data":84756,"content":84757,"nodeType":883},{"uri":3751},[84758],{"data":84759,"marks":84760,"value":77964,"nodeType":864},{},[84761],{"type":1455},{"data":84763,"marks":84764,"value":83930,"nodeType":864},{},[],{"data":84766,"content":84767,"nodeType":860},{},[84768,84771],{"data":84769,"marks":84770,"value":83937,"nodeType":864},{},[],{"data":84772,"marks":84773,"value":83942,"nodeType":864},{},[84774],{"type":899},{"data":84776,"content":84777,"nodeType":860},{},[84778],{"data":84779,"marks":84780,"value":83949,"nodeType":864},{},[],{"data":84782,"content":84785,"nodeType":996},{"target":84783},{"sys":84784},{"id":83954,"type":1001,"linkType":1002},[],{"data":84787,"content":84788,"nodeType":1005},{},[],{"data":84790,"content":84791,"nodeType":1009},{},[84792],{"data":84793,"marks":84794,"value":83966,"nodeType":864},{},[84795],{"type":899},{"data":84797,"content":84798,"nodeType":860},{},[84799,84802,84806],{"data":84800,"marks":84801,"value":83973,"nodeType":864},{},[],{"data":84803,"marks":84804,"value":83978,"nodeType":864},{},[84805],{"type":899},{"data":84807,"marks":84808,"value":83982,"nodeType":864},{},[],{"data":84810,"content":84813,"nodeType":996},{"target":84811},{"sys":84812},{"id":83987,"type":1001,"linkType":1002},[],{"data":84815,"content":84816,"nodeType":860},{},[84817],{"data":84818,"marks":84819,"value":83995,"nodeType":864},{},[],{"data":84821,"content":84824,"nodeType":996},{"target":84822},{"sys":84823},{"id":84000,"type":1001,"linkType":1002},[],{"data":84826,"content":84827,"nodeType":860},{},[84828],{"data":84829,"marks":84830,"value":84008,"nodeType":864},{},[],{"data":84832,"content":84833,"nodeType":860},{},[84834,84837,84841,84844,84848,84851,84858],{"data":84835,"marks":84836,"value":84015,"nodeType":864},{},[],{"data":84838,"marks":84839,"value":84020,"nodeType":864},{},[84840],{"type":899},{"data":84842,"marks":84843,"value":84024,"nodeType":864},{},[],{"data":84845,"marks":84846,"value":84029,"nodeType":864},{},[84847],{"type":899},{"data":84849,"marks":84850,"value":84033,"nodeType":864},{},[],{"data":84852,"content":84853,"nodeType":883},{"uri":84036},[84854],{"data":84855,"marks":84856,"value":84042,"nodeType":864},{},[84857],{"type":1455},{"data":84859,"marks":84860,"value":84046,"nodeType":864},{},[],{"data":84862,"content":84865,"nodeType":996},{"target":84863},{"sys":84864},{"id":79155,"type":1001,"linkType":1002},[],{"data":84867,"content":84868,"nodeType":1005},{},[],{"data":84870,"content":84871,"nodeType":1009},{},[84872],{"data":84873,"marks":84874,"value":84062,"nodeType":864},{},[84875],{"type":899},{"data":84877,"content":84878,"nodeType":860},{},[84879],{"data":84880,"marks":84881,"value":84069,"nodeType":864},{},[],{"data":84883,"content":84884,"nodeType":860},{},[84885],{"data":84886,"marks":84887,"value":84076,"nodeType":864},{},[],{"data":84889,"content":84890,"nodeType":941},{},[84891,84910,84929,84948],{"data":84892,"content":84893,"nodeType":945},{},[84894],{"data":84895,"content":84896,"nodeType":860},{},[84897,84900,84907],{"data":84898,"marks":84899,"value":21,"nodeType":864},{},[],{"data":84901,"content":84902,"nodeType":883},{"uri":25338},[84903],{"data":84904,"marks":84905,"value":84096,"nodeType":864},{},[84906],{"type":1455},{"data":84908,"marks":84909,"value":84100,"nodeType":864},{},[],{"data":84911,"content":84912,"nodeType":945},{},[84913],{"data":84914,"content":84915,"nodeType":860},{},[84916,84919,84926],{"data":84917,"marks":84918,"value":84110,"nodeType":864},{},[],{"data":84920,"content":84921,"nodeType":883},{"uri":84036},[84922],{"data":84923,"marks":84924,"value":84118,"nodeType":864},{},[84925],{"type":1455},{"data":84927,"marks":84928,"value":2924,"nodeType":864},{},[],{"data":84930,"content":84931,"nodeType":945},{},[84932],{"data":84933,"content":84934,"nodeType":860},{},[84935,84938,84945],{"data":84936,"marks":84937,"value":84131,"nodeType":864},{},[],{"data":84939,"content":84940,"nodeType":883},{"uri":57333},[84941],{"data":84942,"marks":84943,"value":62634,"nodeType":864},{},[84944],{"type":1455},{"data":84946,"marks":84947,"value":49943,"nodeType":864},{},[],{"data":84949,"content":84950,"nodeType":945},{},[84951],{"data":84952,"content":84953,"nodeType":860},{},[84954,84957,84964,84967,84974,84977,84984,84987,84994],{"data":84955,"marks":84956,"value":84151,"nodeType":864},{},[],{"data":84958,"content":84959,"nodeType":883},{"uri":84154},[84960],{"data":84961,"marks":84962,"value":84160,"nodeType":864},{},[84963],{"type":1455},{"data":84965,"marks":84966,"value":3731,"nodeType":864},{},[],{"data":84968,"content":84969,"nodeType":883},{"uri":79523},[84970],{"data":84971,"marks":84972,"value":84171,"nodeType":864},{},[84973],{"type":1455},{"data":84975,"marks":84976,"value":84175,"nodeType":864},{},[],{"data":84978,"content":84979,"nodeType":883},{"uri":50933},[84980],{"data":84981,"marks":84982,"value":72707,"nodeType":864},{},[84983],{"type":1455},{"data":84985,"marks":84986,"value":3731,"nodeType":864},{},[],{"data":84988,"content":84989,"nodeType":883},{"uri":79610},[84990],{"data":84991,"marks":84992,"value":84193,"nodeType":864},{},[84993],{"type":1455},{"data":84995,"marks":84996,"value":84197,"nodeType":864},{},[],{"data":84998,"content":85001,"nodeType":996},{"target":84999},{"sys":85000},{"id":84202,"type":1001,"linkType":1002},[],{"data":85003,"content":85004,"nodeType":860},{},[85005,85008,85015,85018,85025],{"data":85006,"marks":85007,"value":84210,"nodeType":864},{},[],{"data":85009,"content":85010,"nodeType":883},{"uri":18920},[85011],{"data":85012,"marks":85013,"value":84218,"nodeType":864},{},[85014],{"type":1455},{"data":85016,"marks":85017,"value":84222,"nodeType":864},{},[],{"data":85019,"content":85020,"nodeType":883},{"uri":3751},[85021],{"data":85022,"marks":85023,"value":77964,"nodeType":864},{},[85024],{"type":1455},{"data":85026,"marks":85027,"value":84233,"nodeType":864},{},[],{"data":85029,"content":85030,"nodeType":860},{},[85031],{"data":85032,"marks":85033,"value":84240,"nodeType":864},{},[],{"data":85035,"content":85036,"nodeType":1005},{},[],{"data":85038,"content":85039,"nodeType":1009},{},[85040],{"data":85041,"marks":85042,"value":84251,"nodeType":864},{},[85043],{"type":899},{"data":85045,"content":85046,"nodeType":860},{},[85047],{"data":85048,"marks":85049,"value":84258,"nodeType":864},{},[],{"data":85051,"content":85052,"nodeType":860},{},[85053],{"data":85054,"marks":85055,"value":84265,"nodeType":864},{},[],{"data":85057,"content":85058,"nodeType":941},{},[85059,85068,85077],{"data":85060,"content":85061,"nodeType":945},{},[85062],{"data":85063,"content":85064,"nodeType":860},{},[85065],{"data":85066,"marks":85067,"value":84278,"nodeType":864},{},[],{"data":85069,"content":85070,"nodeType":945},{},[85071],{"data":85072,"content":85073,"nodeType":860},{},[85074],{"data":85075,"marks":85076,"value":84288,"nodeType":864},{},[],{"data":85078,"content":85079,"nodeType":945},{},[85080],{"data":85081,"content":85082,"nodeType":860},{},[85083,85086,85090],{"data":85084,"marks":85085,"value":84298,"nodeType":864},{},[],{"data":85087,"marks":85088,"value":84303,"nodeType":864},{},[85089],{"type":2246},{"data":85091,"marks":85092,"value":84307,"nodeType":864},{},[],{"data":85094,"content":85095,"nodeType":860},{},[85096,85099,85103,85106,85113],{"data":85097,"marks":85098,"value":84314,"nodeType":864},{},[],{"data":85100,"marks":85101,"value":84319,"nodeType":864},{},[85102],{"type":899},{"data":85104,"marks":85105,"value":84323,"nodeType":864},{},[],{"data":85107,"content":85108,"nodeType":883},{"uri":57532},[85109],{"data":85110,"marks":85111,"value":84331,"nodeType":864},{},[85112],{"type":1455},{"data":85114,"marks":85115,"value":84335,"nodeType":864},{},[],{"data":85117,"content":85118,"nodeType":860},{},[85119],{"data":85120,"marks":85121,"value":84342,"nodeType":864},{},[],{"data":85123,"content":85124,"nodeType":941},{},[85125,85134,85143,85152,85171,85180],{"data":85126,"content":85127,"nodeType":945},{},[85128],{"data":85129,"content":85130,"nodeType":860},{},[85131],{"data":85132,"marks":85133,"value":84355,"nodeType":864},{},[],{"data":85135,"content":85136,"nodeType":945},{},[85137],{"data":85138,"content":85139,"nodeType":860},{},[85140],{"data":85141,"marks":85142,"value":84365,"nodeType":864},{},[],{"data":85144,"content":85145,"nodeType":945},{},[85146],{"data":85147,"content":85148,"nodeType":860},{},[85149],{"data":85150,"marks":85151,"value":84375,"nodeType":864},{},[],{"data":85153,"content":85154,"nodeType":945},{},[85155],{"data":85156,"content":85157,"nodeType":860},{},[85158,85161,85168],{"data":85159,"marks":85160,"value":84385,"nodeType":864},{},[],{"data":85162,"content":85163,"nodeType":883},{"uri":82951},[85164],{"data":85165,"marks":85166,"value":84393,"nodeType":864},{},[85167],{"type":1455},{"data":85169,"marks":85170,"value":84397,"nodeType":864},{},[],{"data":85172,"content":85173,"nodeType":945},{},[85174],{"data":85175,"content":85176,"nodeType":860},{},[85177],{"data":85178,"marks":85179,"value":84407,"nodeType":864},{},[],{"data":85181,"content":85182,"nodeType":945},{},[85183],{"data":85184,"content":85185,"nodeType":860},{},[85186],{"data":85187,"marks":85188,"value":84417,"nodeType":864},{},[],{"data":85190,"content":85193,"nodeType":996},{"target":85191},{"sys":85192},{"id":84422,"type":1001,"linkType":1002},[],{"data":85195,"content":85196,"nodeType":1005},{},[],{"data":85198,"content":85199,"nodeType":1009},{},[85200],{"data":85201,"marks":85202,"value":51911,"nodeType":864},{},[85203],{"type":899},{"data":85205,"content":85206,"nodeType":860},{},[85207],{"data":85208,"marks":85209,"value":84440,"nodeType":864},{},[],{"data":85211,"content":85212,"nodeType":860},{},[85213,85216,85223],{"data":85214,"marks":85215,"value":84447,"nodeType":864},{},[],{"data":85217,"content":85218,"nodeType":883},{"uri":84450},[85219],{"data":85220,"marks":85221,"value":84456,"nodeType":864},{},[85222],{"type":1455},{"data":85224,"marks":85225,"value":84460,"nodeType":864},{},[],{"data":85227,"content":85228,"nodeType":1005},{},[],{"data":85230,"content":85231,"nodeType":1009},{},[85232],{"data":85233,"marks":85234,"value":84471,"nodeType":864},{},[85235],{"type":899},{"data":85237,"content":85238,"nodeType":860},{},[85239],{"data":85240,"marks":85241,"value":84478,"nodeType":864},{},[],{"data":85243,"content":85244,"nodeType":860},{},[85245,85248,85255],{"data":85246,"marks":85247,"value":78529,"nodeType":864},{},[],{"data":85249,"content":85250,"nodeType":883},{"uri":1700},[85251],{"data":85252,"marks":85253,"value":16894,"nodeType":864},{},[85254],{"type":1455},{"data":85256,"marks":85257,"value":2924,"nodeType":864},{},[],{"entries":85259},{"hyperlink":85260,"inline":85261,"block":85262},[],[],[85263,85270,85274,85280,85284,85292,85296,85304],{"sys":85264,"__typename":1724,"title":85265,"caption":85265,"layoutMode":59,"file":85266},{"id":83779},"Attacks have shifted from targeting local networks to SaaS services, accessed through employee web browsers.",{"url":85267,"width":85268,"height":85269},"https://images.ctfassets.net/y1cdw1ablpvd/SadRsmdnNZofhrKddH01D/1ba16316bdfa666b2bc387d5b694e515/image2.png",1506,574,{"sys":85271,"__typename":1717,"type":1718,"ctaText":85272,"buttonLabel":36838,"buttonColour":85273,"buttonUrl":82089},{"id":83830},"Read how the transformation of business IT has shaped the evolution of phishing attacks in our latest whitepaper.","sea blue",{"sys":85275,"__typename":1724,"title":85276,"caption":85276,"layoutMode":59,"file":85277},{"id":83954},"EDR solved endpoint attacks by getting deep visibility into OS-level processes and activity — we now face a similar visibility problem in the browser. ",{"url":85278,"width":1736,"height":85279},"https://images.ctfassets.net/y1cdw1ablpvd/2KuUuYKf2Q9TlIJ9fkOI82/9a52cae72564e69d3cfe8b3b613eb950/image5.png",632,{"sys":85281,"__typename":1724,"title":82074,"caption":82074,"layoutMode":59,"file":85282},{"id":83987},{"url":85283,"width":1736,"height":82077},"https://images.ctfassets.net/y1cdw1ablpvd/4p8sf1x8PfWF06ndwTsdf9/136ed45c7912459a70dbb53b62cf5a90/image6.png",{"sys":85285,"__typename":1724,"title":85286,"caption":85287,"layoutMode":59,"file":85288},{"id":84000},"Cloudflare Turnstile is a simple way for attackers to block automated analysis of their phishing kits — it should probably come with a trigger warning for incident responders.","Cloudflare Turnstile is a simple way for security teams to prevent automated analysis — it should probably come with a trigger warning for incident responders.",{"url":85289,"width":85290,"height":85291},"https://images.ctfassets.net/y1cdw1ablpvd/6gGDHL1jECCm4j02gZZlYe/92e4362eea9fb712aeb64bdd7fb19d59/image3.png",1262,464,{"sys":85293,"__typename":12999,"title":85294,"arcadeDemoUrl":85295,"playText":13002},{"id":79155},"MFA Downgrade Demo","https://demo.arcade.software/1MzRfFaRCD2pYPhIXkvi?embed",{"sys":85297,"__typename":1724,"title":85298,"caption":85299,"layoutMode":59,"file":85300},{"id":84202},"Infographic showing the identity vulnerability spread for a 1,000 seat organization","A 1,000 user organization has over 15,000 accounts with various configurations and associated vulnerabilities.",{"url":85301,"width":85302,"height":85303},"https://images.ctfassets.net/y1cdw1ablpvd/266iLQBVsJIQEx6dnUEVrZ/eb5b1be79b7b29365baf299053fddf42/Infographic.png",5480,3012,{"sys":85305,"__typename":1724,"title":85306,"caption":85306,"layoutMode":59,"file":85307},{"id":84422},"Being in the browser gives you unrivalled visibility of phishing page activity and user behavior.",{"url":85308,"width":85309,"height":5721},"https://images.ctfassets.net/y1cdw1ablpvd/42mmDkjfXn0uOkTyvFLNqG/0385dadcb0731bea1de1ca5ae6ee7c18/image1.png",1560,{"items":85311},[],{},"Why the browser is now the main cyber attack surface",{"items":85315},[85316,86176,86529],{"__typename":2059,"sys":85317,"content":85318,"title":71409,"synopsis":83101,"hashTags":59,"publishedDate":83102,"slug":71410,"tagsCollection":86166,"authorsCollection":86172},{"id":67318},{"json":85319},{"data":85320,"content":85321,"nodeType":856},{},[85322,85328,85338,85348,85358,85368,85373,85389,85395,85408,85414,85419,85422,85429,85435,85441,85447,85452,85455,85462,85468,85484,85490,85496,85502,85508,85513,85519,85525,85531,85556,85562,85578,85584,85590,85606,85622,85638,85643,85649,85662,85668,85674,85680,85696,85703,85709,85715,85718,85725,85731,85737,85743,85782,85787,85793,85806,85883,85888,85894,85900,85957,85963,85969,85975,85980,85986,85992,85998,86003,86009,86015,86021,86026,86042,86048,86054,86093,86098,86101,86108,86128,86131,86138,86144,86150],{"data":85323,"content":85324,"nodeType":860},{},[85325],{"data":85326,"marks":85327,"value":82126,"nodeType":864},{},[],{"data":85329,"content":85330,"nodeType":860},{},[85331,85335],{"data":85332,"marks":85333,"value":82134,"nodeType":864},{},[85334],{"type":899},{"data":85336,"marks":85337,"value":82138,"nodeType":864},{},[],{"data":85339,"content":85340,"nodeType":860},{},[85341,85345],{"data":85342,"marks":85343,"value":82146,"nodeType":864},{},[85344],{"type":899},{"data":85346,"marks":85347,"value":82150,"nodeType":864},{},[],{"data":85349,"content":85350,"nodeType":860},{},[85351,85355],{"data":85352,"marks":85353,"value":82158,"nodeType":864},{},[85354],{"type":899},{"data":85356,"marks":85357,"value":82162,"nodeType":864},{},[],{"data":85359,"content":85360,"nodeType":860},{},[85361,85365],{"data":85362,"marks":85363,"value":82170,"nodeType":864},{},[85364],{"type":899},{"data":85366,"marks":85367,"value":82174,"nodeType":864},{},[],{"data":85369,"content":85372,"nodeType":996},{"target":85370},{"sys":85371},{"id":82179,"type":1001,"linkType":1002},[],{"data":85374,"content":85375,"nodeType":860},{},[85376,85379,85386],{"data":85377,"marks":85378,"value":82187,"nodeType":864},{},[],{"data":85380,"content":85381,"nodeType":883},{"uri":82190},[85382],{"data":85383,"marks":85384,"value":82196,"nodeType":864},{},[85385],{"type":1455},{"data":85387,"marks":85388,"value":82200,"nodeType":864},{},[],{"data":85390,"content":85391,"nodeType":860},{},[85392],{"data":85393,"marks":85394,"value":82207,"nodeType":864},{},[],{"data":85396,"content":85397,"nodeType":860},{},[85398,85401,85405],{"data":85399,"marks":85400,"value":82214,"nodeType":864},{},[],{"data":85402,"marks":85403,"value":64544,"nodeType":864},{},[85404],{"type":899},{"data":85406,"marks":85407,"value":82222,"nodeType":864},{},[],{"data":85409,"content":85410,"nodeType":860},{},[85411],{"data":85412,"marks":85413,"value":82229,"nodeType":864},{},[],{"data":85415,"content":85418,"nodeType":996},{"target":85416},{"sys":85417},{"id":82234,"type":1001,"linkType":1002},[],{"data":85420,"content":85421,"nodeType":1005},{},[],{"data":85423,"content":85424,"nodeType":1009},{},[85425],{"data":85426,"marks":85427,"value":82246,"nodeType":864},{},[85428],{"type":899},{"data":85430,"content":85431,"nodeType":860},{},[85432],{"data":85433,"marks":85434,"value":82253,"nodeType":864},{},[],{"data":85436,"content":85437,"nodeType":860},{},[85438],{"data":85439,"marks":85440,"value":82260,"nodeType":864},{},[],{"data":85442,"content":85443,"nodeType":860},{},[85444],{"data":85445,"marks":85446,"value":82267,"nodeType":864},{},[],{"data":85448,"content":85451,"nodeType":996},{"target":85449},{"sys":85450},{"id":82272,"type":1001,"linkType":1002},[],{"data":85453,"content":85454,"nodeType":1005},{},[],{"data":85456,"content":85457,"nodeType":1009},{},[85458],{"data":85459,"marks":85460,"value":82284,"nodeType":864},{},[85461],{"type":899},{"data":85463,"content":85464,"nodeType":860},{},[85465],{"data":85466,"marks":85467,"value":82291,"nodeType":864},{},[],{"data":85469,"content":85470,"nodeType":860},{},[85471,85474,85481],{"data":85472,"marks":85473,"value":82298,"nodeType":864},{},[],{"data":85475,"content":85476,"nodeType":883},{"uri":82301},[85477],{"data":85478,"marks":85479,"value":82307,"nodeType":864},{},[85480],{"type":1455},{"data":85482,"marks":85483,"value":82311,"nodeType":864},{},[],{"data":85485,"content":85486,"nodeType":860},{},[85487],{"data":85488,"marks":85489,"value":82318,"nodeType":864},{},[],{"data":85491,"content":85492,"nodeType":860},{},[85493],{"data":85494,"marks":85495,"value":82325,"nodeType":864},{},[],{"data":85497,"content":85498,"nodeType":1312},{},[85499],{"data":85500,"marks":85501,"value":82332,"nodeType":864},{},[],{"data":85503,"content":85504,"nodeType":860},{},[85505],{"data":85506,"marks":85507,"value":82339,"nodeType":864},{},[],{"data":85509,"content":85512,"nodeType":996},{"target":85510},{"sys":85511},{"id":82344,"type":1001,"linkType":1002},[],{"data":85514,"content":85515,"nodeType":860},{},[85516],{"data":85517,"marks":85518,"value":82352,"nodeType":864},{},[],{"data":85520,"content":85521,"nodeType":1312},{},[85522],{"data":85523,"marks":85524,"value":82359,"nodeType":864},{},[],{"data":85526,"content":85527,"nodeType":860},{},[85528],{"data":85529,"marks":85530,"value":82366,"nodeType":864},{},[],{"data":85532,"content":85533,"nodeType":860},{},[85534,85537,85545,85549,85552],{"data":85535,"marks":85536,"value":82373,"nodeType":864},{},[],{"data":85538,"content":85539,"nodeType":883},{"uri":13094},[85540],{"data":85541,"marks":85542,"value":82382,"nodeType":864},{},[85543,85544],{"type":1455},{"type":899},{"data":85546,"marks":85547,"value":1171,"nodeType":864},{},[85548],{"type":899},{"data":85550,"marks":85551,"value":82390,"nodeType":864},{},[],{"data":85553,"marks":85554,"value":82395,"nodeType":864},{},[85555],{"type":899},{"data":85557,"content":85558,"nodeType":860},{},[85559],{"data":85560,"marks":85561,"value":82402,"nodeType":864},{},[],{"data":85563,"content":85564,"nodeType":860},{},[85565,85568,85575],{"data":85566,"marks":85567,"value":82409,"nodeType":864},{},[],{"data":85569,"content":85570,"nodeType":883},{"uri":82190},[85571],{"data":85572,"marks":85573,"value":67962,"nodeType":864},{},[85574],{"type":1455},{"data":85576,"marks":85577,"value":82420,"nodeType":864},{},[],{"data":85579,"content":85580,"nodeType":1312},{},[85581],{"data":85582,"marks":85583,"value":82427,"nodeType":864},{},[],{"data":85585,"content":85586,"nodeType":860},{},[85587],{"data":85588,"marks":85589,"value":82434,"nodeType":864},{},[],{"data":85591,"content":85592,"nodeType":860},{},[85593,85596,85603],{"data":85594,"marks":85595,"value":82441,"nodeType":864},{},[],{"data":85597,"content":85598,"nodeType":883},{"uri":82444},[85599],{"data":85600,"marks":85601,"value":82450,"nodeType":864},{},[85602],{"type":1455},{"data":85604,"marks":85605,"value":82454,"nodeType":864},{},[],{"data":85607,"content":85608,"nodeType":860},{},[85609,85612,85619],{"data":85610,"marks":85611,"value":82461,"nodeType":864},{},[],{"data":85613,"content":85614,"nodeType":883},{"uri":82464},[85615],{"data":85616,"marks":85617,"value":82470,"nodeType":864},{},[85618],{"type":1455},{"data":85620,"marks":85621,"value":82474,"nodeType":864},{},[],{"data":85623,"content":85624,"nodeType":860},{},[85625,85628,85635],{"data":85626,"marks":85627,"value":82481,"nodeType":864},{},[],{"data":85629,"content":85630,"nodeType":883},{"uri":82484},[85631],{"data":85632,"marks":85633,"value":82490,"nodeType":864},{},[85634],{"type":1455},{"data":85636,"marks":85637,"value":82494,"nodeType":864},{},[],{"data":85639,"content":85642,"nodeType":996},{"target":85640},{"sys":85641},{"id":82499,"type":1001,"linkType":1002},[],{"data":85644,"content":85645,"nodeType":1312},{},[85646],{"data":85647,"marks":85648,"value":82507,"nodeType":864},{},[],{"data":85650,"content":85651,"nodeType":860},{},[85652,85655,85659],{"data":85653,"marks":85654,"value":82514,"nodeType":864},{},[],{"data":85656,"marks":85657,"value":82519,"nodeType":864},{},[85658],{"type":2246},{"data":85660,"marks":85661,"value":82523,"nodeType":864},{},[],{"data":85663,"content":85664,"nodeType":860},{},[85665],{"data":85666,"marks":85667,"value":82530,"nodeType":864},{},[],{"data":85669,"content":85670,"nodeType":860},{},[85671],{"data":85672,"marks":85673,"value":82537,"nodeType":864},{},[],{"data":85675,"content":85676,"nodeType":860},{},[85677],{"data":85678,"marks":85679,"value":82544,"nodeType":864},{},[],{"data":85681,"content":85682,"nodeType":860},{},[85683,85686,85693],{"data":85684,"marks":85685,"value":82551,"nodeType":864},{},[],{"data":85687,"content":85688,"nodeType":883},{"uri":57333},[85689],{"data":85690,"marks":85691,"value":82559,"nodeType":864},{},[85692],{"type":1455},{"data":85694,"marks":85695,"value":82563,"nodeType":864},{},[],{"data":85697,"content":85698,"nodeType":860},{},[85699],{"data":85700,"marks":85701,"value":82571,"nodeType":864},{},[85702],{"type":899},{"data":85704,"content":85705,"nodeType":860},{},[85706],{"data":85707,"marks":85708,"value":82578,"nodeType":864},{},[],{"data":85710,"content":85711,"nodeType":860},{},[85712],{"data":85713,"marks":85714,"value":82585,"nodeType":864},{},[],{"data":85716,"content":85717,"nodeType":1005},{},[],{"data":85719,"content":85720,"nodeType":1009},{},[85721],{"data":85722,"marks":85723,"value":82596,"nodeType":864},{},[85724],{"type":899},{"data":85726,"content":85727,"nodeType":860},{},[85728],{"data":85729,"marks":85730,"value":82603,"nodeType":864},{},[],{"data":85732,"content":85733,"nodeType":860},{},[85734],{"data":85735,"marks":85736,"value":82610,"nodeType":864},{},[],{"data":85738,"content":85739,"nodeType":860},{},[85740],{"data":85741,"marks":85742,"value":82617,"nodeType":864},{},[],{"data":85744,"content":85745,"nodeType":941},{},[85746,85755,85764,85773],{"data":85747,"content":85748,"nodeType":945},{},[85749],{"data":85750,"content":85751,"nodeType":860},{},[85752],{"data":85753,"marks":85754,"value":82630,"nodeType":864},{},[],{"data":85756,"content":85757,"nodeType":945},{},[85758],{"data":85759,"content":85760,"nodeType":860},{},[85761],{"data":85762,"marks":85763,"value":82640,"nodeType":864},{},[],{"data":85765,"content":85766,"nodeType":945},{},[85767],{"data":85768,"content":85769,"nodeType":860},{},[85770],{"data":85771,"marks":85772,"value":82650,"nodeType":864},{},[],{"data":85774,"content":85775,"nodeType":945},{},[85776],{"data":85777,"content":85778,"nodeType":860},{},[85779],{"data":85780,"marks":85781,"value":82660,"nodeType":864},{},[],{"data":85783,"content":85786,"nodeType":996},{"target":85784},{"sys":85785},{"id":82665,"type":1001,"linkType":1002},[],{"data":85788,"content":85789,"nodeType":860},{},[85790],{"data":85791,"marks":85792,"value":82673,"nodeType":864},{},[],{"data":85794,"content":85795,"nodeType":860},{},[85796,85799,85803],{"data":85797,"marks":85798,"value":82680,"nodeType":864},{},[],{"data":85800,"marks":85801,"value":64544,"nodeType":864},{},[85802],{"type":899},{"data":85804,"marks":85805,"value":82688,"nodeType":864},{},[],{"data":85807,"content":85808,"nodeType":941},{},[85809,85838,85847,85856,85865,85874],{"data":85810,"content":85811,"nodeType":945},{},[85812],{"data":85813,"content":85814,"nodeType":860},{},[85815,85818,85825,85828,85835],{"data":85816,"marks":85817,"value":82701,"nodeType":864},{},[],{"data":85819,"content":85820,"nodeType":883},{"uri":82704},[85821],{"data":85822,"marks":85823,"value":82710,"nodeType":864},{},[85824],{"type":1455},{"data":85826,"marks":85827,"value":82714,"nodeType":864},{},[],{"data":85829,"content":85830,"nodeType":883},{"uri":82717},[85831],{"data":85832,"marks":85833,"value":82723,"nodeType":864},{},[85834],{"type":1455},{"data":85836,"marks":85837,"value":82727,"nodeType":864},{},[],{"data":85839,"content":85840,"nodeType":945},{},[85841],{"data":85842,"content":85843,"nodeType":860},{},[85844],{"data":85845,"marks":85846,"value":82737,"nodeType":864},{},[],{"data":85848,"content":85849,"nodeType":945},{},[85850],{"data":85851,"content":85852,"nodeType":860},{},[85853],{"data":85854,"marks":85855,"value":82747,"nodeType":864},{},[],{"data":85857,"content":85858,"nodeType":945},{},[85859],{"data":85860,"content":85861,"nodeType":860},{},[85862],{"data":85863,"marks":85864,"value":82757,"nodeType":864},{},[],{"data":85866,"content":85867,"nodeType":945},{},[85868],{"data":85869,"content":85870,"nodeType":860},{},[85871],{"data":85872,"marks":85873,"value":82767,"nodeType":864},{},[],{"data":85875,"content":85876,"nodeType":945},{},[85877],{"data":85878,"content":85879,"nodeType":860},{},[85880],{"data":85881,"marks":85882,"value":82777,"nodeType":864},{},[],{"data":85884,"content":85887,"nodeType":996},{"target":85885},{"sys":85886},{"id":82782,"type":1001,"linkType":1002},[],{"data":85889,"content":85890,"nodeType":1312},{},[85891],{"data":85892,"marks":85893,"value":82790,"nodeType":864},{},[],{"data":85895,"content":85896,"nodeType":860},{},[85897],{"data":85898,"marks":85899,"value":82797,"nodeType":864},{},[],{"data":85901,"content":85902,"nodeType":941},{},[85903,85912,85921,85930,85939,85948],{"data":85904,"content":85905,"nodeType":945},{},[85906],{"data":85907,"content":85908,"nodeType":860},{},[85909],{"data":85910,"marks":85911,"value":82810,"nodeType":864},{},[],{"data":85913,"content":85914,"nodeType":945},{},[85915],{"data":85916,"content":85917,"nodeType":860},{},[85918],{"data":85919,"marks":85920,"value":82820,"nodeType":864},{},[],{"data":85922,"content":85923,"nodeType":945},{},[85924],{"data":85925,"content":85926,"nodeType":860},{},[85927],{"data":85928,"marks":85929,"value":82830,"nodeType":864},{},[],{"data":85931,"content":85932,"nodeType":945},{},[85933],{"data":85934,"content":85935,"nodeType":860},{},[85936],{"data":85937,"marks":85938,"value":82840,"nodeType":864},{},[],{"data":85940,"content":85941,"nodeType":945},{},[85942],{"data":85943,"content":85944,"nodeType":860},{},[85945],{"data":85946,"marks":85947,"value":82850,"nodeType":864},{},[],{"data":85949,"content":85950,"nodeType":945},{},[85951],{"data":85952,"content":85953,"nodeType":860},{},[85954],{"data":85955,"marks":85956,"value":82860,"nodeType":864},{},[],{"data":85958,"content":85959,"nodeType":860},{},[85960],{"data":85961,"marks":85962,"value":82867,"nodeType":864},{},[],{"data":85964,"content":85965,"nodeType":860},{},[85966],{"data":85967,"marks":85968,"value":82874,"nodeType":864},{},[],{"data":85970,"content":85971,"nodeType":860},{},[85972],{"data":85973,"marks":85974,"value":82881,"nodeType":864},{},[],{"data":85976,"content":85979,"nodeType":996},{"target":85977},{"sys":85978},{"id":82886,"type":1001,"linkType":1002},[],{"data":85981,"content":85982,"nodeType":860},{},[85983],{"data":85984,"marks":85985,"value":82894,"nodeType":864},{},[],{"data":85987,"content":85988,"nodeType":1312},{},[85989],{"data":85990,"marks":85991,"value":82901,"nodeType":864},{},[],{"data":85993,"content":85994,"nodeType":860},{},[85995],{"data":85996,"marks":85997,"value":82908,"nodeType":864},{},[],{"data":85999,"content":86002,"nodeType":996},{"target":86000},{"sys":86001},{"id":82913,"type":1001,"linkType":1002},[],{"data":86004,"content":86005,"nodeType":1312},{},[86006],{"data":86007,"marks":86008,"value":82921,"nodeType":864},{},[],{"data":86010,"content":86011,"nodeType":860},{},[86012],{"data":86013,"marks":86014,"value":82928,"nodeType":864},{},[],{"data":86016,"content":86017,"nodeType":860},{},[86018],{"data":86019,"marks":86020,"value":82935,"nodeType":864},{},[],{"data":86022,"content":86025,"nodeType":996},{"target":86023},{"sys":86024},{"id":82940,"type":1001,"linkType":1002},[],{"data":86027,"content":86028,"nodeType":860},{},[86029,86032,86039],{"data":86030,"marks":86031,"value":82948,"nodeType":864},{},[],{"data":86033,"content":86034,"nodeType":883},{"uri":82951},[86035],{"data":86036,"marks":86037,"value":82957,"nodeType":864},{},[86038],{"type":1455},{"data":86040,"marks":86041,"value":82961,"nodeType":864},{},[],{"data":86043,"content":86044,"nodeType":1312},{},[86045],{"data":86046,"marks":86047,"value":82968,"nodeType":864},{},[],{"data":86049,"content":86050,"nodeType":860},{},[86051],{"data":86052,"marks":86053,"value":82975,"nodeType":864},{},[],{"data":86055,"content":86056,"nodeType":941},{},[86057,86066,86075,86084],{"data":86058,"content":86059,"nodeType":945},{},[86060],{"data":86061,"content":86062,"nodeType":860},{},[86063],{"data":86064,"marks":86065,"value":82988,"nodeType":864},{},[],{"data":86067,"content":86068,"nodeType":945},{},[86069],{"data":86070,"content":86071,"nodeType":860},{},[86072],{"data":86073,"marks":86074,"value":82998,"nodeType":864},{},[],{"data":86076,"content":86077,"nodeType":945},{},[86078],{"data":86079,"content":86080,"nodeType":860},{},[86081],{"data":86082,"marks":86083,"value":83008,"nodeType":864},{},[],{"data":86085,"content":86086,"nodeType":945},{},[86087],{"data":86088,"content":86089,"nodeType":860},{},[86090],{"data":86091,"marks":86092,"value":83018,"nodeType":864},{},[],{"data":86094,"content":86097,"nodeType":996},{"target":86095},{"sys":86096},{"id":83023,"type":1001,"linkType":1002},[],{"data":86099,"content":86100,"nodeType":1005},{},[],{"data":86102,"content":86103,"nodeType":1009},{},[86104],{"data":86105,"marks":86106,"value":83035,"nodeType":864},{},[86107],{"type":899},{"data":86109,"content":86110,"nodeType":860},{},[86111,86114,86121,86124],{"data":86112,"marks":86113,"value":83042,"nodeType":864},{},[],{"data":86115,"content":86116,"nodeType":883},{"uri":83045},[86117],{"data":86118,"marks":86119,"value":83051,"nodeType":864},{},[86120],{"type":1455},{"data":86122,"marks":86123,"value":3731,"nodeType":864},{},[],{"data":86125,"marks":86126,"value":83059,"nodeType":864},{},[86127],{"type":899},{"data":86129,"content":86130,"nodeType":1005},{},[],{"data":86132,"content":86133,"nodeType":1009},{},[86134],{"data":86135,"marks":86136,"value":3578,"nodeType":864},{},[86137],{"type":899},{"data":86139,"content":86140,"nodeType":860},{},[86141],{"data":86142,"marks":86143,"value":83076,"nodeType":864},{},[],{"data":86145,"content":86146,"nodeType":860},{},[86147],{"data":86148,"marks":86149,"value":83083,"nodeType":864},{},[],{"data":86151,"content":86152,"nodeType":860},{},[86153,86156,86163],{"data":86154,"marks":86155,"value":79656,"nodeType":864},{},[],{"data":86157,"content":86158,"nodeType":883},{"uri":14401},[86159],{"data":86160,"marks":86161,"value":83097,"nodeType":864},{},[86162],{"type":1455},{"data":86164,"marks":86165,"value":21,"nodeType":864},{},[],{"items":86167},[86168,86170],{"sys":86169,"name":342},{"id":13775},{"sys":86171,"name":13779},{"id":13778},{"items":86173},[86174],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":86175},{"url":853},{"__typename":2059,"sys":86177,"content":86178,"title":71449,"synopsis":86519,"hashTags":59,"publishedDate":86520,"slug":71450,"tagsCollection":86521,"authorsCollection":86525},{"id":68019},{"json":86179},{"data":86180,"content":86181,"nodeType":856},{},[86182,86189,86196,86203,86209,86216,86249,86256,86263,86270,86276,86283,86290,86308,86314,86321,86341,86359,86366,86373,86380,86387,86394,86401,86408,86428,86435,86442,86448,86455,86462,86482,86488,86507,86513],{"data":86183,"content":86184,"nodeType":860},{},[86185],{"data":86186,"marks":86187,"value":86188,"nodeType":864},{},[],"Scattered Spider has shown the world the devastating effects attackers can achieve by socially engineering IT help desks into performing MFA resets so they can take over accounts on sensitive corporate apps. ",{"data":86190,"content":86191,"nodeType":860},{},[86192],{"data":86193,"marks":86194,"value":86195,"nodeType":864},{},[],"That’s why we’re introducing Employee Identity Verification Codes — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",{"data":86197,"content":86198,"nodeType":860},{},[86199],{"data":86200,"marks":86201,"value":86202,"nodeType":864},{},[],"Push now provides your employees with a rotating 6-digit verification code in their browser via the Push Security extension. When an employee contacts your IT help desk to request an MFA reset or access recovery, the help desk can ask for this code to verify their identity — ensuring it’s really them, and not an attacker.",{"data":86204,"content":86208,"nodeType":996},{"target":86205},{"sys":86206},{"id":86207,"type":1001,"linkType":1002},"3PkiGgzwSt9Nb5rsGRiQVZ",[],{"data":86210,"content":86211,"nodeType":860},{},[86212],{"data":86213,"marks":86214,"value":86215,"nodeType":864},{},[],"The employee identity verification codes are:",{"data":86217,"content":86218,"nodeType":941},{},[86219,86229,86239],{"data":86220,"content":86221,"nodeType":945},{},[86222],{"data":86223,"content":86224,"nodeType":860},{},[86225],{"data":86226,"marks":86227,"value":86228,"nodeType":864},{},[],"Session-aware - generated in users’ browsers and only visible to them when they click on the Push Security extension icon in their browser toolbar.",{"data":86230,"content":86231,"nodeType":945},{},[86232],{"data":86233,"content":86234,"nodeType":860},{},[86235],{"data":86236,"marks":86237,"value":86238,"nodeType":864},{},[],"Rotating: they change every 24 hours",{"data":86240,"content":86241,"nodeType":945},{},[86242],{"data":86243,"content":86244,"nodeType":860},{},[86245],{"data":86246,"marks":86247,"value":86248,"nodeType":864},{},[],"Lightweight: no additional apps or devices required",{"data":86250,"content":86251,"nodeType":860},{},[86252],{"data":86253,"marks":86254,"value":86255,"nodeType":864},{},[],"It’s a fast, simple verification method — directly in the employee’s browser — that addresses a real-world threat.",{"data":86257,"content":86258,"nodeType":1009},{},[86259],{"data":86260,"marks":86261,"value":86262,"nodeType":864},{},[],"We think it’s swell, but don’t just take our word for it …",{"data":86264,"content":86265,"nodeType":860},{},[86266],{"data":86267,"marks":86268,"value":86269,"nodeType":864},{},[],"Eric Rubin — a Senior Manager in GitLab’s Corporate Security team — has already rolled out Employee Identity Verification Codes across his workforce. Here’s what he had to say about it:",{"data":86271,"content":86275,"nodeType":996},{"target":86272},{"sys":86273},{"id":86274,"type":1001,"linkType":1002},"5ZLaA869NXpMjVwkswEyOB",[],{"data":86277,"content":86278,"nodeType":860},{},[86279],{"data":86280,"marks":86281,"value":86282,"nodeType":864},{},[],"Thank you, Eric!",{"data":86284,"content":86285,"nodeType":1009},{},[86286],{"data":86287,"marks":86288,"value":86289,"nodeType":864},{},[],"Why are help desk identity verification methods so hot right now?",{"data":86291,"content":86292,"nodeType":860},{},[86293,86297,86304],{"data":86294,"marks":86295,"value":86296,"nodeType":864},{},[],"A number of the high-profile incidents attributed to the ",{"data":86298,"content":86299,"nodeType":883},{"uri":82190},[86300],{"data":86301,"marks":86302,"value":86303,"nodeType":864},{},[],"Scattered Spider cybercriminal group",{"data":86305,"marks":86306,"value":86307,"nodeType":864},{},[]," saw them socially engineer IT help desks into resetting MFA on employee accounts that they had already acquired valid credentials for. These compromised accounts were typically on IdP systems like Okta providing SSO access to large numbers of downstream applications.",{"data":86309,"content":86313,"nodeType":996},{"target":86310},{"sys":86311},{"id":86312,"type":1001,"linkType":1002},"2F2dpOkyXWnrKgFC3dSl67",[],{"data":86315,"content":86316,"nodeType":1312},{},[86317],{"data":86318,"marks":86319,"value":86320,"nodeType":864},{},[],"Case study: The MGM Resorts breach",{"data":86322,"content":86323,"nodeType":860},{},[86324,86328,86337],{"data":86325,"marks":86326,"value":86327,"nodeType":864},{},[],"One of Scattered Spider’s most notorious and well-documented attacks was against ",{"data":86329,"content":86331,"nodeType":883},{"uri":86330},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-mgm-resorts-september-2023",[86332],{"data":86333,"marks":86334,"value":86336,"nodeType":864},{},[86335],{"type":1455},"MGM Resorts",{"data":86338,"marks":86339,"value":86340,"nodeType":864},{},[],". Scattered Spider socially engineered MGM Resorts’ help desk personnel to bypass MFA and log in to accounts for which they had acquired valid login credentials via credential phishing and historical infostealer compromises. ",{"data":86342,"content":86343,"nodeType":860},{},[86344,86348,86355],{"data":86345,"marks":86346,"value":86347,"nodeType":864},{},[],"They specifically targeted accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",{"data":86349,"content":86350,"nodeType":883},{"uri":57487},[86351],{"data":86352,"marks":86353,"value":57493,"nodeType":864},{},[86354],{"type":1455},{"data":86356,"marks":86357,"value":86358,"nodeType":864},{},[],". This then enabled them to impersonate any user within the Okta tenant. ",{"data":86360,"content":86361,"nodeType":860},{},[86362],{"data":86363,"marks":86364,"value":86365,"nodeType":864},{},[],"The attackers were then able to abuse SSO access to downstream apps and platforms from various accounts, culminating in deployment of ransomware to around 100 ESXi servers and data exfiltration. ",{"data":86367,"content":86368,"nodeType":860},{},[86369],{"data":86370,"marks":86371,"value":86372,"nodeType":864},{},[],"The breach resulted in a 36-hour outage, a $100M hit to its Q3 results, one-time cyber consulting fees in the region of $10M, and a class-action lawsuit later settled for $45M. ",{"data":86374,"content":86375,"nodeType":1312},{},[86376],{"data":86377,"marks":86378,"value":86379,"nodeType":864},{},[],"Reassessing help desk verification processes",{"data":86381,"content":86382,"nodeType":860},{},[86383],{"data":86384,"marks":86385,"value":86386,"nodeType":864},{},[],"Scattered Spider’s high-profile attacks — including its most recent against UK retailers Marks & Spencer’s and the Co-op — has prompted many security teams to reassess the verification processes used by their IT help desks when an employee requests an MFA reset or access to sensitive applications. ",{"data":86388,"content":86389,"nodeType":860},{},[86390],{"data":86391,"marks":86392,"value":86393,"nodeType":864},{},[],"Initial guidance from across the industry included the use of call-back verification for any MFA or credential changes requested by an employee. However, Scattered Spider are also known to use SIM-swapping to trick mobile carriers into transferring a victim’s phone number to a SIM card controlled by the attacker - thereby allowing them to intercept verification calls. ",{"data":86395,"content":86396,"nodeType":1009},{},[86397],{"data":86398,"marks":86399,"value":86400,"nodeType":864},{},[],"Simple verification using your employees’ browsers",{"data":86402,"content":86403,"nodeType":860},{},[86404],{"data":86405,"marks":86406,"value":86407,"nodeType":864},{},[],"Push already provides several controls that directly align to the other TTPs used by Scattered Spider. They include detecting stolen credentials, cloned login pages, AitM toolkits and compromised IdP sessions. ",{"data":86409,"content":86410,"nodeType":860},{},[86411,86415,86424],{"data":86412,"marks":86413,"value":86414,"nodeType":864},{},[],"(BTW, if this piques your interest, you can ",{"data":86416,"content":86418,"nodeType":883},{"uri":86417},"https://pushsecurity.com/resources?type=webinar#content",[86419],{"data":86420,"marks":86421,"value":86423,"nodeType":864},{},[86422],{"type":1455},"stream our latest webinar",{"data":86425,"marks":86426,"value":86427,"nodeType":864},{},[]," where we deep-dive into Scattered Spider, how their TTPs are evolving in 2025, and what Push is doing to protect organizations against them.) ",{"data":86429,"content":86430,"nodeType":860},{},[86431],{"data":86432,"marks":86433,"value":86434,"nodeType":864},{},[],"But to provide our customers with an additional layer of defense against the Scattered Spider attack chain, we wanted to see how we could make it harder for attackers to socially engineer IT help desks into gaining access to IdP systems and sensitive apps.",{"data":86436,"content":86437,"nodeType":860},{},[86438],{"data":86439,"marks":86440,"value":86441,"nodeType":864},{},[],"As so often is the case, the answer was staring us right in the face - we can use our browser extension. By placing a verification code in the details tray of every employees’ Push extension, they can use that to verify their identity with their help desk team.",{"data":86443,"content":86447,"nodeType":996},{"target":86444},{"sys":86445},{"id":86446,"type":1001,"linkType":1002},"4hRJVGqKGyOHJ8NSsQYWGP",[],{"data":86449,"content":86450,"nodeType":1009},{},[86451],{"data":86452,"marks":86453,"value":86454,"nodeType":864},{},[],"Get started today!",{"data":86456,"content":86457,"nodeType":860},{},[86458],{"data":86459,"marks":86460,"value":86461,"nodeType":864},{},[],"Employee verification codes is a Labs feature, which means it’s available on an early-access basis. We're particularly interested in hearing your feedback on how to develop this feature further.",{"data":86463,"content":86464,"nodeType":860},{},[86465,86468,86472,86475,86479],{"data":86466,"marks":86467,"value":81161,"nodeType":864},{},[],{"data":86469,"marks":86470,"value":53319,"nodeType":864},{},[86471],{"type":899},{"data":86473,"marks":86474,"value":81169,"nodeType":864},{},[],{"data":86476,"marks":86477,"value":81174,"nodeType":864},{},[86478],{"type":899},{"data":86480,"marks":86481,"value":81178,"nodeType":864},{},[],{"data":86483,"content":86487,"nodeType":996},{"target":86484},{"sys":86485},{"id":86486,"type":1001,"linkType":1002},"6TyqP2eOmalIF6RRoe476Y",[],{"data":86489,"content":86490,"nodeType":860},{},[86491,86495,86503],{"data":86492,"marks":86493,"value":86494,"nodeType":864},{},[],"If you’d like to find out more about this feature, and the other ways Push is stopping identity attacks in the browser, ",{"data":86496,"content":86497,"nodeType":883},{"uri":14401},[86498],{"data":86499,"marks":86500,"value":86502,"nodeType":864},{},[86501],{"type":1455},"book a demo",{"data":86504,"marks":86505,"value":86506,"nodeType":864},{},[]," with one of our team. ",{"data":86508,"content":86512,"nodeType":996},{"target":86509},{"sys":86510},{"id":86511,"type":1001,"linkType":1002},"7xBE9MrnMy3hfwIkhLhNhQ",[],{"data":86514,"content":86515,"nodeType":860},{},[86516],{"data":86517,"marks":86518,"value":21,"nodeType":864},{},[],"Push's new Employee Identity Verification Codes feature is a simple way for your help desk to confirm they’re talking to someone from your organization.\n","2025-06-19T00:00:00.000Z",{"items":86522},[86523],{"sys":86524,"name":297},{"id":2732},{"items":86526},[86527],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":86528},{"url":4881},{"__typename":2059,"sys":86530,"content":86531,"title":71393,"synopsis":87076,"hashTags":59,"publishedDate":87077,"slug":71394,"tagsCollection":87078,"authorsCollection":87084},{"id":67016},{"json":86532},{"data":86533,"content":86534,"nodeType":856},{},[86535,86554,86561,86584,86591,86598,86605,86624,86630,86633,86641,86648,86668,86712,86755,86785,86805,86810,86813,86821,86828,86835,86842,86849,86972,86979,86982,86989,87006,87023,87026,87034,87051,87058],{"data":86536,"content":86537,"nodeType":860},{},[86538,86542,86550],{"data":86539,"marks":86540,"value":86541,"nodeType":864},{},[],"Almost two years ago, we released our ",{"data":86543,"content":86544,"nodeType":883},{"uri":24059},[86545],{"data":86546,"marks":86547,"value":86549,"nodeType":864},{},[86548],{"type":1455},"SaaS attacks matrix",{"data":86551,"marks":86552,"value":86553,"nodeType":864},{},[]," on GitHub. At the time, our research into modern attack patterns showed us that attackers were increasingly relying on cloud-native techniques, taking advantage of the shift in business IT from traditional on-premise networks to a web of third-party services accessed over the internet. ",{"data":86555,"content":86556,"nodeType":860},{},[86557],{"data":86558,"marks":86559,"value":86560,"nodeType":864},{},[],"As part of our work in maintaining and updating the SaaS attacks matrix in line with our own research and attacks in the wild, we identified that:",{"data":86562,"content":86563,"nodeType":941},{},[86564,86574],{"data":86565,"content":86566,"nodeType":945},{},[86567],{"data":86568,"content":86569,"nodeType":860},{},[86570],{"data":86571,"marks":86572,"value":86573,"nodeType":864},{},[],"The fastest growing category since day 1 has been initial access, which is entirely driven by identity-based techniques (i.e. logging into apps).",{"data":86575,"content":86576,"nodeType":945},{},[86577],{"data":86578,"content":86579,"nodeType":860},{},[86580],{"data":86581,"marks":86582,"value":86583,"nodeType":864},{},[],"Phishing in various forms is the most widely used, and generally effective, of all the initial access techniques we encounter. ",{"data":86585,"content":86586,"nodeType":860},{},[86587],{"data":86588,"marks":86589,"value":86590,"nodeType":864},{},[],"It’s increasingly difficult to reflect a lot of the research we’re doing within the parameters of the SaaS attacks matrix when attackers are doing so much (and to varying levels) in how they architect their phishing sites, distribute links and lures, and find novel ways around authentication and access controls. ",{"data":86592,"content":86593,"nodeType":860},{},[86594],{"data":86595,"marks":86596,"value":86597,"nodeType":864},{},[],"Equally, while there’s a huge amount of valuable research and deep-dive analysis of how individual phishing kits are behaving produced by security firms, there’s a gap in how we’re bringing together this knowledge and understanding the broad strokes of why and how phishing attacks are still so successful.  ",{"data":86599,"content":86600,"nodeType":860},{},[86601],{"data":86602,"marks":86603,"value":86604,"nodeType":864},{},[],"We come across so many phishing attacks on a daily basis that it’s impossible to write a deep-dive teardown on every one — and to some extent it wouldn’t be useful to do so. What’s arguably more valuable is understanding the patterns and commonalities across phishing campaigns that can help us to understand, generally, how malicious tooling and tradecraft is evolving. ",{"data":86606,"content":86607,"nodeType":860},{},[86608,86612,86620],{"data":86609,"marks":86610,"value":86611,"nodeType":864},{},[],"So, we decided to ",{"data":86613,"content":86614,"nodeType":883},{"uri":67105},[86615],{"data":86616,"marks":86617,"value":86619,"nodeType":864},{},[86618],{"type":1455},"create a new resource",{"data":86621,"marks":86622,"value":86623,"nodeType":864},{},[]," giving phishing the space to breathe that it deserves. ",{"data":86625,"content":86629,"nodeType":996},{"target":86626},{"sys":86627},{"id":86628,"type":1001,"linkType":1002},"7rK8RR8KKQ9DbBouZKnjs6",[],{"data":86631,"content":86632,"nodeType":1005},{},[],{"data":86634,"content":86635,"nodeType":1009},{},[86636],{"data":86637,"marks":86638,"value":86640,"nodeType":864},{},[86639],{"type":899},"How phishing has evolved",{"data":86642,"content":86643,"nodeType":860},{},[86644],{"data":86645,"marks":86646,"value":86647,"nodeType":864},{},[],"It’s easy to write off phishing as unsophisticated and simplistic, particularly when we think back to the first generation of phishing attacks — static HTML pages purely designed to steal your username and password, linked directly from an email. ",{"data":86649,"content":86650,"nodeType":860},{},[86651,86655,86664],{"data":86652,"marks":86653,"value":86654,"nodeType":864},{},[],"Modern phishing has changed a lot in the past decade or so. ",{"data":86656,"content":86658,"nodeType":883},{"uri":86657},"https://phishing-techniques.pushsecurity.com/techniques/aitm-phishing/",[86659],{"data":86660,"marks":86661,"value":86663,"nodeType":864},{},[86662],{"type":1455},"MFA-bypassing  Attacker-in-the-Middle (AitM) kits",{"data":86665,"marks":86666,"value":86667,"nodeType":864},{},[]," are table stakes — anyone can pick up a copy of Evilginx and immediately blow past most email and network security solutions on the market.  ",{"data":86669,"content":86670,"nodeType":860},{},[86671,86675,86684,86688,86696,86700,86708],{"data":86672,"marks":86673,"value":86674,"nodeType":864},{},[],"But the most sophisticated attacks — the ones that usually hit the headlines in the form of major breaches — are doing much more than this. The latest generation of fully customized AitM phishing kits are ",{"data":86676,"content":86678,"nodeType":883},{"uri":86677},"https://phishing-techniques.pushsecurity.com/techniques/code-obfuscation/",[86679],{"data":86680,"marks":86681,"value":86683,"nodeType":864},{},[86682],{"type":1455},"dynamically obfuscating the code that loads the web page",{"data":86685,"marks":86686,"value":86687,"nodeType":864},{},[],", implementing ",{"data":86689,"content":86690,"nodeType":883},{"uri":78836},[86691],{"data":86692,"marks":86693,"value":86695,"nodeType":864},{},[86694],{"type":1455},"bot protection through custom CAPTCHA",{"data":86697,"marks":86698,"value":86699,"nodeType":864},{},[],", and using ",{"data":86701,"content":86702,"nodeType":883},{"uri":75759},[86703],{"data":86704,"marks":86705,"value":86707,"nodeType":864},{},[86706],{"type":1455},"runtime anti-analysis features",{"data":86709,"marks":86710,"value":86711,"nodeType":864},{},[],", making them increasingly difficult to detect by the tools most enterprises are using to combat the problem. ",{"data":86713,"content":86714,"nodeType":860},{},[86715,86719,86726,86730,86739,86743,86751],{"data":86716,"marks":86717,"value":86718,"nodeType":864},{},[],"The techniques used by attackers to deliver phishing lures are also more sophisticated. Groups like Scattered Spider have been seen using ",{"data":86720,"content":86721,"nodeType":883},{"uri":72657},[86722],{"data":86723,"marks":86724,"value":441,"nodeType":864},{},[86725],{"type":1455},{"data":86727,"marks":86728,"value":86729,"nodeType":864},{},[]," techniques, delivering phishing links via paid Google ads, while phishing campaigns are frequently encountered in ",{"data":86731,"content":86733,"nodeType":883},{"uri":86732},"https://phishing-techniques.pushsecurity.com/techniques/instant-messenger/",[86734],{"data":86735,"marks":86736,"value":86738,"nodeType":864},{},[86737],{"type":1455},"IM apps",{"data":86740,"marks":86741,"value":86742,"nodeType":864},{},[]," (such as Slack and Teams), as well as ",{"data":86744,"content":86745,"nodeType":883},{"uri":78761},[86746],{"data":86747,"marks":86748,"value":86750,"nodeType":864},{},[86749],{"type":1455},"public messaging services",{"data":86752,"marks":86753,"value":86754,"nodeType":864},{},[]," like LinkedIn messenger and Reddit — bypassing email altogether. ",{"data":86756,"content":86757,"nodeType":860},{},[86758,86762,86771,86775,86782],{"data":86759,"marks":86760,"value":86761,"nodeType":864},{},[],"The latest trends indicate that attackers are responding to increasingly hardened IdP/SSO configuration by using alternative phishing techniques that circumvent MFA and passkeys, either by ",{"data":86763,"content":86765,"nodeType":883},{"uri":86764},"https://phishing-techniques.pushsecurity.com/techniques/mfa-downgrade/",[86766],{"data":86767,"marks":86768,"value":86770,"nodeType":864},{},[86769],{"type":1455},"downgrading to a backup (less secure) authentication method",{"data":86772,"marks":86773,"value":86774,"nodeType":864},{},[],", or sidestepping the legitimate auth process entirely through methods like ",{"data":86776,"content":86777,"nodeType":883},{"uri":72701},[86778],{"data":86779,"marks":86780,"value":72707,"nodeType":864},{},[86781],{"type":1455},{"data":86783,"marks":86784,"value":11546,"nodeType":864},{},[],{"data":86786,"content":86787,"nodeType":860},{},[86788,86792,86801],{"data":86789,"marks":86790,"value":86791,"nodeType":864},{},[],"Attackers have also realized how much valuable data exists in Shadow SaaS highlighted by major SaaS breaches impacting apps like Snowflake. This is driving ",{"data":86793,"content":86795,"nodeType":883},{"uri":86794},"https://phishing-techniques.pushsecurity.com/techniques/saas-admins/",[86796],{"data":86797,"marks":86798,"value":86800,"nodeType":864},{},[86799],{"type":1455},"broader targeting against apps like Slack, Mailchimp, Postman, GitHub, and other commonly-used business apps directly",{"data":86802,"marks":86803,"value":86804,"nodeType":864},{},[]," — bypassing IdPs (MS, Google, Okta, etc.) that typically have more robust authentication controls in place.",{"data":86806,"content":86809,"nodeType":996},{"target":86807},{"sys":86808},{"id":78111,"type":1001,"linkType":1002},[],{"data":86811,"content":86812,"nodeType":1005},{},[],{"data":86814,"content":86815,"nodeType":1009},{},[86816],{"data":86817,"marks":86818,"value":86820,"nodeType":864},{},[86819],{"type":899},"Using the phishing detection evasion techniques matrix",{"data":86822,"content":86823,"nodeType":860},{},[86824],{"data":86825,"marks":86826,"value":86827,"nodeType":864},{},[],"With so much attacker innovation happening in the phishing space, it’s tricky for security teams and solution vendors to have a big picture view of the subtle changes attackers are making to their phishing attacks, and precisely why they’re doing it — or more specifically, which detection techniques they’re evading. ",{"data":86829,"content":86830,"nodeType":860},{},[86831],{"data":86832,"marks":86833,"value":86834,"nodeType":864},{},[],"If you look at one of the many phishing kit teardowns found in security blogs online (including our own) it can be hard to see the wood for the trees when it comes to understanding why a phishing page behaves in the way it does — why is it behaving in this way? What control exactly is this trying to get around? ",{"data":86836,"content":86837,"nodeType":860},{},[86838],{"data":86839,"marks":86840,"value":86841,"nodeType":864},{},[],"By creating a simple framework breaking down the categories of a phishing attack into phases, each with its own specific attacker objective, we can better understand phishing kit behavior and track meaningful changes over time. This ensures that we understand how we need to adapt to as an industry in order to detect and block these attacks. ",{"data":86843,"content":86844,"nodeType":860},{},[86845],{"data":86846,"marks":86847,"value":86848,"nodeType":864},{},[],"The matrix covers the following categories:",{"data":86850,"content":86851,"nodeType":941},{},[86852,86867,86882,86897,86912,86927,86942,86957],{"data":86853,"content":86854,"nodeType":945},{},[86855],{"data":86856,"content":86857,"nodeType":860},{},[86858,86863],{"data":86859,"marks":86860,"value":86862,"nodeType":864},{},[86861],{"type":899},"Phase 1: Targeting",{"data":86864,"marks":86865,"value":86866,"nodeType":864},{},[]," — Identifying apps and users to evade security controls and achieve the shortest time-to-impact of a phishing attack. ",{"data":86868,"content":86869,"nodeType":945},{},[86870],{"data":86871,"content":86872,"nodeType":860},{},[86873,86878],{"data":86874,"marks":86875,"value":86877,"nodeType":864},{},[86876],{"type":899},"Phase 2: Link delivery",{"data":86879,"marks":86880,"value":86881,"nodeType":864},{},[]," — Deliver links using phishing vectors that evade traditional security controls. ",{"data":86883,"content":86884,"nodeType":945},{},[86885],{"data":86886,"content":86887,"nodeType":860},{},[86888,86893],{"data":86889,"marks":86890,"value":86892,"nodeType":864},{},[86891],{"type":899},"Phase 3: Link camouflage",{"data":86894,"marks":86895,"value":86896,"nodeType":864},{},[]," — Masking malicious links to prevent detection at the email, network proxy, or safe browsing layer. ",{"data":86898,"content":86899,"nodeType":945},{},[86900],{"data":86901,"content":86902,"nodeType":860},{},[86903,86908],{"data":86904,"marks":86905,"value":86907,"nodeType":864},{},[86906],{"type":899},"Phase 4: TI evasion ",{"data":86909,"marks":86910,"value":86911,"nodeType":864},{},[],"— Preventing TI feeds from flagging and blocking known-bad domains by masking or changing elements likely to be flagged.",{"data":86913,"content":86914,"nodeType":945},{},[86915],{"data":86916,"content":86917,"nodeType":860},{},[86918,86923],{"data":86919,"marks":86920,"value":86922,"nodeType":864},{},[86921],{"type":899},"Phase 5: Anti-analysis",{"data":86924,"marks":86925,"value":86926,"nodeType":864},{},[]," — Techniques to defeat automated “sandbox” analysis tools by preventing security teams and bots from accessing the page.",{"data":86928,"content":86929,"nodeType":945},{},[86930],{"data":86931,"content":86932,"nodeType":860},{},[86933,86938],{"data":86934,"marks":86935,"value":86937,"nodeType":864},{},[86936],{"type":899},"Phase 6: Page obfuscation",{"data":86939,"marks":86940,"value":86941,"nodeType":864},{},[]," — Obfuscating page elements to break detection signatures analysing page content and code. ",{"data":86943,"content":86944,"nodeType":945},{},[86945],{"data":86946,"content":86947,"nodeType":860},{},[86948,86953],{"data":86949,"marks":86950,"value":86952,"nodeType":864},{},[86951],{"type":899},"Phase 7: Defeat MFA & CA",{"data":86954,"marks":86955,"value":86956,"nodeType":864},{},[]," — Defeat authentication and access controls in order to successfully execute the phishing attack.",{"data":86958,"content":86959,"nodeType":945},{},[86960],{"data":86961,"content":86962,"nodeType":860},{},[86963,86968],{"data":86964,"marks":86965,"value":86967,"nodeType":864},{},[86966],{"type":899},"Phase 8: Account takeover",{"data":86969,"marks":86970,"value":86971,"nodeType":864},{},[]," — Achieve a form of account takeover and conclude the identity attack, enabling further exploitation to take place.",{"data":86973,"content":86974,"nodeType":860},{},[86975],{"data":86976,"marks":86977,"value":86978,"nodeType":864},{},[],"Combining techniques and approaches from these categories is what enables attackers to bypass the majority of phishing detection controls they encounter today. You typically find that the more advanced the phishing kit / attacker, the more techniques they’ll leverage. And as phishing infrastructure becomes increasingly templated and commodified with as-a-Service or for-hire models, the average phishing attack will employ more of these measures to counter security controls. ",{"data":86980,"content":86981,"nodeType":1005},{},[],{"data":86983,"content":86984,"nodeType":1009},{},[86985],{"data":86986,"marks":86987,"value":40614,"nodeType":864},{},[86988],{"type":899},{"data":86990,"content":86991,"nodeType":860},{},[86992,86995,87003],{"data":86993,"marks":86994,"value":21,"nodeType":864},{},[],{"data":86996,"content":86997,"nodeType":883},{"uri":67105},[86998],{"data":86999,"marks":87000,"value":87002,"nodeType":864},{},[87001],{"type":1455},"You can find the matrix here.",{"data":87004,"marks":87005,"value":21,"nodeType":864},{},[],{"data":87007,"content":87008,"nodeType":860},{},[87009,87013,87020],{"data":87010,"marks":87011,"value":87012,"nodeType":864},{},[],"If you want to learn more about the research that led us to this point, and our take on how and why phishing attacks have evolved, ",{"data":87014,"content":87015,"nodeType":883},{"uri":82089},[87016],{"data":87017,"marks":87018,"value":87019,"nodeType":864},{},[],"you can also check out our latest whitepaper. ",{"data":87021,"marks":87022,"value":21,"nodeType":864},{},[],{"data":87024,"content":87025,"nodeType":1005},{},[],{"data":87027,"content":87028,"nodeType":1009},{},[87029],{"data":87030,"marks":87031,"value":87033,"nodeType":864},{},[87032],{"type":899},"Get involved!",{"data":87035,"content":87036,"nodeType":860},{},[87037,87041,87047],{"data":87038,"marks":87039,"value":87040,"nodeType":864},{},[],"Like the ",{"data":87042,"content":87043,"nodeType":883},{"uri":24059},[87044],{"data":87045,"marks":87046,"value":23416,"nodeType":864},{},[],{"data":87048,"marks":87049,"value":87050,"nodeType":864},{},[],", we’d love to see the security community using and helping us to maintain this resource to ensure it stays up to date with techniques as they evolve. ",{"data":87052,"content":87053,"nodeType":860},{},[87054],{"data":87055,"marks":87056,"value":87057,"nodeType":864},{},[],"Unlike the SaaS matrix, which we’ve seen mostly leveraged by offensive security practitioners, phishing detection evasion techniques are most useful to blue teamers looking to assess current detection capabilities and understand why certain attacks got through existing defenses. ",{"data":87059,"content":87060,"nodeType":860},{},[87061,87065,87073],{"data":87062,"marks":87063,"value":87064,"nodeType":864},{},[],"If you’d like to add techniques you’ve observed or examples that you think demonstrate them, ",{"data":87066,"content":87068,"nodeType":883},{"uri":87067},"https://github.com/pushsecurity/phishing-techniques",[87069],{"data":87070,"marks":87071,"value":87072,"nodeType":864},{},[],"get involved on GitHub!",{"data":87074,"marks":87075,"value":21,"nodeType":864},{},[],"Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection. ","2025-08-06T00:00:00.000Z",{"items":87079},[87080,87082],{"sys":87081,"name":342},{"id":13775},{"sys":87083,"name":13779},{"id":13778},{"items":87085},[87086],{"fullName":52068,"firstName":52069,"jobTitle":52070,"profilePicture":87087},{"url":52072},"blog/how-the-browser-became-the-main-cyber-battleground",{"json":87090},{"data":87091,"content":87092,"nodeType":856},{},[87093],{"data":87094,"content":87095,"nodeType":860},{},[87096],{"data":87097,"marks":87098,"value":84496,"nodeType":864},{},[],{"id":83723,"publishedAt":87100},"2026-08-12T11:53:53.682Z",{"items":87102},[87103,87105],{"sys":87104,"name":342},{"id":13775},{"sys":87106,"name":13779},{"id":13778},{"items":87108},[87109,87111,87113,87115,87117,87119,87121,87123,87125,87127,87129,87131,87133,87135,87137,87139,87141,87143,87145,87147,87149,87151,87153,87155,87157],{"sys":87110,"name":279,"slug":280,"tier":31},{"id":276},{"sys":87112,"name":297,"slug":298,"tier":31},{"id":294},{"sys":87114,"name":413,"slug":414,"tier":31},{"id":410},{"sys":87116,"name":519,"slug":520,"tier":31},{"id":516},{"sys":87118,"name":545,"slug":546,"tier":31},{"id":542},{"sys":87120,"name":342,"slug":343,"tier":31},{"id":339},{"sys":87122,"name":642,"slug":643,"tier":31},{"id":639},{"sys":87124,"name":377,"slug":378,"tier":45},{"id":374},{"sys":87126,"name":404,"slug":405,"tier":45},{"id":401},{"sys":87128,"name":324,"slug":325,"tier":45},{"id":321},{"sys":87130,"name":333,"slug":334,"tier":45},{"id":330},{"sys":87132,"name":571,"slug":572,"tier":45},{"id":568},{"sys":87134,"name":422,"slug":423,"tier":45},{"id":419},{"sys":87136,"name":261,"slug":262,"tier":45},{"id":258},{"sys":87138,"name":466,"slug":467,"tier":45},{"id":463},{"sys":87140,"name":457,"slug":458,"tier":45},{"id":454},{"sys":87142,"name":395,"slug":396,"tier":45},{"id":392},{"sys":87144,"name":288,"slug":289,"tier":45},{"id":285},{"sys":87146,"name":484,"slug":485,"tier":45},{"id":481},{"sys":87148,"name":589,"slug":590,"tier":45},{"id":586},{"sys":87150,"name":607,"slug":608,"tier":45},{"id":604},{"sys":87152,"name":475,"slug":476,"tier":45},{"id":472},{"sys":87154,"name":511,"slug":512,"tier":45},{"id":508},{"sys":87156,"name":493,"slug":494,"tier":45},{"id":490},{"sys":87158,"name":440,"slug":441,"tier":45},{"id":437},"PonpZ2he3fGXpKQWTeIZC0k0nbZ5ZfYtQyn8NDwmYDI",{"id":87161,"title":87162,"authorsCollection":87163,"content":87169,"extension":228,"faqItemsCollection":87823,"faqTitle":59,"featured":6,"hashTags":59,"meta":87825,"metaTitle":87826,"ogImage":87827,"postType":59861,"publishedDate":87829,"relatedBlogPostsCollection":87830,"slug":90351,"stem":90352,"subtitle":59,"summary":90353,"synopsis":90364,"sys":90365,"tagsCollection":90368,"topicsCollection":90374,"__hash__":90410},"blog/blog/considering-the-impact-of-computer-using-agents.json","Considering the security implications of Computer-Using Agents (like OpenAI Operator)",{"items":87164},[87165],{"fullName":52068,"firstName":52069,"jobTitle":52070,"socialLinks":87166,"profilePicture":87168},[87167],"https://www.linkedin.com/in/jacques-louw-o-62608594/",{"url":52072},{"json":87170,"links":87786},{"data":87171,"content":87172,"nodeType":856},{},[87173,87180,87196,87203,87209,87216,87223,87226,87233,87240,87247,87270,87277,87293,87296,87303,87310,87333,87340,87347,87365,87371,87378,87397,87403,87410,87456,87464,87471,87483,87495,87502,87535,87542,87545,87552,87572,87579,87586,87593,87596,87603,87611,87618,87625,87688,87695,87702,87709,87742,87748,87755,87762,87768],{"data":87174,"content":87175,"nodeType":860},{},[87176],{"data":87177,"marks":87178,"value":87179,"nodeType":864},{},[],"Computer-Using Agents (CUAs) are a new type of AI agent that drives your browser/OS for you. With the research preview release of OpenAI Operator last week, it’s likely that we’ll be seeing a lot more of this technology in the future as OpenAI iterates and competitors launch their own versions. ",{"data":87181,"content":87182,"nodeType":860},{},[87183,87187,87192],{"data":87184,"marks":87185,"value":87186,"nodeType":864},{},[],"These models run on the same UI as the user sees, rather than using code or API based add-ons or tools (e.g. with access via API keys). In Operator’s case, the agent runs in its own browser, where it can navigate to and interact with webpages by typing, clicking, and scrolling. It effectively sees and interacts with pages as a human would, ",{"data":87188,"marks":87189,"value":87191,"nodeType":864},{},[87190],{"type":899},"using human (not machine) identities",{"data":87193,"marks":87194,"value":87195,"nodeType":864},{},[]," — taking actions on the web without requiring custom API integrations. ",{"data":87197,"content":87198,"nodeType":860},{},[87199],{"data":87200,"marks":87201,"value":87202,"nodeType":864},{},[],"This means that a user describes a task, and Operator performs it autonomously on their behalf. The examples provided by OpenAI are things like booking a dinner reservation or shopping for groceries — but naturally the potential use cases are much, much broader, especially in a work context.",{"data":87204,"content":87208,"nodeType":996},{"target":87205},{"sys":87206},{"id":87207,"type":1001,"linkType":1002},"5mWWi5mfqEcSQX12gOtyQm",[],{"data":87210,"content":87211,"nodeType":860},{},[87212],{"data":87213,"marks":87214,"value":87215,"nodeType":864},{},[],"Obviously the broad impact of this technology is almost impossible to predict this early in the game. But since we’re focussed on identity security at Push, we can at least describe some of the very predictable impacts in this area.",{"data":87217,"content":87218,"nodeType":860},{},[87219],{"data":87220,"marks":87221,"value":87222,"nodeType":864},{},[],"CUAs like Operator are essentially very flexible no-code automation platforms. This means that these tools (or future iterations of them) will enable low-cost, low-effort automation of common web tasks — the very tasks that app developers and vendors have worked hard to prevent from being automated — including those frequently performed by attackers.",{"data":87224,"content":87225,"nodeType":1005},{},[],{"data":87227,"content":87228,"nodeType":1009},{},[87229],{"data":87230,"marks":87231,"value":87232,"nodeType":864},{},[],"Why do CUAs stand to benefit attackers more than previous AI tools? ",{"data":87234,"content":87235,"nodeType":860},{},[87236],{"data":87237,"marks":87238,"value":87239,"nodeType":864},{},[],"Organizations have been concerned about the security and privacy implications of GenAI tools and platforms for a while now — mainly concerning the risk of inputting sensitive data into LLMs, and prompt injection attacks in which models can be tricked into disclosing internal data. ",{"data":87241,"content":87242,"nodeType":860},{},[87243],{"data":87244,"marks":87245,"value":87246,"nodeType":864},{},[],"But so far, the primary impact of GenAI on attacker capabilities specifically has been mainly limited to the use of LLMs for the creation of phishing emails and in AI-assisted malware development — no doubt significant, but not exactly transformative. And although the concept of an AI agent is nothing new, they haven’t been particularly common outside of research circles. ",{"data":87248,"content":87249,"nodeType":860},{},[87250,87254,87259,87262,87267],{"data":87251,"marks":87252,"value":87253,"nodeType":864},{},[],"CUAs, on the other hand, use LLMs trained using datasets which make them far more able to understand and interact with web pages. Coupled with what is essentially a production-grade integration between browser and LLM, and you have an agent that is able to understand and interact with websites to achieve an outcome, with minimal human input and oversight (as opposed to simply scraping the data) ",{"data":87255,"marks":87256,"value":87258,"nodeType":864},{},[87257],{"type":899},"with much the same behaviors and capabilities",{"data":87260,"marks":87261,"value":1171,"nodeType":864},{},[],{"data":87263,"marks":87264,"value":87266,"nodeType":864},{},[87265],{"type":899},"as a human operator.",{"data":87268,"marks":87269,"value":7160,"nodeType":864},{},[],{"data":87271,"content":87272,"nodeType":860},{},[87273],{"data":87274,"marks":87275,"value":87276,"nodeType":864},{},[],"By performing actions autonomously on the user’s behalf, it has a lot in common with a low/no-code automation platform like Zapier or Make.com — except it doesn’t perform actions via API, but by performing actions in the browser as a user would. Unlike no/low-code automations, it doesn’t need a strict or rigid step-by-step description of tasks that should be automated and can dynamically generate steps like a human does. ",{"data":87278,"content":87279,"nodeType":860},{},[87280,87284,87289],{"data":87281,"marks":87282,"value":87283,"nodeType":864},{},[],"None of this can’t be done using other automation tools, but it’s the difference between writing code to automate a task by hand and asking a human assistant to do something for you — ",{"data":87285,"marks":87286,"value":87288,"nodeType":864},{},[87287],{"type":899},"the effort required is reduced by orders of magnitude.",{"data":87290,"marks":87291,"value":87292,"nodeType":864},{},[]," This makes it both more flexible and accessible to a much wider range of users. ",{"data":87294,"content":87295,"nodeType":1005},{},[],{"data":87297,"content":87298,"nodeType":1009},{},[87299],{"data":87300,"marks":87301,"value":87302,"nodeType":864},{},[],"How can CUAs be abused by attackers?",{"data":87304,"content":87305,"nodeType":860},{},[87306],{"data":87307,"marks":87308,"value":87309,"nodeType":864},{},[],"There are two main groups of attack to be aware of:",{"data":87311,"content":87312,"nodeType":941},{},[87313,87323],{"data":87314,"content":87315,"nodeType":945},{},[87316],{"data":87317,"content":87318,"nodeType":860},{},[87319],{"data":87320,"marks":87321,"value":87322,"nodeType":864},{},[],"Attacks enabled by the technology (CUA)",{"data":87324,"content":87325,"nodeType":945},{},[87326],{"data":87327,"content":87328,"nodeType":860},{},[87329],{"data":87330,"marks":87331,"value":87332,"nodeType":864},{},[],"Attacks against specific CUA tools/implementations (e.g. Operator)",{"data":87334,"content":87335,"nodeType":860},{},[87336],{"data":87337,"marks":87338,"value":87339,"nodeType":864},{},[],"Because the answer to the latter question is subjective depending on the CUA being targeted (and Operator is still in its “research preview” release) we’ll focus on how attackers can potentially use CUAs for malicious purposes in general. ",{"data":87341,"content":87342,"nodeType":1312},{},[87343],{"data":87344,"marks":87345,"value":87346,"nodeType":864},{},[],"How attackers can use their own CUAs to conduct AI-powered cyber attacks",{"data":87348,"content":87349,"nodeType":860},{},[87350,87354,87362],{"data":87351,"marks":87352,"value":87353,"nodeType":864},{},[],"The most obvious use-case for an attacker-controlled CUA is targeting internet-based app accounts. Most organizations are now using hundreds of apps, with thousands of sprawling identities (including both inside enterprise SSO connected accounts and local username & password logins) — ",{"data":87355,"content":87356,"nodeType":883},{"uri":25338},[87357],{"data":87358,"marks":87359,"value":87361,"nodeType":864},{},[87360],{"type":1455},"many of which are highly vulnerable to even low-sophistication attack techniques",{"data":87363,"marks":87364,"value":11546,"nodeType":864},{},[],{"data":87366,"content":87370,"nodeType":996},{"target":87367},{"sys":87368},{"id":87369,"type":1001,"linkType":1002},"7itjimRwqpkrCF7YRI8FTq",[],{"data":87372,"content":87373,"nodeType":860},{},[87374],{"data":87375,"marks":87376,"value":87377,"nodeType":864},{},[],"Previously, identity attacks against modern SaaS environments and the sprawl of apps and accounts required a lot of manual work to scale. Because web identities are implemented in mostly bespoke ways across thousands of sites (and they are constantly changing) attacks on them are challenging to automate. Further, the act of logging in using automated methods has been impacted by widespread bot protection — specifically to prevent malicious automation. ",{"data":87379,"content":87380,"nodeType":860},{},[87381,87385,87393],{"data":87382,"marks":87383,"value":87384,"nodeType":864},{},[],"So, attackers end up sending phishing links through email, and targeting only a few high value apps for cred stuffing — despite the availability of credentials online (which, ",{"data":87386,"content":87387,"nodeType":883},{"uri":3751},[87388],{"data":87389,"marks":87390,"value":87392,"nodeType":864},{},[87391],{"type":1455},"as the Snowflake attacks demonstrate",{"data":87394,"marks":87395,"value":87396,"nodeType":864},{},[],", can be an untapped treasure trove for attackers).",{"data":87398,"content":87402,"nodeType":996},{"target":87399},{"sys":87400},{"id":87401,"type":1001,"linkType":1002},"24HV5O6LJ12ZVECTSel2WL",[],{"data":87404,"content":87405,"nodeType":860},{},[87406],{"data":87407,"marks":87408,"value":87409,"nodeType":864},{},[],"We know that about 1 in 3 users re-use passwords, so there is a great chance a lot of those exact same credentials were actually valid for many other apps. It’s very tough to manually test each credential by logging into even a few dozen apps (or building a web automation to do so). But this is significantly easier if you can ask a CUA to: ",{"data":87411,"content":87412,"nodeType":941},{},[87413,87423,87433],{"data":87414,"content":87415,"nodeType":945},{},[87416],{"data":87417,"content":87418,"nodeType":860},{},[87419],{"data":87420,"marks":87421,"value":87422,"nodeType":864},{},[],"“Find a list of the top 1000 SaaS apps”. ",{"data":87424,"content":87425,"nodeType":945},{},[87426],{"data":87427,"content":87428,"nodeType":860},{},[87429],{"data":87430,"marks":87431,"value":87432,"nodeType":864},{},[],"“Try to login to the app using this username and password. Let me know which apps you successfully logged into”. ",{"data":87434,"content":87435,"nodeType":945},{},[87436],{"data":87437,"content":87438,"nodeType":860},{},[87439,87443,87452],{"data":87440,"marks":87441,"value":87442,"nodeType":864},{},[],"“Use ",{"data":87444,"content":87446,"nodeType":883},{"uri":87445},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/takeout_services/description.md",[87447],{"data":87448,"marks":87449,"value":87451,"nodeType":864},{},[87450],{"type":1455},"takeout services",{"data":87453,"marks":87454,"value":87455,"nodeType":864},{},[]," to download data from each app and send it to this location, grouping by company name” (or even just ask the model to cut and paste or download the data from the account).",{"data":87457,"content":87458,"nodeType":860},{},[87459],{"data":87460,"marks":87461,"value":87463,"nodeType":864},{},[87462],{"type":899},"This is how you really scale these attacks.",{"data":87465,"content":87466,"nodeType":860},{},[87467],{"data":87468,"marks":87469,"value":87470,"nodeType":864},{},[],"CUA agents also change how and where phishing can take place. Where phishing takes place outside of email, it’s much less likely to be intercepted by enterprise anti-phishing controls. You could:",{"data":87472,"content":87473,"nodeType":860},{},[87474,87479],{"data":87475,"marks":87476,"value":87478,"nodeType":864},{},[87477],{"type":899},"1.",{"data":87480,"marks":87481,"value":87482,"nodeType":864},{},[]," Task an agent to create Reddit, Discord, and Slack accounts, login, and find the 100 (or 10000?) biggest subreddits/communities/channels. Now have it join those, and write posts that seem relevant to ongoing threads, or write targeted DMs and include links to a phishing page. If the account gets banned, no problem, automatically start over. Not enough karma? Instruct the agent to build karma.",{"data":87484,"content":87485,"nodeType":860},{},[87486,87491],{"data":87487,"marks":87488,"value":87490,"nodeType":864},{},[87489],{"type":899},"2.",{"data":87492,"marks":87493,"value":87494,"nodeType":864},{},[]," Or consider a more targeted scenario: connect to a specific target (or group of targets) via LinkedIn, read all your target’s posts and comments, and using that context start a conversation with them, using a topic you know that will interest them to create a phishing lure, and direct them to your phishing site. ",{"data":87496,"content":87497,"nodeType":1312},{},[87498],{"data":87499,"marks":87500,"value":87501,"nodeType":864},{},[],"Operator caveats",{"data":87503,"content":87504,"nodeType":860},{},[87505,87509,87518,87522,87531],{"data":87506,"marks":87507,"value":87508,"nodeType":864},{},[],"Now, it’s worth pointing out that Operator has controls that are designed to prevent this sort of abuse. ",{"data":87510,"content":87512,"nodeType":883},{"uri":87511},"https://openai.com/index/introducing-operator/",[87513],{"data":87514,"marks":87515,"value":87517,"nodeType":864},{},[87516],{"type":1455},"For example",{"data":87519,"marks":87520,"value":87521,"nodeType":864},{},[],", Operator is trained to proactively ask the user to take over for tasks that require login, payment details, or when solving CAPTCHAs. The ",{"data":87523,"content":87525,"nodeType":883},{"uri":87524},"https://openai.com/index/operator-system-card/",[87526],{"data":87527,"marks":87528,"value":87530,"nodeType":864},{},[87529],{"type":1455},"Operator System Card",{"data":87532,"marks":87533,"value":87534,"nodeType":864},{},[]," also cites proactive refusals of high-risk tasks, confirmation prompts before critical actions, and active monitoring systems to detect and mitigate potential threats.",{"data":87536,"content":87537,"nodeType":860},{},[87538],{"data":87539,"marks":87540,"value":87541,"nodeType":864},{},[],"It’s unclear at this point how resistant Operator will be to attack or abuse, but really, as we said earlier, this is not about Operator — once CUA tech becomes more widely available (if recent trends are anything to go by) there’s no doubt that models will emerge with fewer (or no) safety controls. ",{"data":87543,"content":87544,"nodeType":1005},{},[],{"data":87546,"content":87547,"nodeType":1009},{},[87548],{"data":87549,"marks":87550,"value":87551,"nodeType":864},{},[],"Why CUA-based automation is a problem for security teams",{"data":87553,"content":87554,"nodeType":860},{},[87555,87559,87568],{"data":87556,"marks":87557,"value":87558,"nodeType":864},{},[],"Attackers have been using automation tools forever, and in response, developers have been building protections against them (e.g. Cloudflare Turnstile and CAPTCHAs). Using LLMs to super power them isn’t even new, nor is using automation apps for malicious purposes (see our SaaS attack matrix entry for ",{"data":87560,"content":87562,"nodeType":883},{"uri":87561},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/shadow_workflows/description.md",[87563],{"data":87564,"marks":87565,"value":87567,"nodeType":864},{},[87566],{"type":1455},"shadow workflows",{"data":87569,"marks":87570,"value":87571,"nodeType":864},{},[],") — so what’s the difference?",{"data":87573,"content":87574,"nodeType":860},{},[87575],{"data":87576,"marks":87577,"value":87578,"nodeType":864},{},[],"Previously, attackers needed to tie together automated browsers, get bot protection bypasses working, write code to extract screenshots from these browsers, pump those screenshots into a traditional LLM, generate response actions, and write code to execute those actions using browser automation. It was a lot of manual work — and needed constant maintenance — and wasn’t very effective because the general LLMs weren’t good at interpreting what they were seeing.",{"data":87580,"content":87581,"nodeType":860},{},[87582],{"data":87583,"marks":87584,"value":87585,"nodeType":864},{},[],"So, this isn’t so much a change in capability but a signal that there is going to be a massive increase in performance compared to other AI agents. Bundle the new model’s ability to understand with the ability to interact with webpages and you have something that might soon create real world impact at scale. ",{"data":87587,"content":87588,"nodeType":860},{},[87589],{"data":87590,"marks":87591,"value":87592,"nodeType":864},{},[],"Perhaps the only real obstacles are safety controls and cost. But as we’ve seen after previous GenAI launches, most recently with DeepSeek — competitors have been fast following with models that out-perform the original. Some of these models will be open and contain far fewer safety protections. An open CUA model in the future might be the trigger that enables attackers to leverage these capabilities at scale. ",{"data":87594,"content":87595,"nodeType":1005},{},[],{"data":87597,"content":87598,"nodeType":1009},{},[87599],{"data":87600,"marks":87601,"value":87602,"nodeType":864},{},[],"So what?",{"data":87604,"content":87605,"nodeType":860},{},[87606],{"data":87607,"marks":87608,"value":87610,"nodeType":864},{},[87609],{"type":899},"The TL;DR is that the adoption of CUAs has the potential to significantly lower the cost to attackers of running identity attacks such as phishing and credential stuffing, while increasing their reach.",{"data":87612,"content":87613,"nodeType":860},{},[87614],{"data":87615,"marks":87616,"value":87617,"nodeType":864},{},[],"We can expect improved account takeover attacks in the future as this technology becomes more widespread, with phishing attacks being increasingly delivered outside of traditional (well-protected) mediums like email, and credential stuffing being weaponized on an even more widespread scale, across a broader range of apps. These capabilities will also become more accessible, with even less advanced attackers able to harness them.",{"data":87619,"content":87620,"nodeType":860},{},[87621],{"data":87622,"marks":87623,"value":87624,"nodeType":864},{},[],"Right now, Operator runs in a sandboxed browser environment. But going forward, more value will require an increased ability to perform authenticated access as the user — so one could imagine a world where new features are built to expose passwords into this sandbox — or that these agents will be enabled outside these sandboxes and operate in your browser (primarily) or directly on your OS using agents. We’ve already seen these agents implemented as browser extensions. This makes sense as extensions can see the tab, and interact with the page — and some early extension-based agents have existed for a while:",{"data":87626,"content":87627,"nodeType":941},{},[87628,87648,87668],{"data":87629,"content":87630,"nodeType":945},{},[87631],{"data":87632,"content":87633,"nodeType":860},{},[87634,87637,87645],{"data":87635,"marks":87636,"value":21,"nodeType":864},{},[],{"data":87638,"content":87640,"nodeType":883},{"uri":87639},"https://github.com/richardyc/Chrome-GPT",[87641],{"data":87642,"marks":87643,"value":87639,"nodeType":864},{},[87644],{"type":1455},{"data":87646,"marks":87647,"value":7160,"nodeType":864},{},[],{"data":87649,"content":87650,"nodeType":945},{},[87651],{"data":87652,"content":87653,"nodeType":860},{},[87654,87657,87665],{"data":87655,"marks":87656,"value":21,"nodeType":864},{},[],{"data":87658,"content":87660,"nodeType":883},{"uri":87659},"https://github.com/handrew/browserpilot",[87661],{"data":87662,"marks":87663,"value":87659,"nodeType":864},{},[87664],{"type":1455},{"data":87666,"marks":87667,"value":21,"nodeType":864},{},[],{"data":87669,"content":87670,"nodeType":945},{},[87671],{"data":87672,"content":87673,"nodeType":860},{},[87674,87677,87685],{"data":87675,"marks":87676,"value":21,"nodeType":864},{},[],{"data":87678,"content":87680,"nodeType":883},{"uri":87679},"https://github.com/TaxyAI/browser-extension",[87681],{"data":87682,"marks":87683,"value":87679,"nodeType":864},{},[87684],{"type":1455},{"data":87686,"marks":87687,"value":2924,"nodeType":864},{},[],{"data":87689,"content":87690,"nodeType":860},{},[87691],{"data":87692,"marks":87693,"value":87694,"nodeType":864},{},[],"If we have agents operating on user endpoints, not in sandboxes, that means they will have access to all identities that are already authenticated, or that can be automatically authenticated (password manager autofills etc.). There’s nothing fundamentally stopping you from prompt-injecting a victim's CUA and tricking it into creating a malicious integration, or sending you an API key.",{"data":87696,"content":87697,"nodeType":1312},{},[87698],{"data":87699,"marks":87700,"value":87701,"nodeType":864},{},[],"So to summarize...",{"data":87703,"content":87704,"nodeType":860},{},[87705],{"data":87706,"marks":87707,"value":87708,"nodeType":864},{},[],"Organizations should anticipate an increase in identity attacks targeting web-based apps and services using techniques that can be amplified by CUAs such as phishing and credential stuffing. We recommend that organizations:",{"data":87710,"content":87711,"nodeType":941},{},[87712,87722,87732],{"data":87713,"content":87714,"nodeType":945},{},[87715],{"data":87716,"content":87717,"nodeType":860},{},[87718],{"data":87719,"marks":87720,"value":87721,"nodeType":864},{},[],"Anticipate an increase in phishing attacks delivered outside of email, and evaluate your detection capabilities for mediums such as IM platforms and social media sites.",{"data":87723,"content":87724,"nodeType":945},{},[87725],{"data":87726,"content":87727,"nodeType":860},{},[87728],{"data":87729,"marks":87730,"value":87731,"nodeType":864},{},[],"Find and harden identities that could be vulnerable to attacks using techniques that can be automated (e.g. mass credential stuffing) such as those missing phishing resistant MFA (or MFA altogether).",{"data":87733,"content":87734,"nodeType":945},{},[87735],{"data":87736,"content":87737,"nodeType":860},{},[87738],{"data":87739,"marks":87740,"value":87741,"nodeType":864},{},[],"Ensure that all identities are suitably protected — even those outside the scope of traditional identity stores (such as Active Directory and modern equivalents e.g. Entra, Okta) used to access the much broader set of web-based services. ",{"data":87743,"content":87744,"nodeType":1312},{},[87745],{"data":87746,"marks":87747,"value":7533,"nodeType":864},{},[],{"data":87749,"content":87750,"nodeType":860},{},[87751],{"data":87752,"marks":87753,"value":87754,"nodeType":864},{},[],"AI-powered or not, identity attacks are what Push is designed to combat. Our features and controls designed to stop account takeover via phishing, credential stuffing, and session hijacking remain effective in this new world — in fact, as attackers are granted the ability to conduct these attacks with greater speed and scale, they become more valuable than ever. ",{"data":87756,"content":87757,"nodeType":860},{},[87758],{"data":87759,"marks":87760,"value":87761,"nodeType":864},{},[],"If you're interested in learning more, check out our on-demand webinar where we demonstrate the use of CUAs for automating identity attacks, particularly in the context of SaaS account takeover. ",{"data":87763,"content":87767,"nodeType":996},{"target":87764},{"sys":87765},{"id":87766,"type":1001,"linkType":1002},"UCmd5kqVZ03ce5Cs9M0r5",[],{"data":87769,"content":87770,"nodeType":860},{},[87771,87775,87782],{"data":87772,"marks":87773,"value":87774,"nodeType":864},{},[],"If you’d like to learn more about Push, ",{"data":87776,"content":87777,"nodeType":883},{"uri":14401},[87778],{"data":87779,"marks":87780,"value":87781,"nodeType":864},{},[],"set up a demo with our team",{"data":87783,"marks":87784,"value":87785,"nodeType":864},{},[]," or sign up yourself to have a look at the platform.",{"entries":87787},{"hyperlink":87788,"inline":87789,"block":87790},[],[],[87791,87797,87802,87816],{"sys":87792,"__typename":1724,"title":87793,"caption":87793,"layoutMode":59,"file":87794},{"id":87207},"OpenAI Operator being tasked with “find and book me the highest rated one-day tour of Rome on Tripadvisor”",{"url":87795,"width":87796,"height":74599},"https://images.ctfassets.net/y1cdw1ablpvd/5iIuabafJE9Ppd3MBVPQr1/c28b519b0ea62b926a0ef17c404fc550/image1.png",1920,{"sys":87798,"__typename":1717,"type":1718,"ctaText":87799,"buttonLabel":87800,"buttonColour":85273,"buttonUrl":87801},{"id":87369},"Read about how identity-based techniques were used by attackers in 2024s biggest cyber breaches","Read Blog","https://pushsecurity.com/blog/2024-identity-breaches/",{"sys":87803,"__typename":1740,"content":87804,"name":87815,"title":59},{"id":87401},{"json":87805},{"nodeType":856,"data":87806,"content":87807},{},[87808],{"nodeType":860,"data":87809,"content":87810},{},[87811],{"nodeType":864,"value":87812,"marks":87813,"data":87814},"The Snowflake attacks saw credentials from infostealer infections dating back to 2020 used to breach ~165 customer tenants, resulting in hundreds of millions of breached customer records — arguably the biggest cyber breach of the year. But the impact could have been significantly worse than this if the attackers had access to a CUA. ",[],{},"The Snowflake attacks saw credentials from infostealer infections dating back to 2020 used against ~165 customer tenants. But the impact could have been significantly worse than this if the attackers had access to a CUA. ",{"sys":87817,"__typename":87818,"title":87819,"youTubeUrl":87820,"imagePlaceholder":87821},{"id":87766},"ExternalVideo","5 ways Computer-Using Agents can automate identity attacks","https://www.youtube.com/watch?v=BuefsnMMyrM",{"url":87822,"width":87796,"height":74599},"https://images.ctfassets.net/y1cdw1ablpvd/7kFAZLy7gbAMifHkkKpfo/add59eb5173ee6b0910d86d5406bb946/Slide_16_9_-_104__1_.png",{"items":87824},[],{},"How Computer-Using Agents can be leveraged in cyber attacks",{"url":87828},"https://images.ctfassets.net/y1cdw1ablpvd/4ACAoxro2X0ONhQrEMDd8C/a066c8b0ec720732f98da1ed5dd2c382/Youtube_Video_Thumbnail_V2__3_.jpg","2025-01-28T00:00:00.000Z",{"items":87831},[87832,88468,89168],{"__typename":2059,"sys":87833,"content":87835,"title":88456,"synopsis":88457,"hashTags":59,"publishedDate":88458,"slug":88459,"tagsCollection":88460,"authorsCollection":88464},{"id":87834},"1pJdOGN0dOd3BKVqO4CxHh",{"json":87836},{"data":87837,"content":87838,"nodeType":856},{},[87839,87846,87853,87860,87879,87886,87893,87896,87904,87911,87918,87925,87931,87938,87941,87949,87956,87963,87970,87977,87983,87990,87993,88001,88009,88016,88023,88030,88050,88058,88065,88072,88079,88086,88094,88101,88108,88114,88117,88125,88132,88139,88146,88153,88160,88163,88171,88178,88185,88192,88199,88206,88316,88332,88339,88345,88348,88356,88363,88431,88438],{"data":87840,"content":87841,"nodeType":860},{},[87842],{"data":87843,"marks":87844,"value":87845,"nodeType":864},{},[],"2024 was an unprecedented year in terms of the impact of identity-based attacks. Or that’s what it felt like anyway, so I decided to trawl through a year of news to see if reality stacked up. ",{"data":87847,"content":87848,"nodeType":860},{},[87849],{"data":87850,"marks":87851,"value":87852,"nodeType":864},{},[],"My main obstacles here were the ever-disappointing levels of public information disclosure for cyber breaches. Even where breaches are disclosed, it’s rare that any public information contains the nature of the initial access vector (though I can’t say I’m surprised — it’s hard to argue the ‘highly sophisticated’ nature of a breach that involved stolen credentials and no MFA). ",{"data":87854,"content":87855,"nodeType":860},{},[87856],{"data":87857,"marks":87858,"value":87859,"nodeType":864},{},[],"Publicly disclosed breaches are just the tip of the iceberg, and with the rise in data theft and extortion over more disruptive attacks (e.g. ransomware), there is often no obvious service interruption indicating that an incident has taken place. This makes it more likely that these situations can be settled quietly or smoothed over, without hitting the headlines. ",{"data":87861,"content":87862,"nodeType":860},{},[87863,87867,87876],{"data":87864,"marks":87865,"value":87866,"nodeType":864},{},[],"That said, the requirement that US companies submit a Form-8K for breaches of a material nature does appear to have increased the number of voluntary declarations (inside the US, at least) and the growing willingness of the SEC to prosecute negligent or misleading behavior is also a considerable motivator, such as ",{"data":87868,"content":87870,"nodeType":883},{"uri":87869},"https://www.bleepingcomputer.com/news/security/sec-charges-tech-companies-for-downplaying-solarwinds-breaches/",[87871],{"data":87872,"marks":87873,"value":87875,"nodeType":864},{},[87874],{"type":1455},"the recent prosecution of companies for misleading investors about the impact of the 2020 SolarWinds Orion hack",{"data":87877,"marks":87878,"value":2924,"nodeType":864},{},[],{"data":87880,"content":87881,"nodeType":860},{},[87882],{"data":87883,"marks":87884,"value":87885,"nodeType":864},{},[],"Despite all this, I totalled 30 breaches that were the result of an identity-based initial access vector, such as phishing, credential stuffing, social engineering, session hijacking, etc. To make the list, it had to have appeared in the public domain, confirmed by the victim or an authoritative source, and the breach vector had to have been named. ",{"data":87887,"content":87888,"nodeType":860},{},[87889],{"data":87890,"marks":87891,"value":87892,"nodeType":864},{},[],"Public identity-related breaches in 2024 resulted in hundreds of millions of breached customer records (with the final impact of many still yet to appear in the public domain).",{"data":87894,"content":87895,"nodeType":1005},{},[],{"data":87897,"content":87898,"nodeType":1009},{},[87899],{"data":87900,"marks":87901,"value":87903,"nodeType":864},{},[87902],{"type":899},"What is an identity attack?",{"data":87905,"content":87906,"nodeType":860},{},[87907],{"data":87908,"marks":87909,"value":87910,"nodeType":864},{},[],"First, what do we mean by identity attack? ",{"data":87912,"content":87913,"nodeType":860},{},[87914],{"data":87915,"marks":87916,"value":87917,"nodeType":864},{},[],"An identity attack is any attack (regardless of the steps that follow) involving identity-based techniques, such as phishing, credential stuffing, and session hijacking, to log into an account/service. Basically, where identity is the initial breach vector.",{"data":87919,"content":87920,"nodeType":860},{},[87921],{"data":87922,"marks":87923,"value":87924,"nodeType":864},{},[],"The length and complexity of the overall attack chain will vary. For example, a SaaS-based account takeover where the attacker logs in and dumps the data from the app is naturally going to be more direct than a scenario in which an identity-based compromise leads to the takeover of an endpoint or device in a traditional networking environment. ",{"data":87926,"content":87930,"nodeType":996},{"target":87927},{"sys":87928},{"id":87929,"type":1001,"linkType":1002},"SCbhb6dzXnaKUianhgLEL",[],{"data":87932,"content":87933,"nodeType":860},{},[87934],{"data":87935,"marks":87936,"value":87937,"nodeType":864},{},[],"In 2024, we’ve seen examples of both SaaS-based account takeover as well as identity attacks being used for initial access to more traditional networks, often resulting in ransomware deployment.",{"data":87939,"content":87940,"nodeType":1005},{},[],{"data":87942,"content":87943,"nodeType":1009},{},[87944],{"data":87945,"marks":87946,"value":87948,"nodeType":864},{},[87947],{"type":899},"Breakdown of public identity breaches in 2024",{"data":87950,"content":87951,"nodeType":860},{},[87952],{"data":87953,"marks":87954,"value":87955,"nodeType":864},{},[],"It’s always tricky to gauge the impact of a cyber breach, particularly when considering the limited information typically shared. Different types of breach are easier to assess than others — for example, any breach involving extortion/ransom payment has a clear cost associated. Regulator fines and penalties are also clear cut. But aside from these, you’re looking at the extent of any disruption/downtime, recovery costs, and the like. Long term, indirect impacts such as the loss of customer confidence are naturally tricky to estimate. ",{"data":87957,"content":87958,"nodeType":860},{},[87959],{"data":87960,"marks":87961,"value":87962,"nodeType":864},{},[],"However, many identity breaches don’t even have these metrics to go by. The general shift toward data theft only (as opposed to ransomware deployment) continued in 2024, and many of the public identity breaches reflect this. In these attacks, attackers steal data to extort a ransom payment, blackmail end-customers, and/or sell the data via underground criminal marketplaces. ",{"data":87964,"content":87965,"nodeType":860},{},[87966],{"data":87967,"marks":87968,"value":87969,"nodeType":864},{},[],"The one consistent metric we do have is the number of breached records, which is available in many (but not all) cases. Some organizations have attempted to calculate the financial impact per breached record. Most notably IBMs annual ‘Cost of a Data Breach’ report estimates the average data breach to cost $4.88m, and the cost per compromised record to be $169. But when applied to the sheer magnitude of 2024’s biggest attacks (in the region of hundreds of millions of breached records) the figures quickly reach unbelievable levels. ",{"data":87971,"content":87972,"nodeType":860},{},[87973],{"data":87974,"marks":87975,"value":87976,"nodeType":864},{},[],"All this is to say: It’s hard to pin down the relative impact of data breaches. But with the information available (profile of the victim organization, type of data impacted, number of customers impacted) it’s possible to provide a finger-in-the-air assessment — which is what I’ve attempted to do below. Here, we can see the overall month-by-month impact of public identity breaches, dated from when they were first reported (or using dates provided in said reports). ",{"data":87978,"content":87982,"nodeType":996},{"target":87979},{"sys":87980},{"id":87981,"type":1001,"linkType":1002},"2XYuNqLuKhZbISb4II9IW4",[],{"data":87984,"content":87985,"nodeType":860},{},[87986],{"data":87987,"marks":87988,"value":87989,"nodeType":864},{},[],"Let’s take a closer look at the most notable breaches (and why they were especially significant). ",{"data":87991,"content":87992,"nodeType":1005},{},[],{"data":87994,"content":87995,"nodeType":1009},{},[87996],{"data":87997,"marks":87998,"value":88000,"nodeType":864},{},[87999],{"type":899},"Top 3 public identity-related breaches in 2024",{"data":88002,"content":88003,"nodeType":1312},{},[88004],{"data":88005,"marks":88006,"value":88008,"nodeType":864},{},[88007],{"type":899},"#3: Microsoft — January 2024",{"data":88010,"content":88011,"nodeType":860},{},[88012],{"data":88013,"marks":88014,"value":88015,"nodeType":864},{},[],"The threat group known as APT29, associated with the Russian SVR intelligence service, utilized password spray attacks that successfully compromised a non-production tenant account that did not have multi-factor authentication (MFA) enabled. They then leveraged this account to compromise a ‘test’ OAuth application that had elevated access to the Microsoft corporate environment. This was then used to access the email accounts of Microsoft employees. ",{"data":88017,"content":88018,"nodeType":860},{},[88019],{"data":88020,"marks":88021,"value":88022,"nodeType":864},{},[],"The attacks then continued throughout the year using information stolen from Microsoft mailboxes, with password spraying attacks increasing tenfold since the initial attack, resulting in the further compromise of source code repositories. ",{"data":88024,"content":88025,"nodeType":860},{},[88026],{"data":88027,"marks":88028,"value":88029,"nodeType":864},{},[],"Microsoft has shared limited information about the breach, but despite this it caused a significant stir. We can expect the number of email accounts compromised to be significant, given that it was later suggested that at least 100 external organizations had been contacted by Microsoft regarding their communications being breached (we only know this because 100-ish organizations reported the email as spam). The list of companies impacted included both public and private sector organizations, from major enterprises to government agencies in the US and other countries. ",{"data":88031,"content":88032,"nodeType":860},{},[88033,88037,88046],{"data":88034,"marks":88035,"value":88036,"nodeType":864},{},[],"Microsoft’s challenges with credential management didn’t end here either, ",{"data":88038,"content":88040,"nodeType":883},{"uri":88039},"https://pushsecurity.com/blog/learning-from-the-servicenow-disclosure/",[88041],{"data":88042,"marks":88043,"value":88045,"nodeType":864},{},[88044],{"type":1455},"with bug bounty hunters able to use stolen credentials from a TI platform to breach Microsoft’s ServiceNow tenant",{"data":88047,"marks":88048,"value":88049,"nodeType":864},{},[],", accessing 1,000s of support ticket descriptions and attachments, and 250k+ employee emails.",{"data":88051,"content":88052,"nodeType":1312},{},[88053],{"data":88054,"marks":88055,"value":88057,"nodeType":864},{},[88056],{"type":899},"#2: Change Healthcare — February 2024",{"data":88059,"content":88060,"nodeType":860},{},[88061],{"data":88062,"marks":88063,"value":88064,"nodeType":864},{},[],"In February, attackers stole 6TB of data from UnitedHealth subsidiary Change Healthcare as part of a severe ransomware attack that caused massive disruption to the US healthcare industry. This impacted a wide range of critical services used by healthcare providers across the U.S., including payment processing, prescription writing, and insurance claims, and caused financial damages estimated at $872 million. The attack impacted the personal medical data of over 100M customers. ",{"data":88066,"content":88067,"nodeType":860},{},[88068],{"data":88069,"marks":88070,"value":88071,"nodeType":864},{},[],"The attacker used stolen credentials to breach the company's Citrix remote access service, which did not have multi-factor authentication enabled, as the initial breach vector for the attack. ",{"data":88073,"content":88074,"nodeType":860},{},[88075],{"data":88076,"marks":88077,"value":88078,"nodeType":864},{},[],"Following the attack, the organization's IT team replaced thousands of laptops, rotated credentials, and completely rebuilt Change Healthcare's data center network and core services.",{"data":88080,"content":88081,"nodeType":860},{},[88082],{"data":88083,"marks":88084,"value":88085,"nodeType":864},{},[],"The UnitedHealth Group admitted to paying a ransom demand to receive a decryptor and for the threat actors to delete the stolen data. The ransom payment was allegedly $22 million, according to the BlackCat ransomware affiliate who conducted the attack.",{"data":88087,"content":88088,"nodeType":1312},{},[88089],{"data":88090,"marks":88091,"value":88093,"nodeType":864},{},[88092],{"type":899},"#1: Snowflake — April-June 2024",{"data":88095,"content":88096,"nodeType":860},{},[88097],{"data":88098,"marks":88099,"value":88100,"nodeType":864},{},[],"165 organizations around the world were targeted using stolen credentials gathered from infostealer infections dating back to 2020. The impacted accounts lacked MFA, meaning successful authentication only required a valid username and password. As the Snowflake credentials found in infostealer malware credential dumps had not been rotated or updated, they remained valid and could be used to authenticate to user accounts on Snowflake tenants belonging to various customers. It has been touted by some news outlets as ‘one of the biggest breaches ever’. ",{"data":88102,"content":88103,"nodeType":860},{},[88104],{"data":88105,"marks":88106,"value":88107,"nodeType":864},{},[],"In total, nine public victims were named following the breach, collectively impacting hundreds of millions of their respective customers. Data was put up for sale on criminal forums for fees ranging from $150k to $2m per organization, while AT&T was also confirmed as paying an undisclosed ransom fee. ",{"data":88109,"content":88113,"nodeType":996},{"target":88110},{"sys":88111},{"id":88112,"type":1001,"linkType":1002},"68txz4KkLmCX2hF9QySUZs",[],{"data":88115,"content":88116,"nodeType":1005},{},[],{"data":88118,"content":88119,"nodeType":1009},{},[88120],{"data":88121,"marks":88122,"value":88124,"nodeType":864},{},[88123],{"type":899},"Identity attacks vs. other attacks in 2024",{"data":88126,"content":88127,"nodeType":860},{},[88128],{"data":88129,"marks":88130,"value":88131,"nodeType":864},{},[],"In many ways, 2024 was a year of identity attacks. The attacks on Snowflake customers was unarguably one of (if not the most) significant cyber security event of the year (at least, if you exclude CrowdStrike causing a worldwide outage in July) — certainly, it was the largest perpetrated by a criminal group against commercial enterprises. ",{"data":88133,"content":88134,"nodeType":860},{},[88135],{"data":88136,"marks":88137,"value":88138,"nodeType":864},{},[],"Arguably the biggest non-identity story of the year was the Chinese state-sponsored “Salt Typhoon” campaign against global telecommunications firms, with at least nine major providers compromised — including AT&T, Verizon, and T-Mobile. The group reportedly focused on infiltrating telecommunications infrastructure to steal text messages, phone call information, and voicemails from targeted people. The threat actors also targeted the wiretapping platforms used by the US government, raising serious national security concerns.",{"data":88140,"content":88141,"nodeType":860},{},[88142],{"data":88143,"marks":88144,"value":88145,"nodeType":864},{},[],"Undoubtedly this was one of the biggest intelligence compromises in US history and is of major significance. But it’s also arguable that identity attacks had a more widespread commercial impact in 2024 when we look at the big picture.   ",{"data":88147,"content":88148,"nodeType":860},{},[88149],{"data":88150,"marks":88151,"value":88152,"nodeType":864},{},[],"Attacks on edge networking devices were also incredibly prominent, as were very much interlinked with the targeting of telecommunications infrastructure. A barrage of 0-days generated a huge amount of concern about the software security practices of many vendors. ",{"data":88154,"content":88155,"nodeType":860},{},[88156],{"data":88157,"marks":88158,"value":88159,"nodeType":864},{},[],"But despite these honorable mentions, the runaway threat of the year was an identity-based one… ",{"data":88161,"content":88162,"nodeType":1005},{},[],{"data":88164,"content":88165,"nodeType":1009},{},[88166],{"data":88167,"marks":88168,"value":88170,"nodeType":864},{},[88169],{"type":899},"Threat of the year: Infostealers",{"data":88172,"content":88173,"nodeType":860},{},[88174],{"data":88175,"marks":88176,"value":88177,"nodeType":864},{},[],"2024 saw an unprecedented rise in the role of infostealers. The played a huge role in the attacks on Snowflake customers, where 80% of the accounts were targeted using credentials found in infostealer infections. ",{"data":88179,"content":88180,"nodeType":860},{},[88181],{"data":88182,"marks":88183,"value":88184,"nodeType":864},{},[],"News relating to new infostealer variants and distributions campaigns came thick and fast in 2024, as attackers sought to harvest credentials from victims to use as part of their own malicious campaigns, or to sell on to other criminals on underground marketplaces for compromised credentials. Attackers leaned into alternative distribution channels, branching away from email-based campaigns to target victims via gaming forums, Facebook ads, and YouTube video descriptions. GitHub was also continuously targeted as a malware distribution mechanism throughout the year — and the majority of the time it was to push infostealers. ",{"data":88186,"content":88187,"nodeType":860},{},[88188],{"data":88189,"marks":88190,"value":88191,"nodeType":864},{},[],"Infostealers are the weapon of choice for attackers looking to harvest credentials at scale. Compared to credential harvesting phishing campaigns, infostealers target a much broader range of credentials, taking everything saved in the victim’s browser (and often also from local apps, including password managers).",{"data":88193,"content":88194,"nodeType":860},{},[88195],{"data":88196,"marks":88197,"value":88198,"nodeType":864},{},[],"Infostealers are nothing new, but have historically been seen as a problem affecting less secure personal devices and accounts. But 2024 has demonstrated that infostealers are finding ways to harvest business data — by finding ways around controls like EDR, and because of the ways that personal and business identities and accounts are converging in the modern workplace. For example, it’s not uncommon for employees to log into their personal Google account on their work device (and vice versa), inadvertently saving corporate credentials to their personal password store — which is later compromised through an infostealer infection on a personal device. ",{"data":88200,"content":88201,"nodeType":860},{},[88202],{"data":88203,"marks":88204,"value":88205,"nodeType":864},{},[],"The impact of infostealers (and the resulting stolen credentials and session cookies) is underlined by various figures:",{"data":88207,"content":88208,"nodeType":941},{},[88209,88229,88251,88273,88294],{"data":88210,"content":88211,"nodeType":945},{},[88212],{"data":88213,"content":88214,"nodeType":860},{},[88215,88219,88226],{"data":88216,"marks":88217,"value":88218,"nodeType":864},{},[],"79% of web application compromises were the result of breached credentials (",{"data":88220,"content":88221,"nodeType":883},{"uri":4408},[88222],{"data":88223,"marks":88224,"value":57796,"nodeType":864},{},[88225],{"type":1455},{"data":88227,"marks":88228,"value":49943,"nodeType":864},{},[],{"data":88230,"content":88231,"nodeType":945},{},[88232],{"data":88233,"content":88234,"nodeType":860},{},[88235,88239,88248],{"data":88236,"marks":88237,"value":88238,"nodeType":864},{},[],"Infostealer activity increased by 266% in 2023, while the number of attacks featuring valid credentials saw a 71% increase year-over-year (",{"data":88240,"content":88242,"nodeType":883},{"uri":88241},"https://www.ibm.com/downloads/cas/L0GKXDWJ",[88243],{"data":88244,"marks":88245,"value":88247,"nodeType":864},{},[88246],{"type":1455},"IBM",{"data":88249,"marks":88250,"value":49943,"nodeType":864},{},[],{"data":88252,"content":88253,"nodeType":945},{},[88254],{"data":88255,"content":88256,"nodeType":860},{},[88257,88261,88270],{"data":88258,"marks":88259,"value":88260,"nodeType":864},{},[],"Nearly half of the malware detected last year targeted victims’ data specifically, and the majority of that malware was classified as infostealers (",{"data":88262,"content":88264,"nodeType":883},{"uri":88263},"https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report/",[88265],{"data":88266,"marks":88267,"value":88269,"nodeType":864},{},[88268],{"type":1455},"Sophos",{"data":88271,"marks":88272,"value":49943,"nodeType":864},{},[],{"data":88274,"content":88275,"nodeType":945},{},[88276],{"data":88277,"content":88278,"nodeType":860},{},[88279,88283,88291],{"data":88280,"marks":88281,"value":88282,"nodeType":864},{},[],"39,000 session token attacks are detected per day (",{"data":88284,"content":88286,"nodeType":883},{"uri":88285},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[88287],{"data":88288,"marks":88289,"value":19538,"nodeType":864},{},[88290],{"type":1455},{"data":88292,"marks":88293,"value":49943,"nodeType":864},{},[],{"data":88295,"content":88296,"nodeType":945},{},[88297],{"data":88298,"content":88299,"nodeType":860},{},[88300,88304,88313],{"data":88301,"marks":88302,"value":88303,"nodeType":864},{},[],"Attacks on session cookies happen at the same rough order of magnitude as password-based attacks (",{"data":88305,"content":88307,"nodeType":883},{"uri":88306},"https://github.com/WICG/dbsc/issues/13#issuecomment-1977657864",[88308],{"data":88309,"marks":88310,"value":88312,"nodeType":864},{},[88311],{"type":1455},"Google",{"data":88314,"marks":88315,"value":49943,"nodeType":864},{},[],{"data":88317,"content":88318,"nodeType":860},{},[88319,88323,88328],{"data":88320,"marks":88321,"value":88322,"nodeType":864},{},[],"And of the confirmed identity-based breaches in the public domain that we identified, ",{"data":88324,"marks":88325,"value":88327,"nodeType":864},{},[88326],{"type":899},"a whopping 73% were the result of compromised credentials ",{"data":88329,"marks":88330,"value":88331,"nodeType":864},{},[],"(the rest were phishing attacks). ",{"data":88333,"content":88334,"nodeType":860},{},[88335],{"data":88336,"marks":88337,"value":88338,"nodeType":864},{},[],"As the primary source of compromised credentials, it’s fair to say that infostealers deserve the top spot for 2024.",{"data":88340,"content":88344,"nodeType":996},{"target":88341},{"sys":88342},{"id":88343,"type":1001,"linkType":1002},"7mMQEYQTXKAajIGFviDJKt",[],{"data":88346,"content":88347,"nodeType":1005},{},[],{"data":88349,"content":88350,"nodeType":1009},{},[88351],{"data":88352,"marks":88353,"value":88355,"nodeType":864},{},[88354],{"type":899},"Defend against infostealers with Push",{"data":88357,"content":88358,"nodeType":860},{},[88359],{"data":88360,"marks":88361,"value":88362,"nodeType":864},{},[],"As a browser-based identity security platform designed to stop identity attacks, Push helps organizations to defend against the rise in infostealers by:",{"data":88364,"content":88365,"nodeType":941},{},[88366,88400,88421],{"data":88367,"content":88368,"nodeType":945},{},[88369],{"data":88370,"content":88371,"nodeType":860},{},[88372,88375,88383,88387,88396],{"data":88373,"marks":88374,"value":21,"nodeType":864},{},[],{"data":88376,"content":88377,"nodeType":883},{"uri":77770},[88378],{"data":88379,"marks":88380,"value":88382,"nodeType":864},{},[88381],{"type":1455},"Alerting you whenever the valid credentials your employees are using appear in a compromised credential data feed",{"data":88384,"marks":88385,"value":88386,"nodeType":864},{},[],", which can be leveraged to ",{"data":88388,"content":88390,"nodeType":883},{"uri":88389},"https://pushsecurity.com/blog/automating-sso-password-resets-using-push/",[88391],{"data":88392,"marks":88393,"value":88395,"nodeType":864},{},[88394],{"type":1455},"trigger automated password resets",{"data":88397,"marks":88398,"value":88399,"nodeType":864},{},[]," whenever an event fires and is received by your SIEM tool.",{"data":88401,"content":88402,"nodeType":945},{},[88403],{"data":88404,"content":88405,"nodeType":860},{},[88406,88409,88417],{"data":88407,"marks":88408,"value":21,"nodeType":864},{},[],{"data":88410,"content":88411,"nodeType":883},{"uri":62865},[88412],{"data":88413,"marks":88414,"value":88416,"nodeType":864},{},[88415],{"type":1455},"Detecting session hijacking attacks using stolen cookies to identify when an attacker logs into an app",{"data":88418,"marks":88419,"value":88420,"nodeType":864},{},[]," from an unmanaged device without the Push browser extension — this can also be used to detect suspicious access in general!",{"data":88422,"content":88423,"nodeType":945},{},[88424],{"data":88425,"content":88426,"nodeType":860},{},[88427],{"data":88428,"marks":88429,"value":88430,"nodeType":864},{},[],"Enabling you to enforce MFA the next time an employee logs into an app (even when the app itself doesn’t allow you to enforce mandatory MFA) — particularly handy if a weak, breached, or reused password is detected for their account!  ",{"data":88432,"content":88433,"nodeType":860},{},[88434],{"data":88435,"marks":88436,"value":88437,"nodeType":864},{},[],"And much, much more. ",{"data":88439,"content":88440,"nodeType":860},{},[88441,88445,88453],{"data":88442,"marks":88443,"value":88444,"nodeType":864},{},[],"If you’d like to explore the platform yourself and discover more of our great features, you can ",{"data":88446,"content":88447,"nodeType":883},{"uri":1700},[88448],{"data":88449,"marks":88450,"value":88452,"nodeType":864},{},[88451],{"type":1455},"request a demo",{"data":88454,"marks":88455,"value":2924,"nodeType":864},{},[],"Looking back on identity-based breaches in 2024","Reviewing public breaches that stemmed from identity attacks in 2024. ","2025-01-10T00:00:00.000Z","2024-identity-breaches",{"items":88461},[88462],{"sys":88463,"name":13779},{"id":13778},{"items":88465},[88466],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":88467},{"url":2740},{"__typename":2059,"sys":88469,"content":88470,"title":62888,"synopsis":62889,"hashTags":59,"publishedDate":62890,"slug":62891,"tagsCollection":89160,"authorsCollection":89164},{"id":62097},{"json":88471},{"data":88472,"content":88473,"nodeType":856},{},[88474,88479,88495,88501,88507,88512,88515,88522,88528,88544,88554,88560,88566,88572,88656,88659,88666,88741,88746,88749,88756,88763,88769,88775,88782,88798,88804,88811,88817,88823,88830,88836,88842,88858,88863,88866,88873,88880,88886,88975,88981,88988,88994,89000,89005,89012,89018,89024,89030,89037,89043,89049,89055,89061,89066,89069,89076,89082,89112,89118,89133,89149,89154],{"data":88475,"content":88478,"nodeType":996},{"target":88476},{"sys":88477},{"id":62106,"type":1001,"linkType":1002},[],{"data":88480,"content":88481,"nodeType":860},{},[88482,88485,88492],{"data":88483,"marks":88484,"value":62114,"nodeType":864},{},[],{"data":88486,"content":88487,"nodeType":883},{"uri":62117},[88488],{"data":88489,"marks":88490,"value":62123,"nodeType":864},{},[88491],{"type":1455},{"data":88493,"marks":88494,"value":62127,"nodeType":864},{},[],{"data":88496,"content":88497,"nodeType":860},{},[88498],{"data":88499,"marks":88500,"value":62134,"nodeType":864},{},[],{"data":88502,"content":88503,"nodeType":860},{},[88504],{"data":88505,"marks":88506,"value":62141,"nodeType":864},{},[],{"data":88508,"content":88511,"nodeType":996},{"target":88509},{"sys":88510},{"id":62146,"type":1001,"linkType":1002},[],{"data":88513,"content":88514,"nodeType":1005},{},[],{"data":88516,"content":88517,"nodeType":1009},{},[88518],{"data":88519,"marks":88520,"value":62158,"nodeType":864},{},[88521],{"type":899},{"data":88523,"content":88524,"nodeType":860},{},[88525],{"data":88526,"marks":88527,"value":62165,"nodeType":864},{},[],{"data":88529,"content":88530,"nodeType":860},{},[88531,88534,88541],{"data":88532,"marks":88533,"value":62172,"nodeType":864},{},[],{"data":88535,"content":88536,"nodeType":883},{"uri":29070},[88537],{"data":88538,"marks":88539,"value":62180,"nodeType":864},{},[88540],{"type":1455},{"data":88542,"marks":88543,"value":11546,"nodeType":864},{},[],{"data":88545,"content":88546,"nodeType":1116},{},[88547],{"data":88548,"content":88549,"nodeType":860},{},[88550],{"data":88551,"marks":88552,"value":62194,"nodeType":864},{},[88553],{"type":899},{"data":88555,"content":88556,"nodeType":860},{},[88557],{"data":88558,"marks":88559,"value":62201,"nodeType":864},{},[],{"data":88561,"content":88562,"nodeType":860},{},[88563],{"data":88564,"marks":88565,"value":62208,"nodeType":864},{},[],{"data":88567,"content":88568,"nodeType":860},{},[88569],{"data":88570,"marks":88571,"value":62215,"nodeType":864},{},[],{"data":88573,"content":88574,"nodeType":941},{},[88575,88584,88593,88602,88611,88620,88629,88638,88647],{"data":88576,"content":88577,"nodeType":945},{},[88578],{"data":88579,"content":88580,"nodeType":860},{},[88581],{"data":88582,"marks":88583,"value":62228,"nodeType":864},{},[],{"data":88585,"content":88586,"nodeType":945},{},[88587],{"data":88588,"content":88589,"nodeType":860},{},[88590],{"data":88591,"marks":88592,"value":62238,"nodeType":864},{},[],{"data":88594,"content":88595,"nodeType":945},{},[88596],{"data":88597,"content":88598,"nodeType":860},{},[88599],{"data":88600,"marks":88601,"value":62248,"nodeType":864},{},[],{"data":88603,"content":88604,"nodeType":945},{},[88605],{"data":88606,"content":88607,"nodeType":860},{},[88608],{"data":88609,"marks":88610,"value":62258,"nodeType":864},{},[],{"data":88612,"content":88613,"nodeType":945},{},[88614],{"data":88615,"content":88616,"nodeType":860},{},[88617],{"data":88618,"marks":88619,"value":62268,"nodeType":864},{},[],{"data":88621,"content":88622,"nodeType":945},{},[88623],{"data":88624,"content":88625,"nodeType":860},{},[88626],{"data":88627,"marks":88628,"value":62278,"nodeType":864},{},[],{"data":88630,"content":88631,"nodeType":945},{},[88632],{"data":88633,"content":88634,"nodeType":860},{},[88635],{"data":88636,"marks":88637,"value":62288,"nodeType":864},{},[],{"data":88639,"content":88640,"nodeType":945},{},[88641],{"data":88642,"content":88643,"nodeType":860},{},[88644],{"data":88645,"marks":88646,"value":62298,"nodeType":864},{},[],{"data":88648,"content":88649,"nodeType":945},{},[88650],{"data":88651,"content":88652,"nodeType":860},{},[88653],{"data":88654,"marks":88655,"value":62308,"nodeType":864},{},[],{"data":88657,"content":88658,"nodeType":1005},{},[],{"data":88660,"content":88661,"nodeType":1009},{},[88662],{"data":88663,"marks":88664,"value":62319,"nodeType":864},{},[88665],{"type":899},{"data":88667,"content":88668,"nodeType":941},{},[88669,88678,88687,88696,88705,88714,88723,88732],{"data":88670,"content":88671,"nodeType":945},{},[88672],{"data":88673,"content":88674,"nodeType":860},{},[88675],{"data":88676,"marks":88677,"value":62332,"nodeType":864},{},[],{"data":88679,"content":88680,"nodeType":945},{},[88681],{"data":88682,"content":88683,"nodeType":860},{},[88684],{"data":88685,"marks":88686,"value":62342,"nodeType":864},{},[],{"data":88688,"content":88689,"nodeType":945},{},[88690],{"data":88691,"content":88692,"nodeType":860},{},[88693],{"data":88694,"marks":88695,"value":62352,"nodeType":864},{},[],{"data":88697,"content":88698,"nodeType":945},{},[88699],{"data":88700,"content":88701,"nodeType":860},{},[88702],{"data":88703,"marks":88704,"value":62362,"nodeType":864},{},[],{"data":88706,"content":88707,"nodeType":945},{},[88708],{"data":88709,"content":88710,"nodeType":860},{},[88711],{"data":88712,"marks":88713,"value":62372,"nodeType":864},{},[],{"data":88715,"content":88716,"nodeType":945},{},[88717],{"data":88718,"content":88719,"nodeType":860},{},[88720],{"data":88721,"marks":88722,"value":62382,"nodeType":864},{},[],{"data":88724,"content":88725,"nodeType":945},{},[88726],{"data":88727,"content":88728,"nodeType":860},{},[88729],{"data":88730,"marks":88731,"value":62392,"nodeType":864},{},[],{"data":88733,"content":88734,"nodeType":945},{},[88735],{"data":88736,"content":88737,"nodeType":860},{},[88738],{"data":88739,"marks":88740,"value":62402,"nodeType":864},{},[],{"data":88742,"content":88745,"nodeType":996},{"target":88743},{"sys":88744},{"id":62407,"type":1001,"linkType":1002},[],{"data":88747,"content":88748,"nodeType":1005},{},[],{"data":88750,"content":88751,"nodeType":1009},{},[88752],{"data":88753,"marks":88754,"value":62419,"nodeType":864},{},[88755],{"type":899},{"data":88757,"content":88758,"nodeType":1312},{},[88759],{"data":88760,"marks":88761,"value":62427,"nodeType":864},{},[88762],{"type":899},{"data":88764,"content":88765,"nodeType":860},{},[88766],{"data":88767,"marks":88768,"value":62434,"nodeType":864},{},[],{"data":88770,"content":88771,"nodeType":860},{},[88772],{"data":88773,"marks":88774,"value":62441,"nodeType":864},{},[],{"data":88776,"content":88777,"nodeType":1312},{},[88778],{"data":88779,"marks":88780,"value":62449,"nodeType":864},{},[88781],{"type":899},{"data":88783,"content":88784,"nodeType":860},{},[88785,88788,88795],{"data":88786,"marks":88787,"value":62456,"nodeType":864},{},[],{"data":88789,"content":88790,"nodeType":883},{"uri":11813},[88791],{"data":88792,"marks":88793,"value":29819,"nodeType":864},{},[88794],{"type":1455},{"data":88796,"marks":88797,"value":11546,"nodeType":864},{},[],{"data":88799,"content":88800,"nodeType":860},{},[88801],{"data":88802,"marks":88803,"value":62473,"nodeType":864},{},[],{"data":88805,"content":88806,"nodeType":1312},{},[88807],{"data":88808,"marks":88809,"value":62481,"nodeType":864},{},[88810],{"type":899},{"data":88812,"content":88813,"nodeType":860},{},[88814],{"data":88815,"marks":88816,"value":62488,"nodeType":864},{},[],{"data":88818,"content":88819,"nodeType":860},{},[88820],{"data":88821,"marks":88822,"value":62495,"nodeType":864},{},[],{"data":88824,"content":88825,"nodeType":1312},{},[88826],{"data":88827,"marks":88828,"value":62503,"nodeType":864},{},[88829],{"type":899},{"data":88831,"content":88832,"nodeType":860},{},[88833],{"data":88834,"marks":88835,"value":62510,"nodeType":864},{},[],{"data":88837,"content":88838,"nodeType":860},{},[88839],{"data":88840,"marks":88841,"value":62517,"nodeType":864},{},[],{"data":88843,"content":88844,"nodeType":860},{},[88845,88848,88855],{"data":88846,"marks":88847,"value":62524,"nodeType":864},{},[],{"data":88849,"content":88850,"nodeType":883},{"uri":62527},[88851],{"data":88852,"marks":88853,"value":62533,"nodeType":864},{},[88854],{"type":1455},{"data":88856,"marks":88857,"value":62537,"nodeType":864},{},[],{"data":88859,"content":88862,"nodeType":996},{"target":88860},{"sys":88861},{"id":62542,"type":1001,"linkType":1002},[],{"data":88864,"content":88865,"nodeType":1005},{},[],{"data":88867,"content":88868,"nodeType":1009},{},[88869],{"data":88870,"marks":88871,"value":62554,"nodeType":864},{},[88872],{"type":899},{"data":88874,"content":88875,"nodeType":1312},{},[88876],{"data":88877,"marks":88878,"value":62562,"nodeType":864},{},[88879],{"type":899},{"data":88881,"content":88882,"nodeType":860},{},[88883],{"data":88884,"marks":88885,"value":62569,"nodeType":864},{},[],{"data":88887,"content":88888,"nodeType":941},{},[88889,88908,88927,88956],{"data":88890,"content":88891,"nodeType":945},{},[88892],{"data":88893,"content":88894,"nodeType":860},{},[88895,88898,88905],{"data":88896,"marks":88897,"value":62582,"nodeType":864},{},[],{"data":88899,"content":88900,"nodeType":883},{"uri":62585},[88901],{"data":88902,"marks":88903,"value":62591,"nodeType":864},{},[88904],{"type":1455},{"data":88906,"marks":88907,"value":62595,"nodeType":864},{},[],{"data":88909,"content":88910,"nodeType":945},{},[88911],{"data":88912,"content":88913,"nodeType":860},{},[88914,88917,88924],{"data":88915,"marks":88916,"value":62605,"nodeType":864},{},[],{"data":88918,"content":88919,"nodeType":883},{"uri":25338},[88920],{"data":88921,"marks":88922,"value":62613,"nodeType":864},{},[88923],{"type":1455},{"data":88925,"marks":88926,"value":2924,"nodeType":864},{},[],{"data":88928,"content":88929,"nodeType":945},{},[88930],{"data":88931,"content":88932,"nodeType":860},{},[88933,88936,88943,88946,88953],{"data":88934,"marks":88935,"value":62626,"nodeType":864},{},[],{"data":88937,"content":88938,"nodeType":883},{"uri":11813},[88939],{"data":88940,"marks":88941,"value":62634,"nodeType":864},{},[88942],{"type":1455},{"data":88944,"marks":88945,"value":62638,"nodeType":864},{},[],{"data":88947,"content":88948,"nodeType":883},{"uri":62641},[88949],{"data":88950,"marks":88951,"value":62647,"nodeType":864},{},[88952],{"type":1455},{"data":88954,"marks":88955,"value":62651,"nodeType":864},{},[],{"data":88957,"content":88958,"nodeType":945},{},[88959],{"data":88960,"content":88961,"nodeType":860},{},[88962,88965,88972],{"data":88963,"marks":88964,"value":62661,"nodeType":864},{},[],{"data":88966,"content":88967,"nodeType":883},{"uri":25338},[88968],{"data":88969,"marks":88970,"value":62669,"nodeType":864},{},[88971],{"type":1455},{"data":88973,"marks":88974,"value":62673,"nodeType":864},{},[],{"data":88976,"content":88977,"nodeType":860},{},[88978],{"data":88979,"marks":88980,"value":62680,"nodeType":864},{},[],{"data":88982,"content":88983,"nodeType":1312},{},[88984],{"data":88985,"marks":88986,"value":62688,"nodeType":864},{},[88987],{"type":899},{"data":88989,"content":88990,"nodeType":860},{},[88991],{"data":88992,"marks":88993,"value":62695,"nodeType":864},{},[],{"data":88995,"content":88996,"nodeType":860},{},[88997],{"data":88998,"marks":88999,"value":62702,"nodeType":864},{},[],{"data":89001,"content":89004,"nodeType":996},{"target":89002},{"sys":89003},{"id":62707,"type":1001,"linkType":1002},[],{"data":89006,"content":89007,"nodeType":1312},{},[89008],{"data":89009,"marks":89010,"value":62716,"nodeType":864},{},[89011],{"type":899},{"data":89013,"content":89014,"nodeType":860},{},[89015],{"data":89016,"marks":89017,"value":62723,"nodeType":864},{},[],{"data":89019,"content":89020,"nodeType":860},{},[89021],{"data":89022,"marks":89023,"value":62730,"nodeType":864},{},[],{"data":89025,"content":89026,"nodeType":860},{},[89027],{"data":89028,"marks":89029,"value":62737,"nodeType":864},{},[],{"data":89031,"content":89032,"nodeType":1312},{},[89033],{"data":89034,"marks":89035,"value":62745,"nodeType":864},{},[89036],{"type":899},{"data":89038,"content":89039,"nodeType":860},{},[89040],{"data":89041,"marks":89042,"value":62752,"nodeType":864},{},[],{"data":89044,"content":89045,"nodeType":860},{},[89046],{"data":89047,"marks":89048,"value":62759,"nodeType":864},{},[],{"data":89050,"content":89051,"nodeType":860},{},[89052],{"data":89053,"marks":89054,"value":62766,"nodeType":864},{},[],{"data":89056,"content":89057,"nodeType":860},{},[89058],{"data":89059,"marks":89060,"value":62773,"nodeType":864},{},[],{"data":89062,"content":89065,"nodeType":996},{"target":89063},{"sys":89064},{"id":62778,"type":1001,"linkType":1002},[],{"data":89067,"content":89068,"nodeType":1005},{},[],{"data":89070,"content":89071,"nodeType":1009},{},[89072],{"data":89073,"marks":89074,"value":62790,"nodeType":864},{},[89075],{"type":899},{"data":89077,"content":89078,"nodeType":860},{},[89079],{"data":89080,"marks":89081,"value":62797,"nodeType":864},{},[],{"data":89083,"content":89084,"nodeType":941},{},[89085,89094,89103],{"data":89086,"content":89087,"nodeType":945},{},[89088],{"data":89089,"content":89090,"nodeType":860},{},[89091],{"data":89092,"marks":89093,"value":62810,"nodeType":864},{},[],{"data":89095,"content":89096,"nodeType":945},{},[89097],{"data":89098,"content":89099,"nodeType":860},{},[89100],{"data":89101,"marks":89102,"value":62820,"nodeType":864},{},[],{"data":89104,"content":89105,"nodeType":945},{},[89106],{"data":89107,"content":89108,"nodeType":860},{},[89109],{"data":89110,"marks":89111,"value":62830,"nodeType":864},{},[],{"data":89113,"content":89114,"nodeType":860},{},[89115],{"data":89116,"marks":89117,"value":62837,"nodeType":864},{},[],{"data":89119,"content":89120,"nodeType":860},{},[89121,89124,89130],{"data":89122,"marks":89123,"value":1238,"nodeType":864},{},[],{"data":89125,"content":89126,"nodeType":883},{"uri":62846},[89127],{"data":89128,"marks":89129,"value":62851,"nodeType":864},{},[],{"data":89131,"marks":89132,"value":62855,"nodeType":864},{},[],{"data":89134,"content":89135,"nodeType":860},{},[89136,89139,89146],{"data":89137,"marks":89138,"value":62862,"nodeType":864},{},[],{"data":89140,"content":89141,"nodeType":883},{"uri":62865},[89142],{"data":89143,"marks":89144,"value":62871,"nodeType":864},{},[89145],{"type":1455},{"data":89147,"marks":89148,"value":62875,"nodeType":864},{},[],{"data":89150,"content":89153,"nodeType":996},{"target":89151},{"sys":89152},{"id":62880,"type":1001,"linkType":1002},[],{"data":89155,"content":89156,"nodeType":860},{},[89157],{"data":89158,"marks":89159,"value":21,"nodeType":864},{},[],{"items":89161},[89162],{"sys":89163,"name":13779},{"id":13778},{"items":89165},[89166],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":89167},{"url":2740},{"__typename":2059,"sys":89169,"content":89171,"title":90337,"synopsis":90338,"hashTags":59,"publishedDate":90339,"slug":90340,"tagsCollection":90341,"authorsCollection":90347},{"id":89170},"5KqYY7p174lSpuinfTfEZU",{"json":89172},{"data":89173,"content":89174,"nodeType":856},{},[89175,89182,89237,89244,89247,89254,89261,89294,89306,89309,89316,89327,89334,89354,89360,89380,89387,89397,89418,89438,89445,89464,89470,89489,89492,89499,89506,89513,89533,89550,89557,89577,89584,89591,89616,89623,89642,89663,89669,89676,89695,89698,89705,89722,89741,89748,89801,89808,89811,89818,89825,89844,89864,89871,89878,89885,89904,89911,89918,89924,89930,89933,89940,89947,89954,89973,89983,90002,90009,90016,90026,90033,90040,90060,90066,90069,90076,90083,90090,90161,90168,90175,90182,90190,90211,90218,90224,90235,90256,90263,90271,90291,90298,90305,90311,90314,90321],{"data":89176,"content":89177,"nodeType":860},{},[89178],{"data":89179,"marks":89180,"value":89181,"nodeType":864},{},[],"From massive breaches like the Snowflake incident to novel phishing techniques documented by Push researchers, 2024 was the year that identity attacks left their mark. Looking back over what we saw in the wild and what we found through Push’s own research, three key themes stand out:",{"data":89183,"content":89184,"nodeType":941},{},[89185,89204,89214],{"data":89186,"content":89187,"nodeType":945},{},[89188],{"data":89189,"content":89190,"nodeType":860},{},[89191,89195,89200],{"data":89192,"marks":89193,"value":89194,"nodeType":864},{},[],"Account takeover techniques on cloud apps are fundamentally different from traditional network-based attacks. To have the best chance of preventing account takeover, defenders need to  disrupt attacks ",{"data":89196,"marks":89197,"value":89199,"nodeType":864},{},[89198],{"type":2246},"before",{"data":89201,"marks":89202,"value":89203,"nodeType":864},{},[]," they’re successful.",{"data":89205,"content":89206,"nodeType":945},{},[89207],{"data":89208,"content":89209,"nodeType":860},{},[89210],{"data":89211,"marks":89212,"value":89213,"nodeType":864},{},[],"It’s not easy or practical to maintain 100 percent compliance on identity posture standards in a world where employees are using and signing up to apps outside of IT oversight — but it is possible to make this work a lot easier by using tools that help you scale your remediation activities.",{"data":89215,"content":89216,"nodeType":945},{},[89217],{"data":89218,"content":89219,"nodeType":860},{},[89220,89224,89233],{"data":89221,"marks":89222,"value":89223,"nodeType":864},{},[],"Despite another year where cybersecurity spend increased (now up to almost $1,100 per user, according to ",{"data":89225,"content":89227,"nodeType":883},{"uri":89226},"https://www.forrester.com/report/2024-cybersecurity-benchmarks-global/RES181118",[89228],{"data":89229,"marks":89230,"value":89232,"nodeType":864},{},[89231],{"type":1455},"Forrester",{"data":89234,"marks":89235,"value":89236,"nodeType":864},{},[],"), existing approaches are not successfully preventing account takeovers. Security teams need to be able to detect and respond to these attacks where they happen: The browser.",{"data":89238,"content":89239,"nodeType":860},{},[89240],{"data":89241,"marks":89242,"value":89243,"nodeType":864},{},[],"In this article, we’ll take a look back at how these themes influenced key features we delivered for Push customers in 2024.",{"data":89245,"content":89246,"nodeType":1005},{},[],{"data":89248,"content":89249,"nodeType":1009},{},[89250],{"data":89251,"marks":89252,"value":89253,"nodeType":864},{},[],"Defending against modern phishing attacks",{"data":89255,"content":89256,"nodeType":860},{},[89257],{"data":89258,"marks":89259,"value":89260,"nodeType":864},{},[],"Phishing techniques that bypass MFA are now the norm, and few organizations have successfully achieved full coverage of phishing-resistant MFA methods. ",{"data":89262,"content":89263,"nodeType":860},{},[89264,89268,89277,89281,89290],{"data":89265,"marks":89266,"value":89267,"nodeType":864},{},[],"Equally, while phishing attacks via email remain the most commonly reported vector, phishing attacks increasingly target users outside of email. For example, phishing links are often encountered through normal internet use — such as ",{"data":89269,"content":89271,"nodeType":883},{"uri":89270},"https://www.bleepingcomputer.com/news/security/hackers-use-google-search-ads-to-steal-google-ads-accounts/",[89272],{"data":89273,"marks":89274,"value":89276,"nodeType":864},{},[89275],{"type":1455},"in malicious Google ads",{"data":89278,"marks":89279,"value":89280,"nodeType":864},{},[]," — and attackers frequently conduct their campaigns over IM platforms like Slack and Teams. Late last year there was ",{"data":89282,"content":89284,"nodeType":883},{"uri":89283},"https://www.linkedin.com/posts/kevin-beaumont-security_ive-been-assisting-a-few-orgs-hit-with-successful-activity-7268055739116445701-xxjZ?utm_source=share&utm_medium=member_desktop",[89285],{"data":89286,"marks":89287,"value":89289,"nodeType":864},{},[89288],{"type":1455},"a rise in attackers inundating users with spam via Teams",{"data":89291,"marks":89292,"value":89293,"nodeType":864},{},[],", combined with phone scams posing as IT admins. Since anti-phishing controls are usually email-based, they fail to protect users from attacks taking place elsewhere. ",{"data":89295,"content":89296,"nodeType":860},{},[89297,89301],{"data":89298,"marks":89299,"value":89300,"nodeType":864},{},[],"At Push, we’ve built a suite of anti-phishing features over the last year that act as a defense-in-depth approach to the types of modern phishing techniques we’ve been observing in the wild. ",{"data":89302,"marks":89303,"value":89305,"nodeType":864},{},[89304],{"type":899},"Here’s what we built and why.",{"data":89307,"content":89308,"nodeType":1005},{},[],{"data":89310,"content":89311,"nodeType":1009},{},[89312],{"data":89313,"marks":89314,"value":89315,"nodeType":864},{},[],"Protecting passwords used for SSO",{"data":89317,"content":89318,"nodeType":1312},{},[89319,89324],{"data":89320,"marks":89321,"value":89323,"nodeType":864},{},[89322],{"type":899},"What happened?",{"data":89325,"marks":89326,"value":1171,"nodeType":864},{},[],{"data":89328,"content":89329,"nodeType":860},{},[89330],{"data":89331,"marks":89332,"value":89333,"nodeType":864},{},[],"Attackers explicitly targeted Okta, Entra, and Google Workspace accounts in 2023 and 2024, so we knew a top priority would be protecting identity provider accounts. These IdP accounts are a key target because they allow attackers to move laterally to other valuable apps and data via SSO following the initial account takeover.",{"data":89335,"content":89336,"nodeType":860},{},[89337,89341,89350],{"data":89338,"marks":89339,"value":89340,"nodeType":864},{},[],"It’s not just the typical IdPs you need to watch out for, either: Apps like GitHub, Slack, Salesforce, Facebook, X, and others all provide SSO functionality, increasing the blast radius of a compromise. And as we reported in ",{"data":89342,"content":89344,"nodeType":883},{"uri":89343},"https://pushsecurity.com/blog/cross-idp-impersonation/",[89345],{"data":89346,"marks":89347,"value":89349,"nodeType":864},{},[89348],{"type":1455},"our research on cross-IdP impersonation",{"data":89351,"marks":89352,"value":89353,"nodeType":864},{},[],", apps can be accessed using multiple SSO methods simultaneously — and 3 in 5 apps that we tested recently did not require re-verification by default when adding a new login method.",{"data":89355,"content":89359,"nodeType":996},{"target":89356},{"sys":89357},{"id":89358,"type":1001,"linkType":1002},"3EOOr4dVQoiPjl2ucUs1mA",[],{"data":89361,"content":89362,"nodeType":860},{},[89363,89367,89376],{"data":89364,"marks":89365,"value":89366,"nodeType":864},{},[],"Phishing is a problem that would be significantly reduced in a world without passwords. But while the ideal case is that organizations can put in place phishing-resistant authentication methods like passkeys or other WebAuthn-based methods, the reality is that ",{"data":89368,"content":89370,"nodeType":883},{"uri":89369},"https://www.ncsc.gov.uk/blog-post/passkeys-not-perfect-getting-better",[89371],{"data":89372,"marks":89373,"value":89375,"nodeType":864},{},[89374],{"type":1455},"it’s not a perfect solution right now",{"data":89377,"marks":89378,"value":89379,"nodeType":864},{},[]," — widespread passkey implementation is hard to achieve.",{"data":89381,"content":89382,"nodeType":860},{},[89383],{"data":89384,"marks":89385,"value":89386,"nodeType":864},{},[],"One of the key advantages of passkeys is that they are domain-bound: Meaning they can’t be used on a site with the wrong domain. So, we started thinking: What if it were possible to essentially domain-bind a password? ",{"data":89388,"content":89389,"nodeType":1312},{},[89390,89394],{"data":89391,"marks":89392,"value":67177,"nodeType":864},{},[89393],{"type":899},{"data":89395,"marks":89396,"value":1171,"nodeType":864},{},[],{"data":89398,"content":89399,"nodeType":860},{},[89400,89404,89414],{"data":89401,"marks":89402,"value":89403,"nodeType":864},{},[],"In the first half of 2024, we delivered our ",{"data":89405,"content":89407,"nodeType":883},{"uri":89406},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[89408],{"data":89409,"marks":89410,"value":89413,"nodeType":864},{},[89411,89412],{"type":1455},{"type":899},"SSO password protection",{"data":89415,"marks":89416,"value":89417,"nodeType":864},{},[]," feature, which allows Push administrators to block employees from entering their IdP password into any site that’s not the identity provider — in effect domain-binding SSO credentials. ",{"data":89419,"content":89420,"nodeType":860},{},[89421,89425,89434],{"data":89422,"marks":89423,"value":89424,"nodeType":864},{},[],"Push accomplishes this via the Push browser agent, which ",{"data":89426,"content":89428,"nodeType":883},{"uri":89427},"https://pushsecurity.com/help/10109/#how-does-sso-password-protection-work",[89429],{"data":89430,"marks":89431,"value":89433,"nodeType":864},{},[89432],{"type":1455},"observes and fingerprints",{"data":89435,"marks":89436,"value":89437,"nodeType":864},{},[]," the user’s SSO password and legitimate SSO login pages, and then enforces in-browser controls to prevent an SSO password from being submitted on any URL that doesn’t match the legitimate provider, an extremely strong anti-phishing protection. Separately, Push also verifies that passwords it observes are not easily guessable.",{"data":89439,"content":89440,"nodeType":860},{},[89441],{"data":89442,"marks":89443,"value":89444,"nodeType":864},{},[],"The idea behind this approach is to gain some similar benefits to passkeys — by ensuring that passwords used for SSO access to your apps cannot be phished and are unique and strong — but in a way that “just works” with existing password-based authentication. ",{"data":89446,"content":89447,"nodeType":860},{},[89448,89452,89460],{"data":89449,"marks":89450,"value":89451,"nodeType":864},{},[],"Organizations that monitor for SSO password reuse will find that the practice turns out to be incredibly widespread, so being able to detect and prevent password reuse — even outside of actual phishing attempts — is an asset to security teams. (Our ",{"data":89453,"content":89454,"nodeType":883},{"uri":25338},[89455],{"data":89456,"marks":89457,"value":89459,"nodeType":864},{},[89458],{"type":1455},"research shows",{"data":89461,"marks":89462,"value":89463,"nodeType":864},{},[]," that 10% of IdP accounts are using a password that is shared with another app — where it is much more likely to be compromised.) ",{"data":89465,"content":89469,"nodeType":996},{"target":89466},{"sys":89467},{"id":89468,"type":1001,"linkType":1002},"4Ce999wf4mqCZwu1jLofsx",[],{"data":89471,"content":89472,"nodeType":860},{},[89473,89477,89485],{"data":89474,"marks":89475,"value":89476,"nodeType":864},{},[],"By streaming events to your SIEM and setting up a simple automation, you can also use Push-supplied intelligence on SSO password reuse to ",{"data":89478,"content":89479,"nodeType":883},{"uri":88389},[89480],{"data":89481,"marks":89482,"value":89484,"nodeType":864},{},[89483],{"type":1455},"automatically reset",{"data":89486,"marks":89487,"value":89488,"nodeType":864},{},[]," potentially compromised passwords — this provides instant response to successful phishing and gets rid of password re-use of your most sensitive credentials in one move - the kind of combo we love!",{"data":89490,"content":89491,"nodeType":1005},{},[],{"data":89493,"content":89494,"nodeType":1009},{},[89495],{"data":89496,"marks":89497,"value":89498,"nodeType":864},{},[],"Blocking AitM phishing and cloned login pages",{"data":89500,"content":89501,"nodeType":1312},{},[89502],{"data":89503,"marks":89504,"value":89323,"nodeType":864},{},[89505],{"type":899},{"data":89507,"content":89508,"nodeType":860},{},[89509],{"data":89510,"marks":89511,"value":89512,"nodeType":864},{},[],"When you’re able to detect SSO passwords being used in all the wrong places, it’s not surprising that one of the main offenders is phishing attacks. ",{"data":89514,"content":89515,"nodeType":860},{},[89516,89520,89529],{"data":89517,"marks":89518,"value":89519,"nodeType":864},{},[],"In 2024, we wrote extensively about the rise in ",{"data":89521,"content":89523,"nodeType":883},{"uri":89522},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[89524],{"data":89525,"marks":89526,"value":89528,"nodeType":864},{},[89527],{"type":1455},"modern phishing attacks",{"data":89530,"marks":89531,"value":89532,"nodeType":864},{},[]," that use adversary-in-the middle toolkits (AiTM), including EvilNoVNC, Evilginx, and others.",{"data":89534,"content":89535,"nodeType":860},{},[89536,89540,89547],{"data":89537,"marks":89538,"value":89539,"nodeType":864},{},[],"AiTM phishing is a newer variant of phishing that allows attackers to bypass MFA protection by using tools that act as a proxy between the end-user and a legitimate login portal. AitM attacks increased 146% in 2023 (",{"data":89541,"content":89542,"nodeType":883},{"uri":88285},[89543],{"data":89544,"marks":89545,"value":19538,"nodeType":864},{},[89546],{"type":1455},{"data":89548,"marks":89549,"value":49943,"nodeType":864},{},[],{"data":89551,"content":89552,"nodeType":860},{},[89553],{"data":89554,"marks":89555,"value":89556,"nodeType":864},{},[],"This trend in tradecraft was reflected in our own customer base last year, but what’s interesting is that we observed a lot of phish kits and tactics that were new — meaning traditional detections failed to find them before Push did. ",{"data":89558,"content":89559,"nodeType":860},{},[89560,89564,89573],{"data":89561,"marks":89562,"value":89563,"nodeType":864},{},[],"In particular, we saw newer ",{"data":89565,"content":89567,"nodeType":883},{"uri":89566},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/",[89568],{"data":89569,"marks":89570,"value":89572,"nodeType":864},{},[89571],{"type":1455},"web-based obfuscation techniques",{"data":89574,"marks":89575,"value":89576,"nodeType":864},{},[]," that allowed attackers to get past the features of email security tools like web gateways and email scanning appliances, such as bypassing web sandbox analysis, and deter other forms of automated investigation by using Cloudflare Turnstile and other tactics — similar to the approaches legit websites use to protect against automated bots (this is essentially the same problem for both).",{"data":89578,"content":89579,"nodeType":860},{},[89580],{"data":89581,"marks":89582,"value":89583,"nodeType":864},{},[],"The gap in existing controls was obvious: When all phishing routes eventually lead to the browser, security teams need to be able to detect and respond in the browser. To do this well they need to observe what the employee sees, not what loads in a sandbox.",{"data":89585,"content":89586,"nodeType":1312},{},[89587],{"data":89588,"marks":89589,"value":67177,"nodeType":864},{},[89590],{"type":899},{"data":89592,"content":89593,"nodeType":860},{},[89594,89598,89608,89613],{"data":89595,"marks":89596,"value":89597,"nodeType":864},{},[],"To address this gap, we released new capabilities for the Push browser agent to be able to ",{"data":89599,"content":89601,"nodeType":883},{"uri":89600},"https://pushsecurity.com/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser/",[89602],{"data":89603,"marks":89604,"value":89607,"nodeType":864},{},[89605,89606],{"type":1455},{"type":899},"detect and block",{"data":89609,"marks":89610,"value":89612,"nodeType":864},{},[89611],{"type":899}," when a site is running AiTM phishing toolkits",{"data":89614,"marks":89615,"value":11546,"nodeType":864},{},[],{"data":89617,"content":89618,"nodeType":860},{},[89619],{"data":89620,"marks":89621,"value":89622,"nodeType":864},{},[],"Push does this via a set of readymade detections for common AiTM tools. By dynamically analyzing the behavior of malware in the browser, the Push browser agent can find indicators of compromise beyond just domains, file names, IP addresses, etc., focusing instead on behavioral attributes, such as Javascript calls being made or data structures saved to local storage.",{"data":89624,"content":89625,"nodeType":860},{},[89626,89630,89638],{"data":89627,"marks":89628,"value":89629,"nodeType":864},{},[],"This approach of focusing on the top of the ",{"data":89631,"content":89633,"nodeType":883},{"uri":89632},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/#id-building-effective-identity-threat-detection-controls_id-scenario-detecting-a-web-based-phishing-attack",[89634],{"data":89635,"marks":89636,"value":40075,"nodeType":864},{},[89637],{"type":1455},{"data":89639,"marks":89640,"value":89641,"nodeType":864},{},[]," — e.g. building detections for attributes of an attack that are the hardest for attackers to change, and therefore the most reliably accurate — is core to Push’s design philosophy. ",{"data":89643,"content":89644,"nodeType":860},{},[89645,89649,89659],{"data":89646,"marks":89647,"value":89648,"nodeType":864},{},[],"Finally, toward the second half of the year, we released ",{"data":89650,"content":89652,"nodeType":883},{"uri":89651},"https://pushsecurity.com/blog/introducing-cloned-login-page-detection/",[89653],{"data":89654,"marks":89655,"value":89658,"nodeType":864},{},[89656,89657],{"type":1455},{"type":899},"cloned login page detection",{"data":89660,"marks":89661,"value":89662,"nodeType":864},{},[],", a natural extension of our layered approach to preventing phishing attacks in the browser. With this security control, you can identify malicious webpages that are masquerading as legitimate IdP login portals. ",{"data":89664,"content":89668,"nodeType":996},{"target":89665},{"sys":89666},{"id":89667,"type":1001,"linkType":1002},"4y25OxesssUk9lzEx12HFa",[],{"data":89670,"content":89671,"nodeType":860},{},[89672],{"data":89673,"marks":89674,"value":89675,"nodeType":864},{},[],"When a cloned login page is detected, you can add the URL to your blocklist in Push and prevent any other employees from being targeted. ",{"data":89677,"content":89678,"nodeType":860},{},[89679,89683,89691],{"data":89680,"marks":89681,"value":89682,"nodeType":864},{},[],"By layering multiple anti-phishing controls that all prevent account takeover, defenders have the best chance at thwarting the ",{"data":89684,"content":89685,"nodeType":883},{"uri":82444},[89686],{"data":89687,"marks":89688,"value":89690,"nodeType":864},{},[89689],{"type":1455},"short, fast attack chains",{"data":89692,"marks":89693,"value":89694,"nodeType":864},{},[]," that are emblematic of today’s identity attacks.",{"data":89696,"content":89697,"nodeType":1005},{},[],{"data":89699,"content":89700,"nodeType":1009},{},[89701],{"data":89702,"marks":89703,"value":89704,"nodeType":864},{},[],"Defending against stolen sessions and stolen credentials",{"data":89706,"content":89707,"nodeType":860},{},[89708,89712,89719],{"data":89709,"marks":89710,"value":89711,"nodeType":864},{},[],"With as little as $10 to buy a stolen password and a little skill, attackers capitalized on the use of stolen credentials last year. Stolen creds were the No. 1 attacker action in 2023 and 2024, according to ",{"data":89713,"content":89714,"nodeType":883},{"uri":4408},[89715],{"data":89716,"marks":89717,"value":57796,"nodeType":864},{},[89718],{"type":1455},{"data":89720,"marks":89721,"value":2924,"nodeType":864},{},[],{"data":89723,"content":89724,"nodeType":860},{},[89725,89729,89737],{"data":89726,"marks":89727,"value":89728,"nodeType":864},{},[],"Nowhere was this more plain than in the ",{"data":89730,"content":89731,"nodeType":883},{"uri":3751},[89732],{"data":89733,"marks":89734,"value":89736,"nodeType":864},{},[89735],{"type":1455},"attacks on Snowflake customers",{"data":89738,"marks":89739,"value":89740,"nodeType":864},{},[],", one of the biggest breaches of last year. In this incident, cyber criminals targeted around 165 customers of the cloud-based data warehouse tool Snowflake by taking over accounts using credentials harvested from infostealer infections dating as far back as 2020.",{"data":89742,"content":89743,"nodeType":860},{},[89744],{"data":89745,"marks":89746,"value":89747,"nodeType":864},{},[],"The Snowflake incident underscored the challenges of control and visibility that security teams face when attempting to secure identities on a patchwork of managed and unmanaged apps:",{"data":89749,"content":89750,"nodeType":941},{},[89751,89761,89771,89781,89791],{"data":89752,"content":89753,"nodeType":945},{},[89754],{"data":89755,"content":89756,"nodeType":860},{},[89757],{"data":89758,"marks":89759,"value":89760,"nodeType":864},{},[],"Do I know all the workforce accounts my employees use?",{"data":89762,"content":89763,"nodeType":945},{},[89764],{"data":89765,"content":89766,"nodeType":860},{},[89767],{"data":89768,"marks":89769,"value":89770,"nodeType":864},{},[],"Do those accounts have a strong security posture?",{"data":89772,"content":89773,"nodeType":945},{},[89774],{"data":89775,"content":89776,"nodeType":860},{},[89777],{"data":89778,"marks":89779,"value":89780,"nodeType":864},{},[],"Do those accounts use MFA? The most phishing-resistant methods?",{"data":89782,"content":89783,"nodeType":945},{},[89784],{"data":89785,"content":89786,"nodeType":860},{},[89787],{"data":89788,"marks":89789,"value":89790,"nodeType":864},{},[],"Do I have tools to detect, respond, and remediate after an account takeover or breach of a critical software vendor?",{"data":89792,"content":89793,"nodeType":945},{},[89794],{"data":89795,"content":89796,"nodeType":860},{},[89797],{"data":89798,"marks":89799,"value":89800,"nodeType":864},{},[],"Do I know when a session has been stolen, pointing to a device compromised by infostealer malware?",{"data":89802,"content":89803,"nodeType":860},{},[89804],{"data":89805,"marks":89806,"value":89807,"nodeType":864},{},[],"Here’s what we delivered last year to make it easier for security teams to protect their organizations from the threat of stolen sessions and stolen creds.",{"data":89809,"content":89810,"nodeType":1005},{},[],{"data":89812,"content":89813,"nodeType":1009},{},[89814],{"data":89815,"marks":89816,"value":89817,"nodeType":864},{},[],"Detecting stolen sessions",{"data":89819,"content":89820,"nodeType":1312},{},[89821],{"data":89822,"marks":89823,"value":89323,"nodeType":864},{},[89824],{"type":899},{"data":89826,"content":89827,"nodeType":860},{},[89828,89831,89840],{"data":89829,"marks":89830,"value":21,"nodeType":864},{},[],{"data":89832,"content":89834,"nodeType":883},{"uri":89833},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/",[89835],{"data":89836,"marks":89837,"value":89839,"nodeType":864},{},[89838],{"type":1455},"Infostealer malware",{"data":89841,"marks":89842,"value":89843,"nodeType":864},{},[]," — a type of malware designed to collect user credentials, including session cookies, from end-user devices — had a very successful 2024, accounting for nearly 10 percent of activity that Red Canary was able to associate with named threats, and the majority of all detected malware that Sophos threat researchers documented last year.",{"data":89845,"content":89846,"nodeType":860},{},[89847,89851,89860],{"data":89848,"marks":89849,"value":89850,"nodeType":864},{},[],"While the use of stolen credentials is rampant, often facilitated by successful infostealer campaigns, a related attack type also ",{"data":89852,"content":89854,"nodeType":883},{"uri":89853},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/#id-the-state-of-infostealers-today",[89855],{"data":89856,"marks":89857,"value":89859,"nodeType":864},{},[89858],{"type":1455},"jumped in prevalence",{"data":89861,"marks":89862,"value":89863,"nodeType":864},{},[]," last year: session token theft attacks.",{"data":89865,"content":89866,"nodeType":860},{},[89867],{"data":89868,"marks":89869,"value":89870,"nodeType":864},{},[],"Using stolen tokens, adversaries don’t need to bypass MFA directly. They can simply import the tokens into their browser and assume an already authorized session. ",{"data":89872,"content":89873,"nodeType":1312},{},[89874],{"data":89875,"marks":89876,"value":67177,"nodeType":864},{},[89877],{"type":899},{"data":89879,"content":89880,"nodeType":860},{},[89881],{"data":89882,"marks":89883,"value":89884,"nodeType":864},{},[],"In order to detect a stolen session in use, you need telemetry that allows you to tie activity to a trusted endpoint. This didn’t previously exist, and you have to be in the browser to do it. So that’s what we built. ",{"data":89886,"content":89887,"nodeType":860},{},[89888,89891,89900],{"data":89889,"marks":89890,"value":1238,"nodeType":864},{},[],{"data":89892,"content":89893,"nodeType":883},{"uri":62865},[89894],{"data":89895,"marks":89896,"value":89899,"nodeType":864},{},[89897,89898],{"type":1455},{"type":899},"session theft detection",{"data":89901,"marks":89902,"value":89903,"nodeType":864},{},[]," capability uses the power of the Push browser extension to inject a unique marker into the user-agent string of sessions that occur in browsers enrolled in Push. ",{"data":89905,"content":89906,"nodeType":860},{},[89907],{"data":89908,"marks":89909,"value":89910,"nodeType":864},{},[],"By analyzing logs from your IdP in your SIEM, you can then identify activity from the same session that both has and that lacks the Push marker, indicating that a session has been extracted from the browser and maliciously imported into a different browser that is not enrolled in Push.",{"data":89912,"content":89913,"nodeType":860},{},[89914],{"data":89915,"marks":89916,"value":89917,"nodeType":864},{},[],"This is a reliable signal that a stolen session token is being used and an endpoint has been compromised.",{"data":89919,"content":89923,"nodeType":996},{"target":89920},{"sys":89921},{"id":89922,"type":1001,"linkType":1002},"1XNNkaoW64t3PPvC54KGXF",[],{"data":89925,"content":89929,"nodeType":996},{"target":89926},{"sys":89927},{"id":89928,"type":1001,"linkType":1002},"6dOEnPzZXd9DqeSdalqlzO",[],{"data":89931,"content":89932,"nodeType":1005},{},[],{"data":89934,"content":89935,"nodeType":1009},{},[89936],{"data":89937,"marks":89938,"value":89939,"nodeType":864},{},[],"Detecting compromised credentials",{"data":89941,"content":89942,"nodeType":1312},{},[89943],{"data":89944,"marks":89945,"value":89323,"nodeType":864},{},[89946],{"type":899},{"data":89948,"content":89949,"nodeType":860},{},[89950],{"data":89951,"marks":89952,"value":89953,"nodeType":864},{},[],"Alongside stolen session cookies, stolen credentials made a lot of headlines last year. The 2024 Verizon DBIR found that 79% of web application compromises were the result of breached creds, and researchers at IBM found a 71% year-over-year increase in cyberattacks using stolen or compromised credentials.",{"data":89955,"content":89956,"nodeType":860},{},[89957,89961,89969],{"data":89958,"marks":89959,"value":89960,"nodeType":864},{},[],"In Push’s own research, we counted ",{"data":89962,"content":89963,"nodeType":883},{"uri":87801},[89964],{"data":89965,"marks":89966,"value":89968,"nodeType":864},{},[89967],{"type":1455},"30 public identity-related breaches",{"data":89970,"marks":89971,"value":89972,"nodeType":864},{},[]," in 2024 where the breach and the breach vector were disclosed. Of those, nearly three-quarters were the result of compromised credentials, including notable breaches such as Microsoft, Change Healthcare, and the attacks on Snowflake customers.",{"data":89974,"content":89975,"nodeType":1116},{},[89976],{"data":89977,"content":89978,"nodeType":860},{},[89979],{"data":89980,"marks":89981,"value":89982,"nodeType":864},{},[],"73% of public identity-related breaches in 2024 were the result of compromised credentials (the rest were phishing attacks). ",{"data":89984,"content":89985,"nodeType":860},{},[89986,89990,89998],{"data":89987,"marks":89988,"value":89989,"nodeType":864},{},[],"The influx of compromised credentials has been amplified by the ",{"data":89991,"content":89992,"nodeType":883},{"uri":89833},[89993],{"data":89994,"marks":89995,"value":89997,"nodeType":864},{},[89996],{"type":1455},"rise of infostealers",{"data":89999,"marks":90000,"value":90001,"nodeType":864},{},[],", which contribute the vast majority of valid stolen credentials, alongside mass credential phishing campaigns and third-party data breach dumps. ",{"data":90003,"content":90004,"nodeType":860},{},[90005],{"data":90006,"marks":90007,"value":90008,"nodeType":864},{},[],"And while there’s no shortage of threat intelligence about stolen credentials for sale on the web, security teams struggle to separate the needle from the haystack because a large portion of TI on stolen creds is out of date.",{"data":90010,"content":90011,"nodeType":860},{},[90012],{"data":90013,"marks":90014,"value":90015,"nodeType":864},{},[],"In evaluating TI data here at Push, we reviewed 5,763 username and password combos that matched domains in use by Push customers. We found that less than 1% of the creds in a multi-vendor dataset were true positives. In other words, 99.5% of the stolen creds we checked were false positives at the time of review — illustrating the challenge security teams face when trying to extract actionable intelligence from this kind of data. ",{"data":90017,"content":90018,"nodeType":1116},{},[90019],{"data":90020,"content":90021,"nodeType":860},{},[90022],{"data":90023,"marks":90024,"value":90025,"nodeType":864},{},[],"99.5% of the findings in compromised credential feeds were found to be false positives.",{"data":90027,"content":90028,"nodeType":1312},{},[90029],{"data":90030,"marks":90031,"value":67177,"nodeType":864},{},[90032],{"type":899},{"data":90034,"content":90035,"nodeType":860},{},[90036],{"data":90037,"marks":90038,"value":90039,"nodeType":864},{},[],"Using its browser agent, Push assesses the strength of end-user passwords by creating and analyzing a truncated, salted SHA256 hash of the password for a given account. (These k-anonymized fingerprints are never seen by Push’s back-end and exist only in local browser extension storage.) ",{"data":90041,"content":90042,"nodeType":860},{},[90043,90047,90056],{"data":90044,"marks":90045,"value":90046,"nodeType":864},{},[],"These fingerprints give Push a directly observable source of truth for corporate creds, which allowed us to build a ",{"data":90048,"content":90049,"nodeType":883},{"uri":77770},[90050],{"data":90051,"marks":90052,"value":90055,"nodeType":864},{},[90053,90054],{"type":1455},{"type":899},"verified stolen credential detection",{"data":90057,"marks":90058,"value":90059,"nodeType":864},{},[]," capability last year that removes all false positives from TI sources to pinpoint only those stolen creds still actively in use by employees.",{"data":90061,"content":90065,"nodeType":996},{"target":90062},{"sys":90063},{"id":90064,"type":1001,"linkType":1002},"3BITHZvDadjHpOAqIn0g4w",[],{"data":90067,"content":90068,"nodeType":1005},{},[],{"data":90070,"content":90071,"nodeType":1009},{},[90072],{"data":90073,"marks":90074,"value":90075,"nodeType":864},{},[],"Reducing and securing shadow IT and account sprawl",{"data":90077,"content":90078,"nodeType":860},{},[90079],{"data":90080,"marks":90081,"value":90082,"nodeType":864},{},[],"You can think of this last part of the story as the ground from which the attack trends we’ve been talking about emerged: The shift to doing business almost entirely in the browser, and the resulting sprawl in accounts and unmanaged apps, leading to an explosion of internet-facing identities for threat actors to target.",{"data":90084,"content":90085,"nodeType":860},{},[90086],{"data":90087,"marks":90088,"value":90089,"nodeType":864},{},[],"Even in organizations with mature security practices, the challenge of getting 100% compliance with identity posture best practices is evident. Last year, Push researchers analyzed a data set of 300,000 accounts from our customer base and found that:",{"data":90091,"content":90092,"nodeType":941},{},[90093,90112,90131],{"data":90094,"content":90095,"nodeType":945},{},[90096],{"data":90097,"content":90098,"nodeType":860},{},[90099,90103,90108],{"data":90100,"marks":90101,"value":90102,"nodeType":864},{},[],"Organizations have ",{"data":90104,"marks":90105,"value":90107,"nodeType":864},{},[90106],{"type":899},"more apps and identities than they thought",{"data":90109,"marks":90110,"value":90111,"nodeType":864},{},[]," — an average of ~15 identities per employee and ~220 apps per organization.",{"data":90113,"content":90114,"nodeType":945},{},[90115],{"data":90116,"content":90117,"nodeType":860},{},[90118,90122,90127],{"data":90119,"marks":90120,"value":90121,"nodeType":864},{},[],"Many accounts ",{"data":90123,"marks":90124,"value":90126,"nodeType":864},{},[90125],{"type":899},"lack basic security protections",{"data":90128,"marks":90129,"value":90130,"nodeType":864},{},[],", with 37% of accounts lacking any form of MFA and ~9% of accounts using a password that is leaked, weak, or reused, making them especially susceptible to account takeover. On accounts where password is the only login method in use (e.g. not using SSO or any other federated login like OIDC), there was no MFA in use in 4 out of 5 cases.",{"data":90132,"content":90133,"nodeType":945},{},[90134],{"data":90135,"content":90136,"nodeType":860},{},[90137,90141,90146,90150,90157],{"data":90138,"marks":90139,"value":90140,"nodeType":864},{},[],"Security ",{"data":90142,"marks":90143,"value":90145,"nodeType":864},{},[90144],{"type":899},"gaps persist even with SSO",{"data":90147,"marks":90148,"value":90149,"nodeType":864},{},[]," accounts — with 10% of SSO-using accounts also having a local password, a risk for ",{"data":90151,"content":90152,"nodeType":883},{"uri":11813},[90153],{"data":90154,"marks":90155,"value":29819,"nodeType":864},{},[90156],{"type":1455},{"data":90158,"marks":90159,"value":90160,"nodeType":864},{},[],"; and 1 in 5 IdP accounts themselves missing MFA.",{"data":90162,"content":90163,"nodeType":860},{},[90164],{"data":90165,"marks":90166,"value":90167,"nodeType":864},{},[],"From our perspective, organizations need scalable controls, and they need easy-to-deploy tools that get them visibility of all their workforce identities, apps, and accounts alongside telemetry that makes the information actionable.",{"data":90169,"content":90170,"nodeType":860},{},[90171],{"data":90172,"marks":90173,"value":90174,"nodeType":864},{},[],"Push already provides a real-time inventory of all your accounts and apps, including internal corporate apps, and analyzes the security posture, login methods, and MFA status of those accounts to offer a comprehensive picture of your identity attack surface. ",{"data":90176,"content":90177,"nodeType":860},{},[90178],{"data":90179,"marks":90180,"value":90181,"nodeType":864},{},[],"To help customers enforce their security policies even more seamlessly, here’s what we built last year:",{"data":90183,"content":90184,"nodeType":1312},{},[90185],{"data":90186,"marks":90187,"value":90189,"nodeType":864},{},[90188],{"type":899},"1. App banners",{"data":90191,"content":90192,"nodeType":860},{},[90193,90197,90207],{"data":90194,"marks":90195,"value":90196,"nodeType":864},{},[],"With a range of modes from informing to blocking, ",{"data":90198,"content":90200,"nodeType":883},{"uri":90199},"https://pushsecurity.com/help/10106#start",[90201],{"data":90202,"marks":90203,"value":90206,"nodeType":864},{},[90204,90205],{"type":1455},{"type":899},"app banners",{"data":90208,"marks":90209,"value":90210,"nodeType":864},{},[]," allow security teams to communicate best practices and policies with end-users directly in their browser. It works by displaying a banner with your custom message on the login and signup pages for workplace apps. ",{"data":90212,"content":90213,"nodeType":860},{},[90214],{"data":90215,"marks":90216,"value":90217,"nodeType":864},{},[],"Using configuration rules, you can set conditions for how banner controls get applied. Common use cases include: Restricting use of GenAI software; carving out an exception for admins on a specific app; reminding users to log in with SSO instead of a password, and others. ",{"data":90219,"content":90223,"nodeType":996},{"target":90220},{"sys":90221},{"id":90222,"type":1001,"linkType":1002},"4RPHmeMLyZmb5V8rXYLtey",[],{"data":90225,"content":90226,"nodeType":1312},{},[90227,90232],{"data":90228,"marks":90229,"value":90231,"nodeType":864},{},[90230],{"type":899},"2. Password manager identification",{"data":90233,"marks":90234,"value":1171,"nodeType":864},{},[],{"data":90236,"content":90237,"nodeType":860},{},[90238,90242,90252],{"data":90239,"marks":90240,"value":90241,"nodeType":864},{},[],"We also expanded Push’s capability to observe employees’ account security posture by adding an identification of ",{"data":90243,"content":90245,"nodeType":883},{"uri":90244},"https://pushsecurity.com/blog/stop-users-saving-corp-creds-into-personal-password-managers/",[90246],{"data":90247,"marks":90248,"value":90251,"nodeType":864},{},[90249,90250],{"type":1455},{"type":899},"which password manager",{"data":90253,"marks":90254,"value":90255,"nodeType":864},{},[]," (if any) they’re using. ",{"data":90257,"content":90258,"nodeType":860},{},[90259],{"data":90260,"marks":90261,"value":90262,"nodeType":864},{},[],"We’ve heard from many security teams that they’re concerned about corporate credentials being stored in unapproved password managers — not to mention the ROI from ensuring employees are all using the corporate password manager you already pay for. This feature helps them achieve both objectives.",{"data":90264,"content":90265,"nodeType":1312},{},[90266],{"data":90267,"marks":90268,"value":90270,"nodeType":864},{},[90269],{"type":899},"3. MFA enforcement",{"data":90272,"content":90273,"nodeType":860},{},[90274,90278,90287],{"data":90275,"marks":90276,"value":90277,"nodeType":864},{},[],"Finally, we rounded out 2024 with a new security control called ",{"data":90279,"content":90281,"nodeType":883},{"uri":90280},"https://pushsecurity.com/blog/enforce-mfa-on-third-party-apps/",[90282],{"data":90283,"marks":90284,"value":53104,"nodeType":864},{},[90285,90286],{"type":1455},{"type":899},{"data":90288,"marks":90289,"value":90290,"nodeType":864},{},[]," that builds on the popular app banners concept by detecting when users lack MFA and then prompting them to register for MFA. ",{"data":90292,"content":90293,"nodeType":860},{},[90294],{"data":90295,"marks":90296,"value":90297,"nodeType":864},{},[],"Admins choose which apps they wish to enforce MFA on, and the Push extension does the rest. ",{"data":90299,"content":90300,"nodeType":860},{},[90301],{"data":90302,"marks":90303,"value":90304,"nodeType":864},{},[],"Security teams we work with are especially eager to use this feature to close MFA coverage gaps on non-SSO and otherwise unmanaged applications.",{"data":90306,"content":90310,"nodeType":996},{"target":90307},{"sys":90308},{"id":90309,"type":1001,"linkType":1002},"4imhff7SWJi2Gan5iFEs2P",[],{"data":90312,"content":90313,"nodeType":1005},{},[],{"data":90315,"content":90316,"nodeType":1009},{},[90317],{"data":90318,"marks":90319,"value":90320,"nodeType":864},{},[],"Want to see more?",{"data":90322,"content":90323,"nodeType":860},{},[90324,90328,90334],{"data":90325,"marks":90326,"value":90327,"nodeType":864},{},[],"There’s a lot we didn’t touch on here that Push can help you achieve. If you’d like to learn more, ",{"data":90329,"content":90330,"nodeType":883},{"uri":14401},[90331],{"data":90332,"marks":90333,"value":87781,"nodeType":864},{},[],{"data":90335,"marks":90336,"value":87785,"nodeType":864},{},[],"How real-world attacks and research drove Push’s most popular features of 2024","How in-the-wild attacks and our own R&D inspired what we built in 2024 to stop account takeover and reduce security risks across your workforce identities. ","2025-01-16T00:00:00.000Z","push-features-2024",{"items":90342},[90343,90345],{"sys":90344,"name":342},{"id":13775},{"sys":90346,"name":297},{"id":2732},{"items":90348},[90349],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":90350},{"url":853},"considering-the-impact-of-computer-using-agents","blog/considering-the-impact-of-computer-using-agents",{"json":90354},{"data":90355,"content":90356,"nodeType":856},{},[90357],{"data":90358,"content":90359,"nodeType":860},{},[90360],{"data":90361,"marks":90362,"value":90363,"nodeType":864},{},[],"Computer-Using Agents (CUAs) are a new type of AI agent that drives your browser/OS for you. These tools (or future iterations of them) will enable low-cost, low-effort automation of common web tasks — including those frequently performed by attackers.","CUAs are a new type of AI agent that drives your browser/OS for you, enabling effortless automation of web tasks — including those performed by attackers.",{"id":90366,"publishedAt":90367},"SiALa9w13C6q3OzeTeUum","2026-08-12T11:54:30.875Z",{"items":90369},[90370,90372],{"sys":90371,"name":13779},{"id":13778},{"sys":90373,"name":297},{"id":2732},{"items":90375},[90376,90378,90380,90382,90384,90386,90388,90390,90392,90394,90396,90398,90400,90402,90404,90406,90408],{"sys":90377,"name":279,"slug":280,"tier":31},{"id":276},{"sys":90379,"name":235,"slug":236,"tier":31},{"id":232},{"sys":90381,"name":413,"slug":414,"tier":31},{"id":410},{"sys":90383,"name":545,"slug":546,"tier":31},{"id":542},{"sys":90385,"name":642,"slug":643,"tier":31},{"id":639},{"sys":90387,"name":297,"slug":298,"tier":31},{"id":294},{"sys":90389,"name":519,"slug":520,"tier":31},{"id":516},{"sys":90391,"name":244,"slug":245,"tier":45},{"id":241},{"sys":90393,"name":404,"slug":405,"tier":45},{"id":401},{"sys":90395,"name":333,"slug":334,"tier":45},{"id":330},{"sys":90397,"name":324,"slug":325,"tier":45},{"id":321},{"sys":90399,"name":475,"slug":476,"tier":45},{"id":472},{"sys":90401,"name":607,"slug":608,"tier":45},{"id":604},{"sys":90403,"name":571,"slug":572,"tier":45},{"id":568},{"sys":90405,"name":422,"slug":423,"tier":45},{"id":419},{"sys":90407,"name":502,"slug":503,"tier":45},{"id":499},{"sys":90409,"name":288,"slug":289,"tier":45},{"id":285},"BXC9egMG__WJ8DlAdMBbENBH-pmptSUJ4ZypBxm0Dzs",{"id":90412,"title":52055,"authorsCollection":90413,"content":90418,"extension":228,"faqItemsCollection":91511,"faqTitle":59,"featured":6,"hashTags":59,"meta":91513,"metaTitle":91514,"ogImage":59,"postType":59812,"publishedDate":52057,"relatedBlogPostsCollection":91515,"slug":52058,"stem":93118,"subtitle":59,"summary":93119,"synopsis":52056,"sys":93130,"tagsCollection":93132,"topicsCollection":93138,"__hash__":93168},"blog/blog/guide-to-secure-browser-extension-deployment.json",{"items":90414},[90415],{"fullName":52068,"firstName":52069,"jobTitle":52070,"socialLinks":90416,"profilePicture":90417},[87167],{"url":52072},{"json":90419,"links":91485},{"data":90420,"content":90421,"nodeType":856},{},[90422,90428,90431,90437,90443,90473,90479,90482,90488,90504,90530,90536,90542,90545,90551,90557,90563,90584,90590,90596,90599,90605,90611,90617,90623,90629,90635,90641,90647,90653,90659,90689,90695,90701,90704,90710,90716,90721,90727,90757,90763,90766,90772,90778,90784,90805,90811,90817,90823,90829,90835,90841,90847,90853,90879,90918,90924,90930,90936,90942,90948,90954,90960,91002,91007,91023,91029,91059,91065,91070,91073,91079,91085,91091,91097,91103,91109,91115,91121,91127,91130,91136,91142,91148,91154,91170,91176,91182,91212,91218,91224,91230,91236,91242,91302,91305,91311,91317,91356,91359,91365,91371,91387,91393,91399,91405,91408,91414,91420,91426,91442,91448,91454,91460,91466,91472],{"data":90423,"content":90424,"nodeType":860},{},[90425],{"data":90426,"marks":90427,"value":50836,"nodeType":864},{},[],{"data":90429,"content":90430,"nodeType":1005},{},[],{"data":90432,"content":90433,"nodeType":1009},{},[90434],{"data":90435,"marks":90436,"value":50846,"nodeType":864},{},[],{"data":90438,"content":90439,"nodeType":860},{},[90440],{"data":90441,"marks":90442,"value":50853,"nodeType":864},{},[],{"data":90444,"content":90445,"nodeType":941},{},[90446,90455,90464],{"data":90447,"content":90448,"nodeType":945},{},[90449],{"data":90450,"content":90451,"nodeType":860},{},[90452],{"data":90453,"marks":90454,"value":50866,"nodeType":864},{},[],{"data":90456,"content":90457,"nodeType":945},{},[90458],{"data":90459,"content":90460,"nodeType":860},{},[90461],{"data":90462,"marks":90463,"value":50876,"nodeType":864},{},[],{"data":90465,"content":90466,"nodeType":945},{},[90467],{"data":90468,"content":90469,"nodeType":860},{},[90470],{"data":90471,"marks":90472,"value":50886,"nodeType":864},{},[],{"data":90474,"content":90475,"nodeType":860},{},[90476],{"data":90477,"marks":90478,"value":50893,"nodeType":864},{},[],{"data":90480,"content":90481,"nodeType":1005},{},[],{"data":90483,"content":90484,"nodeType":1009},{},[90485],{"data":90486,"marks":90487,"value":50903,"nodeType":864},{},[],{"data":90489,"content":90490,"nodeType":860},{},[90491,90494,90501],{"data":90492,"marks":90493,"value":50910,"nodeType":864},{},[],{"data":90495,"content":90496,"nodeType":883},{"uri":50913},[90497],{"data":90498,"marks":90499,"value":50919,"nodeType":864},{},[90500],{"type":1455},{"data":90502,"marks":90503,"value":50923,"nodeType":864},{},[],{"data":90505,"content":90506,"nodeType":860},{},[90507,90510,90517,90520,90527],{"data":90508,"marks":90509,"value":50930,"nodeType":864},{},[],{"data":90511,"content":90512,"nodeType":883},{"uri":50933},[90513],{"data":90514,"marks":90515,"value":50939,"nodeType":864},{},[90516],{"type":1455},{"data":90518,"marks":90519,"value":50943,"nodeType":864},{},[],{"data":90521,"content":90522,"nodeType":883},{"uri":50946},[90523],{"data":90524,"marks":90525,"value":50952,"nodeType":864},{},[90526],{"type":1455},{"data":90528,"marks":90529,"value":50956,"nodeType":864},{},[],{"data":90531,"content":90532,"nodeType":860},{},[90533],{"data":90534,"marks":90535,"value":50963,"nodeType":864},{},[],{"data":90537,"content":90538,"nodeType":860},{},[90539],{"data":90540,"marks":90541,"value":50970,"nodeType":864},{},[],{"data":90543,"content":90544,"nodeType":1005},{},[],{"data":90546,"content":90547,"nodeType":1009},{},[90548],{"data":90549,"marks":90550,"value":50980,"nodeType":864},{},[],{"data":90552,"content":90553,"nodeType":860},{},[90554],{"data":90555,"marks":90556,"value":50987,"nodeType":864},{},[],{"data":90558,"content":90559,"nodeType":860},{},[90560],{"data":90561,"marks":90562,"value":50994,"nodeType":864},{},[],{"data":90564,"content":90565,"nodeType":941},{},[90566,90575],{"data":90567,"content":90568,"nodeType":945},{},[90569],{"data":90570,"content":90571,"nodeType":860},{},[90572],{"data":90573,"marks":90574,"value":51007,"nodeType":864},{},[],{"data":90576,"content":90577,"nodeType":945},{},[90578],{"data":90579,"content":90580,"nodeType":860},{},[90581],{"data":90582,"marks":90583,"value":51017,"nodeType":864},{},[],{"data":90585,"content":90586,"nodeType":860},{},[90587],{"data":90588,"marks":90589,"value":51024,"nodeType":864},{},[],{"data":90591,"content":90592,"nodeType":860},{},[90593],{"data":90594,"marks":90595,"value":51031,"nodeType":864},{},[],{"data":90597,"content":90598,"nodeType":1005},{},[],{"data":90600,"content":90601,"nodeType":1009},{},[90602],{"data":90603,"marks":90604,"value":51041,"nodeType":864},{},[],{"data":90606,"content":90607,"nodeType":860},{},[90608],{"data":90609,"marks":90610,"value":51048,"nodeType":864},{},[],{"data":90612,"content":90613,"nodeType":860},{},[90614],{"data":90615,"marks":90616,"value":51055,"nodeType":864},{},[],{"data":90618,"content":90619,"nodeType":860},{},[90620],{"data":90621,"marks":90622,"value":51062,"nodeType":864},{},[],{"data":90624,"content":90625,"nodeType":860},{},[90626],{"data":90627,"marks":90628,"value":51069,"nodeType":864},{},[],{"data":90630,"content":90631,"nodeType":860},{},[90632],{"data":90633,"marks":90634,"value":51076,"nodeType":864},{},[],{"data":90636,"content":90637,"nodeType":860},{},[90638],{"data":90639,"marks":90640,"value":51083,"nodeType":864},{},[],{"data":90642,"content":90643,"nodeType":1312},{},[90644],{"data":90645,"marks":90646,"value":51090,"nodeType":864},{},[],{"data":90648,"content":90649,"nodeType":860},{},[90650],{"data":90651,"marks":90652,"value":51097,"nodeType":864},{},[],{"data":90654,"content":90655,"nodeType":860},{},[90656],{"data":90657,"marks":90658,"value":51104,"nodeType":864},{},[],{"data":90660,"content":90661,"nodeType":941},{},[90662,90671,90680],{"data":90663,"content":90664,"nodeType":945},{},[90665],{"data":90666,"content":90667,"nodeType":860},{},[90668],{"data":90669,"marks":90670,"value":51117,"nodeType":864},{},[],{"data":90672,"content":90673,"nodeType":945},{},[90674],{"data":90675,"content":90676,"nodeType":860},{},[90677],{"data":90678,"marks":90679,"value":51127,"nodeType":864},{},[],{"data":90681,"content":90682,"nodeType":945},{},[90683],{"data":90684,"content":90685,"nodeType":860},{},[90686],{"data":90687,"marks":90688,"value":51137,"nodeType":864},{},[],{"data":90690,"content":90691,"nodeType":860},{},[90692],{"data":90693,"marks":90694,"value":51144,"nodeType":864},{},[],{"data":90696,"content":90697,"nodeType":860},{},[90698],{"data":90699,"marks":90700,"value":51151,"nodeType":864},{},[],{"data":90702,"content":90703,"nodeType":1005},{},[],{"data":90705,"content":90706,"nodeType":1009},{},[90707],{"data":90708,"marks":90709,"value":51161,"nodeType":864},{},[],{"data":90711,"content":90712,"nodeType":860},{},[90713],{"data":90714,"marks":90715,"value":51168,"nodeType":864},{},[],{"data":90717,"content":90720,"nodeType":996},{"target":90718},{"sys":90719},{"id":51173,"type":1001,"linkType":1002},[],{"data":90722,"content":90723,"nodeType":860},{},[90724],{"data":90725,"marks":90726,"value":51181,"nodeType":864},{},[],{"data":90728,"content":90729,"nodeType":941},{},[90730,90739,90748],{"data":90731,"content":90732,"nodeType":945},{},[90733],{"data":90734,"content":90735,"nodeType":860},{},[90736],{"data":90737,"marks":90738,"value":51194,"nodeType":864},{},[],{"data":90740,"content":90741,"nodeType":945},{},[90742],{"data":90743,"content":90744,"nodeType":860},{},[90745],{"data":90746,"marks":90747,"value":51204,"nodeType":864},{},[],{"data":90749,"content":90750,"nodeType":945},{},[90751],{"data":90752,"content":90753,"nodeType":860},{},[90754],{"data":90755,"marks":90756,"value":51214,"nodeType":864},{},[],{"data":90758,"content":90759,"nodeType":860},{},[90760],{"data":90761,"marks":90762,"value":51221,"nodeType":864},{},[],{"data":90764,"content":90765,"nodeType":1005},{},[],{"data":90767,"content":90768,"nodeType":1009},{},[90769],{"data":90770,"marks":90771,"value":51231,"nodeType":864},{},[],{"data":90773,"content":90774,"nodeType":860},{},[90775],{"data":90776,"marks":90777,"value":51238,"nodeType":864},{},[],{"data":90779,"content":90780,"nodeType":860},{},[90781],{"data":90782,"marks":90783,"value":51245,"nodeType":864},{},[],{"data":90785,"content":90786,"nodeType":941},{},[90787,90796],{"data":90788,"content":90789,"nodeType":945},{},[90790],{"data":90791,"content":90792,"nodeType":860},{},[90793],{"data":90794,"marks":90795,"value":51258,"nodeType":864},{},[],{"data":90797,"content":90798,"nodeType":945},{},[90799],{"data":90800,"content":90801,"nodeType":860},{},[90802],{"data":90803,"marks":90804,"value":51268,"nodeType":864},{},[],{"data":90806,"content":90807,"nodeType":860},{},[90808],{"data":90809,"marks":90810,"value":51275,"nodeType":864},{},[],{"data":90812,"content":90813,"nodeType":860},{},[90814],{"data":90815,"marks":90816,"value":51282,"nodeType":864},{},[],{"data":90818,"content":90819,"nodeType":1312},{},[90820],{"data":90821,"marks":90822,"value":51289,"nodeType":864},{},[],{"data":90824,"content":90825,"nodeType":860},{},[90826],{"data":90827,"marks":90828,"value":51296,"nodeType":864},{},[],{"data":90830,"content":90831,"nodeType":860},{},[90832],{"data":90833,"marks":90834,"value":51303,"nodeType":864},{},[],{"data":90836,"content":90837,"nodeType":860},{},[90838],{"data":90839,"marks":90840,"value":51310,"nodeType":864},{},[],{"data":90842,"content":90843,"nodeType":860},{},[90844],{"data":90845,"marks":90846,"value":51317,"nodeType":864},{},[],{"data":90848,"content":90849,"nodeType":1312},{},[90850],{"data":90851,"marks":90852,"value":51324,"nodeType":864},{},[],{"data":90854,"content":90855,"nodeType":860},{},[90856,90859,90866,90869,90876],{"data":90857,"marks":90858,"value":51331,"nodeType":864},{},[],{"data":90860,"content":90861,"nodeType":883},{"uri":51334},[90862],{"data":90863,"marks":90864,"value":51340,"nodeType":864},{},[90865],{"type":1455},{"data":90867,"marks":90868,"value":51344,"nodeType":864},{},[],{"data":90870,"content":90871,"nodeType":883},{"uri":51347},[90872],{"data":90873,"marks":90874,"value":51353,"nodeType":864},{},[90875],{"type":1455},{"data":90877,"marks":90878,"value":51357,"nodeType":864},{},[],{"data":90880,"content":90881,"nodeType":941},{},[90882,90891,90900,90909],{"data":90883,"content":90884,"nodeType":945},{},[90885],{"data":90886,"content":90887,"nodeType":860},{},[90888],{"data":90889,"marks":90890,"value":51370,"nodeType":864},{},[],{"data":90892,"content":90893,"nodeType":945},{},[90894],{"data":90895,"content":90896,"nodeType":860},{},[90897],{"data":90898,"marks":90899,"value":51380,"nodeType":864},{},[],{"data":90901,"content":90902,"nodeType":945},{},[90903],{"data":90904,"content":90905,"nodeType":860},{},[90906],{"data":90907,"marks":90908,"value":51390,"nodeType":864},{},[],{"data":90910,"content":90911,"nodeType":945},{},[90912],{"data":90913,"content":90914,"nodeType":860},{},[90915],{"data":90916,"marks":90917,"value":51400,"nodeType":864},{},[],{"data":90919,"content":90920,"nodeType":860},{},[90921],{"data":90922,"marks":90923,"value":51407,"nodeType":864},{},[],{"data":90925,"content":90926,"nodeType":1312},{},[90927],{"data":90928,"marks":90929,"value":51414,"nodeType":864},{},[],{"data":90931,"content":90932,"nodeType":860},{},[90933],{"data":90934,"marks":90935,"value":51421,"nodeType":864},{},[],{"data":90937,"content":90938,"nodeType":860},{},[90939],{"data":90940,"marks":90941,"value":51428,"nodeType":864},{},[],{"data":90943,"content":90944,"nodeType":860},{},[90945],{"data":90946,"marks":90947,"value":51435,"nodeType":864},{},[],{"data":90949,"content":90950,"nodeType":1312},{},[90951],{"data":90952,"marks":90953,"value":51442,"nodeType":864},{},[],{"data":90955,"content":90956,"nodeType":860},{},[90957],{"data":90958,"marks":90959,"value":51449,"nodeType":864},{},[],{"data":90961,"content":90962,"nodeType":941},{},[90963,90976,90989],{"data":90964,"content":90965,"nodeType":945},{},[90966],{"data":90967,"content":90968,"nodeType":860},{},[90969,90973],{"data":90970,"marks":90971,"value":51463,"nodeType":864},{},[90972],{"type":899},{"data":90974,"marks":90975,"value":51467,"nodeType":864},{},[],{"data":90977,"content":90978,"nodeType":945},{},[90979],{"data":90980,"content":90981,"nodeType":860},{},[90982,90986],{"data":90983,"marks":90984,"value":51478,"nodeType":864},{},[90985],{"type":899},{"data":90987,"marks":90988,"value":51482,"nodeType":864},{},[],{"data":90990,"content":90991,"nodeType":945},{},[90992],{"data":90993,"content":90994,"nodeType":860},{},[90995,90999],{"data":90996,"marks":90997,"value":51493,"nodeType":864},{},[90998],{"type":899},{"data":91000,"marks":91001,"value":51497,"nodeType":864},{},[],{"data":91003,"content":91006,"nodeType":996},{"target":91004},{"sys":91005},{"id":51502,"type":1001,"linkType":1002},[],{"data":91008,"content":91009,"nodeType":860},{},[91010,91013,91020],{"data":91011,"marks":91012,"value":51510,"nodeType":864},{},[],{"data":91014,"content":91015,"nodeType":883},{"uri":51513},[91016],{"data":91017,"marks":91018,"value":51519,"nodeType":864},{},[91019],{"type":1455},{"data":91021,"marks":91022,"value":51523,"nodeType":864},{},[],{"data":91024,"content":91025,"nodeType":860},{},[91026],{"data":91027,"marks":91028,"value":51530,"nodeType":864},{},[],{"data":91030,"content":91031,"nodeType":941},{},[91032,91041,91050],{"data":91033,"content":91034,"nodeType":945},{},[91035],{"data":91036,"content":91037,"nodeType":860},{},[91038],{"data":91039,"marks":91040,"value":51543,"nodeType":864},{},[],{"data":91042,"content":91043,"nodeType":945},{},[91044],{"data":91045,"content":91046,"nodeType":860},{},[91047],{"data":91048,"marks":91049,"value":51553,"nodeType":864},{},[],{"data":91051,"content":91052,"nodeType":945},{},[91053],{"data":91054,"content":91055,"nodeType":860},{},[91056],{"data":91057,"marks":91058,"value":51563,"nodeType":864},{},[],{"data":91060,"content":91061,"nodeType":860},{},[91062],{"data":91063,"marks":91064,"value":51570,"nodeType":864},{},[],{"data":91066,"content":91069,"nodeType":996},{"target":91067},{"sys":91068},{"id":51575,"type":1001,"linkType":1002},[],{"data":91071,"content":91072,"nodeType":1005},{},[],{"data":91074,"content":91075,"nodeType":1009},{},[91076],{"data":91077,"marks":91078,"value":51586,"nodeType":864},{},[],{"data":91080,"content":91081,"nodeType":860},{},[91082],{"data":91083,"marks":91084,"value":51593,"nodeType":864},{},[],{"data":91086,"content":91087,"nodeType":860},{},[91088],{"data":91089,"marks":91090,"value":51600,"nodeType":864},{},[],{"data":91092,"content":91093,"nodeType":860},{},[91094],{"data":91095,"marks":91096,"value":51607,"nodeType":864},{},[],{"data":91098,"content":91099,"nodeType":1312},{},[91100],{"data":91101,"marks":91102,"value":51614,"nodeType":864},{},[],{"data":91104,"content":91105,"nodeType":860},{},[91106],{"data":91107,"marks":91108,"value":51621,"nodeType":864},{},[],{"data":91110,"content":91111,"nodeType":860},{},[91112],{"data":91113,"marks":91114,"value":51628,"nodeType":864},{},[],{"data":91116,"content":91117,"nodeType":860},{},[91118],{"data":91119,"marks":91120,"value":51635,"nodeType":864},{},[],{"data":91122,"content":91123,"nodeType":860},{},[91124],{"data":91125,"marks":91126,"value":51642,"nodeType":864},{},[],{"data":91128,"content":91129,"nodeType":1005},{},[],{"data":91131,"content":91132,"nodeType":1009},{},[91133],{"data":91134,"marks":91135,"value":51652,"nodeType":864},{},[],{"data":91137,"content":91138,"nodeType":860},{},[91139],{"data":91140,"marks":91141,"value":51659,"nodeType":864},{},[],{"data":91143,"content":91144,"nodeType":1312},{},[91145],{"data":91146,"marks":91147,"value":51666,"nodeType":864},{},[],{"data":91149,"content":91150,"nodeType":860},{},[91151],{"data":91152,"marks":91153,"value":51673,"nodeType":864},{},[],{"data":91155,"content":91156,"nodeType":860},{},[91157,91160,91167],{"data":91158,"marks":91159,"value":51680,"nodeType":864},{},[],{"data":91161,"content":91162,"nodeType":883},{"uri":51683},[91163],{"data":91164,"marks":91165,"value":51689,"nodeType":864},{},[91166],{"type":1455},{"data":91168,"marks":91169,"value":51693,"nodeType":864},{},[],{"data":91171,"content":91172,"nodeType":1312},{},[91173],{"data":91174,"marks":91175,"value":51700,"nodeType":864},{},[],{"data":91177,"content":91178,"nodeType":860},{},[91179],{"data":91180,"marks":91181,"value":51707,"nodeType":864},{},[],{"data":91183,"content":91184,"nodeType":941},{},[91185,91194,91203],{"data":91186,"content":91187,"nodeType":945},{},[91188],{"data":91189,"content":91190,"nodeType":860},{},[91191],{"data":91192,"marks":91193,"value":51720,"nodeType":864},{},[],{"data":91195,"content":91196,"nodeType":945},{},[91197],{"data":91198,"content":91199,"nodeType":860},{},[91200],{"data":91201,"marks":91202,"value":51730,"nodeType":864},{},[],{"data":91204,"content":91205,"nodeType":945},{},[91206],{"data":91207,"content":91208,"nodeType":860},{},[91209],{"data":91210,"marks":91211,"value":51740,"nodeType":864},{},[],{"data":91213,"content":91214,"nodeType":860},{},[91215],{"data":91216,"marks":91217,"value":51747,"nodeType":864},{},[],{"data":91219,"content":91220,"nodeType":1312},{},[91221],{"data":91222,"marks":91223,"value":51754,"nodeType":864},{},[],{"data":91225,"content":91226,"nodeType":860},{},[91227],{"data":91228,"marks":91229,"value":51761,"nodeType":864},{},[],{"data":91231,"content":91232,"nodeType":1312},{},[91233],{"data":91234,"marks":91235,"value":51768,"nodeType":864},{},[],{"data":91237,"content":91238,"nodeType":860},{},[91239],{"data":91240,"marks":91241,"value":51775,"nodeType":864},{},[],{"data":91243,"content":91244,"nodeType":941},{},[91245,91284,91293],{"data":91246,"content":91247,"nodeType":945},{},[91248,91254],{"data":91249,"content":91250,"nodeType":860},{},[91251],{"data":91252,"marks":91253,"value":51788,"nodeType":864},{},[],{"data":91255,"content":91256,"nodeType":941},{},[91257,91266,91275],{"data":91258,"content":91259,"nodeType":945},{},[91260],{"data":91261,"content":91262,"nodeType":860},{},[91263],{"data":91264,"marks":91265,"value":51801,"nodeType":864},{},[],{"data":91267,"content":91268,"nodeType":945},{},[91269],{"data":91270,"content":91271,"nodeType":860},{},[91272],{"data":91273,"marks":91274,"value":51811,"nodeType":864},{},[],{"data":91276,"content":91277,"nodeType":945},{},[91278],{"data":91279,"content":91280,"nodeType":860},{},[91281],{"data":91282,"marks":91283,"value":51821,"nodeType":864},{},[],{"data":91285,"content":91286,"nodeType":945},{},[91287],{"data":91288,"content":91289,"nodeType":860},{},[91290],{"data":91291,"marks":91292,"value":51831,"nodeType":864},{},[],{"data":91294,"content":91295,"nodeType":945},{},[91296],{"data":91297,"content":91298,"nodeType":860},{},[91299],{"data":91300,"marks":91301,"value":51841,"nodeType":864},{},[],{"data":91303,"content":91304,"nodeType":1005},{},[],{"data":91306,"content":91307,"nodeType":1009},{},[91308],{"data":91309,"marks":91310,"value":51851,"nodeType":864},{},[],{"data":91312,"content":91313,"nodeType":860},{},[91314],{"data":91315,"marks":91316,"value":51858,"nodeType":864},{},[],{"data":91318,"content":91319,"nodeType":941},{},[91320,91329,91338,91347],{"data":91321,"content":91322,"nodeType":945},{},[91323],{"data":91324,"content":91325,"nodeType":860},{},[91326],{"data":91327,"marks":91328,"value":51871,"nodeType":864},{},[],{"data":91330,"content":91331,"nodeType":945},{},[91332],{"data":91333,"content":91334,"nodeType":860},{},[91335],{"data":91336,"marks":91337,"value":51881,"nodeType":864},{},[],{"data":91339,"content":91340,"nodeType":945},{},[91341],{"data":91342,"content":91343,"nodeType":860},{},[91344],{"data":91345,"marks":91346,"value":51891,"nodeType":864},{},[],{"data":91348,"content":91349,"nodeType":945},{},[91350],{"data":91351,"content":91352,"nodeType":860},{},[91353],{"data":91354,"marks":91355,"value":51901,"nodeType":864},{},[],{"data":91357,"content":91358,"nodeType":1005},{},[],{"data":91360,"content":91361,"nodeType":1009},{},[91362],{"data":91363,"marks":91364,"value":51911,"nodeType":864},{},[],{"data":91366,"content":91367,"nodeType":860},{},[91368],{"data":91369,"marks":91370,"value":51918,"nodeType":864},{},[],{"data":91372,"content":91373,"nodeType":860},{},[91374,91377,91384],{"data":91375,"marks":91376,"value":51925,"nodeType":864},{},[],{"data":91378,"content":91379,"nodeType":883},{"uri":51928},[91380],{"data":91381,"marks":91382,"value":51934,"nodeType":864},{},[91383],{"type":1455},{"data":91385,"marks":91386,"value":51938,"nodeType":864},{},[],{"data":91388,"content":91389,"nodeType":860},{},[91390],{"data":91391,"marks":91392,"value":51945,"nodeType":864},{},[],{"data":91394,"content":91395,"nodeType":860},{},[91396],{"data":91397,"marks":91398,"value":51952,"nodeType":864},{},[],{"data":91400,"content":91401,"nodeType":860},{},[91402],{"data":91403,"marks":91404,"value":51959,"nodeType":864},{},[],{"data":91406,"content":91407,"nodeType":1005},{},[],{"data":91409,"content":91410,"nodeType":1009},{},[91411],{"data":91412,"marks":91413,"value":51969,"nodeType":864},{},[],{"data":91415,"content":91416,"nodeType":860},{},[91417],{"data":91418,"marks":91419,"value":51976,"nodeType":864},{},[],{"data":91421,"content":91422,"nodeType":1312},{},[91423],{"data":91424,"marks":91425,"value":51983,"nodeType":864},{},[],{"data":91427,"content":91428,"nodeType":860},{},[91429,91432,91439],{"data":91430,"marks":91431,"value":51990,"nodeType":864},{},[],{"data":91433,"content":91434,"nodeType":883},{"uri":51993},[91435],{"data":91436,"marks":91437,"value":51999,"nodeType":864},{},[91438],{"type":1455},{"data":91440,"marks":91441,"value":52003,"nodeType":864},{},[],{"data":91443,"content":91444,"nodeType":860},{},[91445],{"data":91446,"marks":91447,"value":52010,"nodeType":864},{},[],{"data":91449,"content":91450,"nodeType":860},{},[91451],{"data":91452,"marks":91453,"value":52017,"nodeType":864},{},[],{"data":91455,"content":91456,"nodeType":1312},{},[91457],{"data":91458,"marks":91459,"value":52024,"nodeType":864},{},[],{"data":91461,"content":91462,"nodeType":860},{},[91463],{"data":91464,"marks":91465,"value":52031,"nodeType":864},{},[],{"data":91467,"content":91468,"nodeType":860},{},[91469],{"data":91470,"marks":91471,"value":52038,"nodeType":864},{},[],{"data":91473,"content":91474,"nodeType":860},{},[91475,91478,91482],{"data":91476,"marks":91477,"value":52045,"nodeType":864},{},[],{"data":91479,"marks":91480,"value":52050,"nodeType":864},{},[91481],{"type":1455},{"data":91483,"marks":91484,"value":52054,"nodeType":864},{},[],{"entries":91486},{"hyperlink":91487,"inline":91488,"block":91489},[],[],[91490,91498,91505],{"sys":91491,"__typename":1724,"title":91492,"caption":91493,"layoutMode":59,"file":91494},{"id":51173},"Attack paths to publishing a malicious extension","Graphic showing the possible high-level attack paths to publishing a malicious extension. The path in bold (consent phishing) represents the path traversed in the Cyberhaven breach. ",{"url":91495,"width":91496,"height":91497},"https://images.ctfassets.net/y1cdw1ablpvd/449fRkebgBONYaYRJQuZZd/f1b9d7487dd6208516a760b5cac458a4/Attack_paths_to_publishing_a_malicious_extension.png",1423,1912,{"sys":91499,"__typename":1724,"title":91500,"caption":91500,"layoutMode":59,"file":91501},{"id":51502},"Steps required to automate a publish to the Apple store",{"url":91502,"width":91503,"height":91504},"https://images.ctfassets.net/y1cdw1ablpvd/63QG3teGwNduKQkKP7QfVo/7a78a4b433ab426bd6b8935b0701137c/image2.png",676,506,{"sys":91506,"__typename":1724,"title":91507,"caption":91508,"layoutMode":59,"file":91509},{"id":51575},"Secure multiparty auth diagram","Strong hardware-backed multiparty authenticated deployments to the stores",{"url":91510,"width":87796,"height":74599},"https://images.ctfassets.net/y1cdw1ablpvd/6j4ZRB7D1VA7TfcvIED9Q1/ebf88ffa4082759f77f5a99594a1a9b7/Secure_multiparty_auth_diagram__3_.png",{"items":91512},[],{},"How to securely deploy browser extensions to the web store",{"items":91516},[91517,92222,92568],{"__typename":2059,"sys":91518,"content":91520,"title":92208,"synopsis":92209,"hashTags":59,"publishedDate":92210,"slug":92211,"tagsCollection":92212,"authorsCollection":92218},{"id":91519},"6rflXTFCRMvmM8JU8ZPSCt",{"json":91521},{"data":91522,"content":91523,"nodeType":856},{},[91524,91531,91538,91545,91552,91559,91566,91572,91579,91586,91593,91600,91616,91623,91630,91637,91644,91651,91658,91665,91671,91678,91685,91692,91699,91705,91713,91720,91727,91734,91741,91749,91756,91762,91769,91776,91799,91806,91839,91846,91862,91870,91877,91884,91891,91898,91951,91958,91964,91971,91978,91985,91993,92000,92007,92014,92044,92051,92085,92092,92099,92106,92113,92121,92128,92135,92142,92149,92156,92163,92170,92177,92196,92202],{"data":91525,"content":91526,"nodeType":1009},{},[91527],{"data":91528,"marks":91529,"value":91530,"nodeType":864},{},[],"What is in an identity?",{"data":91532,"content":91533,"nodeType":860},{},[91534],{"data":91535,"marks":91536,"value":91537,"nodeType":864},{},[],"Like real identities, digital identities are a little hard to define. Formally it’s a mapping of a human into the digital world, but more often this term is used as synonymous with a credential (e.g. a username and password, a Multi-Factor Authentication (MFA) device, or a fingerprint) - the thing you use to prove you own the identity in an authentication process. When people say an identity is breached, they typically mean the credentials have been stolen.",{"data":91539,"content":91540,"nodeType":860},{},[91541],{"data":91542,"marks":91543,"value":91544,"nodeType":864},{},[],"This is a useful simplification, but bear in mind that reality is a bit more complex. For example - identities are typically tied to an account on an application (you want to login to Slack, Slack knows your password), but can also trust a third party (an Identity Provider or IdP) to authenticate an identity on your behalf in what’s known as federation (“login with Google” on Slack).",{"data":91546,"content":91547,"nodeType":860},{},[91548],{"data":91549,"marks":91550,"value":91551,"nodeType":864},{},[],"Surprisingly, it’s very common for modern apps to allow a user to authenticate to the same account using a local credential (a username and password) and a federated identity (e.g. the “login with Google” or “login with Microsoft” buttons) interchangeably.",{"data":91553,"content":91554,"nodeType":860},{},[91555],{"data":91556,"marks":91557,"value":91558,"nodeType":864},{},[],"That’s how you could wind up with multiple identities tied to a single account, or multiple accounts tied to a single federated identity. This is exactly what you see for real users - and every weird in-between case to boot.",{"data":91560,"content":91561,"nodeType":1009},{},[91562],{"data":91563,"marks":91564,"value":91565,"nodeType":864},{},[],"The “new perimeter” … from a red-teamer’s perspective",{"data":91567,"content":91568,"nodeType":860},{},[91569],{"data":91570,"marks":91571,"value":21,"nodeType":864},{},[],{"data":91573,"content":91574,"nodeType":860},{},[91575],{"data":91576,"marks":91577,"value":91578,"nodeType":864},{},[],"To see how identities are the new thing, it helps to see how we got here.",{"data":91580,"content":91581,"nodeType":1312},{},[91582],{"data":91583,"marks":91584,"value":91585,"nodeType":864},{},[],"The good old days",{"data":91587,"content":91588,"nodeType":860},{},[91589],{"data":91590,"marks":91591,"value":91592,"nodeType":864},{},[],"A couple of decades ago, I was just getting started as a red-teamer or penetration tester, or whatever you want to call it. The job is to do what real attackers do so clients could understand the attack techniques and better defend against them. The most stressful part of each project was the first step - getting initial access to the target - getting past their perimeter and into the (usually) soft internals.",{"data":91594,"content":91595,"nodeType":860},{},[91596],{"data":91597,"marks":91598,"value":91599,"nodeType":864},{},[],"A security perimeter is a boundary at which controls can be enforced. From an offensive perspective, a security perimeter is the same as an attack surface: where you can target initial attacks to gain a foothold, from which you can launch further attacks. I use perimeter and attack surface interchangeably going forward.",{"data":91601,"content":91602,"nodeType":860},{},[91603,91607,91612],{"data":91604,"marks":91605,"value":91606,"nodeType":864},{},[],"A perimeter can be physical, like a wall around a house, or virtual like the network boundary between an internal network and the internet where controls are things like firewalls. A couple of decades ago this internet network boundary was ",{"data":91608,"marks":91609,"value":91611,"nodeType":864},{},[91610],{"type":2246},"the",{"data":91613,"marks":91614,"value":91615,"nodeType":864},{},[]," perimeter. As any decent red-teamer during this era, we had a pretty well-oiled process of mapping a client’s external network, scanning it for services, and then identifying and exploiting known vulnerabilities in those services. With this foothold on a target network, we could pivot to other, more sensitive internal systems.",{"data":91617,"content":91618,"nodeType":860},{},[91619],{"data":91620,"marks":91621,"value":91622,"nodeType":864},{},[],"Blue teams started having success with automated vulnerability scanning and patching programs, during this time. Then red teams responded by focusing on finding new vulnerabilities, especially in custom code like web applications. I fondly remember using techniques like xp_cmdshell with SQL injection to get access to breach perimeter systems and get access to internal networks. As DMZs, SDLC, vuln scanning and a dozen other tactics became generally adopted things improved to the point where those standard red-team playbooks weren’t working anymore. ",{"data":91624,"content":91625,"nodeType":1312},{},[91626],{"data":91627,"marks":91628,"value":91629,"nodeType":864},{},[],"The shift to targeting users and their endpoints",{"data":91631,"content":91632,"nodeType":860},{},[91633],{"data":91634,"marks":91635,"value":91636,"nodeType":864},{},[],"About a decade ago, attackers realized it was easier to breach the perimeter and gain access to internal networks by simply targeting users with endpoints directly connected to the internal network. At the time the main techniques were email phishing and malicious web pages delivering exploits or straight malware. We put down Burp and our other web app testing tools and started spending our time crafting phishing emails with malicious macro-laden Microsoft Office documents for that initial entrypoint.",{"data":91638,"content":91639,"nodeType":860},{},[91640],{"data":91641,"marks":91642,"value":91643,"nodeType":864},{},[],"Defenders were on the back foot and even back then the “train your employees to spot attacks” advice felt as totally unrealistic as it’s now proved to be. The zeitgeist suggested, \"Attackers only need to succeed once; defenders must succeed every time.\" Defenders were blind and the focus was firmly on detection. Much much better telemetry was needed, which spawned the endpoint detection and response (EDR) revolution. ",{"data":91645,"content":91646,"nodeType":860},{},[91647],{"data":91648,"marks":91649,"value":91650,"nodeType":864},{},[],"EDR required immediate changes to red team tactics, and together with better endpoint security defaults, automatic OS updates (that actually started working) and memory exploit protections (things like DEP and ASLR) the timelines for successful attacks were stretching a lot.",{"data":91652,"content":91653,"nodeType":1312},{},[91654],{"data":91655,"marks":91656,"value":91657,"nodeType":864},{},[],"The modern perimeter",{"data":91659,"content":91660,"nodeType":860},{},[91661],{"data":91662,"marks":91663,"value":91664,"nodeType":864},{},[],"Attackers have had to change tactics yet again, due to the rising cost of attacking endpoints and the fact that data has moved off endpoints and internal networks and onto cloud systems or Software as a Service (SaaS) applications.",{"data":91666,"content":91670,"nodeType":996},{"target":91667},{"sys":91668},{"id":91669,"type":1001,"linkType":1002},"79wGG37CY7aBdRrdjO5eQY",[],{"data":91672,"content":91673,"nodeType":860},{},[91674],{"data":91675,"marks":91676,"value":91677,"nodeType":864},{},[],"Identities have always existed as a target for attackers and were a critical part of the kill chain, but they used to be protected by some other perimeter, be that a network perimeter or an endpoint perimeter. ",{"data":91679,"content":91680,"nodeType":860},{},[91681],{"data":91682,"marks":91683,"value":91684,"nodeType":864},{},[],"This has fundamentally changed as modern work applications are now directly exposed to the internet  - and the only thing needed to access these apps are identities. That means identities are now no longer the second or third target but the initial target, the new perimeter.",{"data":91686,"content":91687,"nodeType":1009},{},[91688],{"data":91689,"marks":91690,"value":91691,"nodeType":864},{},[],"Securing the (identity) perimeter",{"data":91693,"content":91694,"nodeType":860},{},[91695],{"data":91696,"marks":91697,"value":91698,"nodeType":864},{},[],"To understand how we can protect this new perimeter, I’ll discuss the general approach to securing any perimeter, and then how this applies to the identity attack surface.",{"data":91700,"content":91704,"nodeType":996},{"target":91701},{"sys":91702},{"id":91703,"type":1001,"linkType":1002},"c0YSk60vVULBPorLkkBPL",[],{"data":91706,"content":91707,"nodeType":1312},{},[91708],{"data":91709,"marks":91710,"value":91712,"nodeType":864},{},[91711],{"type":899},"1. Map your perimeter",{"data":91714,"content":91715,"nodeType":860},{},[91716],{"data":91717,"marks":91718,"value":91719,"nodeType":864},{},[],"It’s impossible to secure what you don’t know about. Whether your perimeter is made of network services, user endpoints or identities, you must know what they are before you can implement controls to protect them, and crucially, verify those controls are effective.",{"data":91721,"content":91722,"nodeType":860},{},[91723],{"data":91724,"marks":91725,"value":91726,"nodeType":864},{},[],"In a traditional network setting, you might ask IT to inventory public network ranges, domains you own, and internet facing servers and services to get visibility into your attack surface. This is a pretty complex task and lots of the static inventory will quickly become outdated and incomplete. That’s why many orgs will perform network discovery activities to find internet-exposed network services, using anything from basic network scans to find onsite or self-hosted services to querying APIs in cloud infrastructure platforms (like AWS or Azure).",{"data":91728,"content":91729,"nodeType":860},{},[91730],{"data":91731,"marks":91732,"value":91733,"nodeType":864},{},[],"There are parallels in the identity perimeter space, like querying Identity Providers (IdPs like Entra/AzureAD or Okta) for federated identities to map the attack surface. Unfortunately there is no equivalent to scanning your public network ranges for identities, since you can’t scan or query an app to find accounts on your domain (would that we could!). This problem is compounded by the fact that while IT and developers are typically the only ones that can create and expose new network services, most apps allow any employee to create a new identity by signing up to a free account outside your SSO solution.",{"data":91735,"content":91736,"nodeType":860},{},[91737],{"data":91738,"marks":91739,"value":91740,"nodeType":864},{},[],"Knowing your perimeter without a technical solution is going to be a very hit and miss affair. To have confidence that you understand your identity perimeter, you need an inventory solution that can discover SSO identities (the easy part), as well as identities created outside SSO, like local accounts those employees created just by signing up. To secure identities it’s not enough to know that an employee is accessing an app website, you need to know if they are logged in and what identity they are using (is the username a company email or personal gmail?) or you’ll be dealing with endless false positives.",{"data":91742,"content":91743,"nodeType":1312},{},[91744],{"data":91745,"marks":91746,"value":91748,"nodeType":864},{},[91747],{"type":899},"2. Reduce the size of your attack surface",{"data":91750,"content":91751,"nodeType":860},{},[91752],{"data":91753,"marks":91754,"value":91755,"nodeType":864},{},[],"Once you have an idea of what makes up your perimeter, it’s generally a good idea to make it as small as possible. If you halve the number of network services an attacker can target, that means you can spend twice as long per service to secure the ones that remain - the same goes for identities!",{"data":91757,"content":91761,"nodeType":996},{"target":91758},{"sys":91759},{"id":91760,"type":1001,"linkType":1002},"2XZ5vADLzuEnc2aAdZrkbO",[],{"data":91763,"content":91764,"nodeType":860},{},[91765],{"data":91766,"marks":91767,"value":91768,"nodeType":864},{},[],"To start this process, remove unused or unnecessary targets from the perimeter. ",{"data":91770,"content":91771,"nodeType":860},{},[91772],{"data":91773,"marks":91774,"value":91775,"nodeType":864},{},[],"On a network perimeter that might mean:",{"data":91777,"content":91778,"nodeType":941},{},[91779,91789],{"data":91780,"content":91781,"nodeType":945},{},[91782],{"data":91783,"content":91784,"nodeType":860},{},[91785],{"data":91786,"marks":91787,"value":91788,"nodeType":864},{},[],"Shutting down unused servers or",{"data":91790,"content":91791,"nodeType":945},{},[91792],{"data":91793,"content":91794,"nodeType":860},{},[91795],{"data":91796,"marks":91797,"value":91798,"nodeType":864},{},[],"Firewalling services that don’t need to be exposed to the internet.",{"data":91800,"content":91801,"nodeType":860},{},[91802],{"data":91803,"marks":91804,"value":91805,"nodeType":864},{},[],"In the identity space, you might:",{"data":91807,"content":91808,"nodeType":941},{},[91809,91819,91829],{"data":91810,"content":91811,"nodeType":945},{},[91812],{"data":91813,"content":91814,"nodeType":860},{},[91815],{"data":91816,"marks":91817,"value":91818,"nodeType":864},{},[],"Make sure new accounts use existing federated identities,",{"data":91820,"content":91821,"nodeType":945},{},[91822],{"data":91823,"content":91824,"nodeType":860},{},[91825],{"data":91826,"marks":91827,"value":91828,"nodeType":864},{},[],"Delete or disable unused SSO identities on your IdP, or ",{"data":91830,"content":91831,"nodeType":945},{},[91832],{"data":91833,"content":91834,"nodeType":860},{},[91835],{"data":91836,"marks":91837,"value":91838,"nodeType":864},{},[],"Manually delete unnecessary user accounts on work apps.",{"data":91840,"content":91841,"nodeType":860},{},[91842],{"data":91843,"marks":91844,"value":91845,"nodeType":864},{},[],"Manually deleting an unmanaged local identity on an app, e.g. after an employee leaves your org, is a (very) non-trivial task. This is because you often don’t known of the accounts and don't have access to manage the account (the IT or security team aren’t admin on the app tenant where it exists). You might have access to the user’s mailbox and be able to get access to the account by going through an account recovery flow and delete the account that way - but this is very time consuming and even more difficult if the user enabled MFA (which is what you want them to do!).",{"data":91847,"content":91848,"nodeType":860},{},[91849,91853,91858],{"data":91850,"marks":91851,"value":91852,"nodeType":864},{},[],"Given the difficulty of managing these accounts, a better strategy is to ",{"data":91854,"marks":91855,"value":91857,"nodeType":864},{},[91856],{"type":899},"make sure they never exist in the first place",{"data":91859,"marks":91860,"value":91861,"nodeType":864},{},[],". If you find you have lots of identities on an app you may decide the risk warrants IT effort and you can take over management of the app and integrate it with your IdP solution - or ask employees to use an alternative app instead. You can also use browser-based technical controls to prevent users from creating local identities in the first place.",{"data":91863,"content":91864,"nodeType":1312},{},[91865],{"data":91866,"marks":91867,"value":91869,"nodeType":864},{},[91868],{"type":899},"3. Harden the perimeter",{"data":91871,"content":91872,"nodeType":860},{},[91873],{"data":91874,"marks":91875,"value":91876,"nodeType":864},{},[],"Once you’ve made the perimeter as small as possible, the next step is to make it more difficult to breach that perimeter. Similar to the other objectives, but especially here, there are two sides to this. First the implementation; you have processes, configuration standards, and tools to make sure network services are updated and securely configured. Virtually no one achieves success simply through implementing good processes, you must continually verify that these processes work and that it continues to work.",{"data":91878,"content":91879,"nodeType":860},{},[91880],{"data":91881,"marks":91882,"value":91883,"nodeType":864},{},[],"To verify network controls are in place and working you do something like vulnerability scanning, where you check the perimeter for known vulnerabilities that an attacker could exploit and gain a foothold on your internal network. You might even have a risk profile that means you are concerned about more targeted attacks and hire pentesters or run a bug-bounty program to find weaknesses that can’t be automatically discovered. Very few organizations with an external network of any significant size perform a vulnerability scan for the first time - even a low-quality automated one - and find no serious issues. ",{"data":91885,"content":91886,"nodeType":860},{},[91887],{"data":91888,"marks":91889,"value":91890,"nodeType":864},{},[],"In the identity space, the status-quo is to be content with making policies and implementing and configuring an SSO system without explicit verification that it works as it should. We should be following the same level of verification processes for the identity perimeter as we do/did for the endpoint and network perimeter. ",{"data":91892,"content":91893,"nodeType":860},{},[91894],{"data":91895,"marks":91896,"value":91897,"nodeType":864},{},[],"In this case, the vulnerabilities we are looking for aren’t unpatched systems or zero-days. Instead, we’re looking for:",{"data":91899,"content":91900,"nodeType":941},{},[91901,91911,91921,91931,91941],{"data":91902,"content":91903,"nodeType":945},{},[91904],{"data":91905,"content":91906,"nodeType":860},{},[91907],{"data":91908,"marks":91909,"value":91910,"nodeType":864},{},[],"Accounts without MFA, ",{"data":91912,"content":91913,"nodeType":945},{},[91914],{"data":91915,"content":91916,"nodeType":860},{},[91917],{"data":91918,"marks":91919,"value":91920,"nodeType":864},{},[],"Those using weak MFA methods that make them phish-able,",{"data":91922,"content":91923,"nodeType":945},{},[91924],{"data":91925,"content":91926,"nodeType":860},{},[91927],{"data":91928,"marks":91929,"value":91930,"nodeType":864},{},[],"Employees re-using the same password across multiple accounts, ",{"data":91932,"content":91933,"nodeType":945},{},[91934],{"data":91935,"content":91936,"nodeType":860},{},[91937],{"data":91938,"marks":91939,"value":91940,"nodeType":864},{},[],"Passwords that exist in public breach dumps,",{"data":91942,"content":91943,"nodeType":945},{},[91944],{"data":91945,"content":91946,"nodeType":860},{},[91947],{"data":91948,"marks":91949,"value":91950,"nodeType":864},{},[],"Identities that should be in SSO but aren’t.",{"data":91952,"content":91953,"nodeType":860},{},[91954],{"data":91955,"marks":91956,"value":91957,"nodeType":864},{},[],"It’s not yet standard practice to test or verify that identity controls are in place, but if the past has taught us anything it soon will be. You'd be surprised how many times we find that the MFA policies security teams thought they had in place, actually aren't.",{"data":91959,"content":91963,"nodeType":996},{"target":91960},{"sys":91961},{"id":91962,"type":1001,"linkType":1002},"4w5UZcf5hJ7ADuoT5W2tkC",[],{"data":91965,"content":91966,"nodeType":860},{},[91967],{"data":91968,"marks":91969,"value":91970,"nodeType":864},{},[],"Part of the reason for this lack of verification is due to lack of awareness. While identities used to be an internal thing that we protected with the network perimeter, online identities today are external and have slowly become the perimeter, almost without anyone noticing. While online identities are external, they are absolutely part of your attack surface and must be controlled and hardened to some extent.",{"data":91972,"content":91973,"nodeType":860},{},[91974],{"data":91975,"marks":91976,"value":91977,"nodeType":864},{},[],"Verifying controls is also really difficult, which is another reason we may not be making it a crucial step in the process. Customers feel that SSO solutions are security solutions and using security tools on security tools feel wrong. But it’s no different to vuln-scanning to ensure your firewalls are patched and don’t have default passwords. ",{"data":91979,"content":91980,"nodeType":860},{},[91981],{"data":91982,"marks":91983,"value":91984,"nodeType":864},{},[],"Verification can also be legally challenging because it’s not yet clear whether pentesters or red teamers are allowed to target online identities during assessments. Often these assets aren’t considered in scope during client assessments. This means these vulnerabilities rarely end up in pentest reports and therefore don’t enter many organization’s security or risk management processes. Since you own the identities (even on a third party identity solution or app) and are allowed to grant permission to the red team to use these identities, it seems to me that adding identities to the scope is distinct from bug hunting or vulnerability research on these apps (which is the legally challenging aspect). I would strongly recommend that you discuss including online identities with the red team as part of your next pentest.",{"data":91986,"content":91987,"nodeType":1312},{},[91988],{"data":91989,"marks":91990,"value":91992,"nodeType":864},{},[91991],{"type":899},"4. Limit breach impact",{"data":91994,"content":91995,"nodeType":860},{},[91996],{"data":91997,"marks":91998,"value":91999,"nodeType":864},{},[],"The unfortunate reality is that regardless of what we do to harden a perimeter, there will always be a chance that breaches occur. The goal is to reduce that risk by minimizing the attack surface and hardening identities. ",{"data":92001,"content":92002,"nodeType":860},{},[92003],{"data":92004,"marks":92005,"value":92006,"nodeType":864},{},[],"When an attacker does get a foothold (by compromising an identity, for instance) you need to to restrict their further actions. Risk involves both the likelihood and the impact of an event. Previously, we focused on reducing the likelihood of breaches. Now, we're also aiming to lessen the impact if they do occur.",{"data":92008,"content":92009,"nodeType":860},{},[92010],{"data":92011,"marks":92012,"value":92013,"nodeType":864},{},[],"In our network perimeter story, we might think of using a DMZ network to restrict network access for systems exposed to the internet. A common example of a failure to limit impact on a Windows endpoint breach is having service accounts on all endpoints with Domain Administrator permission - which effectively turns a breach of any endpoint very quickly into a breach of every endpoint.",{"data":92015,"content":92016,"nodeType":860},{},[92017,92021,92030,92034,92040],{"data":92018,"marks":92019,"value":92020,"nodeType":864},{},[],"In an identity context, we need to think not only of the direct effect of an identity compromise (e.g. what data can this account read), but also of further lateral movement attacks. Consider this ",{"data":92022,"content":92024,"nodeType":883},{"uri":92023},"https://pushsecurity.com/blog/oktajacking/",[92025],{"data":92026,"marks":92027,"value":92029,"nodeType":864},{},[92028],{"type":1455},"Oktajacking",{"data":92031,"marks":92032,"value":92033,"nodeType":864},{},[]," case study where a breached identity with admin permissions on an otherwise low-risk app which is connected to SSO can be used to perform a ",{"data":92035,"content":92036,"nodeType":883},{"uri":83357},[92037],{"data":92038,"marks":92039,"value":83363,"nodeType":864},{},[],{"data":92041,"marks":92042,"value":92043,"nodeType":864},{},[]," attack that compromises SSO credentials for all other users of the same low-risk app.",{"data":92045,"content":92046,"nodeType":860},{},[92047],{"data":92048,"marks":92049,"value":92050,"nodeType":864},{},[],"In contrast to traditional network or endpoint breaches, identity breaches are scoped to the permissions that the compromised account has. If an identity is compromised, whatever that identity is authorized to do is the scope of the breach. For example:",{"data":92052,"content":92053,"nodeType":941},{},[92054,92064],{"data":92055,"content":92056,"nodeType":945},{},[92057],{"data":92058,"content":92059,"nodeType":860},{},[92060],{"data":92061,"marks":92062,"value":92063,"nodeType":864},{},[],"If an identity with read access to a code repository was breached you might consider that all the source code (hopefully no secrets!) they had read access to was taken unless you can prove otherwise. This is often more difficult than you expect - last time I checked Github (by far the world's most popular source code repository app) logs didn’t include, for example, zipped repo downloads. ",{"data":92065,"content":92066,"nodeType":945},{},[92067],{"data":92068,"content":92069,"nodeType":860},{},[92070,92074,92082],{"data":92071,"marks":92072,"value":92073,"nodeType":864},{},[],"If an identity with write permission was compromised, you would also need to check all commits/changes to ensure no code was backdoored. The same applies for other apps - think of an identity with write access to a wiki being used to ",{"data":92075,"content":92077,"nodeType":883},{"uri":92076},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/link_backdooring/description.md",[92078],{"data":92079,"marks":92080,"value":92081,"nodeType":864},{},[],"drop links to phishing pages",{"data":92083,"marks":92084,"value":2924,"nodeType":864},{},[],{"data":92086,"content":92087,"nodeType":860},{},[92088],{"data":92089,"marks":92090,"value":92091,"nodeType":864},{},[],"For primary cloud collaboration platforms with complex data types (think O365 or Google Workspace) your IT team is likely already managing policies to limit the data that a user can read. For primary cloud hosting platforms your DevOps teams are likely maintaining policies to manage privileged access to production systems. The situation is typically very different for the few dozen high risk “core apps” beyond the 2 or 3 apps that receive a lot of attention and have dedicated teams.",{"data":92093,"content":92094,"nodeType":860},{},[92095],{"data":92096,"marks":92097,"value":92098,"nodeType":864},{},[],"Starting to review roles and permissions across the few dozen or so high-risk apps that are not as actively managed (or more likely self-managed by the teams using them) is a good way to start addressing the residual risk. The good news here is that most modern work apps use a much simpler permission model based largely around predefined roles like Owner, Admin, or Employee or similar variations. This means less flexibility, but also makes it a lot easier to manage permissions for identities on these apps - on balance, a good trade!",{"data":92100,"content":92101,"nodeType":860},{},[92102],{"data":92103,"marks":92104,"value":92105,"nodeType":864},{},[],"Consider this as part of your identity and access management review process. Something that used to be scoped around Active Directory group membership, but in a modern online identity context, now must be applied across many different work apps. ",{"data":92107,"content":92108,"nodeType":860},{},[92109],{"data":92110,"marks":92111,"value":92112,"nodeType":864},{},[],"Unless you want to try to get access to each tenant of each app and normalize this data into a mega-spreadsheet, you need access to this data in your identity inventory. This is an especially big challenge as teams find many of the apps they care about support authentication through SSO, but not authorization.",{"data":92114,"content":92115,"nodeType":1312},{},[92116],{"data":92117,"marks":92118,"value":92120,"nodeType":864},{},[92119],{"type":899},"5. Detect and respond to attacks",{"data":92122,"content":92123,"nodeType":860},{},[92124],{"data":92125,"marks":92126,"value":92127,"nodeType":864},{},[],"Your last line of defense in protecting a perimeter is to monitor for attacks. It’s typically when controls and detections fail that breaches end in the news. ",{"data":92129,"content":92130,"nodeType":860},{},[92131],{"data":92132,"marks":92133,"value":92134,"nodeType":864},{},[],"Telemetry is the core building block of attack detection. Typically, you might ingest audit or event logs into a SIEM system. To detect attacks against identities, you’ll typically want to start with telemetry from SSO or IdP logs. These will provide some minimal coverage of many of the IT managed apps, but unfortunately attacks are more likely to happen on apps that aren’t SSO integrated, so we need a strategy to cover these as well. An identity inventory is a critical starting point to identify non-SSO apps from which you can collect event logs, as well as giving you visibility of the identities that are not covered.",{"data":92136,"content":92137,"nodeType":860},{},[92138],{"data":92139,"marks":92140,"value":92141,"nodeType":864},{},[],"Monitoring breaches for hosted work apps is different from other domains, largely because you are almost totally reliant on the app vendor to produce the telemetry. Unfortunately (I suspect primarily due to lack of customer demand), many apps don’t offer any centralized logging functionality at all, and those that do offer limited audit logs, or only do so on the top tier “enterprise” license plans. ",{"data":92143,"content":92144,"nodeType":860},{},[92145],{"data":92146,"marks":92147,"value":92148,"nodeType":864},{},[],"In the network or endpoint world, when you need more telemetry you have all the access you need to install software or hardware to generate that additional telemetry. You could put a network monitoring appliance in-line with your internet gateways or install an endpoint (EDR) agent to generate more telemetry than your router or endpoint OS will generate. You can add a proxy in front of an app for your users, but (except for a very small number of highly configurable apps) you can’t make attackers go through your proxy.",{"data":92150,"content":92151,"nodeType":860},{},[92152],{"data":92153,"marks":92154,"value":92155,"nodeType":864},{},[],"What you can do, however, is generate additional telemetry on what happens to your employee’s identities in the browser. This is possible through browser extensions which can be managed through the enterprise management features available for all mainstream browsers (Chrome, Edge, Firefox, Safari, Brave etc. etc.). This is incredibly powerful, and useful in directly detecting a range of identity attacks like phishing (is an employee trying to enter an SSO password into an app that isn’t the SSO login page?), but also through correlations with existing application or IdP logs that indicate account takeover (e.g. has there been a login event that wasn’t observed through the employee’s browser as well).",{"data":92157,"content":92158,"nodeType":1009},{},[92159],{"data":92160,"marks":92161,"value":92162,"nodeType":864},{},[],"Same, but different",{"data":92164,"content":92165,"nodeType":860},{},[92166],{"data":92167,"marks":92168,"value":92169,"nodeType":864},{},[],"Whether we’re looking at the Verizon DBIR or just keeping up with security news, it’s clear that identity-based attacks are already responsible for a significant number of breaches. Attackers have started shifting their focus and security teams need to recognize this shift and adapt.",{"data":92171,"content":92172,"nodeType":860},{},[92173],{"data":92174,"marks":92175,"value":92176,"nodeType":864},{},[],"This doesn’t require that we fundamentally rethink security or anything that radical, just that we apply what we’ve learned over the last couple of decades to this new domain. There are some new technologies and protocols to understand, new tools are needed, but the fundamentals like authentication and authorization are already familiar to any security professional. ",{"data":92178,"content":92179,"nodeType":860},{},[92180,92184,92192],{"data":92181,"marks":92182,"value":92183,"nodeType":864},{},[],"If you follow what I’ve outlined here, a lot of the decisions we’ve made with building Push will make perfect sense. For example, you can’t make API integrations with apps to find identities when you don’t know about the apps or identities yet, so we needed a unique new data source. We use our own custom-built browser extension that’s force-deployed to your workforce, so we can observe employee identities as they are used in the browser. This gives us some pretty unique capabilities. If you found this interesting, follow us on ",{"data":92185,"content":92187,"nodeType":883},{"uri":92186},"https://www.linkedin.com/company/push-security",[92188],{"data":92189,"marks":92190,"value":92191,"nodeType":864},{},[],"Linkedin",{"data":92193,"marks":92194,"value":92195,"nodeType":864},{},[]," for more detailed blogs as we unpack this topic.",{"data":92197,"content":92201,"nodeType":996},{"target":92198},{"sys":92199},{"id":92200,"type":1001,"linkType":1002},"H7m9DHmbE945FO193oLYP",[],{"data":92203,"content":92204,"nodeType":860},{},[92205],{"data":92206,"marks":92207,"value":21,"nodeType":864},{},[],"5 ways to defeat identity-based attacks","In this blog post we will cover what identities are, how we secure perimeters in general, and and how this maps to the identity space.\n","2024-02-26T00:00:00.000Z","5-ways-to-defeat-identity-based-attacks",{"items":92213},[92214,92216],{"sys":92215,"name":297},{"id":2732},{"sys":92217,"name":342},{"id":13775},{"items":92219},[92220],{"fullName":52068,"firstName":52069,"jobTitle":52070,"profilePicture":92221},{"url":52072},{"__typename":2059,"sys":92223,"content":92225,"title":92550,"synopsis":92551,"hashTags":59,"publishedDate":92552,"slug":92553,"tagsCollection":92554,"authorsCollection":92560},{"id":92224},"75wcCkoZEKwEMl7zBmDMtT",{"json":92226},{"data":92227,"content":92228,"nodeType":856},{},[92229,92236,92243,92262,92280,92303,92310,92326,92333,92340,92347,92350,92357,92377,92395,92401,92420,92427,92434,92440,92447,92453,92486,92493,92512,92515,92522,92532,92538,92544],{"data":92230,"content":92231,"nodeType":1009},{},[92232],{"data":92233,"marks":92234,"value":92235,"nodeType":864},{},[],"Preventing credential attacks with automated password resets ",{"data":92237,"content":92238,"nodeType":860},{},[92239],{"data":92240,"marks":92241,"value":92242,"nodeType":864},{},[],"Preventing credential attacks is not an easy task, especially if you’re a member of the security team tasked with protecting some of your organization’s most valued assets: SSO identities.",{"data":92244,"content":92245,"nodeType":860},{},[92246,92250,92259],{"data":92247,"marks":92248,"value":92249,"nodeType":864},{},[],"IdP accounts such as a user’s Okta, Entra, or Google Workspace login are the most lucrative identities that an attacker can take over. By compromising an SSO identity, attackers not only gain access to the account itself, but also any downstream apps accessed via SSO – and the juicy data and functionality stored there. This was evidenced earlier this year when ",{"data":92251,"content":92253,"nodeType":883},{"uri":92252},"https://www.bleepingcomputer.com/news/security/okta-warns-of-unprecedented-credential-stuffing-attacks-on-customers/",[92254],{"data":92255,"marks":92256,"value":92258,"nodeType":864},{},[92257],{"type":1455},"Okta users experienced unprecedented levels of credential stuffing attacks",{"data":92260,"marks":92261,"value":11546,"nodeType":864},{},[],{"data":92263,"content":92264,"nodeType":860},{},[92265,92269,92277],{"data":92266,"marks":92267,"value":92268,"nodeType":864},{},[],"You might also be surprised to learn that even these most critical accounts have serious security gaps. For example, ",{"data":92270,"content":92271,"nodeType":883},{"uri":25338},[92272],{"data":92273,"marks":92274,"value":92276,"nodeType":864},{},[92275],{"type":1455},"in a recent study we identified that",{"data":92278,"marks":92279,"value":73631,"nodeType":864},{},[],{"data":92281,"content":92282,"nodeType":941},{},[92283,92293],{"data":92284,"content":92285,"nodeType":945},{},[92286],{"data":92287,"content":92288,"nodeType":860},{},[92289],{"data":92290,"marks":92291,"value":92292,"nodeType":864},{},[],"1 in 5 IdP accounts does not have an MFA method set, leaving them exposed to single-factor compromises using stolen credentials.",{"data":92294,"content":92295,"nodeType":945},{},[92296],{"data":92297,"content":92298,"nodeType":860},{},[92299],{"data":92300,"marks":92301,"value":92302,"nodeType":864},{},[],"10% of IdP accounts share a password that is used to access other identities. (We’re not talking about the actual SSO process here – many users will use the same password as they do to log into their Okta or Entra as they do personal accounts such as shopping or food delivery. Yes, really.)  ",{"data":92304,"content":92305,"nodeType":860},{},[92306],{"data":92307,"marks":92308,"value":92309,"nodeType":864},{},[],"It’s a constant worry that your CFO’s Microsoft, Google, or Okta credentials are going to show up in the next big darkweb password dump. Ideally you’d want to prevent users from reusing passwords across multiple services. That’s why your information security policy is mandating password manager use, right?",{"data":92311,"content":92312,"nodeType":860},{},[92313,92317,92322],{"data":92314,"marks":92315,"value":92316,"nodeType":864},{},[],"No matter how many policies you have in place, ",{"data":92318,"marks":92319,"value":92321,"nodeType":864},{},[92320],{"type":1455},"people will inevitably use the same passwords across multiple services",{"data":92323,"marks":92324,"value":92325,"nodeType":864},{},[],". But who can blame them? Having to remember multiple passwords is a drag, especially when they find they can’t log into their company’s password manager from their home computers… The next best thing is to just reuse your Entra or Okta password across all services, right?!",{"data":92327,"content":92328,"nodeType":860},{},[92329],{"data":92330,"marks":92331,"value":92332,"nodeType":864},{},[],"At Push we realize that mistakes happen. That's why it's important to look out for when critical credentials are entered into a dodgy ecommerce platform, or the next entry lands on haveibeenpwnd.com.",{"data":92334,"content":92335,"nodeType":860},{},[92336],{"data":92337,"marks":92338,"value":92339,"nodeType":864},{},[],"By quickly forcing a password change when an SSO password is reused or breached, we can minimize the chance of it being abused by attackers. ",{"data":92341,"content":92342,"nodeType":860},{},[92343],{"data":92344,"marks":92345,"value":92346,"nodeType":864},{},[],"But how will you know when a password is reused or compromised? ",{"data":92348,"content":92349,"nodeType":1005},{},[],{"data":92351,"content":92352,"nodeType":1009},{},[92353],{"data":92354,"marks":92355,"value":92356,"nodeType":864},{},[],"Using Push data to alert on password vulnerabilities ",{"data":92358,"content":92359,"nodeType":860},{},[92360,92364,92373],{"data":92361,"marks":92362,"value":92363,"nodeType":864},{},[],"Enter the Push browser extension. Push fingerprints passwords (",{"data":92365,"content":92367,"nodeType":883},{"uri":92366},"https://pushsecurity.com/help/how-does-the-push-browser-extension-securely-track-reused-passwords",[92368],{"data":92369,"marks":92370,"value":92372,"nodeType":864},{},[92371],{"type":1455},"in a safe way",{"data":92374,"marks":92375,"value":92376,"nodeType":864},{},[],") as they are used by employees to access apps in their browsers. ",{"data":92378,"content":92379,"nodeType":860},{},[92380,92384,92392],{"data":92381,"marks":92382,"value":92383,"nodeType":864},{},[],"When a user logs into an app using credentials that they’ve previously used to login to another account, Push fires off an alert. ",{"data":92385,"content":92386,"nodeType":883},{"uri":77770},[92387],{"data":92388,"marks":92389,"value":92391,"nodeType":864},{},[92390],{"type":1455},"We can also detect when an active password is stolen and appears on a criminal forum",{"data":92393,"marks":92394,"value":11546,"nodeType":864},{},[],{"data":92396,"content":92400,"nodeType":996},{"target":92397},{"sys":92398},{"id":92399,"type":1001,"linkType":1002},"5He3FB0NT3D3lcbwiVtn02",[],{"data":92402,"content":92403,"nodeType":860},{},[92404,92408,92416],{"data":92405,"marks":92406,"value":92407,"nodeType":864},{},[],"If you’ve ",{"data":92409,"content":92410,"nodeType":883},{"uri":61873},[92411],{"data":92412,"marks":92413,"value":92415,"nodeType":864},{},[92414],{"type":1455},"connected Push to your SIEM or SOAR",{"data":92417,"marks":92418,"value":92419,"nodeType":864},{},[],", you’ll be able to create a workflow to respond automatically. ",{"data":92421,"content":92422,"nodeType":1312},{},[92423],{"data":92424,"marks":92425,"value":92426,"nodeType":864},{},[],"Automating password resets in your SIEM using Push webhooks",{"data":92428,"content":92429,"nodeType":860},{},[92430],{"data":92431,"marks":92432,"value":92433,"nodeType":864},{},[],"You can automate password resets for accounts by ingesting this information via webhook into a SIEM, generating an alert. This in turn can fire off another webhook or workflow that sets the ‘force password change on next logon’ attribute on the user’s account.",{"data":92435,"content":92439,"nodeType":996},{"target":92436},{"sys":92437},{"id":92438,"type":1001,"linkType":1002},"5WFLIVm4DWcuH7a6owQlR1",[],{"data":92441,"content":92442,"nodeType":860},{},[92443],{"data":92444,"marks":92445,"value":92446,"nodeType":864},{},[],"Below is some POC python code we use internally. This is specific to Google Workspace, but the general logic should apply to any IdP that allows you to perform these actions via API calls.",{"data":92448,"content":92452,"nodeType":996},{"target":92449},{"sys":92450},{"id":92451,"type":1001,"linkType":1002},"4YNirRo8BlRrgGKwwzXE8R",[],{"data":92454,"content":92455,"nodeType":860},{},[92456,92460,92469,92473,92482],{"data":92457,"marks":92458,"value":92459,"nodeType":864},{},[],"You can perform similar functions in Microsoft Entra ID by modifying the user's ",{"data":92461,"content":92463,"nodeType":883},{"uri":92462},"https://learn.microsoft.com/en-us/graph/api/user-update?view=graph-rest-1.0&tabs=http#:~:text=DisablePasswordExpiration%2C%20DisableStrongPassword.-,passwordProfile,-PasswordProfile",[92464],{"data":92465,"marks":92466,"value":92468,"nodeType":864},{},[92467],{"type":1455},"passwordProfile",{"data":92470,"marks":92471,"value":92472,"nodeType":864},{},[]," attribute via Microsoft Graph API, or in Okta via the ",{"data":92474,"content":92476,"nodeType":883},{"uri":92475},"https://developer.okta.com/docs/api/openapi/okta-management/management/tag/UserCred/#tag/UserCred/operation/expirePassword",[92477],{"data":92478,"marks":92479,"value":92481,"nodeType":864},{},[92480],{"type":1455},"expire_password",{"data":92483,"marks":92484,"value":92485,"nodeType":864},{},[]," API endpoint.",{"data":92487,"content":92488,"nodeType":860},{},[92489],{"data":92490,"marks":92491,"value":92492,"nodeType":864},{},[],"You aren’t limited to just IdP accounts either – any app with an API that provides this functionality can be configured for automated password resets using Push data. ",{"data":92494,"content":92495,"nodeType":860},{},[92496,92500,92508],{"data":92497,"marks":92498,"value":92499,"nodeType":864},{},[],"We also use SSO password data to ",{"data":92501,"content":92502,"nodeType":883},{"uri":89406},[92503],{"data":92504,"marks":92505,"value":92507,"nodeType":864},{},[92506],{"type":1455},"prevent users from entering their SSO credentials into phishing sites",{"data":92509,"marks":92510,"value":92511,"nodeType":864},{},[],", providing strong anti-phishing protection that is extremely hard for attackers to bypass. ",{"data":92513,"content":92514,"nodeType":1005},{},[],{"data":92516,"content":92517,"nodeType":1009},{},[92518],{"data":92519,"marks":92520,"value":92521,"nodeType":864},{},[],"Preventing attackers from exploiting vulnerable credentials has never been easier",{"data":92523,"content":92524,"nodeType":860},{},[92525,92529],{"data":92526,"marks":92527,"value":92528,"nodeType":864},{},[],"This is just one of the possible SecOps use cases that Push streamlines and levels up for security teams. ",{"data":92530,"marks":92531,"value":1682,"nodeType":864},{},[],{"data":92533,"content":92534,"nodeType":860},{},[92535],{"data":92536,"marks":92537,"value":1689,"nodeType":864},{},[],{"data":92539,"content":92543,"nodeType":996},{"target":92540},{"sys":92541},{"id":92542,"type":1001,"linkType":1002},"11p9wnGrZHqp3XPpThHFk3",[],{"data":92545,"content":92546,"nodeType":860},{},[92547],{"data":92548,"marks":92549,"value":21,"nodeType":864},{},[],"Automating SSO password resets using Push","Using Push to automate password resets for your most critical identities when a password vulnerability is detected.","2024-12-13T00:00:00.000Z","automating-sso-password-resets-using-push",{"items":92555},[92556,92558],{"sys":92557,"name":297},{"id":2732},{"sys":92559,"name":342},{"id":13775},{"items":92561},[92562],{"fullName":92563,"firstName":92564,"jobTitle":92565,"profilePicture":92566},"Johann Scheepers","Johann","Senior Security Engineer",{"url":92567},"https://images.ctfassets.net/y1cdw1ablpvd/75IEOH93vR0hbvxuqTu1m3/f6222745ee6892ea07bc18727a5a5ae7/T016S22KZ96-U02LU3SKC2D-e1e755770536-512.png",{"__typename":2059,"sys":92569,"content":92570,"title":88456,"synopsis":88457,"hashTags":59,"publishedDate":88458,"slug":88459,"tagsCollection":93110,"authorsCollection":93114},{"id":87834},{"json":92571},{"data":92572,"content":92573,"nodeType":856},{},[92574,92580,92586,92592,92608,92614,92620,92623,92630,92636,92642,92648,92653,92659,92662,92669,92675,92681,92687,92693,92698,92704,92707,92714,92721,92727,92733,92739,92755,92762,92768,92774,92780,92786,92793,92799,92805,92810,92813,92820,92826,92832,92838,92844,92850,92853,92860,92866,92872,92878,92884,92890,92988,93001,93007,93012,93015,93022,93028,93088,93094],{"data":92575,"content":92576,"nodeType":860},{},[92577],{"data":92578,"marks":92579,"value":87845,"nodeType":864},{},[],{"data":92581,"content":92582,"nodeType":860},{},[92583],{"data":92584,"marks":92585,"value":87852,"nodeType":864},{},[],{"data":92587,"content":92588,"nodeType":860},{},[92589],{"data":92590,"marks":92591,"value":87859,"nodeType":864},{},[],{"data":92593,"content":92594,"nodeType":860},{},[92595,92598,92605],{"data":92596,"marks":92597,"value":87866,"nodeType":864},{},[],{"data":92599,"content":92600,"nodeType":883},{"uri":87869},[92601],{"data":92602,"marks":92603,"value":87875,"nodeType":864},{},[92604],{"type":1455},{"data":92606,"marks":92607,"value":2924,"nodeType":864},{},[],{"data":92609,"content":92610,"nodeType":860},{},[92611],{"data":92612,"marks":92613,"value":87885,"nodeType":864},{},[],{"data":92615,"content":92616,"nodeType":860},{},[92617],{"data":92618,"marks":92619,"value":87892,"nodeType":864},{},[],{"data":92621,"content":92622,"nodeType":1005},{},[],{"data":92624,"content":92625,"nodeType":1009},{},[92626],{"data":92627,"marks":92628,"value":87903,"nodeType":864},{},[92629],{"type":899},{"data":92631,"content":92632,"nodeType":860},{},[92633],{"data":92634,"marks":92635,"value":87910,"nodeType":864},{},[],{"data":92637,"content":92638,"nodeType":860},{},[92639],{"data":92640,"marks":92641,"value":87917,"nodeType":864},{},[],{"data":92643,"content":92644,"nodeType":860},{},[92645],{"data":92646,"marks":92647,"value":87924,"nodeType":864},{},[],{"data":92649,"content":92652,"nodeType":996},{"target":92650},{"sys":92651},{"id":87929,"type":1001,"linkType":1002},[],{"data":92654,"content":92655,"nodeType":860},{},[92656],{"data":92657,"marks":92658,"value":87937,"nodeType":864},{},[],{"data":92660,"content":92661,"nodeType":1005},{},[],{"data":92663,"content":92664,"nodeType":1009},{},[92665],{"data":92666,"marks":92667,"value":87948,"nodeType":864},{},[92668],{"type":899},{"data":92670,"content":92671,"nodeType":860},{},[92672],{"data":92673,"marks":92674,"value":87955,"nodeType":864},{},[],{"data":92676,"content":92677,"nodeType":860},{},[92678],{"data":92679,"marks":92680,"value":87962,"nodeType":864},{},[],{"data":92682,"content":92683,"nodeType":860},{},[92684],{"data":92685,"marks":92686,"value":87969,"nodeType":864},{},[],{"data":92688,"content":92689,"nodeType":860},{},[92690],{"data":92691,"marks":92692,"value":87976,"nodeType":864},{},[],{"data":92694,"content":92697,"nodeType":996},{"target":92695},{"sys":92696},{"id":87981,"type":1001,"linkType":1002},[],{"data":92699,"content":92700,"nodeType":860},{},[92701],{"data":92702,"marks":92703,"value":87989,"nodeType":864},{},[],{"data":92705,"content":92706,"nodeType":1005},{},[],{"data":92708,"content":92709,"nodeType":1009},{},[92710],{"data":92711,"marks":92712,"value":88000,"nodeType":864},{},[92713],{"type":899},{"data":92715,"content":92716,"nodeType":1312},{},[92717],{"data":92718,"marks":92719,"value":88008,"nodeType":864},{},[92720],{"type":899},{"data":92722,"content":92723,"nodeType":860},{},[92724],{"data":92725,"marks":92726,"value":88015,"nodeType":864},{},[],{"data":92728,"content":92729,"nodeType":860},{},[92730],{"data":92731,"marks":92732,"value":88022,"nodeType":864},{},[],{"data":92734,"content":92735,"nodeType":860},{},[92736],{"data":92737,"marks":92738,"value":88029,"nodeType":864},{},[],{"data":92740,"content":92741,"nodeType":860},{},[92742,92745,92752],{"data":92743,"marks":92744,"value":88036,"nodeType":864},{},[],{"data":92746,"content":92747,"nodeType":883},{"uri":88039},[92748],{"data":92749,"marks":92750,"value":88045,"nodeType":864},{},[92751],{"type":1455},{"data":92753,"marks":92754,"value":88049,"nodeType":864},{},[],{"data":92756,"content":92757,"nodeType":1312},{},[92758],{"data":92759,"marks":92760,"value":88057,"nodeType":864},{},[92761],{"type":899},{"data":92763,"content":92764,"nodeType":860},{},[92765],{"data":92766,"marks":92767,"value":88064,"nodeType":864},{},[],{"data":92769,"content":92770,"nodeType":860},{},[92771],{"data":92772,"marks":92773,"value":88071,"nodeType":864},{},[],{"data":92775,"content":92776,"nodeType":860},{},[92777],{"data":92778,"marks":92779,"value":88078,"nodeType":864},{},[],{"data":92781,"content":92782,"nodeType":860},{},[92783],{"data":92784,"marks":92785,"value":88085,"nodeType":864},{},[],{"data":92787,"content":92788,"nodeType":1312},{},[92789],{"data":92790,"marks":92791,"value":88093,"nodeType":864},{},[92792],{"type":899},{"data":92794,"content":92795,"nodeType":860},{},[92796],{"data":92797,"marks":92798,"value":88100,"nodeType":864},{},[],{"data":92800,"content":92801,"nodeType":860},{},[92802],{"data":92803,"marks":92804,"value":88107,"nodeType":864},{},[],{"data":92806,"content":92809,"nodeType":996},{"target":92807},{"sys":92808},{"id":88112,"type":1001,"linkType":1002},[],{"data":92811,"content":92812,"nodeType":1005},{},[],{"data":92814,"content":92815,"nodeType":1009},{},[92816],{"data":92817,"marks":92818,"value":88124,"nodeType":864},{},[92819],{"type":899},{"data":92821,"content":92822,"nodeType":860},{},[92823],{"data":92824,"marks":92825,"value":88131,"nodeType":864},{},[],{"data":92827,"content":92828,"nodeType":860},{},[92829],{"data":92830,"marks":92831,"value":88138,"nodeType":864},{},[],{"data":92833,"content":92834,"nodeType":860},{},[92835],{"data":92836,"marks":92837,"value":88145,"nodeType":864},{},[],{"data":92839,"content":92840,"nodeType":860},{},[92841],{"data":92842,"marks":92843,"value":88152,"nodeType":864},{},[],{"data":92845,"content":92846,"nodeType":860},{},[92847],{"data":92848,"marks":92849,"value":88159,"nodeType":864},{},[],{"data":92851,"content":92852,"nodeType":1005},{},[],{"data":92854,"content":92855,"nodeType":1009},{},[92856],{"data":92857,"marks":92858,"value":88170,"nodeType":864},{},[92859],{"type":899},{"data":92861,"content":92862,"nodeType":860},{},[92863],{"data":92864,"marks":92865,"value":88177,"nodeType":864},{},[],{"data":92867,"content":92868,"nodeType":860},{},[92869],{"data":92870,"marks":92871,"value":88184,"nodeType":864},{},[],{"data":92873,"content":92874,"nodeType":860},{},[92875],{"data":92876,"marks":92877,"value":88191,"nodeType":864},{},[],{"data":92879,"content":92880,"nodeType":860},{},[92881],{"data":92882,"marks":92883,"value":88198,"nodeType":864},{},[],{"data":92885,"content":92886,"nodeType":860},{},[92887],{"data":92888,"marks":92889,"value":88205,"nodeType":864},{},[],{"data":92891,"content":92892,"nodeType":941},{},[92893,92912,92931,92950,92969],{"data":92894,"content":92895,"nodeType":945},{},[92896],{"data":92897,"content":92898,"nodeType":860},{},[92899,92902,92909],{"data":92900,"marks":92901,"value":88218,"nodeType":864},{},[],{"data":92903,"content":92904,"nodeType":883},{"uri":4408},[92905],{"data":92906,"marks":92907,"value":57796,"nodeType":864},{},[92908],{"type":1455},{"data":92910,"marks":92911,"value":49943,"nodeType":864},{},[],{"data":92913,"content":92914,"nodeType":945},{},[92915],{"data":92916,"content":92917,"nodeType":860},{},[92918,92921,92928],{"data":92919,"marks":92920,"value":88238,"nodeType":864},{},[],{"data":92922,"content":92923,"nodeType":883},{"uri":88241},[92924],{"data":92925,"marks":92926,"value":88247,"nodeType":864},{},[92927],{"type":1455},{"data":92929,"marks":92930,"value":49943,"nodeType":864},{},[],{"data":92932,"content":92933,"nodeType":945},{},[92934],{"data":92935,"content":92936,"nodeType":860},{},[92937,92940,92947],{"data":92938,"marks":92939,"value":88260,"nodeType":864},{},[],{"data":92941,"content":92942,"nodeType":883},{"uri":88263},[92943],{"data":92944,"marks":92945,"value":88269,"nodeType":864},{},[92946],{"type":1455},{"data":92948,"marks":92949,"value":49943,"nodeType":864},{},[],{"data":92951,"content":92952,"nodeType":945},{},[92953],{"data":92954,"content":92955,"nodeType":860},{},[92956,92959,92966],{"data":92957,"marks":92958,"value":88282,"nodeType":864},{},[],{"data":92960,"content":92961,"nodeType":883},{"uri":88285},[92962],{"data":92963,"marks":92964,"value":19538,"nodeType":864},{},[92965],{"type":1455},{"data":92967,"marks":92968,"value":49943,"nodeType":864},{},[],{"data":92970,"content":92971,"nodeType":945},{},[92972],{"data":92973,"content":92974,"nodeType":860},{},[92975,92978,92985],{"data":92976,"marks":92977,"value":88303,"nodeType":864},{},[],{"data":92979,"content":92980,"nodeType":883},{"uri":88306},[92981],{"data":92982,"marks":92983,"value":88312,"nodeType":864},{},[92984],{"type":1455},{"data":92986,"marks":92987,"value":49943,"nodeType":864},{},[],{"data":92989,"content":92990,"nodeType":860},{},[92991,92994,92998],{"data":92992,"marks":92993,"value":88322,"nodeType":864},{},[],{"data":92995,"marks":92996,"value":88327,"nodeType":864},{},[92997],{"type":899},{"data":92999,"marks":93000,"value":88331,"nodeType":864},{},[],{"data":93002,"content":93003,"nodeType":860},{},[93004],{"data":93005,"marks":93006,"value":88338,"nodeType":864},{},[],{"data":93008,"content":93011,"nodeType":996},{"target":93009},{"sys":93010},{"id":88343,"type":1001,"linkType":1002},[],{"data":93013,"content":93014,"nodeType":1005},{},[],{"data":93016,"content":93017,"nodeType":1009},{},[93018],{"data":93019,"marks":93020,"value":88355,"nodeType":864},{},[93021],{"type":899},{"data":93023,"content":93024,"nodeType":860},{},[93025],{"data":93026,"marks":93027,"value":88362,"nodeType":864},{},[],{"data":93029,"content":93030,"nodeType":941},{},[93031,93060,93079],{"data":93032,"content":93033,"nodeType":945},{},[93034],{"data":93035,"content":93036,"nodeType":860},{},[93037,93040,93047,93050,93057],{"data":93038,"marks":93039,"value":21,"nodeType":864},{},[],{"data":93041,"content":93042,"nodeType":883},{"uri":77770},[93043],{"data":93044,"marks":93045,"value":88382,"nodeType":864},{},[93046],{"type":1455},{"data":93048,"marks":93049,"value":88386,"nodeType":864},{},[],{"data":93051,"content":93052,"nodeType":883},{"uri":88389},[93053],{"data":93054,"marks":93055,"value":88395,"nodeType":864},{},[93056],{"type":1455},{"data":93058,"marks":93059,"value":88399,"nodeType":864},{},[],{"data":93061,"content":93062,"nodeType":945},{},[93063],{"data":93064,"content":93065,"nodeType":860},{},[93066,93069,93076],{"data":93067,"marks":93068,"value":21,"nodeType":864},{},[],{"data":93070,"content":93071,"nodeType":883},{"uri":62865},[93072],{"data":93073,"marks":93074,"value":88416,"nodeType":864},{},[93075],{"type":1455},{"data":93077,"marks":93078,"value":88420,"nodeType":864},{},[],{"data":93080,"content":93081,"nodeType":945},{},[93082],{"data":93083,"content":93084,"nodeType":860},{},[93085],{"data":93086,"marks":93087,"value":88430,"nodeType":864},{},[],{"data":93089,"content":93090,"nodeType":860},{},[93091],{"data":93092,"marks":93093,"value":88437,"nodeType":864},{},[],{"data":93095,"content":93096,"nodeType":860},{},[93097,93100,93107],{"data":93098,"marks":93099,"value":88444,"nodeType":864},{},[],{"data":93101,"content":93102,"nodeType":883},{"uri":1700},[93103],{"data":93104,"marks":93105,"value":88452,"nodeType":864},{},[93106],{"type":1455},{"data":93108,"marks":93109,"value":2924,"nodeType":864},{},[],{"items":93111},[93112],{"sys":93113,"name":13779},{"id":13778},{"items":93115},[93116],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":93117},{"url":2740},"blog/guide-to-secure-browser-extension-deployment",{"json":93120},{"data":93121,"content":93122,"nodeType":856},{},[93123],{"data":93124,"content":93125,"nodeType":860},{},[93126],{"data":93127,"marks":93128,"value":93129,"nodeType":864},{},[],"This blog is intended as a resource for other extension developers looking to improve the security of their extension in the wake of the Cyberhaven attacks. ",{"id":50825,"publishedAt":93131},"2026-08-12T11:54:35.418Z",{"items":93133},[93134,93136],{"sys":93135,"name":297},{"id":2732},{"sys":93137,"name":342},{"id":13775},{"items":93139},[93140,93142,93144,93146,93148,93150,93152,93154,93156,93158,93160,93162,93164,93166],{"sys":93141,"name":297,"slug":298,"tier":31},{"id":294},{"sys":93143,"name":413,"slug":414,"tier":31},{"id":410},{"sys":93145,"name":279,"slug":280,"tier":31},{"id":276},{"sys":93147,"name":616,"slug":617,"tier":31},{"id":613},{"sys":93149,"name":342,"slug":343,"tier":31},{"id":339},{"sys":93151,"name":288,"slug":289,"tier":45},{"id":285},{"sys":93153,"name":484,"slug":485,"tier":45},{"id":481},{"sys":93155,"name":607,"slug":608,"tier":45},{"id":604},{"sys":93157,"name":324,"slug":325,"tier":45},{"id":321},{"sys":93159,"name":457,"slug":458,"tier":45},{"id":454},{"sys":93161,"name":502,"slug":503,"tier":45},{"id":499},{"sys":93163,"name":633,"slug":634,"tier":45},{"id":630},{"sys":93165,"name":493,"slug":494,"tier":45},{"id":490},{"sys":93167,"name":422,"slug":423,"tier":45},{"id":419},"vrbRLYoMP8Y7pPleME4QIik_4Kc8bWXVUhV2thaWwV8",{"id":93170,"title":93171,"authorsCollection":93172,"content":93178,"extension":228,"faqItemsCollection":93565,"faqTitle":59,"featured":6,"hashTags":59,"meta":93567,"metaTitle":93568,"ogImage":59,"postType":5726,"publishedDate":93569,"relatedBlogPostsCollection":93570,"slug":94502,"stem":94503,"subtitle":59,"summary":94504,"synopsis":94515,"sys":94516,"tagsCollection":94519,"topicsCollection":94525,"__hash__":94543},"blog/blog/want-to-discover-the-full-extent-of-your-saas-sprawl-embrace-browser.json","Want to discover the full extent of your SaaS sprawl? Embrace browser extensions ",{"items":93173},[93174],{"fullName":22309,"firstName":22310,"jobTitle":22311,"socialLinks":93175,"profilePicture":93177},[93176],"https://www.linkedin.com/in/luke-jennings-042b5619b/",{"url":22313},{"json":93179,"links":93551},{"data":93180,"content":93181,"nodeType":856},{},[93182,93189,93196,93203,93210,93217,93237,93257,93264,93271,93278,93284,93291,93310,93330,93337,93344,93364,93380,93396,93403,93423,93430,93449,93456,93463,93470,93477,93484,93503,93510,93517,93524,93531,93538,93544],{"data":93183,"content":93184,"nodeType":860},{},[93185],{"data":93186,"marks":93187,"value":93188,"nodeType":864},{},[],"Security teams know they need full visibility into which SaaS platforms employees are using to even start focusing on SaaS management and security. Even better, they want to understand how employees are using them, right? ",{"data":93190,"content":93191,"nodeType":860},{},[93192],{"data":93193,"marks":93194,"value":93195,"nodeType":864},{},[],"Many people we talk to are starting to chip away at getting visibility into employee-adopted apps by using some combination of central information repositories such as email discovery, financial records, OAuth logs, SSO logs, web proxy logs, etc. So why would anyone want or need to use a browser extension? Browser extensions are the most effective SaaS discovery tool because they can capture employee SaaS use and adoption in real time, as employees sign up. The browser also allows us to work with the user to guide them to use SaaS more securely right where they’re working - in the browser.",{"data":93197,"content":93198,"nodeType":860},{},[93199],{"data":93200,"marks":93201,"value":93202,"nodeType":864},{},[],"We’ll dig into this topic a bit more in this article and we’d love to hear questions, concerns, and have a healthy debate on our social media channels, so hit us up!",{"data":93204,"content":93205,"nodeType":1312},{},[93206],{"data":93207,"marks":93208,"value":93209,"nodeType":864},{},[],"Introduction",{"data":93211,"content":93212,"nodeType":860},{},[93213],{"data":93214,"marks":93215,"value":93216,"nodeType":864},{},[],"Different approaches for discovering SaaS use have unique advantages and disadvantages and the most effective solution is usually to combine several approaches that complement one another. That being said, in the case of SaaS discovery, browser extensions have some really significant advantages that can’t be matched by other approaches - so if you could only pick one approach, then a browser extension is the way to go.",{"data":93218,"content":93219,"nodeType":860},{},[93220,93224,93233],{"data":93221,"marks":93222,"value":93223,"nodeType":864},{},[],"The first point to consider is that it is extremely common for SaaS solutions to be self-adopted by individual employees or teams within a business, without working with IT or following the established procurement process. ",{"data":93225,"content":93227,"nodeType":883},{"uri":93226},"https://track.g2.com/resources/shadow-it-statistics",[93228],{"data":93229,"marks":93230,"value":93232,"nodeType":864},{},[93231],{"type":1455},"According to G2",{"data":93234,"marks":93235,"value":93236,"nodeType":864},{},[],", 80% of workers admit to using SaaS applications at work without getting approval from IT. Employees are likely to access SaaS however is easiest and most familiar for them. So, employees aren’t going to set up a full SSO connection with your own authentication provider (on the off chance that the app even provides SSO integration). They might not be using a social login using your M365/Google tenant and they might not even be using their company email to sign up/login - they could just be using a personal webmail account.",{"data":93238,"content":93239,"nodeType":860},{},[93240,93244,93253],{"data":93241,"marks":93242,"value":93243,"nodeType":864},{},[],"That leaves security teams with limited or no visibility of employee SaaS use using other centralized methods. We found that only around 30% of SaaS providers we analyzed support SSO and of those that do, many require paying for the highest cost enterprise plan in order to gain access to it - i.e. “",{"data":93245,"content":93247,"nodeType":883},{"uri":93246},"https://sso.tax/",[93248],{"data":93249,"marks":93250,"value":93252,"nodeType":864},{},[93251],{"type":1455},"The SSO tax",{"data":93254,"marks":93255,"value":93256,"nodeType":864},{},[],".” ",{"data":93258,"content":93259,"nodeType":860},{},[93260],{"data":93261,"marks":93262,"value":93263,"nodeType":864},{},[],"Many don’t support social logins and, if they do, you’ll find M365 social logins are much less commonly supported than Google, so if you’re a Microsoft house, that pushes users towards individual email/password logins, which are far less secure.",{"data":93265,"content":93266,"nodeType":1312},{},[93267],{"data":93268,"marks":93269,"value":93270,"nodeType":864},{},[],"A comparison of data sources for SaaS discovery",{"data":93272,"content":93273,"nodeType":860},{},[93274],{"data":93275,"marks":93276,"value":93277,"nodeType":864},{},[],"We won’t do a deep dive of comparing data sources for SaaS discovery in this post, but here’s a quick and dirty overview. As we mentioned above, most companies (and off-the-shelf SaaS security and SaaS management tools) use some combination of the data sources depicted in the image below. ",{"data":93279,"content":93283,"nodeType":996},{"target":93280},{"sys":93281},{"id":93282,"type":1001,"linkType":1002},"E8ThSCqbNNa9nggaKE3p1",[],{"data":93285,"content":93286,"nodeType":860},{},[93287],{"data":93288,"marks":93289,"value":93290,"nodeType":864},{},[]," Now, it goes without saying that we’re a bit biased, but as we were deciding how to build our own SaaS discovery methods, we analyzed the pros and cons of each of these approaches before realizing that the most power was in the browser. Ease of deployment, you’ll notice, takes a bit more work than a couple other methods, but it’s worth it once you realize the powerful capabilities uniquely available in the browser. We’ll address the deployment and rollout challenges in a bit more detail later in this post. ",{"data":93292,"content":93293,"nodeType":860},{},[93294,93298,93307],{"data":93295,"marks":93296,"value":93297,"nodeType":864},{},[],"To dig into each of these approaches and how to potentially combine them to build your own SaaS discovery engine, check out ",{"data":93299,"content":93301,"nodeType":883},{"uri":93300},"https://pushsecurity.com/blog/rolling-your-own-saas-discovery/",[93302],{"data":93303,"marks":93304,"value":93306,"nodeType":864},{},[93305],{"type":1455},"this post.",{"data":93308,"marks":93309,"value":7160,"nodeType":864},{},[],{"data":93311,"content":93312,"nodeType":860},{},[93313,93317,93326],{"data":93314,"marks":93315,"value":93316,"nodeType":864},{},[],"If you already know you don’t have the resources (time, team, budget) to build your own and you’re thinking about evaluating solutions, head over to ",{"data":93318,"content":93320,"nodeType":883},{"uri":93319},"https://pushsecurity.com/blog/how-to-find-the-right-saas-security-solution-for-your-organization/",[93321],{"data":93322,"marks":93323,"value":93325,"nodeType":864},{},[93324],{"type":1455},"this post",{"data":93327,"marks":93328,"value":93329,"nodeType":864},{},[]," to understand which might be the best fit for your company. ",{"data":93331,"content":93332,"nodeType":860},{},[93333],{"data":93334,"marks":93335,"value":93336,"nodeType":864},{},[],"Next, we’ll dig into how we manage our own SaaS security to provide some relevant context and we’ll explain where the browser extension fits in",{"data":93338,"content":93339,"nodeType":1312},{},[93340],{"data":93341,"marks":93342,"value":93343,"nodeType":864},{},[],"A case study…with us!",{"data":93345,"content":93346,"nodeType":860},{},[93347,93351,93360],{"data":93348,"marks":93349,"value":93350,"nodeType":864},{},[],"To put this into context, we’ll use ourselves as an example, since we’re a fully SaaS-native company. Our entire business is SaaS security, we have no physical or virtual infrastructure to manage and we actively encourage our employees to self-adopt SaaS solutions to solve their own business needs. We’re also a Google workspace enterprise customer and we educate our employees to ",{"data":93352,"content":93354,"nodeType":883},{"uri":93353},"https://pushsecurity.com/blog/should-i-let-my-employees-login-with-their-work-google-account",[93355],{"data":93356,"marks":93357,"value":93359,"nodeType":864},{},[93358],{"type":1455},"always use Google social logins",{"data":93361,"marks":93362,"value":93363,"nodeType":864},{},[]," for SaaS solutions as the first choice when available ). ",{"data":93365,"content":93366,"nodeType":860},{},[93367,93371,93376],{"data":93368,"marks":93369,"value":93370,"nodeType":864},{},[],"We tuck all SaaS apps behind SSO, wherever we can and wherever our licenses will let us. And since we’re a fairly new company, we’ve been able to push social logins and “login with Google” to our employees since day one, so that’s a pretty clean and ideal world compared to the environments many security folks are working in. This means we really should be a best case example when it comes to centralized SaaS discovery methods. That said, we also use almost 100 different SaaS platforms across the company and, despite everything else above, 33% of these SaaS platforms are ",{"data":93372,"marks":93373,"value":93375,"nodeType":864},{},[93374],{"type":2246},"only ",{"data":93377,"marks":93378,"value":93379,"nodeType":864},{},[],"visible because we’re using a browser extension to discover them as our employees sign up.",{"data":93381,"content":93382,"nodeType":860},{},[93383,93387,93392],{"data":93384,"marks":93385,"value":93386,"nodeType":864},{},[],"A similar company without a browser extension ",{"data":93388,"marks":93389,"value":93391,"nodeType":864},{},[93390],{"type":899},"could be missing out on a third of their SaaS platforms",{"data":93393,"marks":93394,"value":93395,"nodeType":864},{},[],". Once we look at similar stats for our customers, particularly M365 users, we see the percentage of SaaS platforms that are only discovered via the browser extension increase and this is sometimes even as high as 70-80%. If you’re serious about SaaS discovery, then you should really not settle for missing such a large percentage of platforms.",{"data":93397,"content":93398,"nodeType":1312},{},[93399],{"data":93400,"marks":93401,"value":93402,"nodeType":864},{},[],"Why does a browser see so much more?",{"data":93404,"content":93405,"nodeType":860},{},[93406,93410,93419],{"data":93407,"marks":93408,"value":93409,"nodeType":864},{},[],"Since SaaS is often self-adopted, the problem can often be attributed to a decentralized problem. Many SaaS vendors even encourage this as they have a product-led growth (PLG) model and prefer the frictionless growth of a PLG model over the high-friction sales cycle in a centralized procurement model. We’ve got a ",{"data":93411,"content":93413,"nodeType":883},{"uri":93412},"https://pushsecurity.com/webinar/securing-employee-adopted-saas-apps",[93414],{"data":93415,"marks":93416,"value":93418,"nodeType":864},{},[93417],{"type":1455},"webinar with our co-founder",{"data":93420,"marks":93421,"value":93422,"nodeType":864},{},[]," on this topic if you want to explore further. ",{"data":93424,"content":93425,"nodeType":860},{},[93426],{"data":93427,"marks":93428,"value":93429,"nodeType":864},{},[],"Additionally, your average non-technical employee may not be familiar with SSO or social logins as access methods, but everyone knows how to sign-up for a website with an email address, username and password. Consequently, it’s just common for centralized data sources to end up missing a lot of SaaS use if they’re looking at logs, proxies, and other data sources.",{"data":93431,"content":93432,"nodeType":860},{},[93433,93437,93445],{"data":93434,"marks":93435,"value":93436,"nodeType":864},{},[],"Without SSO or social logins, you aren’t seeing anything via those data sources. If you use email discovery, you’ll have lots of false positives to deal with from marketing spam and you’ll only know about it for employees that used their corporate email address and for SaaS platforms that actively send out emails. If you’re relying on network data sources like web proxy data then you need to be capturing everything including home/mobile employees and even then most details will be hidden behind HTTPS connections. You could intercept and decrypt all HTTPS traffic via your proxy, but then you’d be introducing a huge security risk by decrypting all communications in one place. We’ve got a more thorough article on the topic of ",{"data":93438,"content":93439,"nodeType":883},{"uri":93300},[93440],{"data":93441,"marks":93442,"value":93444,"nodeType":864},{},[93443],{"type":1455},"SaaS discovery data sources ",{"data":93446,"marks":93447,"value":93448,"nodeType":864},{},[],"and their pros and cons to read up on, too. ",{"data":93450,"content":93451,"nodeType":860},{},[93452],{"data":93453,"marks":93454,"value":93455,"nodeType":864},{},[],"On the other hand, browsers are quickly becoming the main way people operate from a desktop environment, with the browser as the way they’re doing almost every task. Since they’re using the browser to access their apps, it makes sense to use data collected from the browser to get visibility of SaaS. It doesn’t matter if they use an SSO login, a social login, an email address/password login, a corporate email or a personal webmail account - as long as they login or access the SaaS platform from a browser, then a browser extension is best placed to see that. Wherever the user is in the world, whatever they are doing, the extension can keep an eye out.",{"data":93457,"content":93458,"nodeType":1312},{},[93459],{"data":93460,"marks":93461,"value":93462,"nodeType":864},{},[],"There are so many other security benefits beyond basic visibility",{"data":93464,"content":93465,"nodeType":860},{},[93466],{"data":93467,"marks":93468,"value":93469,"nodeType":864},{},[],"We’ve covered general visibility of SaaS platforms (i.e. whether they are in use or not, what login method is in use and by who), but there’s much more useful information for managing SaaS security risks. To secure SaaS, you also need to know whether multi-factor authentication (MFA) is in use; If the password is secure; If passwords are shared between different accounts; If accounts are shared between users; If sensitive files are uploaded to a particular SaaS platform.",{"data":93471,"content":93472,"nodeType":860},{},[93473],{"data":93474,"marks":93475,"value":93476,"nodeType":864},{},[],"Some SaaS vendors may provide APIs and logs that can answer some of these questions, but this tends to be limited to the biggest or most security conscious vendors. It’s overwhelming to handle this manually because you need to consider separate integrations with all your different SaaS vendors, and that’s assuming you already know they are in use. It might be viable for some of the most important SaaS platforms you use (think Salesforce, Slack, Trello, etc.) , but it’s not easy to go much further when you have hundreds of different SaaS platforms to consider.",{"data":93478,"content":93479,"nodeType":860},{},[93480],{"data":93481,"marks":93482,"value":93483,"nodeType":864},{},[],"A browser extension, on the other hand, can see all the interactions between users and any given SaaS platform, so it can provide insights that may not be visible via a SaaS vendor’s own APIs or logs. This is especially true for fairly standardized mechanisms such as web-based logins, where it provides an easy opportunity to provide password security checks and MFA checks. ",{"data":93485,"content":93486,"nodeType":860},{},[93487,93491,93500],{"data":93488,"marks":93489,"value":93490,"nodeType":864},{},[],"Being a decentralized model, this can all be achieved without sending lots of highly sensitive data (e.g. passwords) to a centralized point. Instead, the browser extension can just report individual security findings as necessary without feeding that private data to a central repository. The Push browser extension identifies weak passwords in use, MFA status, passwords shared between different SaaS platforms and even accounts being shared by multiple different users - none of this requires sending passwords or any other sensitive data to our central servers - just the findings themselves. You can find more information about what data we collect ",{"data":93492,"content":93494,"nodeType":883},{"uri":93493},"https://pushsecurity.com/help/audience/administrators/docs/install-the-browser-extension",[93495],{"data":93496,"marks":93497,"value":93499,"nodeType":864},{},[93498],{"type":1455},"here",{"data":93501,"marks":93502,"value":11546,"nodeType":864},{},[],{"data":93504,"content":93505,"nodeType":1312},{},[93506],{"data":93507,"marks":93508,"value":93509,"nodeType":864},{},[],"How do I roll out a browser extension to every single employee?",{"data":93511,"content":93512,"nodeType":860},{},[93513],{"data":93514,"marks":93515,"value":93516,"nodeType":864},{},[],"Traditionally, browser extensions have been focused on self-adoption by users via a browser extension store. In that case, the user makes the decision to install, rather than IT or security managing the deployment.",{"data":93518,"content":93519,"nodeType":860},{},[93520],{"data":93521,"marks":93522,"value":93523,"nodeType":864},{},[],"However, the major browser vendors have made it easy to install and manage browser extensions centrally, as well as making them more resilient to ensure they’re both secure and cannot induce significant performance issues in the browser.",{"data":93525,"content":93526,"nodeType":860},{},[93527],{"data":93528,"marks":93529,"value":93530,"nodeType":864},{},[],"Most larger organizations will be familiar with deploying desktop software remotely using central device management software, especially for endpoint security software like anti-virus and EDR. The same idea works with a browser extension using most of the common browser and operating system combinations. The Push browser extension can be deployed centrally on Chrome, Edge, Firefox and Brave, depending on the device management software and operating system in use. ",{"data":93532,"content":93533,"nodeType":860},{},[93534],{"data":93535,"marks":93536,"value":93537,"nodeType":864},{},[],"What’s more, browser extensions consist of JavaScript running in a tightly-controlled environment with additional performance controls in place by the browser and they even auto-update too. Compare this with the common case for endpoint security software of having an agent running as SYSTEM/root and users complaining it’s stealing all their CPU cycles and centralized browser deployment starts looking like a more attractive prospect than traditional endpoint agent deployment.",{"data":93539,"content":93540,"nodeType":1312},{},[93541],{"data":93542,"marks":93543,"value":51911,"nodeType":864},{},[],{"data":93545,"content":93546,"nodeType":860},{},[93547],{"data":93548,"marks":93549,"value":93550,"nodeType":864},{},[],"We’re pretty into browser extensions here, but it’s not just because that’s how our product works. We’re not trying to sell you a new thing just for the sake of building something novel. Browser extensions are going to become one of the most important methods of managing SaaS security going forward. They’ve got advantages that other approaches just can’t match and centralized deployment and management is now a slick, easy and - frankly - solved problem. ",{"entries":93552},{"hyperlink":93553,"inline":93554,"block":93555},[],[],[93556],{"sys":93557,"__typename":1724,"title":93558,"caption":93559,"layoutMode":93560,"file":93561},{"id":93282},"SaaS discovery data source comparison","Strengths and weaknesses for finding employee SaaS use via commonly-used discovery data sources ","Centre aligned",{"url":93562,"width":93563,"height":93564},"https://images.ctfassets.net/y1cdw1ablpvd/7FRyXaw4o4baUqG1cta41n/57a9476e83daf0386600c5bb8d4e827b/Screenshot_2023-04-24_at_9.09.16_AM.png",1796,1010,{"items":93566},[],{},"Use browser extension to see the extent of your SaaS sprawl","2023-04-25T00:00:00.000Z",{"items":93571},[93572,93916],{"__typename":2059,"sys":93573,"content":93575,"title":93902,"synopsis":93903,"hashTags":59,"publishedDate":93904,"slug":93905,"tagsCollection":93906,"authorsCollection":93912},{"id":93574},"4LOMe7ez5adQtwbPireIBc",{"json":93576},{"data":93577,"content":93578,"nodeType":856},{},[93579,93586,93607,93614,93621,93628,93635,93642,93649,93656,93663,93670,93677,93684,93691,93707,93714,93721,93728,93735,93742,93749,93767,93774,93781,93788,93794,93801,93809,93842,93850,93883],{"data":93580,"content":93581,"nodeType":860},{},[93582],{"data":93583,"marks":93584,"value":93585,"nodeType":864},{},[],"As part of your larger cloud security strategy, you’ve likely been asked to focus on how to secure SaaS apps used in your company. The first step to securing SaaS is getting a real sense of what platforms employees are actually using, beyond those that you already know about. Since SaaS is so easy for employees to adopt and start using without any input from IT and security, they’re likely using hundreds of SaaS apps that aren’t even on your radar. The first step in securing something is getting full visibility into what you even need to secure in the first place. ",{"data":93587,"content":93588,"nodeType":860},{},[93589,93593,93603],{"data":93590,"marks":93591,"value":93592,"nodeType":864},{},[],"To help guide folks through how you might do SaaS discovery on your own, we wrote an ",{"data":93594,"content":93598,"nodeType":39736},{"target":93595},{"sys":93596},{"id":93597,"type":1001,"linkType":1002},"45iZ69EdPF4629gZ6yf7p5",[93599],{"data":93600,"marks":93601,"value":93602,"nodeType":864},{},[],"article",{"data":93604,"marks":93605,"value":93606,"nodeType":864},{},[]," about how to manually find what apps employees are using. In it, we explored how to analyze data that you already have on hand to find the unknown apps (shadow IT) used within your business. That’s a pretty significant manual effort, though, and most security teams don’t have the resources to do it. Plus, while these manual attempts can chip away at the SaaS discovery process, none are great at giving you a comprehensive view of SaaS use, nor do they keep up with the constant influx of apps employees are signing up for daily. ",{"data":93608,"content":93609,"nodeType":860},{},[93610],{"data":93611,"marks":93612,"value":93613,"nodeType":864},{},[],"To get truly broad coverage of what SaaS employees are using, you need a large dataset of SaaS apps, the domains associated with them, and this dataset must constantly be updated and expanded to include new apps that are launched every day. ",{"data":93615,"content":93616,"nodeType":860},{},[93617],{"data":93618,"marks":93619,"value":93620,"nodeType":864},{},[],"Unless you can find such a dataset, you must create it. And creating a constantly updated dataset is no small undertaking. That’s why there are so many off-the-shelf solutions and tools that focus solely on SaaS discovery these days. Many say that they are full-scale SaaS security platforms, but what that means isn’t always clear, even after reading product marketing materials. If you were to look at a venn diagram of “SaaS security platforms,” you’d have a giant mess of interlocking circles, with some shared activities amongst all (or most) tools and then vastly different features from that core functionality.",{"data":93622,"content":93623,"nodeType":860},{},[93624],{"data":93625,"marks":93626,"value":93627,"nodeType":864},{},[],"How “good” they are at SaaS discovery really depends on what data they’re using, what they have access to within your environment, the quality of their proprietary datasets (breadth, depth, and timeliness of that data), and how they work with your existing data and tools. To help navigate this mess, we’re sharing some pros and cons of the categories of commercial tools on the market.",{"data":93629,"content":93630,"nodeType":860},{},[93631],{"data":93632,"marks":93633,"value":93634,"nodeType":864},{},[],"To determine which solution you need, you need to consider your tech stack, your specific needs, your risk tolerance, and your short and long term objectives. In this article, we’ll break down some major use cases and match them up with what solutions make the most sense to address them.",{"data":93636,"content":93637,"nodeType":1312},{},[93638],{"data":93639,"marks":93640,"value":93641,"nodeType":864},{},[],"You’re a large enterprise interested in securing core SaaS platforms",{"data":93643,"content":93644,"nodeType":860},{},[93645],{"data":93646,"marks":93647,"value":93648,"nodeType":864},{},[],"\nWorking to only secure 20 or so core applications that have already been sanctioned by the security team? A cloud security posture management (CSPM) or SaaS security posture management (SSPM) solution might be the answer you’re looking for, particularly if you’re on the highest tier license for those apps. ",{"data":93650,"content":93651,"nodeType":860},{},[93652],{"data":93653,"marks":93654,"value":93655,"nodeType":864},{},[],"You can make the most of these tools during in-depth investigations or threat hunting exercises. Leverage them to enforce custom SaaS or cloud app policies as well. The caveat with this one is that you’ll need a fairly sophisticated security team to manage, customize, and run SSPM and CSPM tools.",{"data":93657,"content":93658,"nodeType":860},{},[93659],{"data":93660,"marks":93661,"value":93662,"nodeType":864},{},[],"An ideal environment for these solutions is one that has a full SOC capability so that you extend your existing security monitoring and threat hunting coverage into these core SaaS platforms. You’ll be able to secure a small handful of your business critical applications as long as they’re large and well-established platforms. ",{"data":93664,"content":93665,"nodeType":860},{},[93666],{"data":93667,"marks":93668,"value":93669,"nodeType":864},{},[],"The reason you’ll need top-level licenses and well-established SaaS platforms to make these solutions work is because they rely on API data from those SaaS platforms. Those mature APIs provide necessary information about those core apps that CSPMs and SSPMs use to provide security insights you need to manage the risks. Unfortunately, they won’t cover the dozens of smaller SaaS apps most organizations use, and are normally only available on top license tiers.",{"data":93671,"content":93672,"nodeType":1312},{},[93673],{"data":93674,"marks":93675,"value":93676,"nodeType":864},{},[],"You’re a more traditional, on-prem enterprise interested in blocking unsanctioned SaaS",{"data":93678,"content":93679,"nodeType":860},{},[93680],{"data":93681,"marks":93682,"value":93683,"nodeType":864},{},[],"If your environment is traditional on-site internal networks and you have mature gateway monitoring technology in place already, a cloud access security broker (CASB) may be your best path to securing cloud apps. CASBs work best if you have no employees working from home or on the road or you’re forcing employees to only access work platforms and internet browsers through your corporate VPN.",{"data":93685,"content":93686,"nodeType":860},{},[93687],{"data":93688,"marks":93689,"value":93690,"nodeType":864},{},[],"CASBs typically pull network data such as DNS, SASE, VPN, proxy, and firewall logs. They may also require that you install an agent on each employees’ devices if you want coverage when they are out of the office. ",{"data":93692,"content":93693,"nodeType":860},{},[93694,93698,93703],{"data":93695,"marks":93696,"value":93697,"nodeType":864},{},[],"With those data sources, they provide good aggregate information about SaaS platforms that are accessed. What they ",{"data":93699,"marks":93700,"value":93702,"nodeType":864},{},[93701],{"type":2246},"can’t do well",{"data":93704,"marks":93705,"value":93706,"nodeType":864},{},[]," is provide any insight into how the SaaS app is being used, by which employees (you typically get IP addresses not user names), and for what purpose - as an example, they are typically not able to tell the difference between opening a SaaS product’s homepage, or actually logging into the application - so you are going to have a fairly large number of false positives. ",{"data":93708,"content":93709,"nodeType":860},{},[93710],{"data":93711,"marks":93712,"value":93713,"nodeType":864},{},[],"A CASB also really makes sense if you’re forced into complying with strict regulatory requirements to block everything until you’re able to do an in-depth due diligence process on each app. If your goal (or need) is to block access to unknown, unvetted, or unsanctioned SaaS at the network level with no exceptions, a CASB might be for you.",{"data":93715,"content":93716,"nodeType":1312},{},[93717],{"data":93718,"marks":93719,"value":93720,"nodeType":864},{},[],"You’re a cloud-native company who wants to enable SaaS without introducing too much risk",{"data":93722,"content":93723,"nodeType":860},{},[93724],{"data":93725,"marks":93726,"value":93727,"nodeType":864},{},[],"For cloud-native companies that need better coverage, and are looking for more nuanced controls than network-level blocking, a solution that discovers and secures SaaS through the browser is the way to go. Since employees access SaaS through their browser, it’s a logical step to collect data about who is using what apps through a browser extension. ",{"data":93729,"content":93730,"nodeType":860},{},[93731],{"data":93732,"marks":93733,"value":93734,"nodeType":864},{},[],"The browser approach lets you do true SaaS discovery - so you can find what employees are actually using (not just accessing) and then go about securing those apps. You also don’t need to do much in terms of managing a browser-based solution once it’s set up. It simply runs in the background and surfaces employee SaaS use data into a dashboard. ",{"data":93736,"content":93737,"nodeType":860},{},[93738],{"data":93739,"marks":93740,"value":93741,"nodeType":864},{},[],"By combining browser-level data and robust security APIs from those core business platforms that SSPMs typically tap into, you can get broad visibility of SaaS use in your company for those large in number, but less mature, more up-and-coming apps, and the depth of security data you need for those few core apps that most employees are using. ",{"data":93743,"content":93744,"nodeType":860},{},[93745],{"data":93746,"marks":93747,"value":93748,"nodeType":864},{},[],"The other key benefit of a browser-based approach for SaaS discovery is that you can get incredibly powerful data about who is using the app, how they’re using it, if they’re using security features such as MFA, if they’re reusing passwords across multiple apps, if they’re sharing passwords, when they’ve used it last, and so on. That data is critical when it comes to securing SaaS because the devil truly is in the details. ",{"data":93750,"content":93751,"nodeType":860},{},[93752,93756,93764],{"data":93753,"marks":93754,"value":93755,"nodeType":864},{},[],"If we’ve piqued your interest and you’re curious to see what we can discover about SaaS in your business, ",{"data":93757,"content":93759,"nodeType":883},{"uri":93758},"https://login.pushsecurity.com/",[93760],{"data":93761,"marks":93762,"value":93763,"nodeType":864},{},[],"try the free browser extension",{"data":93765,"marks":93766,"value":11546,"nodeType":864},{},[],{"data":93768,"content":93769,"nodeType":1312},{},[93770],{"data":93771,"marks":93772,"value":93773,"nodeType":864},{},[],"Consider their data sources  ",{"data":93775,"content":93776,"nodeType":860},{},[93777],{"data":93778,"marks":93779,"value":93780,"nodeType":864},{},[],"The critical thing to understand when you’re evaluating if a solution will work for you would be understanding what their data sources are, what weaknesses those data sources inherently have, and what aligns best with your goals. We’ve tried to surface some of that information within the use cases in this article.",{"data":93782,"content":93783,"nodeType":860},{},[93784],{"data":93785,"marks":93786,"value":93787,"nodeType":864},{},[],"So if you’re looking at an EDR that says they can discover SaaS usage, they’ll likely be leveraging endpoint data to detect SaaS use. If you’re looking at CASBs that integrate with your proxy, they’re probably looking at network level data – you get the idea.  ",{"data":93789,"content":93790,"nodeType":1312},{},[93791],{"data":93792,"marks":93793,"value":51911,"nodeType":864},{},[],{"data":93795,"content":93796,"nodeType":860},{},[93797],{"data":93798,"marks":93799,"value":93800,"nodeType":864},{},[],"To wrap this up, we’re going to summarize some key points and provide some questions to ask yourself, your team, or even the vendor of the solution you’re evaluating, as you consider what combination of efforts or what tool is right for you. ",{"data":93802,"content":93803,"nodeType":860},{},[93804],{"data":93805,"marks":93806,"value":93808,"nodeType":864},{},[93807],{"type":899},"Does this solution provide SaaS discovery?",{"data":93810,"content":93811,"nodeType":941},{},[93812,93822,93832],{"data":93813,"content":93814,"nodeType":945},{},[93815],{"data":93816,"content":93817,"nodeType":860},{},[93818],{"data":93819,"marks":93820,"value":93821,"nodeType":864},{},[],"Will this tool find what SaaS apps employees are using, including those you don’t already know about? If so, how? ",{"data":93823,"content":93824,"nodeType":945},{},[93825],{"data":93826,"content":93827,"nodeType":860},{},[93828],{"data":93829,"marks":93830,"value":93831,"nodeType":864},{},[],"Will the tool be able to differentiate between a user visiting a SaaS website, and actually logging into the app? How will it determine who the user is?",{"data":93833,"content":93834,"nodeType":945},{},[93835],{"data":93836,"content":93837,"nodeType":860},{},[93838],{"data":93839,"marks":93840,"value":93841,"nodeType":864},{},[],"If the tool doesn’t provide you with SaaS discovery (finding Shadow IT and the apps employees are using that aren’t on your radar), how will you deal with those apps employees are using without your knowledge?",{"data":93843,"content":93844,"nodeType":860},{},[93845],{"data":93846,"marks":93847,"value":93849,"nodeType":864},{},[93848],{"type":899},"Does the tool provide enough context so you can manage SaaS risk?",{"data":93851,"content":93852,"nodeType":941},{},[93853,93863,93873],{"data":93854,"content":93855,"nodeType":945},{},[93856],{"data":93857,"content":93858,"nodeType":860},{},[93859],{"data":93860,"marks":93861,"value":93862,"nodeType":864},{},[],"Are you getting context about how your users are using apps (are they logging in with social logins or passwords, do they have MFA enabled, are they admins on the app, etc.), or is it only providing generic information about the app?",{"data":93864,"content":93865,"nodeType":945},{},[93866],{"data":93867,"content":93868,"nodeType":860},{},[93869],{"data":93870,"marks":93871,"value":93872,"nodeType":864},{},[],"How will you engage employees that already rely on these SaaS platforms, or want to adopt new apps, can you handle that though email or in-person - or do you need something more scalable?",{"data":93874,"content":93875,"nodeType":945},{},[93876],{"data":93877,"content":93878,"nodeType":860},{},[93879],{"data":93880,"marks":93881,"value":93882,"nodeType":864},{},[],"Do you need the ability to apply progressive controls, or simply need the ability to block apps entirely?",{"data":93884,"content":93885,"nodeType":860},{},[93886,93890,93898],{"data":93887,"marks":93888,"value":93889,"nodeType":864},{},[],"\nIf you aren’t sure about these questions, why not consider what a ",{"data":93891,"content":93893,"nodeType":883},{"uri":93892},"/product",[93894],{"data":93895,"marks":93896,"value":93897,"nodeType":864},{},[],"user-powered security approach",{"data":93899,"marks":93900,"value":93901,"nodeType":864},{},[]," might look like for your organization.","How to find the right SaaS security solution for your organization ","In this guide, we’ll break down some major SaaS use cases and match them up with solutions that can address them, covering pros and cons for each.\n","2022-07-25T00:00:00.000Z","how-to-find-the-right-saas-security-solution-for-your-organization",{"items":93907},[93908,93910],{"sys":93909,"name":4904},{"id":4903},{"sys":93911,"name":2729},{"id":2728},{"items":93913},[93914],{"fullName":52068,"firstName":52069,"jobTitle":52070,"profilePicture":93915},{"url":52072},{"__typename":2059,"sys":93917,"content":93918,"title":94482,"synopsis":94483,"hashTags":94484,"publishedDate":94490,"slug":94491,"tagsCollection":94492,"authorsCollection":94498},{"id":93597},{"json":93919},{"data":93920,"content":93921,"nodeType":856},{},[93922,93929,93936,93943,93950,93957,93982,93989,93996,94003,94010,94021,94028,94067,94092,94099,94106,94122,94129,94136,94152,94159,94167,94183,94190,94197,94204,94212,94219,94226,94233,94261,94324,94331,94338,94345,94361,94368,94384,94391,94403,94410,94430,94436,94453],{"data":93923,"content":93924,"nodeType":860},{},[93925],{"data":93926,"marks":93927,"value":93928,"nodeType":864},{},[],"Over the past few years, there’s been massive growth in the number of SaaS apps used for work. With that comes new challenges – how do you allow employees to take advantage of all the SaaS the world has to offer without locking it all down and stifling innovation? How do you figure out if you can trust all these new third parties with access to your data? Well, the first step is figuring out which apps employees are actually using, so that’s where we’re starting.",{"data":93930,"content":93931,"nodeType":860},{},[93932],{"data":93933,"marks":93934,"value":93935,"nodeType":864},{},[],"We’ve compiled a list of various options and approaches we’ve seen people take to SaaS discovery, each with their own pros and cons. ",{"data":93937,"content":93938,"nodeType":1009},{},[93939],{"data":93940,"marks":93941,"value":93942,"nodeType":864},{},[],"Why is SaaS discovery so hard?",{"data":93944,"content":93945,"nodeType":860},{},[93946],{"data":93947,"marks":93948,"value":93949,"nodeType":864},{},[],"\nSomething to note straight off the bat is that with all the data-driven approaches we’re about to cover, you have to know how to extract SaaS use out of that data. That’s one of the reasons SaaS discovery is so hard. With the roll-your-own approaches in this post, you’ll be able to identify some common apps (like Trello, Slack, Dropbox, etc.), but what about all the new or lesser-known apps? Unfortunately, trying to keep track of all the SaaS apps that are available to employees is really difficult. There’s not really a great master list available on the Internet for you to cross-reference with your data.",{"data":93951,"content":93952,"nodeType":860},{},[93953],{"data":93954,"marks":93955,"value":93956,"nodeType":864},{},[],"That means that all of these roll-your-own approaches are dependent on you knowing what you’re looking for. If you must know what SaaS you’re looking for in order to determine if an asset is actually a SaaS app, you’re going to be left with quite a few blindspots given there seem to be new apps launching every day. ",{"data":93958,"content":93959,"nodeType":860},{},[93960,93964,93969,93973,93978],{"data":93961,"marks":93962,"value":93963,"nodeType":864},{},[],"The second hurdle with a roll-your-own discovery approach is differentiating between SaaS ",{"data":93965,"marks":93966,"value":93968,"nodeType":864},{},[93967],{"type":2246},"access",{"data":93970,"marks":93971,"value":93972,"nodeType":864},{},[]," and SaaS ",{"data":93974,"marks":93975,"value":93977,"nodeType":864},{},[93976],{"type":2246},"usage",{"data":93979,"marks":93980,"value":93981,"nodeType":864},{},[],". Just because an employee accesses a SaaS website, it doesn’t mean they’re using their app. Most of the data sources will produce a ton of domains, IPs, etc. for you to sift through, but differentiating access and usage based on this information alone will produce a large number of false positives unless you can correlate it with other data sources (we suggest some below). You will likely also want to know things like exactly who the users, owners and administrators of the app are which will be all but impossible from this “access” data alone.",{"data":93983,"content":93984,"nodeType":860},{},[93985],{"data":93986,"marks":93987,"value":93988,"nodeType":864},{},[],"If we ignore for the moment the difficulties in extracting information about SaaS usage, let’s run through your options for data sources and see which ones will give you the most useful data.",{"data":93990,"content":93991,"nodeType":1009},{},[93992],{"data":93993,"marks":93994,"value":93995,"nodeType":864},{},[],"Collecting financial records",{"data":93997,"content":93998,"nodeType":860},{},[93999],{"data":94000,"marks":94001,"value":94002,"nodeType":864},{},[],"Looking through invoices can provide some visibility into paid SaaS apps, which is probably the lowest false positive data source. However, there are blind spots - you won’t see any free tier or trial accounts, nor will you get any useful business context about who’s using it, how they’re using it, if logins are secure, and what data it has access to. That said, it’s a quick and dirty way to get a partial view of SaaS usage, and might be the best place to start.",{"data":94004,"content":94005,"nodeType":1009},{},[94006],{"data":94007,"marks":94008,"value":94009,"nodeType":864},{},[],"Network-level",{"data":94011,"content":94012,"nodeType":860},{},[94013,94016],{"data":94014,"marks":94015,"value":39614,"nodeType":864},{},[],{"data":94017,"marks":94018,"value":94020,"nodeType":864},{},[94019],{"type":2246},"Summary: Network level data is the standard old-school approach. If you already have great network monitoring in place it provides fairly broad visibility. There are some very key limitations especially around inferring usage from access, as well as outside the office visibility problems.",{"data":94022,"content":94023,"nodeType":860},{},[94024],{"data":94025,"marks":94026,"value":94027,"nodeType":864},{},[],"SaaS apps are accessed over a network - and so that seems like a sensible place to start looking for them. What if we just tried looking for all users accessing a SaaS app’s website? Let’s say we want to see if anyone is using e.g. Dropbox, so we do a Google search for all Dropbox domains and we find Dropbox.com, and a few regional domains as well. We then set about finding employees accessing those domains in our network logs - simple! Perhaps not so much…",{"data":94029,"content":94030,"nodeType":860},{},[94031,94035,94039,94043,94048,94052,94056,94060,94064],{"data":94032,"marks":94033,"value":94034,"nodeType":864},{},[],"As we mentioned in the intro, the best outcome you can hope for is to uncover SaaS ",{"data":94036,"marks":94037,"value":93968,"nodeType":864},{},[94038],{"type":2246},{"data":94040,"marks":94041,"value":94042,"nodeType":864},{},[],", not ",{"data":94044,"marks":94045,"value":94047,"nodeType":864},{},[94046],{"type":2246},"usage.",{"data":94049,"marks":94050,"value":94051,"nodeType":864},{},[]," This might seem like a subtle difference, but SaaS usage is what you want to find, not just information about which employees visited a SaaS website. If you’re looking at all app ",{"data":94053,"marks":94054,"value":93968,"nodeType":864},{},[94055],{"type":2246},{"data":94057,"marks":94058,"value":94059,"nodeType":864},{},[],", you’ll wind up with a massive list of SaaS, with only a portion of it indicating SaaS ",{"data":94061,"marks":94062,"value":93977,"nodeType":864},{},[94063],{"type":2246},{"data":94065,"marks":94066,"value":2924,"nodeType":864},{},[],{"data":94068,"content":94069,"nodeType":860},{},[94070,94074,94079,94083,94088],{"data":94071,"marks":94072,"value":94073,"nodeType":864},{},[],"Since you can’t discover app ",{"data":94075,"marks":94076,"value":94078,"nodeType":864},{},[94077],{"type":2246},"usage ",{"data":94080,"marks":94081,"value":94082,"nodeType":864},{},[],"with network data, you’d have to tie network traffic to a single employee to identify the user, then reach out to each employee to understand the business context of how they’re using the app. A network data approach can work ",{"data":94084,"marks":94085,"value":94087,"nodeType":864},{},[94086],{"type":2246},"if",{"data":94089,"marks":94090,"value":94091,"nodeType":864},{},[]," you have time to get that context by asking employees if they’re using the SaaS detected or by corroborating your findings with subscription invoices from the finance team. ",{"data":94093,"content":94094,"nodeType":860},{},[94095],{"data":94096,"marks":94097,"value":94098,"nodeType":864},{},[],"A few ways to collect SaaS data on the network level are ingesting firewall, web proxy and DNS and VPN logs. These inputs can give you some additional visibility into SaaS access, but you may still be left with significant blind spots to actual usage if you assume it all takes place on the corporate network using a VPN. It’s also a painfully tedious process. That said, a manual process still is better than having no SaaS visibility at all. ",{"data":94100,"content":94101,"nodeType":1009},{},[94102],{"data":94103,"marks":94104,"value":94105,"nodeType":864},{},[],"Endpoint-level",{"data":94107,"content":94108,"nodeType":860},{},[94109,94114,94117],{"data":94110,"marks":94111,"value":94113,"nodeType":864},{},[94112],{"type":2246},"Summary: Endpoint",{"data":94115,"marks":94116,"value":1171,"nodeType":864},{},[],{"data":94118,"marks":94119,"value":94121,"nodeType":864},{},[94120],{"type":2246},"data is hard to get, and of limited value. However, it may be useful if you already have this data available in a SIEM or if it’s otherwise easy to query.",{"data":94123,"content":94124,"nodeType":860},{},[94125],{"data":94126,"marks":94127,"value":94128,"nodeType":864},{},[],"Perhaps we’ll get closer to what we need (usage data instead of just access data and a low false positive rate) if we move up a level and get closer to the users? Users are going to be accessing the SaaS apps through some kind of endpoint and there are some things you could use to do discovery if you have some monitoring capability on that endpoint.",{"data":94130,"content":94131,"nodeType":860},{},[94132],{"data":94133,"marks":94134,"value":94135,"nodeType":864},{},[],"For example, many SaaS apps have desktop or mobile clients (thick clients) you install. You could look for e.g. the Slack client, or the OneDrive sync agent installed on the endpoint. However, many users prefer the in-browser version, so they may not have even installed the thick client and you wouldn’t see their usage by looking at their endpoint data. ",{"data":94137,"content":94138,"nodeType":860},{},[94139,94143,94148],{"data":94140,"marks":94141,"value":94142,"nodeType":864},{},[],"All the good data, the application level data, is in the browser, which is technically on the endpoint but not really accessible ",{"data":94144,"marks":94145,"value":94147,"nodeType":864},{},[94146],{"type":2246},"through the endpoint",{"data":94149,"marks":94150,"value":94151,"nodeType":864},{},[]," without doing something very hacky. Perhaps we need to go a level deeper - either closer to the application or get inside the browser.",{"data":94153,"content":94154,"nodeType":1009},{},[94155],{"data":94156,"marks":94157,"value":94158,"nodeType":864},{},[],"Application-level",{"data":94160,"content":94161,"nodeType":860},{},[94162],{"data":94163,"marks":94164,"value":94166,"nodeType":864},{},[94165],{"type":2246},"Summary: Application level integrations are very useful for discovering unsanctioned SaaS apps that are integrated with the SaaS apps you already know about. But when used in isolation, they have massive blind spots. Application-level data is also a goldmine for finding out how securely employees use the app.",{"data":94168,"content":94169,"nodeType":860},{},[94170,94174,94179],{"data":94171,"marks":94172,"value":94173,"nodeType":864},{},[],"Focusing on the SaaS app directly makes a lot of sense if you need to get really high quality usage data. The challenge is that you need to integrate with the SaaS app to get at this data. And you can’t just integrate with an app like Slack or Trello. In general, these integrations must be within a specific account or tenant that your employees are using if you want to see any of their usage or security data. So, if you must already know about the tenant to discover the SaaS - is this approach useless for detecting unknown SaaS? Maybe, ",{"data":94175,"marks":94176,"value":94178,"nodeType":864},{},[94177],{"type":2246},"but ",{"data":94180,"marks":94181,"value":94182,"nodeType":864},{},[],"there are some very useful edge cases.",{"data":94184,"content":94185,"nodeType":860},{},[94186],{"data":94187,"marks":94188,"value":94189,"nodeType":864},{},[],"For instance, integrations with SaaS apps that are known and sanctioned can be very useful, especially with those apps that are identity providers, like Microsoft Azure/365 and Google Workspace. Lots of SaaS apps let users login with another SaaS app, which is called social login or sometimes single sign-on (SSO). When a user does “login using Google” on Salesforce using their corporate Google account, they are actually integrating (in a very limited way) Salesforce with Google Workspace. If you have application-level access (normally by calling the APIs) to known SaaS apps, you can discover these social logins (among other) integrations with other SaaS apps. These SaaS-to-SaaS links then become very useful as a discovery mechanism.",{"data":94191,"content":94192,"nodeType":860},{},[94193],{"data":94194,"marks":94195,"value":94196,"nodeType":864},{},[],"Something else to keep in mind, application-level access to known SaaS can also be incredibly useful for security beyond simple SaaS discovery. You could check authentication controls, like which users don’t have MFA enabled, sharing settings (perhaps the SaaS allows you to share documents publicly), unusual login events, other anomalous behavior, and so on. ",{"data":94198,"content":94199,"nodeType":1009},{},[94200],{"data":94201,"marks":94202,"value":94203,"nodeType":864},{},[],"Browser-level  ",{"data":94205,"content":94206,"nodeType":860},{},[94207],{"data":94208,"marks":94209,"value":94211,"nodeType":864},{},[94210],{"type":2246},"Summary: Browser data is as good as you can get for SaaS discovery, but with the downside that you must build and deploy a browser extension to get at it.",{"data":94213,"content":94214,"nodeType":860},{},[94215],{"data":94216,"marks":94217,"value":94218,"nodeType":864},{},[],"What if I told you, you could get application level usage-data beyond what events the applications expose through their APIs without needing to know about the app first or fighting network encryption? The other methods in this guide allow you to get at the data using normal log processing techniques, SIEM queries, or even hacky scripts that call APIs, but there’s one reasonable option for SaaS discovery.",{"data":94220,"content":94221,"nodeType":860},{},[94222],{"data":94223,"marks":94224,"value":94225,"nodeType":864},{},[],"The only real viable way to get at this SaaS usage data is through a browser extension. The big hurdle with this approach is that browser extensions require you to develop an extension and a backend where it can send data…AND you need to deploy that extension to all employees. ",{"data":94227,"content":94228,"nodeType":860},{},[94229],{"data":94230,"marks":94231,"value":94232,"nodeType":864},{},[],"Deploying that browser extension might be as simple as setting the extension to default install itself in all managed browsers - that’s possible if you’re using Google Workspace. In other environments, it may be a bit more of a challenge. Fortunately, browser extensions don’t have the complexity of normal endpoint agents. They don’t have runtime dependencies, aren’t platform dependent, don’t need admin permissions to install, have automatic update mechanisms built-in, and don’t affect performance. At the end of the day, they’re just a special piece of JavaScript running in the browser.",{"data":94234,"content":94235,"nodeType":860},{},[94236,94240,94245,94249,94257],{"data":94237,"marks":94238,"value":94239,"nodeType":864},{},[],"If you ",{"data":94241,"marks":94242,"value":94244,"nodeType":864},{},[94243],{"type":899},"are",{"data":94246,"marks":94247,"value":94248,"nodeType":864},{},[]," able to get access to the data in the browser (spoiler alert: we provide an easy - and free - out-of-the-box ",{"data":94250,"content":94252,"nodeType":883},{"uri":94251},"/features/saas-discovery/",[94253],{"data":94254,"marks":94255,"value":94256,"nodeType":864},{},[],"browser extension for SaaS discovery",{"data":94258,"marks":94259,"value":94260,"nodeType":864},{},[],"), there is almost limitless scope to what you can do with this data. You can observe not only access to SaaS websites, you can also see:",{"data":94262,"content":94263,"nodeType":941},{},[94264,94274,94284,94294,94304,94314],{"data":94265,"content":94266,"nodeType":945},{},[94267],{"data":94268,"content":94269,"nodeType":860},{},[94270],{"data":94271,"marks":94272,"value":94273,"nodeType":864},{},[],"the user login,",{"data":94275,"content":94276,"nodeType":945},{},[94277],{"data":94278,"content":94279,"nodeType":860},{},[94280],{"data":94281,"marks":94282,"value":94283,"nodeType":864},{},[],"whether that login was successful,",{"data":94285,"content":94286,"nodeType":945},{},[94287],{"data":94288,"content":94289,"nodeType":860},{},[94290],{"data":94291,"marks":94292,"value":94293,"nodeType":864},{},[],"whether they used MFA to login, ",{"data":94295,"content":94296,"nodeType":945},{},[94297],{"data":94298,"content":94299,"nodeType":860},{},[94300],{"data":94301,"marks":94302,"value":94303,"nodeType":864},{},[],"which email they used to login, ",{"data":94305,"content":94306,"nodeType":945},{},[94307],{"data":94308,"content":94309,"nodeType":860},{},[94310],{"data":94311,"marks":94312,"value":94313,"nodeType":864},{},[],"whether they are the owner/administrator of the SaaS app tenant, and ",{"data":94315,"content":94316,"nodeType":945},{},[94317],{"data":94318,"content":94319,"nodeType":860},{},[94320],{"data":94321,"marks":94322,"value":94323,"nodeType":864},{},[],"all their behavior and settings in the app. ",{"data":94325,"content":94326,"nodeType":860},{},[94327],{"data":94328,"marks":94329,"value":94330,"nodeType":864},{},[],"Best of all, there is no need to stream all this data to a single collection point where it becomes a privacy nightmare. By writing rules in the extension to look for specific issues, you can flag only security relevant events, redacted or anonymized as far as makes sense. You can even limit the scope to only monitor the app use when the employee logs into the SaaS app using their work account to further avoid employee privacy concerns. ",{"data":94332,"content":94333,"nodeType":860},{},[94334],{"data":94335,"marks":94336,"value":94337,"nodeType":864},{},[],"There’s a quick and easy solution to get the best out of the application and browser data approaches we’ve written about in the last two sections - and that’s with our free tool.",{"data":94339,"content":94340,"nodeType":1009},{},[94341],{"data":94342,"marks":94343,"value":94344,"nodeType":864},{},[],"How can Push help?",{"data":94346,"content":94347,"nodeType":860},{},[94348,94352,94357],{"data":94349,"marks":94350,"value":94351,"nodeType":864},{},[],"We found that the most comprehensive approach is to collect data from ",{"data":94353,"marks":94354,"value":94356,"nodeType":864},{},[94355],{"type":2246},"both ",{"data":94358,"marks":94359,"value":94360,"nodeType":864},{},[],"the application and browser level to give you full visibility and actionable security information. With our browser extension, we get full breadth of coverage so you can discover all SaaS usage and with our APIs, you get the depth of coverage you need to understand how employees are using SaaS and if they’re doing so securely. Our combined approach captures SaaS logins and adoption, in real-time, and provides the best visibility and context for security teams. ",{"data":94362,"content":94363,"nodeType":1312},{},[94364],{"data":94365,"marks":94366,"value":94367,"nodeType":864},{},[],"Fixing SaaS security issues automatically by partnering with employees  ",{"data":94369,"content":94370,"nodeType":860},{},[94371,94375,94380],{"data":94372,"marks":94373,"value":94374,"nodeType":864},{},[],"\nWhat we then do with that data is where the magic happens… we can automatically guide employees via ChatOps (Slack and Teams for now, more to come!) to improve SaaS security. Some of those messages will help us enrich our data by asking employees questions they’ll actually know the answers to (",{"data":94376,"marks":94377,"value":94379,"nodeType":864},{},[94378],{"type":2246},"“You logged into Slack from Mexico just now. Are you in Mexico?”",{"data":94381,"marks":94382,"value":94383,"nodeType":864},{},[],"), which provides you with a good snapshot of SaaS usage in your business and lets you make informed security decisions about SaaS use to better manage risks.",{"data":94385,"content":94386,"nodeType":860},{},[94387],{"data":94388,"marks":94389,"value":94390,"nodeType":864},{},[],"Employees can also make immediate improvements to your overall security posture. In case you’re curious about what that looks like, some of the prompts we push to employees are things like: ",{"data":94392,"content":94393,"nodeType":860},{},[94394,94399],{"data":94395,"marks":94396,"value":94398,"nodeType":864},{},[94397],{"type":2246},"“We noticed this SaaS app you’re using has access to all your emails, are you still using it?” Y/N.",{"data":94400,"marks":94401,"value":94402,"nodeType":864},{},[]," If not, they can click a button to remove it and you’ll get an immediate reduction of your attack surface. ",{"data":94404,"content":94405,"nodeType":860},{},[94406],{"data":94407,"marks":94408,"value":94409,"nodeType":864},{},[],"Or ",{"data":94411,"content":94412,"nodeType":860},{},[94413,94418,94422,94427],{"data":94414,"marks":94415,"value":94417,"nodeType":864},{},[94416],{"type":2246},"“It looks like you’re not using MFA for your account on this SaaS app. Can we get this set up really quickly?”",{"data":94419,"marks":94420,"value":94421,"nodeType":864},{},[]," or “",{"data":94423,"marks":94424,"value":94426,"nodeType":864},{},[94425],{"type":2246},"An app you installed called ‘Dropbox’ is not the official Dropbox app, click here to remove it and install the verified app instead.”",{"data":94428,"marks":94429,"value":7160,"nodeType":864},{},[],{"data":94431,"content":94435,"nodeType":996},{"target":94432},{"sys":94433},{"id":94434,"type":1001,"linkType":1002},"27MpbzErmDfAC3bA4dBibv",[],{"data":94437,"content":94438,"nodeType":860},{},[94439,94443,94450],{"data":94440,"marks":94441,"value":94442,"nodeType":864},{},[],"If you’re interested in learning more, check out how we can ",{"data":94444,"content":94445,"nodeType":883},{"uri":94251},[94446],{"data":94447,"marks":94448,"value":94449,"nodeType":864},{},[],"help you discover SaaS use and secure it",{"data":94451,"marks":94452,"value":2924,"nodeType":864},{},[],{"data":94454,"content":94455,"nodeType":860},{},[94456,94460,94468,94471,94478],{"data":94457,"marks":94458,"value":94459,"nodeType":864},{},[],"We’ll also be publishing a SaaS Discovery Evaluation Guide that will explore all the off-the-shelf tools you may consider and evaluate which one is the best fit for your needs as this really does depend on your tech stack. In that, we’ll share our experiences with those products and discuss what additional coverage and context they can provide, as well as where they fall short. Subscribe to our mailing list and follow us on ",{"data":94461,"content":94463,"nodeType":883},{"uri":94462},"https://twitter.com/PushSecurity",[94464],{"data":94465,"marks":94466,"value":94467,"nodeType":864},{},[],"Twitter @pushsecurity",{"data":94469,"marks":94470,"value":52968,"nodeType":864},{},[],{"data":94472,"content":94473,"nodeType":883},{"uri":92186},[94474],{"data":94475,"marks":94476,"value":94477,"nodeType":864},{},[],"LinkedIn",{"data":94479,"marks":94480,"value":94481,"nodeType":864},{},[]," to get a head’s up when that’s live so you can have a read.","How to roll-your-own SaaS discovery","We’ve compiled some methods for discovering SaaS. Lets explore each approach and learn new ways to discover unknown SaaS, capture SaaS use, and secure it.",[94485,94486,94487,94488,94489],"itassetdiscovery","saassecurity","saasdiscovery","sass","cloudfirst","2022-05-03T00:00:00.000+01:00","rolling-your-own-saas-discovery",{"items":94493},[94494,94496],{"sys":94495,"name":4904},{"id":4903},{"sys":94497,"name":297},{"id":2732},{"items":94499},[94500],{"fullName":52068,"firstName":52069,"jobTitle":52070,"profilePicture":94501},{"url":52072},"want-to-discover-the-full-extent-of-your-saas-sprawl-embrace-browser","blog/want-to-discover-the-full-extent-of-your-saas-sprawl-embrace-browser",{"json":94505},{"data":94506,"content":94507,"nodeType":856},{},[94508],{"data":94509,"content":94510,"nodeType":860},{},[94511],{"data":94512,"marks":94513,"value":94514,"nodeType":864},{},[],"Browser extensions are the most effective SaaS discovery tool because they can capture employee SaaS use and adoption in real time, as employees sign up. The browser also allows us to work with the user to guide them to use SaaS more securely right where they’re working - in the browser.","Browser extensions are the most effective SaaS discovery tool because they can capture employee SaaS use and adoption in real time, as employees sign up. ",{"id":94517,"publishedAt":94518},"19dT3oWX2H3EYtZIT3J5UO","2026-08-12T11:56:22.058Z",{"items":94520},[94521,94523],{"sys":94522,"name":4904},{"id":4903},{"sys":94524,"name":297},{"id":2732},{"items":94526},[94527,94529,94531,94533,94535,94537,94539,94541],{"sys":94528,"name":545,"slug":546,"tier":31},{"id":542},{"sys":94530,"name":297,"slug":298,"tier":31},{"id":294},{"sys":94532,"name":413,"slug":414,"tier":31},{"id":410},{"sys":94534,"name":589,"slug":590,"tier":45},{"id":586},{"sys":94536,"name":288,"slug":289,"tier":45},{"id":285},{"sys":94538,"name":457,"slug":458,"tier":45},{"id":454},{"sys":94540,"name":502,"slug":503,"tier":45},{"id":499},{"sys":94542,"name":306,"slug":307,"tier":45},{"id":303},"C7xc-6uxjSSDEQ178kmqFaasLDFSLL5URgdeqMDeS0w",1787040050804]