What we learned from 'Security Theater vs. Security That Works' with Matt Johansen
What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
64 posts
Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.
What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works.
Here are 7 things we learned from our conversation with Troy Hunt on the "Yes, you've been pwned" webinar.
What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.
Why "good enough" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.
Ranking the security problems you can solve in the browser by security value and browser fit.
Securing the browser vs. securing the organization via the browser — what's the difference?
ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture.
We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.
In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider.
Browser sync attacks result in business credentials being compromised via personal account and device breaches. Here's what you need to know.
Analysing the Stryker breach in line with recent changes to the Iran-nexus cyber playbook.
Big changes are being made to the Cyber Essentials scheme in 2026 that will change how companies must validate compliance. Here’s what you need to know.
Here’s how real-world attacks and our own R&D informed what we built for Push customers over the last year.
How Scattered Lapsus$ Hunters breaches demonstrate the evolution of attacker TTPs, shaping the future of cyber attacks.
NYCRR Part 500 is tightening its MFA and asset management requirements. Here's what the changes means for compliance.
MFA regulators, insurers, and policy-makers are getting tighter on their MFA requirements, fuelled by public cyber breaches.
What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.
How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.
We’re launching a new Detections capability, enabling security teams to more effectively investigate and triage alerts, and build more effective workflows.
Scattered Spider continues to dominate the headlines, with attacks on aviation and insurance companies worldwide.
The HIPAA Security Rule is getting a long-overdue facelift in 2025. Here's our quick overview of the key changes and how Push can help you to be compliant.
How the notorious Scattered Spider cyber criminal group are switching up their TTPs in 2025 to bypass MFA and breach cloud services via account takeover.
I’m thrilled to share that Push Security has raised our Series B funding. This is a huge moment for us and our customers in the fight against identity attacks.
HIBP creator and well-known security person Troy Hunt recently blogged about a phish he fell for. Here’s what it tells us about how phishing is evolving.
Detects when employees have weak, reused, or stolen passwords and guide them to update their password using in-browser messaging on any app.
Attackers are persistently targeting Jira accounts with stolen credentials. What can we learn from this trend?
We're back with part 2 of our research into OpenAI Operator to share our findings on how it can be used to automate identity attacks.
Credential stuffing attacks had a huge impact in 2024. But things could be dialled up even further with Computer-Using Agents like OpenAI Operator.
How app developers can go beyond Minimum Viable Secure Product (MVSP) to implement better identity protections and prevent identity-based attacks.
CUAs are a new type of AI agent that drives your browser/OS for you, enabling effortless automation of web tasks — including those performed by attackers.
Using Push to enforce MFA on third-party apps in the browser — even where MFA enforcement isn't supported by the app itself.
How in-the-wild attacks and our own R&D inspired what we built in 2024 to stop account takeover and reduce security risks across your workforce identities.
Reviewing public breaches that stemmed from identity attacks in 2024.
Using Push to automate password resets for your most critical identities when a password vulnerability is detected.
Push now compares user passwords with TI feeds to alert you when valid credentials are available on the clearweb and darkweb.
165 Snowflake customers were targeted by criminals using stolen credentials from infostealer infections, impacting hundreds of millions of people.
Account takeover on third-party apps is the flavor of the month for security researchers — what can we learn from it?
Why relying on post-compromise detection and response is no longer an option for modern browser-based attacks.
Using Push data to calculate how many vulnerable identities the average organization has, and how they lead to different methods of account takeover.
It’s been almost exactly a year since we released our open source repository of SaaS-native attack techniques. Let's reflect on what’s changed.
How Push stops attackers from using identity attack tools and techniques to compromise your employee user accounts.
What the rise in popularity of infostealers tells us about the cybercrime ecosystem and the shift toward identity attacks.
Breaking down common misconceptions about identity threats and controls like MFA, SSO, passkeys, password managers, and more.
How ghost logins can be used by cyber attackers for account takeover and persistence.
How to use Push to investigate and respond to a third-party data breach, which results in credentials being stolen and sold on criminal marketplaces.
Behind the scenes of our approach to designing and developing our latest feature, SSO password protection.
Use the Push browser agent’s unique vantage point to protect SSO credentials by blocking employees from entering their password into any other site.
Some highlights of what we've built over the last year on our mission of stopping identity attacks.
To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of recent breaches.
In this blog post we will cover what identities are, how we secure perimeters in general, and and how this maps to the identity space.
In this article, we define third-party risk management and explore additional approaches that can help manage third-party risk.
Employees are self-adopting SaaS apps and creating new cloud identities without IT approval. Learn how to manage which third parties have access to your data.
A new report on securing digital identities has some interesting takeaways to consider as we think about securing identities in the cloud. Here's our take.
Credential stuffing attacks are incredibly common, but they often go undetected. These attacks are often the entry point for attack. Learn how to prevent them.
Employees sign up to cloud apps on their own every day. Each time, they create a new account and a new identity on that app. How do you find and secure them?
In this article, we’re going to demonstrate how combining two of our favorite new SaaS attack techniques makes a simple, but very stealthy persistence approach.
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face.
Adapt your thinking to secure your data. Security needs to move from being the Department of No to the Department of Yes, Unless...
Attackers commonly target SaaS apps because they know employees sign up without running them past IT first. Learn how to adjust to secure your data.
Employees using a new work app used to be the final step of the software-onboarding process. Now it's the first. Security must adapt to secure business data.
Look at enabling SaaS from a broader understanding of the business and not just the impact to security
SaaS sprawl is not just a raw increase of apps in-use, but also due to employees self-adopting new apps. Orgs need sensible guardrails for employees.
We’re proud to announce our $15M Series A round, led by GV. Here's what we've learned about what our customers need since we launched in July 2022.
Password expirations are still commonly recommended, but most security pros agree that they lead to more predictable passwords. Here's what to do instead.
The latest news, articles, and resources, sent to your inbox.