Authorization phishing: why attackers stopped targeting the login
Why attackers are pivoting to authorization attacks to get around authentication controls, how they work, and what security teams can do about them.
24 posts
Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.
Why attackers are pivoting to authorization attacks to get around authentication controls, how they work, and what security teams can do about them.
PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.
Most organizations know they have an AI security problem. A new SANS framework shows why so few are making progress - and what it actually takes to get unstuck.
Organizations spend billions annually on awareness training. Here's why browser-based technical controls can make the difference where training falls short.
This article explains the gap between what EDR sees and what happens inside the browser, and what it takes to close it.
Why the right browser security tool makes a separate AI visibility and control purchase unnecessary — and how to decide what you actually need.
AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.
What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works.
Here are 7 things we learned from our conversation with John Hammond on the "Why the browser is the new battleground" webinar.
Why "good enough" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.
Unpacking the latest research report from Omdia and what it means for the secure enterprise browser market.
Securing the browser vs. securing the organization via the browser — what's the difference?
How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.
How CISOs can use browser telemetry to support cyber risk quantification in areas where traditional data points fall short.
ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture.
We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.
Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums.
In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider.
Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.
Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026.
What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.
MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.
How App-Specific Password phishing is being used in the wild to bypass phishing-resistant authentication controls like passkeys.
It’s been almost exactly a year since we released our open source repository of SaaS-native attack techniques. Let's reflect on what’s changed.
The latest news, articles, and resources, sent to your inbox.